5G private network user equipment-level traffic anomaly monitoring system, method, device and medium

Through the 5G private network user equipment-level traffic abnormality monitoring system, using the IP address and terminal information mapping relationship, it can quickly locate and analyze CPE abnormalities, solve the UE-level traffic monitoring problem, and improve the efficiency and accuracy of problem positioning.

CN120282265BActive Publication Date: 2025-08-12E SURFING IOT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510766016.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-08-12
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

In 5G private networks, it is difficult for enterprises to monitor UE-level traffic, resulting in long and time-consuming problem positioning, and it is impossible to quickly locate and resolve CPE abnormalities.

Method used

Through the 5G private network user equipment-level traffic abnormality monitoring system, the user plane function module is used to obtain system traffic data, and statistics are performed based on the IP address of the customer's pre-equipped device, combining the mapping relationship between the preset terminal information and the IP address, the device location is determined, and abnormality analysis is performed through signaling tracking and data tracking.

Benefits of technology

UE-level traffic monitoring and statistics can be realized, abnormal CPE and its problems can be quickly located, reducing the time and labor cost of problem location.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282265B_ABST
    Figure CN120282265B_ABST
Patent Text Reader

Abstract

The present application provides a 5G private network user device-level traffic anomaly monitoring system, method, device and medium, which relates to the field of communication technology. The method obtains system traffic data, performs statistics on the system traffic data according to the IP addresses of multiple different customer front-end devices, obtains the traffic statistics results of each customer front-end device, and judges whether the customer front-end device has an abnormality based on the traffic statistics results. If an abnormality occurs, the terminal information is obtained based on the mapping relationship between the IP address of the customer front-end device and the preset terminal information of the customer front-end device and the IP address, and the location information of the customer front-end device is determined. The terminal information includes location information and a user permanent identifier. According to the user permanent identifier, signaling tracking and data tracking are triggered to obtain the abnormal analysis results of the customer front-end device. The present application can realize traffic monitoring and statistics at the user device level, and then realize automatic and rapid positioning of abnormal customer front-end devices and their problems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a 5G private network user equipment-level traffic anomaly monitoring system, method, device and medium. Background Art

[0002] Currently, with a complete industrial supply chain, a diverse industry ecosystem, and a vast market, traditional enterprises are accelerating their transformation towards digitalization, networking, and intelligence. Against this backdrop, 5G private networks tailored for specific enterprises or organizations have emerged. However, due to the shared use of base stations, enterprises struggle to monitor user equipment (UE)-level traffic at the base station. Furthermore, given the diverse variety of CPE (Customer Premises Equipment) purchased by enterprises, monitoring and analyzing UE-level traffic for CPE connected to private networks has become crucial. Currently, when an enterprise CPE problem arises, the customer first discovers the issue, notifies the operator, and then arranges for operations and maintenance personnel to visit the enterprise's factory. This visit often requires approval. Once at the factory, they first confirm the actual operating conditions of the equipment, then verify the base station's signal coverage, and finally, the core network's health. This entire problem-locating process is lengthy and time-consuming, making the rapid identification and resolution of problematic CPEs a pressing challenge. Summary of the Invention

[0003] The main purpose of the embodiments of the present disclosure is to propose a 5G private network user equipment-level traffic anomaly monitoring system, method, device and medium, aiming to achieve UE-level traffic monitoring and statistics, and to accurately and quickly locate abnormal CPEs and their problems.

[0004] To achieve the above objectives, one aspect of an embodiment of the present application provides a 5G private network user device-level traffic anomaly monitoring system, the 5G private network user device-level traffic anomaly monitoring system comprising a user plane function module and a traffic monitoring module; the user plane function module comprises a collection unit and a statistics unit; the traffic monitoring module comprises an anomaly detection unit, a positioning unit, and a tracking unit;

[0005] The acquisition unit is used to obtain system flow data;

[0006] The statistical unit is used to collect statistics on the system traffic data according to the IP addresses of multiple different customer front-end devices to obtain traffic statistics results of each customer front-end device;

[0007] The abnormality detection unit is used to determine whether an abnormality occurs in the customer front-end device according to the traffic statistics result;

[0008] The positioning unit is configured to obtain the terminal information and determine the location information of the customer premises device according to the IP address of the customer premises device and a preset mapping relationship between the terminal information of the customer premises device and the IP address when an abnormality occurs to the customer premises device, wherein the terminal information includes the location information and a user permanent identifier;

[0009] The tracking unit is used to trigger signaling tracking and data tracking according to the user permanent identifier to obtain an abnormality analysis result of the customer premise equipment.

[0010] In some embodiments, the system further includes a control plane function module, the control plane function module including a unified data management module and a session management function module;

[0011] The session management function module is configured to send a second request signal to the unified data management module in response to a first request signal initiated by a customer premises device, wherein the first request signal is configured to initiate a conversation process;

[0012] The unified data management module is used to establish the mapping relationship between the terminal information and the IP address of the customer premise equipment in response to the second request signal.

[0013] In some embodiments, the unified data management module is further configured to send subscription data to the session management function module, wherein the subscription data includes the IP address;

[0014] The session management function module is further configured to send a data packet detection rule flow description protocol value to the user plane function module according to the subscription data, wherein the data packet detection rule flow description protocol value includes the IP address;

[0015] The statistical unit of the user plane function module is used to collect statistics on the system traffic data according to the data packet detection rule flow description protocol value to obtain traffic statistics results of each customer premise equipment.

