NF device and signaling control method performed in NF
By defining a new analysis ID between NF and NWDAF, and using AI/ML to process and analyze NF information, abnormal operations can be quickly identified and responded to, solving the signaling storm problem caused by abnormal NF operations in B5G/6G networks, improving communication quality and saving resources.
Patent Information
- Application Number
- CN202380099210.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-06-09
- Filing Date
- 2023-09-26
- Publication Date
- 2026-01-02
AI Technical Summary
In B5G/6G networks, the lack of methods to identify and respond to abnormal operation of network functions (NFs) and abnormal operation or signaling storms between NFs leads to degraded communication quality and wasted resources.
By defining a new analysis ID between the Network Data Analysis Function (NF) and the Network Data Analysis Function (NWDAF), AI/ML processing is used to analyze the internal and external information of the NF, predict abnormal states, and exchange information between the local and centralized NWDAFs, enabling rapid and accurate identification and response to abnormal states.
It enables rapid identification and response to anomalies in NFs and abnormal operations between NFs, avoiding signaling storms, improving communication quality, and reducing resource waste.
Smart Images

Figure CN121264014A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The disclosure relates to a technology capable of recognizing and coping with normal / abnormal of network functions (NFs) and normal / abnormal operations between the NFs.
[0002] This application claims priority to Korean Patent Application No. 10-2023-0074196, filed on June 9, 2023, and the disclosure of which is incorporated herein by reference in its entirety for all purposes. BACKGROUND
[0003] In the current B5G / 6G network, there are a large number of network functions (NFs), and a large amount of signaling occurs due to communication processed via an NF-based protocol or a service-based interface (SBI) between the NFs.
[0004] In addition, as the central office currently and in the future evolves into a structure such as redundancy / distributed deployment, a much larger amount of signaling than the number of device types occurs during NF-to-NF communication in the actual common B5G / 6G network environment.
[0005] Furthermore, in the B5G / 6G network environment, a large amount of signaling storm can occur in the access and core network due to abnormal operation of the NF, error NF operation, and internal / external factors of the NF.
[0006] However, in the current B5G / 6G standard, there is no method for detecting and coping with abnormal operation of the NF or abnormal operation between the NFs or a signaling storm.
[0007] In the current standard, it is assumed that the NF always operates "normally". However, as the number of NFs increases, abnormal operation of the NF and abnormal operation between the NFs and a signaling storm can occur due to errors, delays, burst signaling, etc.
[0008] That is, it is currently not possible to determine whether the operation of the NF itself or the operation during communication between the NFs is normal / abnormal, which can eventually lead to a decrease in communication and quality experienced by customers. Alternatively, in order to prevent such a situation, a large amount of resources, including a large investment cost of the operator, redundancy / triple redundancy of the NF system, and pre / post-verification processes (work initiation), are consumed.
[0009] In fact, many current failures of the NF are mainly caused by faults, errors, or unexpected operations thereof, resulting in growing concerns about stability of the control plane (signaling) itself or the NF itself.
[0010] Therefore, this disclosure proposes a new technical method for identifying and responding to normal / abnormal NFs and normal / abnormal operations between NFs, in order to address various problem situations caused by the lack of measures in current standards. Summary of the Invention
[0011] Technical issues
[0012] The technical task to be achieved by this disclosure is to implement a new technical method that can identify and respond to normal / abnormal NFs and normal / abnormal operations between NFs.
[0013] Technical solution
[0014] A network function (NF) apparatus according to one aspect of the present disclosure includes: a memory including instructions, and a processor configured to execute instructions to transmit information to be analyzed to an NF (Network Data Analysis Function (NWDAF)) configured to perform an anomaly prediction process through information analysis, to request prediction results obtained by performing the anomaly prediction process, wherein the processor is configured to select a specific NWDAF from a plurality of NWDAFs based on the information to be transmitted and transmit the information to the specific NWDAF.
[0015] Specifically, the processor can be configured to select a particular NWDAF based on at least one of the following: whether the information to be transmitted is real-time or non-real-time data, the estimated processing time consumed by analyzing the information, and the capacity required to analyze the information.
[0016] Specifically, the multiple NWDAFs may include a first NWDAF located close to the NF device (local to the NF device) and a second NWDAF configured to perform anomaly prediction processes by communicating with the multiple first NWDAFs.
[0017] Specifically, the processor can be configured to request a prediction result from another NWDAF among a plurality of NWDAFs based on the prediction result when it receives the prediction result from a specific NWDAF of an abnormal state prediction process performed by analyzing the transmitted information.
[0018] Specifically, the processor can be configured to: execute subsequent processes based on prediction results transmitted from a specific NWDAF or another NWDAF, and when it is determined that the execution of the subsequent process is impossible, re-request prediction results from the specific NWDAF or another NWDAF for the execution of an alternative subsequent process.
[0019] A network data analysis function (NWDAF) apparatus according to one aspect of this disclosure includes: a memory including instructions, and a processor configured to execute the instructions to derive prediction results by performing an anomaly prediction process related to a specific NF by means of analyzing information transmitted from each NF, and to transmit information to another NWDAF apparatus or request additional information from another NWDAF apparatus based on the prediction results.
[0020] Specifically, the processor can be configured to control the transmission of information to another NWDAF device by using at least one of the accuracy, impact, and urgency of the prediction result as criteria.
[0021] Specifically, the processor can be configured to: transmit information to another NWDAF device based on the prediction result to allow the information to be used in an abnormal state prediction process, which is used to derive a final prediction result for a specific NF, the abnormal state prediction process being performed by another NWDAF device, or request additional information from another NWDAF device based on the prediction result and obtain the final prediction result by re-performing the abnormal state prediction process, in which even the additional information is analyzed.
[0022] Specifically, another NWDAF device can be a centralized NWDAF configured to perform anomaly prediction processes by interworking with multiple local NWDAFs.
[0023] A signaling control method performed by a network function (NF) device according to one aspect of the present disclosure may include the following steps: transmitting information to be analyzed to an NF (Network Data Analysis Function (NWDAF)) configured to perform an anomaly prediction process through information analysis to request prediction results obtained by performing the anomaly prediction process, wherein the transmission step includes: selecting a specific NWDAF from a plurality of NWDAFs based on the information to be transmitted, and transmitting the information to the specific NWDAF.
[0024] A signaling control method performed by a Network Data Analysis Function (NWDAF) device according to one aspect of this disclosure includes the following steps: deriving a prediction result by performing an anomaly prediction process related to a specific NF by means of analyzing information transmitted from each NF, and transmitting information to another NWDAF device or requesting additional information from another NWDAF device based on the prediction result.
[0025] Technical effect
[0026] Based on the NF device according to this disclosure and the signaling control method executed by the NF device, a specific technical configuration is realized that can identify normal / abnormal NFs and normal / abnormal operations between NFs and respond adaptively.
[0027] Therefore, this disclosure yields the following effects: the ability to detect anomalies in NFs, abnormal operations between NFs, and signaling storms, and to optimally address these anomalies, as well as to avoid potential degradation in communication and quality of customer experience. Attached Figure Description
[0028] Figure 1 This is an example diagram illustrating a problematic situation where a signaling storm occurs;
[0029] Figure 2 Example diagrams illustrating the core features of this disclosure and multiple NF / NWDAFs are provided.
[0030] Figure 3 and Figure 4 This is a block diagram illustrating the configuration of an NF device and an NWDAF device according to embodiments of the present disclosure;
[0031] Figure 5 This is an example diagram illustrating the communication content between NF and NWDAF in this disclosure;
[0032] Figures 6 to 10 Each illustrates an implementation of a call flow performed by an NF according to the signaling control method of this disclosure; and
[0033] Figures 11 to 16 Each illustrates an implementation of a call flow dependent on the signaling storm state, performed by the signaling control method executed by the NF according to this disclosure. Detailed Implementation
[0034] In the following description, various embodiments of the present disclosure will be described with reference to the accompanying drawings.
[0035] This disclosure relates to techniques capable of identifying and responding to normal / abnormal network functions (NFs) and normal / abnormal operation between NFs.
[0036] In 5G, a network architecture is defined that supports terminals, base stations (access), cores, and servers in an end-to-end manner. Unlike LTE (4G), where individual nodes (e.g., S-GW, P-GW, etc.) perform control signaling and data transmission and reception functions in a combined manner, the network architecture is defined as dividing functions into a domain of control signaling functions (control plane) and a domain of data transmission and reception functions (user plane).
