Method and device for determining user traffic of target area, medium and product
By obtaining the mobile network signaling data of the LTE core network, generating a mapping table and filtering the target user traffic, the problem of high pressure on data processing of the LTE core network analysis system is solved, and the efficiency and accuracy of data processing are improved.
Patent Information
- Application Number
- CN202511013020.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-22
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-07-22
AI Technical Summary
At this stage, when the log retention system of the LTE core network connects to the traffic data of S11, S1-U, S58-C, and S58-U, the data processing pressure of the analysis system is too high, which increases the difficulty of analysis and affects the efficiency and accuracy of data processing.
By obtaining the mobile network signaling data of the target area, including TAC or ECI, a first mapping table is generated, and a second mapping table is generated based on the target information of the signaling traffic, the target user traffic is filtered out and forwarded to the target system, reducing the data processing pressure of the analysis system.
It realizes accurate screening and forwarding of user traffic in the target area, reduces the data processing pressure of the analysis system, and improves the efficiency and accuracy of data processing.
Smart Images

Figure CN120529337A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of LTE core network, and in particular to a method, device, medium and product for determining user traffic in a target area. Background Art
[0002] The main interfaces of the LTE (Long Term Evolution) core network are S11, S1-U, S58-C, and S58-U. S11 and S58-C are control plane interfaces, while S1-U and S58-U are user plane interfaces. Currently, the log retention system simultaneously receives traffic from S11, S1-U, S58-C, and S58-U, analyzes traffic from all users, and generates and stores logs. Simultaneously, this data is fed into subsequent analysis systems, resulting in excessive data volumes and increased analysis complexity.
[0003] How to determine the user traffic that matches a certain area in these traffic data and send it to the matching analysis system to reduce the data processing pressure of the analysis system and provide a basis for improving the efficiency and accuracy of data processing is a key issue in industry research. Summary of the Invention
[0004] The present invention provides a method, device, medium and product for determining user traffic in a target area, so as to determine user traffic matching the target area and send it to a matching analysis system, thereby reducing the data processing pressure of the analysis system and providing a basis for improving the efficiency and accuracy of data processing.
[0005] According to one aspect of the present invention, a target mobile network signaling data method is provided, the method comprising:
[0006] In response to a filter instruction for user traffic in a target area, obtaining at least one target mobile network signaling data matching the target area; wherein the target mobile network signaling data includes: a tracking area code TAC or a cell identifier ECI;
[0007] Acquire each signaling flow, determine target information of each signaling flow, and generate a first mapping table based on each target information;
[0008] The first mapping table is filtered based on the signaling data of each target mobile network to obtain a second mapping table; wherein the second mapping table stores the start time and end time of each user's access to the target base station;
[0009] User traffic is screened based on the second mapping table to obtain target user traffic, and the target user traffic is forwarded to a target system.
[0010] According to another aspect of the present invention, a target mobile network signaling data device is provided, the device comprising:
[0011] an acquisition module, configured to acquire, in response to a filter instruction for user traffic in a target area, at least one target mobile network signaling data matching the target area; wherein the target mobile network signaling data includes: a tracking area code TAC or a cell identifier ECI;
[0012] a first mapping table generating module, configured to obtain each signaling flow, determine target information of each signaling flow, and generate a first mapping table based on each target information;
[0013] A second mapping table generating module is configured to filter the first mapping table based on the target mobile network signaling data to obtain a second mapping table; wherein the second mapping table stores the start time and end time of each user's access to the target base station;
[0014] The user traffic screening module is configured to screen the user traffic based on the second mapping table to obtain target user traffic and forward the target user traffic to a target system.
[0015] According to another aspect of the present invention, an electronic device is provided, comprising:
[0016] at least one processor; and
[0017] a memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the target mobile network signaling data method according to any embodiment of the present invention.
[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the target mobile network signaling data method according to any embodiment of the present invention when executed.
[0020] According to another aspect of the present invention, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the target mobile network signaling data method according to any embodiment of the present invention is implemented.
[0021] The technical solution of an embodiment of the present invention obtains at least one target mobile network signaling data matching the target area by responding to a screening instruction of user traffic in a target area; wherein, the target mobile network signaling data includes: a tracking area code TAC or a cell identifier ECI; obtains each signaling traffic, determines the target information of each signaling traffic, and generates a first mapping table based on each target information; filters the first mapping table based on each target mobile network signaling data to obtain a second mapping table; wherein, the second mapping table stores the start time and end time of each user's access to the target base station; filters the user traffic based on the second mapping table to obtain the target user traffic, and forwards the target user traffic to the target system, so as to determine the user traffic matching the target area and send it to the matching analysis system, thereby reducing the data processing pressure of the analysis system and providing a basis for improving the efficiency and accuracy of data processing.