[0016] In some embodiments, the statistical unit is specifically configured to:

[0017] According to the IP address, the system traffic data is counted to determine the user traffic data of each customer premise equipment;

[0018] dividing the user traffic data into a plurality of first traffic data with different transmission directions according to a transmission direction identifier of a flow description protocol value of the data packet detection rule;

[0019] According to the service type identifier of the flow description protocol value of the data packet detection rule, statistics of different service types are performed on the first flow data of each transmission direction to obtain second flow data of different service types in each transmission direction;

[0020] A traffic statistics result is obtained according to the first traffic data and the second traffic data.

[0021] In some embodiments, the anomaly detection unit is specifically configured to:

[0022] Time-dividing the second flow data based on the time tag of the second flow data to obtain third flow data;

[0023] Counting the packet loss data of the second traffic data of different service types respectively to obtain packet loss statistics results;

[0024] Determine multiple comparison time nodes according to the preset traffic data comparison cycle;

[0025] Comparing the third flow data before and after the comparison time node to obtain a comparison result;

[0026] Whether an abnormality occurs in the customer premises equipment is determined based on the third traffic data, the packet loss statistics result and the comparison result.

[0027] In some embodiments, the positioning unit is specifically configured to send the IP address of the customer premises device to the unified data management module, so that the unified data management module sends the terminal information to the traffic monitoring module according to the mapping relationship; and obtain the location information according to the terminal information;

[0028] The tracking unit is specifically used to send tracking instructions to the control plane function module and the user plane function module respectively, so that the control plane function module performs signaling tracking according to the user permanent identifier, and the user plane function module performs data tracking according to the user permanent identifier, to obtain the abnormality analysis result, wherein the tracking instruction includes the user permanent identifier.

[0029] In some embodiments, the system further comprises a storage output module, wherein the storage output module comprises a display unit and an alarm unit;

[0030] The display unit is used to store the user traffic data of all customer front-end devices in a database to obtain a historical traffic database; in response to the traffic display instruction, the user traffic data of each user in the historical traffic database is displayed through a visual interface;

[0031] The alarm unit is used to generate an alarm message when an abnormality occurs in the customer front-end device; and display the alarm message and the abnormality analysis result on a visual interface.

[0032] On the other hand, an embodiment of the present invention provides a method for monitoring abnormal traffic at the user device level in a 5G private network, comprising the following steps:

[0033] Get system traffic data;

[0034] The system traffic data is counted according to the IP addresses of a plurality of different customer front-end devices to obtain traffic statistics results of each customer front-end device;

[0035] Determine whether an abnormality occurs in the customer front-end device according to the traffic statistics result;

[0036] When an abnormality occurs in the customer premises device, the terminal information is obtained according to the IP address of the customer premises device and a preset mapping relationship between the terminal information of the customer premises device and the IP address, and the location information of the customer premises device is determined, wherein the terminal information includes the location information and a user permanent identifier;

[0037] According to the user permanent identifier of the terminal information, signaling tracking and data tracking are triggered to obtain an abnormality analysis result of the customer front-end device.

[0038] In another aspect, an embodiment of the present invention provides an electronic device, including:

[0039] at least one processor;

[0040] at least one memory for storing at least one program;

[0041] When the at least one program is executed by the at least one processor, the at least one processor implements the 5G private network user device-level traffic anomaly monitoring method as described in the previous embodiment.

[0042] On the other hand, an embodiment of the present invention also provides a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the 5G private network user device-level traffic anomaly monitoring method as described in the previous embodiment.

[0043] The above technical solution of the present invention has at least one of the following advantages or beneficial effects:

[0044] The present application proposes a 5G private network user device-level traffic anomaly monitoring system, method, device and medium, which obtains traffic data through a user plane function module, and counts the traffic data according to the IP addresses of multiple different customer front-end devices to obtain traffic statistics results for each different customer front-end device, and analyzes the traffic statistics results through a traffic monitoring module to determine whether an abnormality occurs in the customer front-end device. When an abnormality occurs in the customer front-end device of the 5G private network user device-level traffic anomaly monitoring, the 5G private network user device-level traffic anomaly monitoring terminal information is obtained based on the mapping relationship between the IP address of the customer front-end device of the 5G private network user device-level traffic anomaly monitoring and the preset customer front-end device terminal information and the 5G private network user device-level traffic anomaly monitoring IP address, and the location information of the customer front-end device of the 5G private network user device-level traffic anomaly monitoring is determined, wherein the 5G private network user device-level traffic anomaly monitoring terminal information includes the 5G private network user device-level traffic anomaly monitoring location information and the user permanent identifier, and then based on the user permanent identifier, signaling tracking and data tracking are triggered to obtain the abnormality analysis result of the customer front-end device. This application can implement UE-level traffic monitoring and statistics based on IP addresses. When a CPE anomaly is detected, the abnormal CPE is determined by the IP address of the traffic statistics result, thereby determining the location information of the abnormal CPE, and then triggering signaling tracking and data tracking to obtain the anomaly analysis results. The anomaly analysis results can determine the cause of the abnormal CPE anomaly, and accurately and quickly locate the abnormal CPE and its problems, so that back-end personnel no longer need to wait for the problem to recur. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 This is a flow chart of a method for monitoring abnormal traffic at the user device level in a 5G private network provided in an embodiment of the present application;