[0037] In 5G, the nodes of the control plane (CP) can be defined as follows: Access and Mobility Management Function (AMF), which controls the radio access of terminals; Policy Control Function (PCF), which manages and controls policies such as terminal information, subscription service information for each terminal, and billing; Session Management Function (SMF), which controls and manages the sessions used for data services by each terminal; Network Exposure Function (NEF), which is responsible for sharing information with external networks; Unified Data Management / Authentication Function (UDM / AUSF), which manages and controls the authentication of subscriber databases and users; Network Storage Function (NRF), which performs the function of managing and controlling information about each network function (NF) within the network; Billing Function (CHF), which processes billing for subscribers; and Network Data Analysis Function (NWDAF), which performs the function of collecting and analyzing various network data.
[0038] In 5G, a node in the user plane (UP) is defined as a user plane function (UPF), which, based on the control (interoperability) of the session management function (SMF), sends and receives data between the terminal and a server on an external service network (e.g., the Internet) through a session with the terminal.
[0039] In 5G, the control nodes of the control plane and the data nodes of the user plane can be collectively referred to as network functions (NFs).
[0040] In other words, 5G defines network functions (NFs) that perform specific functions in the control plane and user plane, and NFs are defined as interoperable with each other by using service-based interfaces (SBIs).
[0041] In addition, in recent years, research has been conducted on configuring the UE as an NF by evolving the terminal (UE) to a 5G architecture and implementing it in the same way as the NF, so that not only the NF of the control plane and the user plane but also the UE (hereinafter referred to as UENF) can perform communication by consistently using the SBI.
[0042] This disclosure relates to techniques capable of identifying and responding to normal / abnormal operations of the aforementioned network functions (e.g., UENF, RANF, AMF, SMF, UPF, ...) and normal / abnormal operations between NFs.
[0043] In current B5G / 6G networks, there are a large number of network functions (NFs), and a large amount of signaling occurs due to communication via NF-based protocols or SBIs between NFs.
[0044] In addition, as the central office evolves into structures such as redundant / distributed deployments, the signaling volume during NF-to-NF communication in the commonly seen B5G / 6G network environment is much larger than the number of device types.
[0045] Furthermore, in B5G / 6G network environments, a large number of signaling storms may occur in the access and core networks due to abnormal NF operations, erroneous NF operations, and internal / external factors of NFs.
[0046] Figure 1 An example of a problematic scenario where a signaling storm occurs between NFs in the control plane is illustrated.
[0047] In communication technologies including 5G, normal call processing is one of the most important aspects for operators in terms of stability, risk management (RM), and customer quality improvement / maintenance.
[0048] However, in the current B5G / 6G standard, there is no method for detecting and responding to abnormal operations of NFs or abnormal operations between NFs or signaling storms.
[0049] In the current standard, it is assumed that NFs always operate "normally". However, as the number of NFs increases, abnormal operations of NFs, as well as abnormal operations between NFs and signaling storms, may occur due to errors, delays, sudden signaling, etc.
[0050] In other words, it is currently impossible to determine whether the operation of the NF itself or the operation during communication between NFs is normal / abnormal, which may ultimately lead to a decline in communication and quality of service for customers. Alternatively, to prevent this situation, significant resources are consumed, including substantial investment costs from operators, redundancy / triple redundancy of the NF system, and pre- and post-verification processes (work start-up).
[0051] In fact, many of the current failures of NF are caused by faults, errors or their unexpected operation, leading to a growing concern about the stability of the control plane (signaling) itself or the NF itself.
[0052] Therefore, this disclosure proposes a new technical method for identifying and responding to normal / abnormal operations of NFs and between NFs, in order to address various problem situations caused by the lack of measures in current standards.
[0053] The core of the new technical method proposed in this disclosure is to define a new analysis ID for use in this disclosure between the NF and the NWDAF, apply the information required for communication between the analysis NFs as input (into) to the NWDAF, and allow the NWDAF to output (perform outgoing operations) the analysis / prediction results obtained through internal analysis processing (e.g., AI / ML processing) and transmit them to the NF.
[0054] Here, NWDAF can be configured by the Business Support System / Operations Support System (BSS / OSS and O&M) responsible for business / operations and management, the Data Collection Coordination Function (DCCF) responsible for storing and connecting messages, the Analysis Data Storage Function (ADRF), the Message Passing Framework Adapter Function (MFAF), the Management Data Analysis Service (MDAS), and the Analysis Logic Function (AnLF) and Model Training Logic Function (MTLF) responsible for AI / ML.
[0055] In this disclosure, it may be assumed that NWDAF is capable of performing all of the above functions.
[0056] Here, the NWDAF proposed in this disclosure may have joint learning (joint / distributed learning model) or centralized model or both.
[0057] This disclosure can be applied to functional units in UE (UENF), base station (RANF), and core (CNF) (that is, all NFs (e.g., UENF, RANF, AMF, SMF, UPF, ...) in all mobile communications domains).
[0058] However, in the following description, for ease of explanation, the core NF will be mentioned to describe the specific implementation.
[0059] First, refer to Figure 2 The core features of this disclosure will be briefly described below.
[0060] like Figure 2 As shown, the technical methods proposed in this disclosure are applicable to all NF 10s (e.g., UENF, RANF, AMF, SMF, UPF, ...) and are suitable for communication between NF 10s (e.g., UENF, RANF, AMF, SMF, UPF, ...) and NWDAF.
[0061] Figure 2 The first NF, the second NF, ... and the Nth NF are illustrated as NF 10 for applying the technical method of this disclosure, and the local NWDAF 20 and the central NWDAF 30 are illustrated as NWDAFs for applying the technical method of this disclosure.
[0062] The difference between the local NWDAF 20 and the central NWDAF 30 lies solely in the fact that the local NWDAF is a component for rapidly collecting and processing real-time information and is implemented on a local area basis, while the central NWDAF 30 is implemented as a component for collecting and processing large amounts of non-real-time information.
[0063] In other words, this disclosure can be applied equally to local NWDAF 20 and central NWDAF 30, but the names may differ depending on their location and local role.
[0064] In other words, according to this disclosure, a new analysis ID can be defined between NF and NWDAF for use in this disclosure.
[0065] For example, as shown in Table 1 below, new analysis IDs can be defined to identify normal / abnormal NFs and normal / abnormal operations between NFs, such as signaling storms, error NFs, or abnormal behavior NFs.
[0066] [Table 1]
[0067]
[0068] However, in the following description, this disclosure will focus on “signaling storm”.
[0069] Of course, when analyzing ID names, you can generally use error NF or abnormal behavior NF depending on the purpose.
[0070] This disclosure relates to a new analysis ID for defining a “signaling storm” between NF 10 and NWDAF 20 or NWDAF 30 and a communication technique using the new analysis ID.
[0071] According to this disclosure, each NF 10 inputs (i.e. performs an ingress operation) to NWDAF 20 or NWDAF 30 based on the analysis ID of the “signaling storm” and transmits the information required by NWDAF 20 or NWDAF 30 to predict the anomalous state (e.g., the presence or absence of a signaling storm) (e.g., internal / external information, specific information specified by NWDAF 20 or NWDAF 30, etc.).
[0072] Therefore, in this disclosure, NWDAF 20 or NWDAF 30 can analyze internal / external or specific information from NF 10 through internal analysis processing (e.g., AI / ML processing) to predict anomalous states (e.g., the presence or absence of signal storms) of each NF 10 and between NF 10 (e.g., the first NF, the second NF, ... and the Nth NF).
[0073] The NWDAF 20 or NWDAF 30 can select and run one of a variety of algorithms (such as machine learning algorithms and deep learning algorithms) as internal analysis processing.
[0074] In other words, NWDAF 20 or NWDAF 30 can specifically predict abnormal states (e.g., the presence or absence of signal storms) by selectively requesting / obtaining specified information from the desired NF (10) and reanalyzing that specified information for detailed analysis / prediction when needed.
[0075] Additionally, in this disclosure, NWDAF 20 or NWDAF 30 can transmit the result by outputting the results of analyzing / predicting the abnormal states (e.g., the presence or absence of a signal storm) of each NF 10 and between NF 10s (performing an outgoing operation) to the NF 10 that needs to receive the result, thereby enabling the NF 10 to perform subsequent processes based on the prediction result.
[0076] Specifically, this disclosure proposes a specific communication technique between multiple NF / NWDAFs using an analysis ID that employs a “signaling storm”.
[0077] In this disclosure, one NF 10 is able to interoperate with multiple NWDAF 20 and NWDAF 30.