[0022] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 This is a flowchart of a target mobile network signaling data method provided according to the first embodiment of the present invention;
[0025] Figure 2 This is a schematic diagram of the relationship between a control tunnel, a default bearer, and a dedicated bearer provided according to the first embodiment of the present invention;
[0026] Figure 3 This is a flowchart of a target mobile network signaling data method provided according to the second embodiment of the present invention;
[0027] Figure 4 This is a schematic structural diagram of a target mobile network signaling data device provided according to a third embodiment of the present invention;
[0028] Figure 5 It is a structural diagram of an electronic device for implementing the target mobile network signaling data method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0031] Example 1
[0032] Figure 1 This is a flow chart of a target mobile network signaling data method provided according to the first embodiment of the present invention. This embodiment is applicable to the case of screening user traffic in the target area. The method can be executed by a target mobile network signaling data device. The target mobile network signaling data device can be implemented in the form of hardware and / or software. The target mobile network signaling data device can be configured in electronic devices such as computers, servers or tablet computers. Figure 1 As shown, the method includes:
[0033] Step 110: In response to a filter instruction for user traffic in a target area, obtain at least one target mobile network signaling data matching the target area.
[0034] The target mobile network signaling data may include: TAC (Tracking Area Code) or ECI (E-UTRAN Cell Identity).
[0035] In this embodiment, the target area may be a target community or a target town or village, for example, community B in city A; or village D in county C, etc., which is not limited in this embodiment.
[0036] In an optional implementation of this embodiment, after receiving an instruction to filter user traffic in a target area, the TAC and ECI of the target area may be further obtained so as to subsequently filter and obtain user traffic data matching the target area.
[0037] Optionally, in this embodiment, the TAC and ECI of the target area can be obtained through the operator, and the acquisition method is reasonable and legal.
[0038] Step 120: Acquire each signaling flow, determine target information of each signaling flow, and generate a first mapping table based on each target information.
[0039] In the LTE core network, the control plane interface transmits signaling traffic containing information such as user location. Therefore, after receiving a filter instruction for user traffic in the target area, the signaling traffic data transmitted by the LTE core network via the control plane interfaces S11 and S58-C can be obtained. In this embodiment, a signaling traffic flow may include information such as user location information or user mobile phone number, which is not limited in this embodiment.
[0040] Optionally, in this embodiment, after obtaining each signaling flow from the control plane interface, the target information of each signaling flow can be further determined, and a first mapping table can be generated based on the obtained target information; wherein, the target information of the signaling flow may include at least one of the following: control tunnel identifier, user identifier, TAC, ECI and base station side tunnel bearer identifier, which is not limited in this embodiment.
[0041] It should be noted that in this embodiment, the mapping table generated based on each target information is named the first mapping table, and it can also be named the full mapping table, which is not a limitation of this embodiment.
[0042] Optionally, in this embodiment, determining the target information of each signaling flow and generating a first mapping table based on each target information may include: parsing the target signaling flow to obtain the target signaling message sequence of the target signaling flow; determining the target signaling process corresponding to the target signaling flow based on the order of each target signaling message sequence and the relationship between them; determining each target information based on the target signaling process, and storing each target information in a preset mapping table to obtain the first mapping table.
[0043] In an optional implementation of this embodiment, after obtaining each signaling flow from the control plane interface, the target signaling flow can be further parsed to obtain the target signaling message sequence of the target signaling flow; wherein, the target signaling flow can be any signaling flow among the obtained signaling flows, and this embodiment does not limit it.
[0044] Furthermore, the target signaling process corresponding to the target signaling traffic can be determined based on the order of each target signaling message sequence and the relationship between them; further, each target information can be determined based on the target signaling process, and each target information can be stored in a preset mapping table respectively, thereby obtaining the first mapping table.
[0045] In this embodiment, the target signaling process can be an attachment request of the target user, a PDN (Packet Data Network, creating a specific packet data network) connection request, or a switching process, etc., which is not limited in this embodiment; among them, the target user can be any user accessing the LTE core network, which is also not limited in this embodiment.
[0046] Optionally, in this embodiment, determining each target information based on the target signaling process may include: if the target signaling process is an attachment request and / or a PDN connection request of the target user, determining the target user identifier, the TAC and the ECI of the target user based on the attachment request and / or the PDN connection request; obtaining a first creation session process that matches the attachment request, and determining the first uplink and downlink tunnels created in the first creation session process, and the first bearer identifier; determining the first uplink and downlink tunnels as the target control tunnel, and determining the first bearer identifier as the default bearer identifier belonging to the target control tunnel; or, obtaining a second creation session process that matches the PDN connection request, and determining the second uplink and downlink tunnels created in the second creation session process, and the second bearer identifier; determining the second uplink and downlink tunnels as the target control tunnel, and determining the second bearer identifier as the default bearer identifier belonging to the target control tunnel; if the target signaling process is a switching process, determining the base station side tunnel bearer identifier from the bearer creation process triggered by the switching process.