[0046] Figure 2 This is a structural diagram of a 5G private network user device-level traffic anomaly monitoring system provided in an embodiment of the present application;

[0047] Figure 3 This is a schematic diagram of the process of establishing a mapping relationship in the 5G private network user device-level traffic anomaly monitoring system provided in an embodiment of the present application;

[0048] Figure 4 This is a schematic diagram of the IP address sending process of the 5G private network user device-level traffic anomaly monitoring system provided in an embodiment of the present application;

[0049] Figure 5 This is a schematic diagram of the storage output module structure provided by an embodiment of the present application;

[0050] Figure 6 This is a schematic diagram of the data interaction process between the terminal and the server provided in an embodiment of the present application;

[0051] Figure 7 This is a schematic diagram of the terminal-to-terminal data interaction process provided by an embodiment of the present application;

[0052] Figure 8 This is a schematic diagram of the overall architecture of the 5G private network user device-level traffic anomaly monitoring system provided in an embodiment of the present application;

[0053] Figure 9 This is a schematic diagram of the complete operation process of the 5G private network user device-level traffic anomaly monitoring system provided by an embodiment of the present application;

[0054] Figure 10 This is a schematic diagram of the hardware structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0055] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0056] It should be noted that although the device schematics illustrate functional module divisions and the flowcharts illustrate logical sequences, in certain circumstances, the steps shown or described may be performed in a sequence that differs from the module divisions in the device or the sequence in the flowcharts. The terms "first," "second," and so on, in the specification, claims, and drawings, are used to distinguish similar items and are not necessarily used to describe a specific sequence or precedence.

[0057] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.

[0058] First, let’s analyze some of the terms used in this application:

[0059] 5G Core Network (5GC): refers to the core network of the fifth-generation mobile communication system. It is a new mobile network architecture that provides faster, more secure, and more reliable mobile communication services. The main feature of 5GC is its distributed architecture, which offers high scalability, reliability, and security. It can support a wider range of application services to meet the needs of diverse users. The 5GC network structure consists of a control layer and a data layer, with the control layer comprising a control plane and a user plane. 5GC applications mainly include smart homes, connected vehicles, the Internet of Things, smart manufacturing, and smart healthcare. It can provide more efficient, secure, and reliable mobile communication services, achieve intelligent, networked, data-driven, and service-oriented development, and promote the development and application of mobile communication technology.

[0060] Customer Premises Equipment (CPE): This is network access equipment deployed at the user's premises (such as a home, business, or factory). It serves as the "border gateway" between the user's internal network and the carrier's wide area network (WAN). It converts external network signals (such as fiber optic and 5G wireless) into locally available Ethernet or Wi-Fi services. Its core functions include physical layer signal conversion (optical to electrical), user authentication, routing and switching, quality of service management, and security protection (firewalls and traffic filtering).

[0061] The 5G private network user equipment-level traffic anomaly monitoring system of the embodiment of the present application can be applied to the 5G core network, wherein the user plane function module in the system is applied to the user plane function network element (User Plane Function, UPF) of the 5G core network, the session management function module is applied to the session management function network element (Session Management Function, SMF) of the 5G core network, the unified data management module is applied to the unified data management function network element (Unified Data Management, UDM) of the 5G core network, and the traffic monitoring module is applied to the OAM network element (Operation Administration and Maintenance, operation maintenance management).

[0062] Please refer to Figure 2 The 5G private network user equipment-level traffic anomaly monitoring system of the embodiment of the present application includes a user plane function module and a traffic monitoring module; the user plane function module includes a collection unit and a statistics unit; the traffic monitoring module includes an anomaly detection unit, a positioning unit and a tracking unit;

[0063] The acquisition unit is used to obtain system flow data;

[0064] The statistical unit is used to collect statistics on system traffic data based on the IP addresses of multiple different customer front-end devices to obtain traffic statistics results of each customer front-end device;

[0065] The anomaly detection unit is used to determine whether an anomaly occurs in the customer's front-end equipment based on traffic statistics results;

[0066] The positioning unit is used to obtain terminal information and determine the location information of the customer premise equipment according to the IP address of the customer premise equipment and the preset mapping relationship between the terminal information of the customer premise equipment and the IP address when an abnormality occurs in the customer premise equipment, wherein the terminal information includes the location information and the user permanent identifier;

[0067] The tracking unit is used to trigger signaling tracking and data tracking based on the user's permanent identifier to obtain abnormal analysis results of the customer's front-end equipment.