[0078] For example, such as Figure 2 As shown, each NF 10 can predict / determine whether the NF is in an anomalous state (that is, in a signaling storm) through the self-analysis of the NF (e.g., self-AI / ML).
[0079] In this scenario, each NF 10 can request prediction results from the local NWDAF 20 located near the NF to clarify the prediction / determination of the NF's anomalous state, and (additionally) request prediction results from the central NWDAF 30 if necessary.
[0080] Generally, the local NWDAF 20 indicates that the NWDAF responsible for predicting anomalous states (e.g., signaling storms) of NFs within the local area can be deployed close to NF 10 and perform rapid collection and analysis of real-time information (AI / ML) with small capacity, low processing or algorithmic constraints in order to quickly predict anomalous states (e.g., signaling storms).
[0081] Central NWDAF 30 refers to an NWDAF deployed in a wider range / area than the local NWDAF 20, and performs rapid collection and analysis (AI / ML) of large amounts of non-real-time information with relatively high capacity or high processing to accurately and specifically predict anomalous states (e.g., signaling storms).
[0082] For example, when NF 10 predicts / determines that NF is in an anomalous state (i.e., in a signaling storm) through NF self-analysis (e.g., self-AI / ML) and requests local NWDAF 20 to perform analysis on NF and send the result of the predicted anomalous state (e.g., signaling storm), local NWDAF 20 can analyze the relevant information fragments and perform the anomalous state (e.g., signaling storm) prediction process through internal analysis processing (e.g., AI / ML processing) to predict whether NF 10 is in an anomalous state (e.g., signaling storm).
[0083] In this scenario, the local NWDAF 20 can immediately transmit the prediction results obtained by predicting whether NF 10 is in an anomalous state (e.g., signaling storm) to NF 10, depending on the accuracy of the prediction results, or transmit them to NF 10 after additional analysis.
[0084] For example, if the prediction accuracy is high, the local NWDAF 20 can immediately transmit the prediction results to the NF10.
[0085] In contrast, if the accuracy of the prediction result is lower than the pre-configured reference value, the local NWDAF 20 can transmit the prediction result to NF 10, and at the same time transmit the necessary information to the central NWDAF 30, and additionally request the analysis of NF10 and the results of the prediction of abnormal states (e.g., signaling storms).
[0086] In this scenario, NF 10 can first perform subsequent processes based on the prediction results received from the local NWDAF 20, and then perform subsequent processes based on the prediction results that reflect "additional analysis and predictions performed by the central NWDAF 30" and are again transmitted from the local NWDAF 20.
[0087] Alternatively, if the accuracy of the prediction results is lower than the pre-configured reference value, the local NWDAF 20 may stop the following operations: transmitting the prediction results to NF 10, transmitting necessary information to the central NWDAF 30, and additionally requesting analysis and prediction results for NF 10 for abnormal states (e.g., signaling storms).
[0088] In this scenario, the local NWDAF 20 can transmit the prediction results from the local NWDAF and the prediction results reflecting the "additional analysis and predictions performed by the central NWDAF 30" to the NF 10, and the NF 10 can perform subsequent processes based on the prediction results.
[0089] As described above, this disclosure proposes specific and adaptive communication techniques between multiple NFs / NWDAFs, which instruct NWDAF 20 or NWDAF 30 to communicate with the NFs and NWDAFs based on the information analysis and prediction results performed by them.
[0090] Additionally, in this disclosure, if necessary, NF 10 can request the results of analysis and prediction of anomalous states (e.g., signaling storms) for NF by sending a request to both local NWDAF 20 and central NWDAF 30.
[0091] For example, NF 10 can request the results of analysis and prediction of abnormal states (e.g., signaling storms) for the NF from both local NWDAF 20 and central NWDAF 30 simultaneously, or it can consider resource or network conditions (e.g., load) to first request the results of analysis and prediction of abnormal states (e.g., signaling storms) for the NF from local NWDAF 20, and, if necessary or possible, also request the results of analysis and prediction of abnormal states (e.g., signaling storms) for the NF from central NWDAF 30.
[0092] In this scenario, if NF 10 requests the results of analysis and prediction of abnormal states (e.g., signaling storms) for NF only from local NWDAF 20, NF can perform subsequent procedures based on the prediction request received from local NWDAF 20. If NF requests the results of analysis and prediction of abnormal states (e.g., signaling storms) for NF from both local NWDAF 20 and central NWDAF 30, NF can perform subsequent procedures based on the prediction request with higher accuracy from both sources.
[0093] As described above, this disclosure proposes specific and adaptive communication techniques between multiple NFs / NWDAFs, which enable NF 10 to communicate with multiple NWDAFs 20 and NWDAF 30 to obtain results predicting anomalous states (e.g., signaling storms) of a particular NF (e.g., the NF itself or another NF).
[0094] Ultimately, this disclosure implements specific technical configurations that can identify and adaptively respond to normal / abnormal NFs, normal / abnormal operations between NFs, signaling storms, etc. (communication technology between multiple NFs / NWDAFs for defining and using a new analysis ID between NFs and NWDAFs).
[0095] In other words, the communication technology implemented in this disclosure for defining and using a new analysis ID between multiple NFs / NWDAFs is an innovative technology that can quickly and easily identify / detect normal / abnormal operations in communication between a large number of NFs, and thus allows for optimal response / handling.
[0096] Figure 3 and Figure 4 The configuration of an NF device according to an embodiment of the present disclosure is illustrated.
[0097] In reference Figure 3 and Figure 4 Before providing a description, the NWDAF used in this disclosure will be described.
[0098] NWDAF is a 3GPP standard device that receives source information (data) for analysis directly from NF or via a data collection function (DCF) and performs the analysis. It may also include operations that transmit control requests (e.g., recommendations) to NF based on the analysis results (insights) (closed-loop feedback).
[0099] Such an NWDAF uses a service-based interface (SBI), so the basic request / response or subscription / notification scheme of the SBI can be used when sending or receiving control requests and collecting data with the NF.
[0100] In the current standard, standardization is underway for NWDAF, and the following is an example of the currently defined analysis ID.
[0101] · UE communication
[0102] UE mobility
[0103] • Expected UE behavior
[0104] • Abnormal UE behavior
[0105] • Observe the service experience
[0106] • QoS sustainability
[0107] User data congestion
[0108] • Network performance
[0109] As mentioned above, the communication technology between NF and NWDAF has not been specifically defined in the current standard, and specifically, there is no communication technology for identifying / detecting normal / abnormal NFs, normal / abnormal operation between NFs, and signaling storms and responding to / taking measures against them.
[0110] In contrast, this disclosure implements specific technical configurations for identifying / detecting normal / abnormal NFs, normal / abnormal operations between NFs, signaling storms, etc., and responding to / taking measures against them (communication technology for defining a new analysis ID between an NF and an NWDAF and using that new analysis ID).
[0111] To continue the description, Figure 3 It considers the graph for each NF 10 (e.g., UENF, RANF, AMF, SMF, UPF, ...), and Figure 4 The diagram is a representation of NWDAF 20 or NWDAF 30 considering the execution of the abnormal state prediction process of this disclosure.
[0112] First, refer to Figure 3 The NF device 10 according to an embodiment of the present disclosure may include: a memory (not illustrated) including instructions, and a processor (hereinafter, controller 11) configured to execute instructions to request prediction results obtained by performing an abnormal state prediction process by transmitting information to be used for analysis to an NWDAF configured to perform an abnormal state prediction process by information analysis, wherein the processor selects a specific NWDAF from a plurality of NWDAFs and transmits the information based on the information to be transmitted.
[0113] The controller 11 can be configured to receive prediction results from the NWDAF by predicting anomalous states associated with a specific NF, and to perform subsequent processes based on the prediction results.
[0114] In this disclosure, each NF 10 or NWDAF 20 or NWDAF 30 is equipped with an SBI module for sending and receiving SBI messages, and the SBI module essentially performs input (receive or enter) / processing (NF process) / output (send or go out).
[0115] Here, the interface of the SBI module can refer to the message defined in SBI (SBI message), and its protocol can refer to data packets including application layer headers, such as UDP / IP, TCP / IP, HTTP, HTTP / 2, HTTP / 3, and QUIC.
[0116] According to this disclosure, the controller 11 in NF 10 can be configured to receive prediction results obtained by predicting abnormal states associated with a specific NF, and to perform subsequent processes based on the prediction results.