[0047] In an optional implementation of this embodiment, if the target signaling process corresponding to the target signaling traffic is determined to be the target user's attachment request and / or PDN connection request, the target user identifier, the TAC and the ECI of the target user can be extracted from the target user's attachment request and / or PDN connection request.
[0048] In this embodiment, a mobile device, such as a mobile phone, triggers the CreateSession process of the S11 and S58-C interfaces in the LTE core network during processes such as attaching and creating a PDN connection. The CreateSession process can carry information such as the mobile phone number, initial location, and default bearer identifier.
[0049] It can be understood that a control tunnel can be associated with multiple default bearers, and a default bearer can be associated with multiple dedicated bearers, that is, there can be multiple default bearers belonging to the target control tunnel and multiple dedicated bearers belonging to the default bearer at the same time, for example, 2, 3 or 10, etc., which is not limited in this embodiment.
[0050] For example, Figure 2 1 is a schematic diagram of the relationship between a control tunnel, a default bearer, and a dedicated bearer according to the first embodiment of the present invention; Figure 2 As shown, the target control tunnel can include control tunnel 1, control tunnel 2 and control tunnel 3; among them, control tunnel 1 is associated with two default bearers, namely default bearer id=5 and default bearer id=6; default bearer id=5 is associated with two dedicated bearers, namely dedicated bearer id=8 and dedicated bearer id=9; default bearer id=6 is associated with dedicated bearer id=11; control tunnel 2 is associated with one default bearer, namely default bearer id=5; default bearer id=5 is associated with dedicated bearer id=13; control tunnel 3 is associated with one default bearer, namely default bearer id=5.
[0051] In an optional implementation of this embodiment, if the target signaling process corresponding to the target signaling traffic is determined to be the target user's attachment request and / or PDN connection request, a first session creation process matching the attachment request can also be obtained, and the first uplink and downlink tunnels created in the first creation session process and the first bearer identifier can be determined; the first uplink and downlink tunnels are determined as the target control tunnels, and the first bearer identifier is determined as the default bearer identifier belonging to the target control tunnels; or, a second creation session process matching the PDN connection request is obtained, and the second uplink and downlink tunnels created in the second creation session process and the second bearer identifier are determined; the second uplink and downlink tunnels are determined as the target control tunnels, and the second bearer identifier is determined as the default bearer identifier belonging to the target control tunnel.
[0052] In an optional implementation of this embodiment, a first create session process that matches the attach request of the target user's mobile device may be obtained. Specifically, when the request and response of the first create session process are received, the user identifier may be extracted from the Create Session Request; and the default bearer identifier (EBI (EPC Bearer Identify, user plane bearer identifier) may be extracted from the Create Session Response. One EBI may correspond to one user plane downlink and downlink tunnel. For example,
[0053] Ip1+teid1ßàip2+teid2; wherein, Ip2+teid2 is called the uplink tunnel identifier;), in this embodiment, the default bearer identifier is referred to as the first bearer identifier; and GW side tunnel information (for example, TEID or creation time), in this embodiment, the GW side tunnel is referred to as the first uplink tunnel, further, the obtained first uplink tunnel can be determined as the target control tunnel, and the first bearer identifier is determined as the default bearer identifier belonging to the target control tunnel.
[0054] It should be noted that in this embodiment, the user name interfaces S1U and S58-U are not distinguished, and the eNB on the AC side replaces the S1U and the SGW-U on the S58-U, and the SGW-U on the GW side replaces the S1U and the PGW-U on the S58-U; in this embodiment, only the GW side tunnel is used as an example for illustration, which is not a limitation of this embodiment.
[0055] In another optional implementation of this embodiment, a second session creation process that matches the PDN connection request of the target user's mobile device can be obtained; specifically, when the request and response of the second session creation process are received, the user identifier can be extracted from the Create Session Request; the default bearer identifier (EBI) can be extracted from the Create Session Response. In this embodiment, the default bearer identifier is referred to as the second bearer identifier; and the GW side tunnel information (for example, TEID or creation time) can be extracted. In this embodiment, the GW side tunnel is referred to as the second uplink and downlink tunnel. Further, the obtained second uplink and downlink tunnel can be determined as the target control tunnel, and the second bearer identifier can be determined as the default bearer identifier belonging to the target control tunnel.
[0056] Optionally, in this embodiment, after the first bearer identifier and the second bearer identifier are determined as the default bearer identifier based on the above steps, the dedicated bearer activation process can be continued to be obtained; specifically, the default bearer identifier (for example, EBI=5) can be found in the Create BearerRequest message; further, the newly created dedicated bearer identifier (for example, EBI=7) can be extracted in the Create BearerResponse message; further, the default bearer identifier can be associated with the dedicated bearer identifier to form a mapping relationship, that is, the default bearer EBI=5 corresponds to the dedicated bearer EBI=7.