[0068] For details, please refer to Figure 2 ,The User Plane Function (UPF) module includes a collection unit and a statistics unit, ,and the traffic monitoring module is OAM (Operation Administration and Maintenance), which includes an anomaly detection unit, a positioning unit, and a tracking unit. The system first uses the collection unit to collect system traffic data on the UPF side. The system traffic data includes traffic data from multiple user premises equipment (CPEs). The statistics unit counts the system traffic data based on the IP address to determine the traffic statistics results for each CPE. The UPF periodically reports the traffic statistics results for each CPE to the OAM. The anomaly detection unit analyzes the traffic statistics results. Since the traffic statistics include the IP address, by determining whether there is an anomaly in the traffic statistics, it can be determined whether an anomaly has occurred in the CPE. When an anomaly occurs in the CPE, the positioning unit obtains terminal information based on the IP address of the CPE and the mapping relationship between the preset terminal information and IP address of the CPE. Since the terminal information includes location information and a Subscription Permanent Identifier (SUPI), the location information of the abnormal CPE can be determined. Furthermore, the tracking unit can perform signaling tracking and data tracking based on the SUPI to obtain anomaly analysis results for the abnormal CPE and quickly locate the abnormal CPE.

[0069] In some embodiments, the system further includes a control plane function module, the control plane function module including a unified data management module and a session management function module;

[0070] The session management function module is used to send a second request signal to the unified data management module in response to a first request signal initiated by the customer premise equipment, wherein the first request signal is used to initiate a dialogue process;

[0071] The unified data management module is used to establish a mapping relationship between the terminal information and the IP address of the customer premise equipment in response to the second request signal.

[0072] For details, please refer to Figure 3 Before collecting system traffic data, the customer premises equipment (CPE) initiates a first request signal to the Session Management Function (SMF) module to establish a session flow. After receiving the first request signal, the SMF module sends a second request signal to the Unified Data Management (UDM) module. Upon receiving the second request signal, the UDM module establishes a mapping between the CPE's terminal information and IP address, effectively binding the CPE's terminal information and IP address. For example, in an enterprise's 5G private network, each CPE segment is planned based on the internal enterprise plan. Within the corresponding segment, the 5G private network assigns a fixed IP address to each SUPI number. For better visualization, the CPE's actual location is also recorded. In the event of an anomaly, the system can quickly locate the corresponding SUPI number, the device, and its location based on the IP address.

[0073] In some embodiments, the unified data management module is further configured to send subscription data to the session management function module, wherein the subscription data includes an IP address;

[0074] The session management function module is further configured to send a data packet detection rule flow description protocol value to the user plane function module according to the contract data, wherein the data packet detection rule flow description protocol value includes an IP address;

[0075] The statistics unit of the user plane function module is used to collect statistics on system traffic data according to the data packet detection rule flow description protocol value to obtain the traffic statistics results of each customer front-end device.

[0076] For details, please refer to Figure 4After the unified data management (UDM) module establishes the mapping relationship between the terminal information and the IP address of the customer's front-end device, the unified data management module will send the contract data to the session management function (SMF) module. The contract data includes the static IP address. When the session management function module obtains the contract data, it finds that there is already a static IP address. The SMF no longer randomly assigns an IP address. The SMF directly sends the packet detection rule (PDR) flow description protocol value carrying the IP address to the user plane function (UPF) module. Subsequently, the UPF can perform message matching and traffic statistics based on the PDR flow description protocol value. Since the PDR flow description protocol value contains the IP address, the UPF can perform statistics on the traffic data of each customer's front-end device in the system traffic data and obtain the traffic statistics results.

[0077] In some embodiments, the statistics unit is specifically configured to:

[0078] Collect statistics on system traffic data based on IP addresses to determine user traffic data for each customer's front-end device;

[0079] dividing user traffic data into a plurality of first traffic data with different transmission directions according to a transmission direction identifier of a data packet detection rule flow description protocol value;

[0080] According to the service type identifier of the data packet detection rule flow description protocol value, different service type statistics are performed on the first flow data of each transmission direction to obtain second flow data of different service types in each transmission direction;

[0081] A traffic statistics result is obtained according to the first traffic data and the second traffic data.

[0082] Specifically, traffic statistics are collected for TCP, UDP, ICMP, and other types of traffic on the N3 and N6 upstream and downstream interfaces on the core network UPF side based on IP. The N3 interface is the interface between the (R)AN (access network) and the UPF in the 5G core network architecture, and the N6 interface is used to connect the UPF to the external data network (DN). First, the statistical unit obtains the user traffic data of each customer front-end device based on the IP address statistics of the PDR flow description protocol value, and then further counts the user traffic data. According to the transmission direction identifier of the PDR flow description protocol value sent by the SMF, the user traffic data is divided into multiple first traffic data with different transmission directions. The multiple first traffic data include N3 uplink data, N3 downlink data, N6 uplink data and N6 downlink data. Then, according to the service type identifier of the PDR flow description protocol value, the traffic data under different service types of each first traffic data are counted separately. The service types include TCP, UDP, and ICMP. The second traffic data is obtained. The second traffic data includes TCP traffic data, UDP traffic data and ICMP traffic data in all transmission directions. According to the first traffic data and the second traffic data, the traffic statistics result is obtained. Exemplarily, the format of the traffic statistics result is specifically shown in Table 1.

[0083] Table 1

[0084]

[0085] In some embodiments, the current scenario used in the enterprise 5G private network is mainly that the terminal needs to access the enterprise intranet server, and the common services are uploading and downloading on the corresponding server, such as Figure 6 The second is the data exchange between terminals, such as Figure 7 The diagram shows the direction of messages sent between terminals for mutual access.