[0117] Here, abnormal states can include signaling storms caused by signals (signaling / transactions) generated in one or more NFs, or failures (errors / behavioral anomalies) in a specific NF or between NFs.
[0118] A specific NF can refer to the NF for which NF 10 has made a prediction, or to the NF within the range for which NF 10 has made a prediction.
[0119] In other words, according to this disclosure, each NF 10 (controller 11) can determine whether NF 10 wants to know whether there is an abnormal state of the NF (NF 10 itself or another NF) or NF range for it, and request NWDAF 20 or NWDAF 30 to transmit the prediction results, and can make the request based on the analysis ID of the "signaling storm".
[0120] Therefore, the controller 11 in NF 10 can receive predictions from NWDAF 20 or NWDAF 30 by predicting anomalous states (e.g., signaling storms) related to a specific NF or a previously requested range of NFs for which predictions have been requested, and receive the predictions based on the analysis ID of the “signaling storm”.
[0121] Then, the controller 11 in NF 10 can execute subsequent processes based on the received prediction results.
[0122] As described above, this disclosure implements a communication technology between NF and NWDAF based on a newly defined analysis ID (e.g., the analysis ID of a “signaling storm”).
[0123] Reference Figure 5 For example, when NWDAF 20 or NWDAF 30 requests specific information from NF 10, NF 10 is the producer NF, and NWDAF 20 or NWDAF 30 is the consumer NF.
[0124]
[0125] When NF 10 wants to know the prediction results for the abnormal state of a specific NF and requests the prediction results from NWDAF 20 or NWDAF 30, NWDAF 20 or NWDAF 30 is the producer NF and NF 10 is the consumer NF.
[0126]
[0127] Here, according to SBI, the request scheme between NF and NWDAF can be a request / response scheme or a subscription / notification scheme.
[0128] Figure 5 The example illustrates a request operation where NWDAF 20 or NWDAF 30 is the producer NF and NF 10 is the consumer NF.
[0129] For example, Figure 5(A) illustrates the following operation: via a subscription / notification scheme, NF 10 determines that it wants to know whether there is an NF (NF 10 itself or another NF) or NF range for which there is an anomalous state, requests NWDAF 20 or NWDAF 30 to transmit the prediction result (Nnwdaf_AnalyticsSubscription_Subscribe), and then receives the prediction result from NWDAF 20 or NWDAF 30 (Nnwdaf_AnalyticsSubscription_Notify).
[0130] In addition, such as Figure 5 As shown in (B), through the request / response scheme, NF 10 can determine that NF 10 wants to know whether there is an abnormal state of NF (NF 10 itself or another NF) or NF range for it, request NWDAF 20 or NWDAF 30 to transmit the prediction result (Nnwdaf_AnalyticsInfo_Request), and immediately receive the prediction result from NWDAF 20 or NWDAF 30 (Nnwdaf_AnalyticsInfo_Request response).
[0131] Prediction results (insights) transmitted from NWDAF 20 or NWDAF 30 (which is the NF that performs the anomaly prediction process through information analysis) can be transmitted based on a specific analysis ID newly defined for the anomaly prediction process (see Table 1).
[0132] In other words, the prediction results transmitted from NWDAF 20 or NWDAF 30 can be transmitted based on the analysis IDs (such as signaling storms, error NFs, and abnormal behavior NFs) that are newly defined between NF and NWDAF for the purposes of this disclosure.
[0133] However, the following description of the implementation will focus on "signaling storm" as an abnormal state as described above.
[0134] Specifically, as described above, the controller 11 in NF 10 according to this disclosure can determine the NF (NF 10 itself or another NF) or NF range that the controller wants to know about the presence of an anomalous state (e.g., signaling storm) for it, and request (i.e. subscribe) its prediction results from NWDAF.
[0135] In the following description, for ease of description, an implementation of analyzing and requesting whether NF 10 itself is in an abnormal state (e.g., signaling storm) will be described.
[0136] As described above, when the controller 11 of NF 10 requests analysis and prediction results based on the execution of an anomaly prediction process for NF 10 itself, the controller can select a specific NWDAF from multiple NWDAFs based on the information to be used for the current analysis in the NWDAF and send the request to the specific NWDAF.
[0137] Specifically, the processor (that is, the controller 11) can be configured to select a particular NWDAF from a plurality of NWDAFs by using at least one of the following as criteria: whether the information to be used (transmitted for) the current analysis in the NWDAF is real-time or non-real-time data, the estimated processing time consumed by the analysis information, and the capacity required for the analysis information.
[0138] For example, if the information to be used (transmitted for) the current analysis corresponds to the type of real-time data, the controller 11 of NF10 can select a local NWDAF 20 located near NF10 as a specific NWDAF from among multiple NWDAFs and send a request to the local NWDAF 20.
[0139] Alternatively, if the estimated processing time consumed by the analysis for the information to be used (transmitted for the current analysis) is longer than the reference time, or if the capacity required for the analysis information is greater than the reference capacity, the controller 11 of NF 10 may select the central NWDAF 30 as the specific NWDAF from a plurality of NWDAFs and send a request to the central NWDAF 30.
[0140] Additionally, the controller 11 of NF 10 can be configured to consider resource or network conditions (e.g., load) to first select local NWDAF 20 as a specific NWDAF and send a request to local NWDAF 20, and thereafter, if necessary or possible, also select another NWDAF (e.g., another local NWDAF 20 or central NWDAF 30) as a specific NWDAF and send a request to central NWDAF 30.
[0141] In a specific example, when the controller 11 of NF 10 receives the prediction result of an abnormal state prediction process performed by requesting analysis (transmitted) information based on the current prediction result from a specific NWDAF (e.g., local NWDAF 20), the controller may select another NWDAF (e.g., another local NWDAF 20 or central NWDAF 30) from among the multiple NWDAFs as the specific NWDAF based on the prediction result, and request the prediction result from that other NWDAF.
[0142] For example, when the controller 11 of NF 10 receives a prediction result from the local NWDAF 20, which is obtained by analyzing and predicting whether NF 10 itself is in an abnormal state (e.g., signaling storm), the controller can execute subsequent processes based on the prediction result.
[0143] In this situation, there may be a scenario where NF 10 is unable to perform subsequent processes based on the current prediction results.
[0144] If it is determined that the subsequent process cannot be performed based on the current prediction results, the controller 11 of NF 10 can determine that it is necessary to re-request the prediction results for performing alternative subsequent processes.
[0145] Therefore, the controller 11 of NF 10 can be configured to: if it is determined that subsequent processes cannot be performed based on the current prediction results, select another NWDAF (e.g., another local NWDAF 20 or central NWDAF 30) from among the multiple NWDAFs as the specific NWDAF, re-request the prediction results from the other NWDAF for performing the alternative subsequent processes (and also transmit the information required for analysis if necessary), and perform subsequent processes based on the prediction results received from the other NWDAF (e.g., another local NWDAF 20 or central NWDAF 30).
[0146] Obviously, if it is determined that the subsequent process cannot be performed based on the current prediction results, the controller 11 of NF 10 can notify the local NWDAF 20 of the situation that the subsequent process cannot be performed, re-request the prediction results from another NWDAF for performing an alternative subsequent process (and also transmit the information required for reanalysis if necessary), and perform the subsequent process based on the re-received prediction results.
[0147] As described above, this disclosure proposes specific and adaptive communication techniques between multiple NFs / NWDAFs, which enable NF 10 to communicate with multiple NWDAFs 20 and NWDAF 30 to obtain results predicting anomalous states (e.g., signaling storms) for the NF itself.
[0148] In this disclosure, each NF 10 (e.g., UENF, RANF, AMF, SMF, UPF, ...) can be implemented in the form of VNF / VM or CNF / Pod, and regardless of the form, internal and external information of the NF can be measured / extracted and transmitted to NWDAF 20.
[0149] Here, the internal information of NF 10 refers to information about the internal processing status within NF 10.
[0150] For example, "internal information of the NF" can include all information that can be obtained in NF 10, such as information about ongoing call processing, subscriber (group) status information and system resource (CPU / memory / disk) utilization, latency information about file I / O, load level or capacity relative to design limits, resource information pools or routing tables for call processing.
[0151] Additionally, the internal information of NF 10 can measure / include the OAM domain and control plane processing logic managed by NF 10.
[0152] The internal information of NF as described above can be graphically represented as shown in Table 2 below. That is, the internal information of NF 10 includes the information shown in Table 2 and can be measured / updated / transmitted under various conditions (such as periodic conditions or conditions that have reached a specific threshold). ).