[0057] In another optional implementation of this embodiment, if the target signaling process is determined to be a switching process, the base station side bearer identifier can be determined from the bearer creation process triggered by the switching process; it can be understood that when the mobile device is moving, it will trigger the x2 or S1 switching process, that is, it will trigger the ModifyBear or CreatSession / DeleteSession process of the S11 interface, and will trigger the ModifyBear process of the S58-C interface, wherein the ModifyBear process carries the current location and the modified downlink data tunnel. Therefore, the base station side bearer identifier corresponding to the target signaling traffic can be determined based on this.
[0058] Furthermore, the target information obtained above may be stored in a preset mapping table, thereby obtaining a first mapping table.
[0059] Step 130: Filter the first mapping table based on the target mobile network signaling data to obtain a second mapping table.
[0060] The second mapping table stores the start time and end time of each user's access to the target base station.
[0061] Optionally, in this embodiment, after determining to obtain the first mapping table, the first mapping table can be further filtered based on the target mobile network signaling data of the target area (i.e., the TAC and ECI of the target area) to obtain a second mapping table; illustratively, the data in the first mapping table that are identical to the TAC and ECI of the target area can be determined as target data, and the second mapping table can be generated based on the target data.
[0062] Optionally, in this embodiment, each TAC and ECI in the first mapping table is obtained, and reference data consistent with the TAC and ECI in the target mobile network signaling data is determined; the base station side tunnel bearer identifier and user identifier of each reference data are stored in the second mapping table.
[0063] Optionally, in this embodiment, each TAC and ECI in the first mapping table can be compared with the TAC and ECI of the target area, and the data in the first mapping table that is consistent with the TAC and ECI of the target area can be determined as reference data, and the base station side tunnel bearer identifier and user identifier of each of the reference data can be stored in the second mapping table.
[0064] Optionally, in this embodiment, after storing the base station side tunnel bearer identifier and user identifier of each reference data in the second mapping table, it can also include: obtaining a first deletion session process matching the attachment request, or obtaining a second deletion session process matching the PDN connection request, or obtaining a bearer deletion process; obtaining attribute information of the first creation session process, the first deletion session process, the second creation session process, the second deletion session process, and the bearer deletion process respectively; determining the start time and end time of each target control tunnel based on each attribute information; and adding the start time and the end time to the second mapping table.
[0065] Among them, the attribute information may include the user identifier, tunnel identifier, default bearer identifier, creation time or deletion time of each session, etc. of each session process; exemplarily, the first session creation process may include: user identifier, tunnel identifier, at least one default bearer identifier and the creation time of the first session creation process; the first session deletion process may include: user identifier, tunnel identifier, at least one default bearer identifier and the deletion time of the first session deletion process.
[0066] In an optional implementation of this embodiment, in the process of determining the target control tunnel associated with the target user and the default bearer identifiers matching the target control tunnel, attribute information of each creation session or deletion session can also be obtained. Furthermore, the creation time and deletion time of the target control tunnel can be determined based on the obtained attribute information.
[0067] It should be noted that during the session creation process, when the target user's phone requests an attachment, the LTE core network creates uplink and downlink tunnels for the phone on the control plane interfaces S11 and S58-C, and assigns a default bearer and ID; for example, id = 5. When the target user's phone creates a PDN connection request, uplink and downlink tunnels S11 and S58-C are created for the phone (in this process, the attachment process may be reused) and a default bearer ID is assigned; for example, id = 6. It is understandable that the same target user's phone may create multiple PDN connections; therefore, a single S11 / S58-C control tunnel may have multiple default bearers attached to it.
[0068] It should also be noted that during the session deletion process, if the default bearer identifier is not included, all default bearers under the control tunnel are deleted, and the control tunnel is also deleted. If the default bearer identifier is included, the default bearer associated with that default bearer identifier is deleted. If multiple deletion sessions with the default bearer identifier result in the deletion of all default bearers, the control tunnel is automatically deleted.
[0069] In summary, the second mapping table stores the base station side tunnel identifier, the user identifier, and the start time and end time of the control tunnel (ie, the start time and end time of the user accessing the target base station).
[0070] Step 140: Filter user traffic based on the second mapping table to obtain target user traffic, and forward the target user traffic to a target system.
[0071] Optionally, in this embodiment, after receiving the first user traffic through the user plane interfaces S1U and S58-U of the LTE core network, the first user traffic can be parsed to determine the first user identifier, the first base station side identifier, or the first access time of the first user traffic. When the first user identifier and the first base station side identifier are in the second mapping table, and the first access time is within the start time and end time recorded in the second mapping table, the first user traffic can be determined as the target user traffic, and the target user traffic can be forwarded to the target system; otherwise, the first user traffic is non-target user traffic and can be filtered out, that is, it will no longer be forwarded.