[0086] Based on the enterprise's actual service scenarios (TCP, UDP, ICMP, etc.), the SMF is controlled to issue the corresponding PDR flow description protocol value, such as "permit out 6 from PDN to UE." "From PDN to UE" indicates the data transmission direction (transmission direction identifier) is from the external data network (PDN) to the user equipment (UE), and "6" represents TCP service (service type identifier). If multiple services are involved, multiple flow descriptions can be issued. The UPF performs traffic counting while performing PDR matching.

[0087] UPF can report UE-level traffic in the format of Table 1. The reporting period of UPF to OAM can be set by adding a configuration, such as reporting once every 5 minutes. The message transmission between UPF and OAM can use grpc (Google Remote Procedure Call). grpc is a high-performance, cross-language remote procedure call (RPC) framework based on the HTTPQ / 2 transmission protocol and uses Protocol Buffers (Protobuf) as the serialization protocol. It is suitable for microservice architecture, high-concurrency systems and cross-language call scenarios.

[0088] In some embodiments, the anomaly detection unit is specifically configured to:

[0089] Time-dividing the second flow data based on the time tag of the second flow data to obtain third flow data;

[0090] Counting the packet loss data of the second traffic data of different service types respectively to obtain packet loss statistical results;

[0091] Determine multiple comparison time nodes according to the preset traffic data comparison cycle;

[0092] Comparing the third flow data before and after the comparison time node to obtain a comparison result;

[0093] Based on the third-party traffic data, packet loss statistics, and comparison results, determine whether the customer's front-end equipment has any abnormalities.

[0094] Specifically, the traffic monitoring module (OAM) will periodically receive traffic statistics results reported by the UPF. As shown in Table 1, the anomaly detection unit of the traffic monitoring module will separately count the packet loss data of multiple second traffic data in the traffic statistics results, that is, count the number of packet losses for TCP traffic data, UDP traffic data and ICMP traffic data in all transmission directions of the second traffic data to obtain packet loss statistics results.

[0095] The anomaly detection unit divides the second traffic data into time segments based on the time tag of the second traffic data to obtain third traffic data. All traffic data transmissions will have time tags. The time tags can represent the transmission time nodes of a certain type of traffic data. The third traffic data can represent TCP traffic data, UDP traffic data and ICMP traffic data on a certain time scale, and can also represent the changes in the third traffic data at different times. Furthermore, according to a preset traffic data comparison period, multiple comparison time nodes are determined. The traffic data comparison period is set by user input. The traffic data comparison period can be set to 5 minutes, that is, each comparison time node is 5 minutes apart. Since the third traffic data is divided based on time, the comparison time nodes are determined. The third traffic data before and after the corresponding time node can be obtained. The third traffic data before the time node and the third traffic data after the time node are compared to obtain a comparison result. By combining the changes in all third traffic data at different times, the packet loss statistics and the comparison results, it can be determined whether the CPE has an abnormality through user traffic data. For example, traffic data anomalies are mainly divided into three categories. The first category is flow interruption, which is easier to monitor, that is, detecting that the CPE has no upstream and downstream traffic; the second category is excessive packet loss in the UPF; the third category is that enterprise production data generally presents a certain pattern. If the data volume on a certain day deviates from the normal item by a certain threshold, it means that the traffic is abnormal. This requires setting a reasonable threshold. For example, 10 o'clock every day is the peak production period and the data volume is about 1G. The average value at 10 o'clock in the past 30 days is 1G. When the traffic at 10 o'clock on the 31st day exceeds the average by +-50%, it can be judged as abnormal traffic data and an alarm is reported.

[0096] In some embodiments, the positioning unit is specifically configured to send the IP address of the customer premises device to the unified data management module, so that the unified data management module sends the terminal information to the traffic monitoring module according to the mapping relationship; and obtain the location information according to the terminal information;

[0097] The tracking unit is specifically used to send tracking instructions to the control plane function module and the user plane function module respectively, so that the control plane function module performs signaling tracking according to the user permanent identifier, and the user plane function module performs data tracking according to the user permanent identifier, to obtain an abnormality analysis result, wherein the tracking instruction includes the user permanent identifier.

[0098] Specifically, the anomaly detection unit identifies an abnormal customer premises equipment (CPE) based on traffic statistics. The positioning unit sends the IP address of the abnormal CPE to the unified data management (UDM) module. The UDM retrieves the mapping relationship for the IP address in the mapping relationship table based on the received IP address, thereby determining the terminal information mapped to the IP address. The UDM then sends the terminal information to the traffic monitoring module, and the positioning unit determines the location of the abnormal CPE based on the terminal information. The tracking unit sends a signaling tracking instruction to the control plane function module and a data tracking instruction to the user plane function module based on the user permanent identifier (SUPI) in the terminal information. Since the tracking instruction includes the user permanent identifier, the control plane function module is triggered to perform signaling tracking based on the SUPI, and the user plane function module is triggered to perform data tracking based on the SUPI, thereby obtaining the anomaly analysis results.

[0099] In some embodiments, the system further comprises a storage output module, the storage output module comprising a display unit and an alarm unit;

[0100] The display unit is used to store the user traffic data of all customer front-end devices into a database to obtain a historical traffic database; in response to the traffic display instruction, the traffic data of each user in the historical traffic database is displayed through a visual interface;

[0101] The alarm unit is used to generate alarm information when an abnormality occurs in the customer's front-end equipment; the alarm information and abnormality analysis results are displayed on a visual interface.