[0153] [Table 2]
[0154]
[0155] When defining this internal information of NF as an implementation method, the internal information can be composed of a combination of the following information fragments:
[0156] • Context count: The amount of unit information (subscriber, session, profile, etc.) currently contained in the system.
[0157] • Context state: The main state information of each unit of information currently contained in the system.
[0158] • Completion (success / attempt) rate for each call process: The primary success rate during the system's internal processing in the primary call processing associated with the system (e.g., overhead elements such as retransmissions between pods in the system).
[0159] • Resource usage: The current load (or utilization) of the main system resources (CPU, memory, or disk).
[0160] • Processing latency: The time consumed by the system's internal processing during the main call processing associated with the system.
[0161] • Capacity / Load: Information on the overall system capacity (not a simple ratio, but a value indicating scale) and load.
[0162] • Location: This is the system's location information, which can be logical location information, physical location information, or operator-designated units.
[0163] • Minimum backoff time to normal state: The estimated time required to ensure that the load is reduced (or the system state changes back to the normal range of major factors).
[0164] • Includes at least one of the statistical information snippets related to configuration management (CM), performance management (PM), or fault management (FM).
[0165] In addition, external information of NF 10 can refer to information about the communication performed by NF 10 through network connection (that is, communication with another NF / UE / base station / ISP).
[0166] For example, external information of an NF can refer to information that can be obtained through communication between the first NF and the second NF, assuming that the first NF and the second NF are interconnected.
[0167] Additionally, for example, "external information of the NF" can include all information that can be obtained during the interworking / communication process, such as the number of messages sent or received / response time / success or failure (success rate) and health check results, status information received from the second NF (load, capacity, status, cause, etc.), the number of TCP connections created for interworking, sequence ID#, and the number of contexts processed by the first NF through interworking with the second NF (absolute value or ratio).
[0168] Therefore, the external information of the NF in this disclosure may include some or all of the status information of the interfaces (hereinafter referred to as communication interfaces) for the input (in) and output (out) of the NF for each signaling type, including the speed, load and consistency.
[0169] More specifically, the signaling type of the communication interface for configuring external information of the NF can be defined as follows:
[0170] • Physical type (e.g., wired) USB type, fiber optic cable, copper cable, etc., wireless Wi-Fi and physical modules (e.g., optical transceivers and RJ45 transceivers).
[0171] • Physical port location (e.g., port 1 or port 2)
[0172] • Physical / logical combination information (e.g., a combination of 4 10 GbE LAN cables and active-standby / active-active redundancy structures)
[0173] • Logical identification information (e.g., Usb1, Eth1, wlan1, br1, etc.)
[0174] The speed of the communication interface for configuring external information in NF can be defined as follows:
[0175] • Bandwidth (e.g., 1 Gb / s, 10 Gb / s, etc.)
[0176] • Transmission rate (e.g., throughput of 10 Mb / s, 1 Gb / s, etc.)
[0177] • Uplink / Downlink distinction
[0178] Total number of sessions being processed
[0179] • Categorization of each detailed message within each session being processed (e.g., categorization by service name, operation, and attribute).
[0180] The payload of the communication interface for configuring external information of NF can be defined as follows:
[0181] • Status information regarding inbound or outbound resource loads related to interface processing (e.g., CPU / memory / storage usage).
[0182] • Status information about incoming or outgoing interface loads connected to and related to interface processing (e.g., transactions per second (TPS) or connections per second (CPS)).
[0183] • Sudden information (e.g., signaling to TPS or CPS, such as Min / Avg / Max)
[0184] • One-way and two-way delay values (e.g., RTT)
[0185] The consistency of the communication interface for configuring external information of NF can be defined as follows:
[0186] • Alarms, errors, fault causes, and reasons for each signaling message type
[0187] • Signaling message verification or confirmation information
[0188] Overload information
[0189] • Retransmission count information
[0190] • Handle delay information between requests and confirmations
[0191] For example, the speed of the communication interface for configuring external information of NF 10 is described as follows.
[0192] NF 10 can classify various signaling types (e.g., SBI, non-SBI, or OAM) for input (in) and output (out) of the control / management plane sent or received via the communication interface, and extract the rate of input (in) to NF 10 for each signaling type.
[0193] For NF 10, the velocity rate can follow a specific Poisson distribution, and the corresponding queuing situation can be extracted together.
[0194] In other words, from the perspective of NF 10, it is possible to extract the rate of bursts that occur at a specific time or period, or the rate that requires a long processing time within a specific period.
[0195] For example, NF 10 can assume that it receives 128 specific SBI heartbeat messages per second from another NF, and that it may take a predetermined time to process the heartbeats normally, after which the NF can process the content and send a reply to the other NF.
[0196] All these values can be measured / extracted as “external information of NF” and transmitted to NWDAF 20 and / or NWDAF 30.
[0197] As described above, NF 10 (controller 11) in this disclosure can periodically or as needed measure / extract the internal / external information of the aforementioned NF, and can periodically or as needed transmit it to NWDAF 20 and / or NWDAF 30.
[0198] In this scenario, NF 10 (controller 11) in this disclosure can input (i.e., perform an ingress operation) the internal / external information of the NF measurement / extraction based on the analysis ID of the “signaling storm” and transmit it to NWDAF 20 and / or NWDAF 30.
[0199] For reference, you can use NF 10 NRF NWDAF (NWDAF 20 or NWDAF 30 or local NWDAF 20) The transmission is performed in the order of NF 10 (Central NWDAF 30), but for the sake of simplicity in this disclosure, it should be understood that it is performed in the order of NF 10. NWDAF (NWDAF 20 or NWDAF 30 or local NWDAF 20) The sequential transmission of the central NWDAF 30.
[0200] The importance of this internal / external information in NF lies in the fact that the actual causes, analysis, and prediction of signaling storms may require both internal and external information from NF.
[0201] In addition, the various information values included in the internal / external information of NF are only relevant to information that may be very helpful in detecting signaling storms.
[0202] Specifically, the external information of the first NF can be related to information sent to / received from the first NF and associated with another NF (the second NF, ... and the Nth NF).
[0203] For example, the TPS / CPS of an SBI message received from another NF (second NF, ..., and Nth NF), along with subsequent information indicating the severity of bursts or delays occurring in other NFs (second NF, ..., and Nth NF) via TPS / CPS, can be transmitted to the NWDAF (NWDAF 20 or NWDAF 30 or local NWDAF 20). Central NWDAF 30).
[0204] Additionally, the NF 10 (controller 11) in this disclosure can input (i.e., perform its input) and transmit only the specific information of the NF 10 specified by the NWDAF 20 or NWDAF 30 (instead of the internal / external information described by the NF) based on the analysis ID of the "signaling storm" to the NWDAF 20 or NWDAF 30.
[0205] For example, autonomously based on NF 10’s local policy, or based on interactions with NWDAF 20 or NWDAF 30, or requests (or subscriptions) from NWDAF 20 or NWDAF 30, NF 10 can filter specific information based on the analysis ID of the “signaling storm” and input it (i.e., execute its input) and send it to NWDAF 20 or NWDAF 30.
[0206] If filtering is performed by NF 10 as described above, it is not necessary to transmit all information to NWDAF 20 or NWDAF 30. Thus, NF 10 can obtain only the specific information that has passed the filtering and transmit it autonomously according to the network state or the state of NF 10.
[0207] In the event of interaction with or a request (or subscription) from NWDAF 20 or NWDAF 30, when NWDAF 20 or NWDAF 30 requires additional information (specific information) about NF 10, NWDAF can... NF requests (or subscribes to) specific information in the direction of NF.
[0208] Reference Figure 4The NFDAF20 or NFDAF30 according to embodiments of the present disclosure may include: a memory (not shown) including instructions, and a processor (hereinafter, processing unit 22) configured to execute instructions to receive information from each NF for an anomaly prediction process, perform the anomaly prediction process by analyzing the information, and transmit the prediction results of anomalies associated with a particular NF to a consumer NF so that the consumer NF can perform subsequent processes based on the prediction results.
[0209] Then, the processing unit 22 can be configured to transmit information to another NWDAF or request additional information from another NWDAF based on the prediction results of the abnormal state associated with a specific NF.
[0210] The abnormal state prediction process related to a specific NF, performed by the processing unit 22 of NFDAF 20 or NFDAF 30, can be performed by analyzing the internal and external information of the specific NF.