[0072] The technical solution of this embodiment obtains at least one target mobile network signaling data matching the target area in response to a screening instruction of user traffic in the target area; wherein, the target mobile network signaling data includes: a tracking area code TAC or a cell identifier ECI; obtains each signaling traffic, determines the target information of each signaling traffic, and generates a first mapping table based on each target information; filters the first mapping table based on each target mobile network signaling data to obtain a second mapping table; wherein, the second mapping table stores the start time and end time of each user's access to the target base station; filters the user traffic based on the second mapping table to obtain the target user traffic, and forwards the target user traffic to the target system, so as to determine the user traffic matching the target area and send it to the matching analysis system, thereby reducing the data processing pressure of the analysis system and providing a basis for improving the efficiency and accuracy of data processing.
[0073] Example 2
[0074] Figure 3 This is a flow chart of a target mobile network signaling data method provided according to the second embodiment of the present invention. This embodiment is a further refinement of the above technical solution. The technical solution in this embodiment can be combined with various optional solutions in one or more of the above embodiments. Figure 3 As shown, the method includes:
[0075] Step 310: determine the target area and obtain the target mobile network signaling data that matches the target area from a preset document or website; or, obtain and parse the first signaling traffic forwarded by the target device within the target area, and parse the first signaling traffic to obtain the target mobile network signaling data that matches the target area.
[0076] Optionally, in this embodiment, after receiving the filtering instruction for user traffic in the target area, the filtering instruction for user traffic in the target area can be parsed to determine the target area, and further, the TAC and ECI matching the target area can be obtained from a preset document or website.
[0077] In another optional implementation of this embodiment, after determining the target area based on the parsing results of the filtering instructions for the user traffic in the target area, it is also possible to obtain and parse the first signaling traffic (any signaling traffic generated in the target area) forwarded by the target device (for example, a mobile terminal such as a mobile phone or tablet computer) within the target area, and parse the first signaling traffic to obtain a TAC and ECI that match the target area.
[0078] Step 320: Acquire each signaling flow, determine target information of each signaling flow, and generate a first mapping table based on each target information.
[0079] Step 330: Filter the first mapping table based on the target mobile network signaling data to obtain a second mapping table.
[0080] Step 340: Filter the user traffic based on the second mapping table to obtain target user traffic, and forward the target user traffic to the target system.
[0081] Optionally, in this embodiment, the user traffic is filtered based on the second mapping table to obtain target user traffic, and the target user traffic is forwarded to the target system, which may include: in response to the filtering instruction of the user traffic in the target area, each user traffic is parsed to determine the first user identifier, the first base station side tunnel bearer identifier, the first start time and the first end time that match the first user traffic; the first user identifier, the first base station side tunnel bearer identifier, the first start time and the first end time are respectively compared with each reference user identifier, the reference base station side tunnel bearer identifier, the reference start time and the reference end time stored in the second mapping table; when the comparison results are consistent, the first user traffic is determined as the target user traffic, and the target user traffic is forwarded to the target system.
[0082] In an optional implementation of this embodiment, after receiving an instruction to filter user traffic within the target area, each user traffic received through the user plane interface can be further parsed to determine the first user identifier, the first base station side tunnel bearer identifier, the first start time, and the first end time that match the first user traffic.
[0083] Furthermore, the first user identifier, the first base station side tunnel bearer identifier, the first start time and the first end time can be compared with the reference user identifiers, reference base station side tunnel bearer identifiers, reference start time and reference end time stored in the second mapping table respectively; when the comparison results are consistent, the target user traffic can be determined as the target user traffic and forwarded to the target system.
[0084] The solution of this embodiment can parse each of the user flows to determine the first user identifier, the first base station side tunnel bearer identifier, the first start time and the first end time that match the first user flow; respectively compare the first user identifier, the first base station side tunnel bearer identifier, the first start time and the first end time with the reference user identifiers, the reference base station side tunnel bearer identifiers, the reference start time and the reference end time stored in the second mapping table; when the comparison results are consistent, the first user flow is determined as the target user flow, and the target user flow is forwarded to the target system. Based on the constructed second mapping table, the user flow in the target area can be quickly screened, thereby improving the efficiency of the user flow selection, and sending it to the matching analysis system, reducing the data processing pressure of the analysis system, and providing a basis for improving the efficiency and accuracy of data processing.
[0085] In order to better understand the method for determining the user traffic in the target area involved in this embodiment, the following describes the implementation of this solution using a specific example:
[0086] It should be noted that mobile Internet services in a certain area are provided by base stations. If the traffic is roughly diverted according to the base station identifier (for example, the base station IP), although the Internet traffic can be diverted, the Internet users cannot be known.