[0102] For details, please refer to Figure 5The storage and output module includes a display unit and an alarm unit. The main function of the storage and output module is to record all data into a database. Based on this database, the traffic of each terminal can be dynamically displayed. The display unit can store the user traffic data obtained by the statistical unit into the database to build a historical traffic database. When the user enters the traffic display instruction, the traffic data of each user in the historical traffic database is displayed through the visual interface, realizing the display of CE-level traffic data. When the abnormality detection unit detects an abnormal CPE, the alarm unit automatically generates a corresponding alarm signal and displays the alarm signal and abnormality analysis results on the visual interface. The alarm signal can be an interface reminder that can promptly remind back-end maintenance personnel of the occurrence of abnormal conditions. The abnormality analysis result is a brief analysis conclusion of the abnormal CPE, which can enable back-end maintenance personnel to quickly determine the location information of the abnormal CPE, the cause of the abnormality of the abnormal CPE, and the method of repairing the abnormality. For example, the abnormal analysis results may be due to CPE disconnection and interruption of flow, UPF packet loss is due to the packet loss indicated by SMF when SMF cannot page CPE, the alarm caused by excessive data volume is due to too many devices hanging under CPE resulting in a large increase in load, and it is possible to consider optimizing the network structure to share the hanging devices, etc.

[0103] Please refer to Figure 1 , Figure 1 This is an optional flowchart of a method for monitoring 5G private network user device-level traffic anomaly provided by some embodiments of the present application. A method for monitoring 5G private network user device-level traffic anomaly according to an embodiment of the present invention includes but is not limited to steps S100 to S500:

[0104] Step S100, obtaining system flow data;

[0105] Step S200, counting system traffic data according to the IP addresses of multiple different customer front-end devices to obtain traffic statistics results of each customer front-end device;

[0106] Step S300: Determine whether the customer premise equipment is abnormal based on the traffic statistics result;

[0107] Step S400: When an abnormality occurs in the customer premises device, terminal information is obtained based on the IP address of the customer premises device and a preset mapping relationship between the terminal information of the customer premises device and the IP address, and the location information of the customer premises device is determined, wherein the terminal information includes the location information and the user permanent identifier;

[0108] Step S500: triggering signaling tracking and data tracking according to the user permanent identifier of the terminal information to obtain abnormality analysis results of the customer premise equipment.

[0109] The 5G private network user device-level traffic anomaly monitoring method provided in the embodiments of the present application can be applied to a terminal, can be applied to a server side, and can also be software running in a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or as a server cluster or distributed system composed of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements a digital management method for indoor items, etc., but is not limited to the above forms.

[0110] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.

[0111] In some embodiments, please refer to Figure 8 , Figure 8This is a schematic diagram of the overall architecture of the 5G private network traffic monitoring system. The system includes a message forwarding module, a protocol stack parsing module, a traffic detection module and a storage output module. Among them, the message forwarding module and the protocol stack parsing module belong to the UPF. The message forwarding module distinguishes the N3 uplink and downlink data and the N6 uplink and downlink data of the user traffic data through the message forwarding thread, and sends the N3 and N6 uplink and downlink data to the protocol stack parsing module. The protocol stack parsing module performs source address and protocol stack parsing on the N3 and N6 uplink and downlink data, thereby distinguishing the source addresses and performing protocol stack statistics on the N3 and N6 uplink and downlink data. Furthermore, the traffic monitoring module performs TCP / UDP / ICMP traffic statistics, periodic comparative analysis and packet loss statistics on the N3 and N6 uplink and downlink data respectively, identifies anomalies based on TCP / UDP / ICMP traffic statistics, periodic comparative analysis and packet loss statistics, thereby reporting the anomalies and triggering signaling and data tracking. The traffic monitoring module transmits all traffic data to the storage output module, which logs all traffic data and records all data in the database. Based on this database, the traffic of each terminal can be dynamically displayed, and an alarm can be output when an abnormality occurs.

[0112] In some embodiments, traffic statistics are collected for TCP, UDP, ICMP, and other types of traffic on the core network UPF side of N3 and N6, and the rate is calculated. This allows for rapid location of problematic CPEs (e.g., no traffic); identification of uneven CPE traffic load (e.g., excessive number of devices connected to the CPE), and optimization of existing enterprise networks. Big data analysis can be used to analyze historical data and predict future data based on a single CPE. When abnormal traffic is detected, network management is automatically notified. Signaling and data tracking is performed based on the device's SUPI number, ensuring timely protection at the fault site.

[0113] In some embodiments, in order to ensure the accuracy of UE-level traffic records, the relationship between the basic information of the CPE terminal (terminal type and actual location) and the IP address of the CPE is first established, which needs to be configured on the UDM. Secondly, based on the various flow descriptions issued by the SMF side, the UPF can use the format of Table 1 to report UE-level traffic; finally, the reported data is saved for further traffic data analysis. When OAM detects abnormal traffic reports, it synchronously triggers the signaling tracking and data tracking of each network element to save the fault site. For details, please refer to Figure 9 , Figure 9 This is the operation flow chart of the 5G private network abnormal traffic monitoring system.