[0211] Specifically, the processing unit 22 can perform an abnormal state prediction process by analyzing internal / external information or specific information from each NF10 through analysis processing (e.g., AI / ML processing), thereby analyzing / predicting the abnormal states of each NF10 and between NF10s (e.g., the presence or absence of signal storms).
[0212] Additionally, when a request is transmitted / received from NF 10 or another NWDAF 20 or NWDAF 30 for predicting the result of an abnormal state (e.g., signaling storm) of a specific NF (e.g., NF 10 itself or another NF), the processing unit 22 can perform an abnormal state prediction process by information analysis according to the request, thereby analyzing / predicting the abnormal state (e.g., the presence or absence of a signaling storm) of a specific NF (e.g., NF 10 itself or other NFs).
[0213] In this case, the analysis processing (e.g., AI / ML processing) used by processing unit 22 can employ centralized or decentralized AL / ML algorithms. These algorithms can be classified into four types.
[0214] • Supervised learning, unsupervised learning, semi-supervised learning, and reinforcement learning
[0215] The detailed algorithms can utilize linear regression, logistic regression, decision trees, SVM, Naive Bayes, KNN, K-means, random forest, dimensionality reduction, gradient boosting, or AdaBoosting and XGBoost. The algorithm can be dynamically modified based on various data types, characteristics / features, and real-time / non-real-time properties or periods.
[0216] Therefore, in this disclosure, the inputs (entries) for information analysis applied from each NF 10 to NWDAF 20 or NWDAF 30 can be applied based on the analysis ID of the “signaling storm” and can include internal / external information of each NF 10, specific information of NF 10 specified by NWDAF 20 or NWDAF 30, request or subscription messages from NF 10 for prediction results of a specific NF (NF 10 itself, another NF, or NFs within the NF range), or request or subscription messages from another NWDAF 20 or NWDAF 30 for information transmission and prediction results.
[0217] Then, in this disclosure, the analysis ID output based on "signaling storm" is the output (outgoing) generated by NWDAF 20 or NWDAF 30.
[0218] As described above, the output (outgoing) generated by NWDAF 20 or NWDAF 30 may include request or subscription messages requesting the transmission of internal / external information for each NF10, request or subscription messages requesting the transmission of specific information for NF10, response or notification messages transmitting prediction results (insights) obtained by predicting abnormal states, or response or notification messages transmitting information or prediction results requested by another NWDAF 20 or NWDAF 30.
[0219] Therefore, the processing unit 22 of NWDAF 20 or NWDAF 30 can perform an anomaly prediction process that analyzes the internal / external information of each NF 10 or the specific information of NF 10 or the information transmitted with the request based on the analysis ID of the “signaling storm”, thereby analyzing / predicting the anomaly state of each NF 10 and between NF 10 (e.g., the presence or absence of a signaling storm).
[0220] Then, the processing unit 22 of NWDAF 20 or NWDAF 30 can output / transmit the prediction results (insights) for a specific NF suspected of being in an anomalous state (e.g., signaling storm) to the NF 10 that has previously requested the transmission of prediction results (insights) for the specific NF based on the analysis ID of the "signaling storm".
[0221] Processing unit 22 can request each NF 10 to transmit internal / external information based on the analysis ID of the "signaling storm", and receive internal / external information from each NF 10 based on the analysis ID of the "signaling storm".
[0222] In addition, processing unit 22 can request additional specific information (more detailed statistics (5 minutes > 1 minute), specific data (cause-specific statistics, logs, and more frequent periodic updates) from a specific NF (or another associated NF) based on the analysis ID of the “signaling storm”, depending on the condition (e.g., accuracy) that a specific NF is suspected of having during the abnormal state prediction process.
[0223] Therefore, the processing unit 22 can receive additional specific information based on the analysis ID input / acquisition and perform a reanalysis / abnormal state prediction process to predict in detail the abnormal state of a specific NF (e.g., the presence or absence of a signaling storm).
[0224] Alternatively, the processing unit 22 may transmit information to another NWDAF 20 or NWDAF 30 or request additional information from another NWDAF 20 or NWDAF 30 based on the prediction results derived by performing an abnormal state prediction process for a specific NF.
[0225] Specifically, the processing unit 22 can be configured to control the transmission of information to another NWDAF 20 or NWDAF 30 by using at least one of the accuracy, impact, and urgency of the prediction result obtained by performing an abnormal state prediction process for a specific NF as a criterion.
[0226] For example, processing unit 22 can be configured to transmit necessary information to another selected NWDAF (another local NWDAF 20 or a central NWDAF 30) when it is determined that the accuracy of the prediction result is lower than a pre-configured reference value or its impact is high. This information can be used to derive the final prediction result for a specific NF during the abnormal state prediction process, which is performed by another NWDAF (another local NWDAF 20 or a central NWDAF 30).
[0227] In this scenario, the final prediction result of the abnormal state prediction process performed for a specific NF in another NWDAF (another local NWDAF 20 or a central NWDAF 30) is transmitted to NF 10. NF 10 can then receive the final prediction result directly requested by the NF from another NWDAF (another local NWDAF 20 or a central NWDAF 30) that collaborates / interoperates with NWDAF 20 or NWDAF 30, and perform subsequent processes accordingly.
[0228] As another example, processing unit 22 can be configured to request and receive necessary additional information from another selected NWDAF (another local NWDAF 20 or central NWDAF 30) when it is determined that the accuracy of the prediction result is lower than a pre-configured reference value or its impact is high, and then re-execute the abnormal state prediction process, and even analyze the additional information of the specific NF, to derive the final prediction result and transmit it to NF 10.
[0229] In this scenario, NF 10 can receive the final prediction result derived from collaboration / interoperability between another NWDAF (another local NWDAF 20 or central NWDAF 30) directly requested by NF and NWDAF 20 or NWDAF 30, and perform subsequent processes accordingly.
[0230] In addition, NWDAF 20 or NWDAF 30 (processing unit 22) can perform anomaly prediction process by classifying the analysis / prediction range (signaling storm area) in which the process is performed as signaling storm range, duration, and service impact failure prediction range.
[0231] In this context, the analysis / prediction range can be distinguished by region ID, and for example, by slice, NF cluster, or specific UE and RAN location (ECGI, NCGI, or GPS).
[0232] Therefore, in this disclosure, each NF 10 can request (or subscribe to) prediction results from NWDAF 20 or NWDAF 30 by using the region ID of the NF range for which the NF wants to know whether there is an anomalous state.
[0233] As described above, the prediction results (analysis output) output by NWDAF 20 or NWDAF 30 in this disclosure may have information indicating the accuracy of the prediction results and subsequent processes for responding to anomalous states of the prediction (e.g., signaling storms).
[0234] For example, the prediction results (analysis output) can be divided into three parts: prediction, required action, and recommended action.
[0235] • Forecast: This indicates the accuracy of the signaling storm's occurrence. Specific values can be as follows:
[0236] - Storm time, for example, 2023-04-12, 17:45:48:700
[0237] - Storm duration, for example, 00:05:03
[0238] - Accuracy, for example, 85% (for reference, this can be achieved by taking into account the final ROC curve value of the accuracy and the recall value).
[0239] - Process Information: This includes a description of the AI / ML type, algorithm, parameters used to extract predicted values, equations, formulas, etc. This information can be referenced from NF 10, and parameter updates can be requested separately if necessary.
[0240] - Signaling Storm Area: This indicates filtered information about a specific NF cluster, such as the location of a specific NF in a group, NW slice, UE / RAN location, etc. This information exists because there may be multiple core networks, base stations, and UEs, and the NF may want to know whether an abnormal state (e.g., a signaling storm) exists only for a specific NF range. Additionally, signaling storms can occur throughout the entire core network, across multiple core networks, or partially within the core network.
[0241] The predictions in this disclosure need to always be included in the prediction results (analysis output).
[0242] Therefore, each NF 10 that receives the prediction results (analysis output) from NWDAF 20 or NWDAF 30 can perform subsequent processes based on the prediction results (analysis output) by referring to the prediction and simultaneously following the two actions described below included in the prediction results (analysis output).
[0243] Of the two actions, "required" is mandatory, and "recommended" can be chosen by NF last.
[0244] • Required actions: This indicates the necessary actions for subsequent processes to minimize the impact of signaling storms.
[0245] NF 10, which receives prediction results (analysis output) from NWDAF 20 or NWDAF 30, must execute subsequent processes with the highest priority according to the (mandated) required actions. For example, the required actions can be defined by the following action plan.