[0087] For mobile phone users to access the Internet, the general process may include:
[0088] Mobile internet access is carried on the mobile core network. Essentially, it involves creating control and data tunnels within the mobile core network. The control tunnel carries control messages, while the data tunnel carries internet traffic. First, a bidirectional control tunnel is created for a user. Furthermore, a bidirectional data tunnel is negotiated within the bidirectional control tunnel (for the user). Furthermore, the uplink tunnel within the bidirectional control tunnel remains unchanged from session creation to session deletion, using the same uplink control tunnel. Finally, the downlink tunnel within the bidirectional data tunnel may be triggered by a modifyBearer event and change.
[0089] In summary, the logical organization of a single user can be as follows:
[0090] --A certain user;
[0091] --Control tunnel for a certain user;
[0092] --The data tunnel under a user's control tunnel (labeled with ebi);
[0093] --Base station side tunnel in the data tunnel under a user's control tunnel.
[0094] Understandably, both control and data tunnels have lifecycles and cannot be permanently used by a single user. Therefore, we output a second mapping table with entries: target base station tunnel - user - start and end time. Traffic hitting the target base station tunnel is forwarded to the directional analysis system, and the second mapping table is provided to the directional analysis system. Ultimately, the directional analysis system receives the expected traffic and, through traffic analysis and comparison with the second mapping table, identifies the online behavior of traffic in the geographic area of interest and the corresponding users.
[0095] Exemplarily, in this embodiment, the first mapping table may include: control tunnel table; Key: control tunnel (only uplink); Val: user, TAC-ECI, ebi-base station side tunnel (multiple, hierarchical relationship); the second mapping table may include: target base station side tunnel; Key: base station side tunnel; Val: start time, end time, user.
[0096] In an example of this embodiment, the mobile network TAC and ECI corresponding to the geographic location of interest can be obtained; further, the signaling process can be analyzed to learn the base stations corresponding to the TAC and ECI; further, the signaling process can be analyzed to learn which users use the target base station from the time and tunnel dimensions, generate a second mapping table, and forward the user-side traffic that hits the target base station in the second mapping table to the directional analysis system; further, the directional analysis system can analyze the user-side traffic and combine it with the second mapping table to obtain the Internet behavior and Internet users of the traffic, thereby greatly reducing the traffic processing pressure of the directional analysis system.
[0097] The solution of this embodiment filters the Internet traffic of certain geographical areas through the S1U and S58-U user plane interfaces and outputs it to the directional analysis system, thereby greatly reducing the traffic processing pressure of the directional analysis system.
[0098] Example 3
[0099] Figure 4 1 is a schematic diagram of the structure of a target mobile network signaling data device provided according to the third embodiment of the present invention. Figure 4 As shown, the device includes: an acquisition module 410, a first mapping table generation module 420, a second mapping table generation module 430 and a user traffic screening module 440.
[0100] The acquisition module 410 is configured to acquire, in response to a filter instruction for user traffic in a target area, at least one target mobile network signaling data matching the target area; wherein the target mobile network signaling data includes: a tracking area code (TAC) or a cell identifier (ECI);
[0101] A first mapping table generating module 420 is configured to obtain each signaling flow, determine target information of each signaling flow, and generate a first mapping table based on each target information;
[0102] A second mapping table generating module 430 is configured to filter the first mapping table based on the target mobile network signaling data to obtain a second mapping table; wherein the second mapping table stores the start time and end time of each user's access to the target base station;
[0103] The user traffic screening module 440 is configured to screen the user traffic based on the second mapping table to obtain target user traffic, and forward the target user traffic to a target system.
[0104] The solution of this embodiment is to obtain at least one target mobile network signaling data matching the target area by an acquisition module in response to a screening instruction of user traffic in the target area; wherein, the target mobile network signaling data includes: a tracking area code TAC or a cell identifier ECI; obtain each signaling traffic by a first mapping table generation module, determine the target information of each signaling traffic, and generate a first mapping table based on each target information; filter the first mapping table based on each target mobile network signaling data by a second mapping table generation module to obtain a second mapping table; wherein, the second mapping table stores the start time and end time of each user's access to the target base station; filter the user traffic based on the second mapping table by a user traffic screening module to obtain the target user traffic, and forward the target user traffic to the target system, so as to determine the user traffic matching the target area and send it to the matching analysis system, thereby reducing the data processing pressure of the analysis system and providing a basis for improving the efficiency and accuracy of data processing.
[0105] In an optional implementation of this embodiment, the acquisition module 410 is specifically configured to:
[0106] Determine a target area, and obtain target mobile network signaling data matching the target area from a preset document or website;
[0107] or,
[0108] The first signaling traffic forwarded by the target device in the target area is acquired and parsed, and the first signaling traffic is parsed to obtain signaling data of each target mobile network matching the target area.
[0109] In an optional implementation of this embodiment, the first mapping table generating module 420 is specifically configured to:
[0110] Parsing the target signaling traffic to obtain a target signaling message sequence of the target signaling traffic;
[0111] Determining a target signaling flow corresponding to the target signaling flow based on the order of the target signaling message sequences and the relationship between them;
[0112] Determining each target information based on the target signaling process, and storing each target information in a preset mapping table to obtain the first mapping table;
[0113] The target information includes at least one of the following: a control tunnel identifier, a user identifier, a TAC, an ECI, and a base station side tunnel bearer identifier.