[0114] First, the CPE device is bound to a fixed IP address.

[0115] Enterprise private networks are designed based on the CPE network segments within the enterprise. 5G private networks assign fixed IP addresses to each SUPI number within the corresponding segment. For better visualization, the actual location of the CPE is also recorded. If an anomaly occurs later, the corresponding SUPI number, the device, and its location can be quickly identified based on the IP address.

[0116] After the UE completes air interface registration, the UE (CPE) initiates a first request signal (pdu req) to the SMF to establish a session. In response, the SMF sends a second request signal (sdm-subscription) to the UDM. The UDM uses this second request signal to obtain the static IP address corresponding to the number and binds the IP address to the CPE's location information and SUPI. The UDM then returns the subscription data to the SMF. After receiving the subscription data, the SMF discovers that a static IP address already exists. Instead of randomly assigning an IP address, the SMF directly sends the PDR, including the UE's IP address, to the UPF in the N4 establish req. The UPF can then use the PDR for subsequent packet matching and traffic statistics. After receiving the PDR from the SMF, the UPF returns a response signal to the SMF. The SMF then sends a pdu rsp to the CPE. A pdu rsp is a response packet sent by one party to a create request (create pdu req) in a communication protocol.

[0117] Then, UE-level traffic statistics are periodically obtained.

[0118] Based on the enterprise's actual service scenarios (TCP, UDP, ICMP, etc.), the SMF issues the corresponding PDR flow description protocol value, such as "permit out 6 from PDN to UE," where "6" indicates TCP services. The PDR includes the IP address. For multiple services, multiple flow descriptions can be issued. The UPF performs traffic counting while matching PDRs. The UPF can configure the UE reporting period through a new configuration, with a default reporting interval of every 5 minutes. UPF and OAM message transmission uses GRPC.

[0119] Finally, the traffic data is further analyzed and abnormal traffic prediction and alarm are issued.

[0120] OAM records traffic data reported by the UPF for different categories, including TCP, UDP, and ICMP, based on time, to monitor traffic data for anomalies. If a UE traffic anomaly is detected, OAM sends the UE's IP address to the UDM. The UDM then returns the corresponding terminal information (supi and CPE location) to OAM. This terminal information then triggers signaling tracking on the control plane network elements and data tracking on the user plane network elements, allowing for timely storage of the fault site.

[0121] According to some embodiments of the present application, the embodiments of the present application have at least the following beneficial effects:

[0122] Achieve periodic traffic monitoring of all access devices at the UE level, which is intuitive and clear;

[0123] The historical traffic data is saved, and comparative analysis can be done before and after the data to optimize the system network;

[0124] When traffic anomalies are detected, an alarm is reported and signaling and data tracking are automatically collected, so that back-end personnel no longer need to wait for the problem to recur and can locate the problem more accurately.

[0125] The following combination Figure 10 The electronic device according to the embodiment of the present application is introduced in detail.

[0126] like Figure 10 , Figure 10 The hardware structure of an electronic device according to another embodiment is shown. The electronic device includes:

[0127] The processor 1100 may be implemented as a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present disclosure.

[0128] The memory 1200 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1200 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1200 and is called by the processor 1100 to execute the 5G private network user device-level traffic anomaly monitoring method of the embodiment of the present disclosure;

[0129] Input / output interface 1300, used for information input and output;

[0130] Communication interface 1400, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);

[0131] Bus 1500 , which transmits information between various components of the device (e.g., processor 1100 , memory 1200 , input / output interface 1300 , and communication interface 1400 );

[0132] The processor 1100 , the memory 1200 , the input / output interface 1300 , and the communication interface 1400 are communicatively connected to each other within the device via a bus 1500 .

[0133] An embodiment of the present disclosure also provides a storage medium, which is a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the above-mentioned 5G private network user device-level traffic anomaly monitoring method.

[0134] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device or other non-transient solid-state storage device. In some embodiments, the memory may include a memory remotely located relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0135] The embodiments described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0136] Those skilled in the art will understand that the technical solutions shown in the drawings do not constitute a limitation on the embodiments of the present disclosure, and may include more or fewer steps than shown in the drawings, or a combination of certain steps, or different steps.

[0137] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0138] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.

[0139] The terms "first," "second," "third," "fourth," and the like (if any) in the specification of the present application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in orders other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such process, method, product, or apparatus.

[0140] It should be understood that in this application, "at least one (item)" means one or more, and "more" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or plural.

[0141] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0142] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0143] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0144] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for enabling an electronic device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store programs, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks or optical disks.

[0145] The preferred embodiments of the present disclosure are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present disclosure. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present disclosure should be within the scope of the present disclosure.