[0246] - Cancel NF# NF#: This excludes a specific NF (where a signaling storm occurs) from a specific call processing (procedure) (thus avoiding the effects of a signaling storm).
[0247] - Reduced PPS: This reduces the speed of a specific target NF (packets per second, transactions per second, or connections per second).
[0248] - Overload protection: This performs overload control for specific UEs, each region / location, and each base station ID. This can be achieved using various backoff timers to adjust the rate / interval of registration (attachment) or session establishment / modification for specific UEs / sessions (data, IMS, etc.).
[0249] - Rejection: This can be adjusted by varying the message indication to send a specific reason (EMM, ESM, SIP, or SBI reason) as a failure response to a specific NF / UE (for a specific procedure).
[0250] - Configuration: This can transmit local and global configuration and settings information to specific NF / UEs to add / change / remove connectivity schemes, NF / UE capabilities, high / medium / low processing modes, and internal / external information in order to change parameters related to the process scheme.
[0251] • Recommended Action: This instruction is recommended as a follow-up action to the impact of signaling storms.
[0252] NF 10, which receives prediction results (analysis output) from NWDAF 20 or NWDAF 30, can selectively perform recommended actions.
[0253] Recommended actions can include the same information as the desired action, but are typically used when prediction accuracy is low.
[0254] As described above, this disclosure implements a specific technical configuration that enables the identification and optimal handling of normal / abnormal NFs, normal / abnormal operations between NFs, signaling storms, etc., by implementing a communication technology between NFs and NWDAFs (which is used to define and use a new analysis ID for predicting abnormal states (e.g., signaling storms) between NFs and NWDAFs) and specifically a communication technology between multiple NFs / NWDAFs.
[0255] The scope of the NFs disclosed herein is not limited to the core NFs.
[0256] In other words, abnormal conditions (e.g., signaling storms) may occur in the non-access stratum (NAS) of the UE (UENF), and may also occur in the CU-CP, CU-UP, DU, and RU (e.g., E1, F1-c, or F1-u) of the base station (RANF).
[0257] If the UE (UENF) is used as the NF device 10 of this disclosure, the UENF 10 can be implemented as an NF including a communication unit (hereinafter, a service-based interface (SBI) module) for performing communication using SBI messages based on the SBI between NFs.
[0258] Therefore, all the embodiments described above in this disclosure can be applied in the same way to UEFE (UE Function) and RANF (Base Station Function), and from the perspective of the UE, base station, and core, the scope of application of this content is common to all NFs. That is to say, the NF device 10 applying this disclosure can be a UE, i.e., a UENF, which is implemented as an NF as described above.
[0259] However, the following description mainly refers to network functions (NFs or cores) that can be publicly applied.
[0260] In addition, since the UE (UENF) sends / receives input / processing / output information and the status for signaling storms during the operation between the UE (UENF) and NAS (MM core), the UE (UENF) can also determine the operation triggers / conditions for signaling storm processing.
[0261] If a UE (UENF) is used as an NF device 10 applying this disclosure, a large number of UENFs 10 may cause a signaling storm.
[0262] For example, UENF 10 can receive prediction results (analysis output) from NWDAF 20 or NWDAF 30, which are obtained by analyzing / predicting abnormal states (e.g., signaling storms) based on the UE (i.e., UENF 10) during handover, when entering a specific coverage area, or based on the UE's UE slice information, emergency mode, or battery status analysis.
[0263] The UENF 10, having received the prediction results (analysis output), can “select” the base station / core network based on the presence or absence of a signaling storm, and can simultaneously continuously notify the core NWDAF 20 or NWDAF 30 of information about the UENF 10 (e.g., internal / external information, specific information specified by NWDAF 20 or NWDAF 30, etc.).
[0264] In other words, UENF 10 can select the core network based on signaling storms (i.e., congestion levels) in either UE-triggered or network-triggered manner.
[0265] As described above, this disclosure implements a communication technology between NFs and NWDAFs and between multiple NFs / NWDAFs (this communication technology is used to define a new analysis ID for predicting anomalous states (e.g., signaling storms) between NFs and NWDAFs, and to analyze / predict anomalous states such as signaling storms by using this ID) to achieve a specific technical configuration that can identify and respond to normal / abnormal NFs (e.g., UENF, RANF, AMF, SMF, UPF, ...), normal / abnormal operation between NFs, signaling storms, etc.
[0266] Therefore, this disclosure yields the following effects: the ability to detect anomalies in NFs, abnormal operations between NFs, and signaling storms, and to optimally address these anomalies, as well as to avoid potential degradation in communication and quality of customer experience.
[0267] The following describes a signaling control method performed by an NF (communication technology between the NF and the NWDAF) according to an embodiment of the present disclosure.
[0268] Figures 6 to 10 Each illustrates an implementation of a call flow based on a signaling control method performed by the NF (i.e., the communication technology between the NF and the NWDAF) according to this disclosure.
[0269] Before describing, Figures 6 to 10 Although not illustrated for ease of description, it should be understood that when sending and receiving messages between NF and NWDAF, a new analysis ID is used to predict abnormal states (e.g., signaling storms).
[0270] In response to Figures 6 to 10 In the following description, for ease of description and illustration, an NWDAF 20 is illustrated and described, and the NWDAF 20 may be a local NWDAF or a central NWDAF.
[0271] Reference Figure 6 , Figure 6 The procedure for searching for signaling storms via communication between NF and NWDAF is illustrated.
[0272] Figure 6 The process (A) is an implementation where NWDAF 20 corresponds to the consumer NF and the NF 10 that receives the current request corresponds to the producer NF.
[0273] For example, NWDAF 20 can request additional specific information (subscription, e.g., NF internal information request with filtering) from another NF or a desired NF based on conditions (e.g., accuracy) that are suspected of an anomalous state (e.g., signaling storm) of a particular NF during the anomalous state prediction process.
[0274] As mentioned above, each NF 10 may require significant resources to measure / extract the entire internal information.
[0275] Therefore, NWDAF 20 can initially determine what information is currently insufficient, and then request only the necessary information from NF 10. Thereafter, NF 10 measures / extracts the required / specified information from NWDAF 20 and transmits it to NWDAF 20.
[0276] Figure 6The process (B) is an implementation where NWDAF 20 corresponds to the producer NF and the NF 10 that receives the current request corresponds to the consumer NF.
[0277] From NF 10's perspective, NF 10 might want to know, for example, whether a signaling storm exists for a particular NF by determining the necessity of detailed detection of specific signaling. In this case, NF 10 could request NWDAF 20 to transmit predictions for the specific NF (subscription, e.g., signaling storm information input).
[0278] Therefore, when NWDAF 20 has completed the execution / analysis of the abnormal state prediction process for a specific NF requested by NF 10, NWDAF can return the prediction results (notification, e.g., signaling storm information output) (notification).
[0279] Then, NF 10 can perform subsequent processes based on the prediction results (notifications, such as signaling storm information output).
[0280] In this case, if necessary, NF 10 can again transmit the completion level (feedback / reward score) of the corresponding action to NWDAF 20, and NWDAF 20 can use this to identify the degree to which the corresponding subsequent actions have been performed and proceed in a closed loop.
[0281] Next, refer to Figure 7 In the event that NWDAF 20 performs the abnormal state prediction process and predicts / determines a signaling storm, NWDAF can transmit its current prediction results to NF 10 (e.g., the first NF) that has requested prediction results.
[0282] In this case, the prediction result (analysis output) must include the prediction, as well as at least one of the required action and the recommended action.
[0283] Figure 7 An implementation method for controlling the allowable ratio by adjusting the AdjustRatio is shown as a recommended action.
[0284] AdjustRatio is the adjustable range value of the backoff timer, and a random value obtained by increasing / decreasing the backoff timer value by a corresponding ratio is applied to prevent multiple overlapping request / access attempts from occurring simultaneously, thereby causing extended request / access attempts for a specific duration after the timer expires.
[0285] Therefore, as Figure 7As shown, NF 10 (e.g., the first NF 10), having received the current prediction result, adjusts the backoff timer value to allow only 50% of the request / access attempts from the UE and reject the remaining access attempts, thereby reducing the number of request / access attempts from the UE and allowing 100% of the request / access attempts after the backoff timer. In this case, since the signaling storm may have been resolved due to the reduced number of request / access attempts, most of the request / access attempts after the backoff timer are expected to succeed.
[0286] In addition, NF 10 (e.g., the first NF) can transfer the completion level (feedback / reward score) of the current recommended action to NWDAF 20 as needed.