[0114] In an optional implementation of this embodiment, the first mapping table generating module 420 is further specifically configured to:
[0115] If the target signaling process is an attach request and / or a request to create a specific packet data network (PDN) connection of a target user, determining a target user identifier, the TAC, and the ECI of the target user based on the attach request and / or the PDN connection request;
[0116] Obtaining a first session creation process that matches the attach request, and determining a first uplink and downlink tunnel created in the first session creation process, and a first bearer identifier;
[0117] The first uplink and downlink tunnel is determined as a target control tunnel, and the first bearer identifier is determined as a default bearer identifier belonging to the target control tunnel; or,
[0118] Obtain a second session creation process that matches the PDN connection request, and determine a second uplink and downlink tunnel created in the second session creation process, and a second bearer identifier;
[0119] Determine the second uplink and downlink tunnel as a target control tunnel, and determine the second bearer identifier as a default bearer identifier belonging to the target control tunnel;
[0120] If the target signaling process is a handover process, the base station side tunnel bearer identifier is determined from the bearer creation process triggered by the handover process.
[0121] In an optional implementation of this embodiment, the second mapping table generating module 430 is specifically configured to:
[0122] Obtaining each TAC and ECI in the first mapping table, and determining reference data consistent with the TAC and ECI in the target mobile network signaling data;
[0123] The base station side tunnel bearer identifier and the user identifier of each reference data are stored in the second mapping table.
[0124] In an optional implementation of this embodiment, the target mobile network signaling data device further includes: a time determination module, configured to:
[0125] Acquire a first session deletion process that matches the attach request, or acquire a second session deletion process that matches the PDN connection request, or acquire a bearer deletion process;
[0126] Respectively obtain the first create session process, the first delete session process, the second create session process, the second delete session process, and the attribute information of the bearer delete process;
[0127] Determining the start time and end time of each target control tunnel according to each attribute information;
[0128] The start time and the end time are added to the second mapping table.
[0129] In an optional implementation of this embodiment, the user traffic screening module 440 is specifically configured to:
[0130] In response to a filter instruction for user traffic in a target area, parsing each of the user traffic, and determining a first user identifier, a first base station-side tunnel bearer identifier, a first start time, and a first end time that match the first user traffic;
[0131] respectively comparing the first user identifier, the first base station side tunnel bearer identifier, the first start time, and the first end time with each reference user identifier, reference base station side tunnel bearer identifier, reference start time, and reference end time stored in the second mapping table;
[0132] When the comparison results are consistent, the first user traffic is determined as the target user traffic, and the target user traffic is forwarded to the target system.
[0133] The target mobile network signaling data device provided in the embodiment of the present invention can execute the target mobile network signaling data method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0134] In the technical solutions of the embodiments of the present invention, the collection, storage, use, processing, transmission, provision and disclosure of user traffic, signaling traffic, etc. comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0135] Example 4
[0136] Figure 5 A schematic diagram of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0137] like Figure 5As shown, electronic device 10 includes at least one processor 11 and memory, such as read-only memory (ROM) 12 and random access memory (RAM) 13, communicatively connected to at least one processor 11. The memory stores computer programs executable by the at least one processor. Processor 11 can perform various appropriate actions and processes based on the computer programs stored in ROM 12 or loaded from storage unit 18 into RAM 13. RAM 13 can also store various programs and data required for the operation of electronic device 10. Processor 11, ROM 12, and RAM 13 are interconnected via bus 14. An input / output (I / O) interface 15 is also connected to bus 14.
[0138] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0139] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processor, controller, microcontroller, etc. Processor 11 executes the various methods and processes described above, such as the target mobile network signaling data method.
[0140] In some embodiments, the target mobile network signaling data method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the target mobile network signaling data method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to execute the target mobile network signaling data method in any other suitable manner (e.g., via firmware).
[0141] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0142] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0143] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, device, or apparatus. A computer-readable storage medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0144] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device that has: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0145] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0146] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0147] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0148] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
[0149] An embodiment of the present invention further provides a computer program product, including a computer program, which, when executed by a processor, implements the database detection method provided in any embodiment of the present application.
[0150] During implementation, the computer program product may be written in one or more programming languages or a combination thereof to perform the operations of the present invention. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0151] It should be noted that in the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned. They should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.
[0152] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will appreciate that the present invention is not limited to the specific embodiments herein, and that various obvious changes, readjustments, and substitutions are possible for those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the scope of the present invention. The scope of the present invention is determined by the scope of the appended claims.