Claims

1. A 5G private network user device-level traffic anomaly monitoring system, characterized by: The 5G private network user equipment-level traffic anomaly monitoring system includes a user plane function module and a traffic monitoring module; the user plane function module includes a collection unit and a statistics unit; the traffic monitoring module includes an anomaly detection unit, a positioning unit and a tracking unit; The acquisition unit is used to obtain system flow data; The statistical unit is used to collect statistics on the system traffic data according to the IP addresses of multiple different customer front-end devices to obtain traffic statistics results of each customer front-end device; The abnormality detection unit is used to determine whether an abnormality occurs in the customer front-end device according to the traffic statistics result; The positioning unit is configured to obtain the terminal information and determine the location information of the customer premises device according to the IP address of the customer premises device and a preset mapping relationship between the terminal information of the customer premises device and the IP address when an abnormality occurs to the customer premises device, wherein the terminal information includes the location information and a user permanent identifier; The tracking unit is used to trigger signaling tracking and data tracking according to the user permanent identifier to obtain an abnormality analysis result of the customer premise equipment; The system further includes a control plane function module, which includes a unified data management module and a session management function module; The session management function module is configured to send a second request signal to the unified data management module in response to a first request signal initiated by a customer premises device, wherein the first request signal is configured to initiate a conversation process; The unified data management module is used to establish the mapping relationship between the terminal information and the IP address of the customer premise equipment in response to the second request signal.

2. The 5G private network user device-level traffic anomaly monitoring system according to claim 1 is characterized in that: The unified data management module is further configured to send contract data to the session management function module, wherein the contract data includes the IP address; The session management function module is further configured to send a data packet detection rule flow description protocol value to the user plane function module according to the subscription data, wherein the data packet detection rule flow description protocol value includes the IP address; The statistical unit of the user plane function module is used to collect statistics on the system traffic data according to the data packet detection rule flow description protocol value to obtain traffic statistics results of each customer premise equipment.

3. The 5G private network user device-level traffic anomaly monitoring system according to claim 2 is characterized in that: The statistical unit is specifically used for: According to the IP address, the system traffic data is counted to determine the user traffic data of each customer premise equipment; dividing the user traffic data into a plurality of first traffic data with different transmission directions according to a transmission direction identifier of a flow description protocol value of the data packet detection rule; According to the service type identifier of the flow description protocol value of the data packet detection rule, statistics of different service types are performed on the first flow data of each transmission direction to obtain second flow data of different service types in each transmission direction; A traffic statistics result is obtained according to the first traffic data and the second traffic data.

4. The 5G private network user device-level traffic anomaly monitoring system according to claim 3 is characterized in that: The anomaly detection unit is specifically used for: Time-dividing the second flow data based on the time tag of the second flow data to obtain third flow data; Counting the packet loss data of the second traffic data of different service types respectively to obtain packet loss statistics results; Determine multiple comparison time nodes according to the preset traffic data comparison cycle; Comparing the third flow data before and after the comparison time node to obtain a comparison result; Whether an abnormality occurs in the customer premises equipment is determined based on the third traffic data, the packet loss statistics result and the comparison result.

5. The 5G private network user equipment-level traffic anomaly monitoring system according to claim 1 is characterized in that: The positioning unit is specifically configured to send the IP address of the customer premises device to the unified data management module, so that the unified data management module sends the terminal information to the traffic monitoring module according to the mapping relationship; and obtain the location information according to the terminal information; The tracking unit is specifically used to send tracking instructions to the control plane function module and the user plane function module respectively, so that the control plane function module performs signaling tracking according to the user permanent identifier, and the user plane function module performs data tracking according to the user permanent identifier, to obtain the abnormality analysis result, wherein the tracking instruction includes the user permanent identifier.

6. The 5G private network user device-level traffic anomaly monitoring system according to claim 1 is characterized in that: The system further includes a storage output module, which includes a display unit and an alarm unit; The display unit is used to store the user traffic data of all customer front-end devices in a database to obtain a historical traffic database; in response to the traffic display instruction, the user traffic data of each user in the historical traffic database is displayed through a visual interface; The alarm unit is used to generate an alarm message when an abnormality occurs in the customer front-end device; and display the alarm message and the abnormality analysis result on a visual interface.

7. A method for monitoring abnormal traffic at the user device level in a 5G private network, characterized in that: The method is applied to the 5G private network user equipment-level traffic anomaly monitoring system according to any one of claims 1 to 6, and the method comprises the following steps: Get system traffic data; The system traffic data is counted according to the IP addresses of a plurality of different customer front-end devices to obtain traffic statistics results of each customer front-end device; Determine whether an abnormality occurs in the customer front-end device according to the traffic statistics result; When an abnormality occurs in the customer premises device, the terminal information is obtained according to the IP address of the customer premises device and a preset mapping relationship between the terminal information of the customer premises device and the IP address, and the location information of the customer premises device is determined, wherein the terminal information includes the location information and a user permanent identifier; triggering signaling tracking and data tracking based on the user permanent identifier of the terminal information to obtain abnormality analysis results of the customer premise equipment; The method further comprises: In response to a first request signal initiated by the customer premises device, sending a second request signal to the unified data management module, wherein the first request signal is used to initiate a dialogue process; In response to the second request signal, the mapping relationship between the terminal information of the customer premise equipment and the IP address is established.

8. An electronic device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the 5G private network user device-level traffic anomaly monitoring method as described in claim 7.

9. A computer-readable storage medium storing a program executable by a processor, characterized in that: When the program executable by the processor is executed by the processor, the 5G private network user device-level traffic anomaly monitoring method as described in claim 7 is implemented.

Citation Information

Patent Citations

  • Method for realizing 5G equipment CPE fault alarm real-time reporting based on SLA

    CN113573352A

  • Tracking system and method for monitoring and ensuring security of shipments

    US20190066042A1