Claims
1. A method for determining user traffic in a target area, characterized in that: include: In response to a filter instruction for user traffic in a target area, obtaining at least one target mobile network signaling data matching the target area; wherein the target mobile network signaling data includes: a tracking area code TAC or a cell identifier ECI; Acquire each signaling flow, determine target information of each signaling flow, and generate a first mapping table based on each target information; The first mapping table is filtered based on the signaling data of each target mobile network to obtain a second mapping table; wherein the second mapping table stores the start time and end time of each user's access to the target base station; User traffic is screened based on the second mapping table to obtain target user traffic, and the target user traffic is forwarded to a target system.
2. The method for determining user traffic in a target area according to claim 1, characterized in that: The obtaining, in response to the instruction for filtering user traffic in the target area, at least one item of target mobile network signaling data matching the target area includes: Determine a target area, and obtain target mobile network signaling data matching the target area from a preset document or website; or, The first signaling traffic forwarded by the target device in the target area is acquired and parsed, and the first signaling traffic is parsed to obtain signaling data of each target mobile network matching the target area.
3. The method for determining user traffic in a target area according to claim 1, wherein: The determining target information of each signaling flow and generating a first mapping table based on each target information includes: Parsing the target signaling traffic to obtain a target signaling message sequence of the target signaling traffic; Determining a target signaling flow corresponding to the target signaling flow based on the order of the target signaling message sequences and the relationship between them; Determining each target information based on the target signaling process, and storing each target information in a preset mapping table to obtain the first mapping table; The target information includes at least one of the following: a control tunnel identifier, a user identifier, a TAC, an ECI, and a base station side tunnel bearer identifier.
4. The method for determining user traffic in a target area according to claim 3, wherein: The determining of each target information based on the target signaling process includes: If the target signaling process is an attach request and / or a request to create a specific packet data network (PDN) connection of a target user, determining a target user identifier, the TAC, and the ECI of the target user based on the attach request and / or the PDN connection request; Obtaining a first session creation process that matches the attach request, and determining a first uplink and downlink tunnel created in the first session creation process, and a first bearer identifier; The first uplink and downlink tunnel is determined as a target control tunnel, and the first bearer identifier is determined as a default bearer identifier belonging to the target control tunnel; or, Obtain a second session creation process that matches the PDN connection request, and determine a second uplink and downlink tunnel created in the second session creation process, and a second bearer identifier; Determine the second uplink and downlink tunnel as a target control tunnel, and determine the second bearer identifier as a default bearer identifier belonging to the target control tunnel; If the target signaling process is a handover process, the base station side tunnel bearer identifier is determined from the bearer creation process triggered by the handover process.
5. The method for determining user traffic in a target area according to claim 4, characterized in that: The filtering of the first mapping table based on each of the target mobile network signaling data to obtain a second mapping table includes: Obtaining each TAC and ECI in the first mapping table, and determining reference data consistent with the TAC and ECI in the target mobile network signaling data; The base station side tunnel bearer identifier and the user identifier of each reference data are stored in the second mapping table.
6. The method for determining user traffic in a target area according to claim 5, characterized in that: After storing the base station side tunnel bearer identifier and the user identifier of each reference data in the second mapping table, the method further includes: Acquire a first session deletion process that matches the attach request, or acquire a second session deletion process that matches the PDN connection request, or acquire a bearer deletion process; Respectively obtain the first create session process, the first delete session process, the second create session process, the second delete session process, and the attribute information of the bearer delete process; Determining the start time and end time of each target control tunnel according to each attribute information; The start time and the end time are added to the second mapping table.
7. The method for determining user traffic in a target area according to claim 1, wherein: The filtering of user traffic based on the second mapping table to obtain target user traffic, and forwarding the target user traffic to a target system includes: In response to a filter instruction for user traffic in a target area, parsing each of the user traffic, and determining a first user identifier, a first base station-side tunnel bearer identifier, a first start time, and a first end time that match the first user traffic; respectively comparing the first user identifier, the first base station side tunnel bearer identifier, the first start time, and the first end time with each reference user identifier, reference base station side tunnel bearer identifier, reference start time, and reference end time stored in the second mapping table; When the comparison results are consistent, the first user traffic is determined as the target user traffic, and the target user traffic is forwarded to the target system.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the method for determining user traffic in a target area according to any one of claims 1 to 7.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the method for determining user traffic in a target area according to any one of claims 1 to 7 when executed.
10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method for determining user traffic in a target area according to any one of claims 1 to 7.
Citation Information
Patent Citations
Base station cell coverage relationship processing method and device and storage medium
CN112566136A
Regional user traffic monitoring method and device, storage medium and computer equipment
CN114531706A
Signaling stream data processing method, location information service method and electronic equipment
CN114666753A
Mobile network 5G traffic offloading capability geography evaluation method and mobile network 5G traffic offloading capability geography evaluation device
CN115866643A
User traffic screening method and device, electronic equipment and storage medium
CN119562306A