[0287] Next, refer to Figure 8 In the event that NWDAF 20 is performing an abnormal state prediction process and predicting / determining a signaling storm, NWDAF can transmit its current prediction result to NF 10 (e.g., the first NF) that has requested the prediction result.
[0288] Figure 8 An implementation is shown as the recommended action to return a specific reason (reason: PLMN not allowed) as a failure response for a predetermined duration.
[0289] like Figure 8 As shown, NF 10 (e.g., the first NF) that has received the current prediction result can return a failure response for a specific reason (reason: PLMN not allowed) for the request / access attempt from the UE during a predetermined duration, thereby reducing the number of request / access attempts from the UE.
[0290] Then, NF 10 (e.g., the first NF) will again accept requests / access attempts from the UE normally after a predetermined duration, and most requests / access attempts are expected to succeed.
[0291] In addition, NF 10 (e.g., the first NF) can transfer the completion level (feedback / reward score) of the current recommended action to NWDAF 20 as needed.
[0292] Next, refer to Figure 9 In the event that NWDAF 20 performs the abnormal state prediction process and predicts / determines a signaling storm, NWDAF can transmit its current prediction results to NF 10 (e.g., the first NF) that has requested prediction results.
[0293] Figure 9 An implementation of rejecting messages from NF based on an NF backoff timer of 600s as the recommended action is shown.
[0294] like Figure 9 As shown, NF 10 (e.g., the first NF) that has received the current prediction result can not process and reject the message sent from the second NF based on the prediction result, and notify the second NF of a backoff timer equal to 600s.
[0295] Therefore, the second NF can exclude NF 10 (e.g., the first NF) from the message transmission target and communicate with the third NF in lieu of it by sending / receiving messages. After a backoff timer of 600 seconds expires, the second NF can send messages to NF 10 (e.g., the first NF) if necessary, and NF 10 (e.g., the first NF) can process the messages sent from the second NF normally after the NF backoff timer of 600 seconds expires.
[0296] Next, refer to Figure 10 In the event that NWDAF 20 performs the abnormal state prediction process and predicts / determines a signaling storm, NWDAF can transmit its current prediction results to NF 10 (e.g., the first NF) that has requested prediction results.
[0297] Figure 10 An implementation of a transmission guideline for controlling overload (e.g., rejecting only 50% of new messages when the CPU is at 70% or higher) is shown as a recommended action.
[0298] like Figure 10 As shown, if the CPU utilization is greater than 70% according to the overload control guidelines, the NF 10 that has received the current prediction result (e.g., the first NF 10) can only allow 50% of the new messages subsequently sent from the second NF and block / reject the remaining messages, and if the CPU utilization changes to 70% or less, then 100% of the new messages sent from the second NF are allowed again.
[0299] Next, a signaling control method performed by an NF (communication technology between multiple NFs / NWDAFs) according to an embodiment of this disclosure will be described.
[0300] Figures 11 to 16 The present disclosure illustrates implementations of call flows based on signaling storm conditions, which are performed according to signaling control methods executed by NFs (i.e., communication techniques between multiple NFs / NWDAFs).
[0301] Before describing, Figures 11 to 16 Although not illustrated for ease of description, it should be understood that a new analysis ID is used to predict anomalous states (e.g., signaling storms) when sending and receiving messages between NF and NWDAF, and between NWDAF and NWDAF.
[0302] First, refer to Figure 11 In the implementation, each NF 10 (first NF, second NF or third NF) can predict / determine whether the NF is in an abnormal state (that is, in a signaling storm) through self-analysis of NF (0-1) (e.g., self-AI / ML).
[0303] Additionally, each NF 10 (first NF, second NF, or third NF) can periodically or as needed measure / extract internal / external information of the NF and transmit it to the NWDAF (e.g., central NWDAF 30) (0-2).
[0304] In this process, the first NF can autonomously predict / determine that the first NF is in an abnormal state (i.e., signaling storm) and transmit the request for analysis of the first NF and the result of predicting the abnormal state (e.g., signaling storm) to the central NWDAF 30 (1).
[0305] In this case, the central NWDAF 30 can analyze relevant information and perform anomaly prediction process (e.g., signaling storm) through internal analysis processing (e.g., AI / ML processing) to predict whether the first NF is in an anomalous state (e.g., signaling storm) (2).
[0306] Then, when the first NF is predicted to be in an abnormal state (i.e., signaling storm), the central NWDAF 30 can transmit such analysis results to the first NF, and / or can transmit control requests (e.g., recommendations) to another NF (or local NWDAF 20) associated with the first NF (3), thereby mitigating the signaling storm state in the first NF through actions caused by the control requests (e.g., recommendations) (e.g., excluding the first NF from the selection targets) (4).
[0307] Figure 12 The call flow between NWDAFs as an implementation example is shown. Figure 12 The NWDAF 1, NWDAF 2 and NWDAF 3 shown in the example can each be a local NWDAF or a central NWDAF.
[0308] like Figure 12 As shown, the communication technology between NF and NWDAF for analyzing / predicting signaling storms according to this disclosure, as well as the communication technology between multiple NF / NWDAF, can also be applied to multi-core network environments (i.e., another network or a network with different PLMN numbers).
[0309] For example, such as Figure 12As shown, each of NWDAF 1, NWDAF 2 and NWDAF 3 can send and receive information and / or prediction results for analyzing and predicting anomalous states (e.g., signaling storms) to and from another NWDAF in a different network.
[0310] Therefore, if a signaling storm is identified targeting NWDAF 3 in core network 3, each of NWDAF 1 and NWDAF 2 can perform subsequent procedures by reducing the amount of traffic transmitted to core network 3 or by performing reselection to prevent transmission during a predetermined period.
[0311] Reference Figure 13 In another implementation, the NF corresponding to the consumer (e.g., UENF, RANF, AMF, SMF, UPF, ... or another NWDAF) can request the central NWDAF to transmit the prediction results (Analytics_Subscription, e.g., signaling storm information input) for a specific NF.
[0312] The central NWDAF can request information (e.g., information to be used for analysis or analysis / prediction results) required by the consumer to perform an anomaly prediction process for a specific NF from each local NWDAF (hereinafter, the first cluster local NWDAF and the second cluster local NWDAF).
[0313] Based on such a request from the central NWDAF, each of the first cluster local NWDAF and the second cluster local NWDAF can obtain internal / external information (subscription / notification) from the first NF and the second NF belonging to its respective cluster, and analyze the information to perform anomaly prediction process (preliminary AI / ML analysis) for the specific NF.
[0314] If it is determined that the prediction result (e.g., accuracy) of the current anomaly prediction process is at a level that indicates the result can be transmitted to the central NWDAF, then each of the first cluster local NWDAF and the second cluster local NWDAF can transmit the information fragments already used for AI / ML analysis and the current prediction result (learning set / outcome information) to the central NWDAF (AI / ML learning data).
[0315] If it is determined that the prediction results are not at a level where the results can be transmitted to the central NWDAF, each of the first cluster local NWDAF and the second cluster local NWDAF can determine the additional information needed to improve the accuracy of the analysis, and request and obtain the necessary additional information from the other NWDAF (e.g., the central NWDAF).
[0316] Each of the first cluster-local NWDAF and the second cluster-local NWDAF can even analyze the additional information obtained to perform anomaly prediction processes for a specific NF (nth AL / ML analysis).
[0317] If an anomalous state (i.e., signaling storm) is identified / detected as a result of performing an anomalous state prediction process for a specific NF, then each of the first cluster local NWDAF and the second cluster local NWDAF can transmit its prediction results (e.g., signaling storm information OUTPUT) to the central NWDAF.
[0318] like Figure 13 As shown, when transmitting prediction results (e.g., signaling storm information OUTPUT), each of the first cluster local NWDAF and the second cluster local NWDAF can transmit delay, accuracy, urgency, area information, etc. together.
[0319] The central NWDAF can collect data (prediction results, latency, accuracy, urgency, regional information, etc.) from multiple clusters (i.e., the first cluster local NWDAF and the second cluster local NWDAF), and autonomously perform AI / ML analysis to obtain / determine the final prediction results for a specific NF and transmit them to the corresponding consumer (Analytics_Notify, e.g., affected NF, NF action, number of affected subscribers, or estimated time).
[0320] The corresponding consumer can perform subsequent processes such as selection exclusion / overload control for NFs and NF clusters that have experienced signaling storms based on the received final prediction results.
[0321] Reference Figure 14 In another implementation, when an abnormal state (i.e., a signaling storm) occurs in the second NF, other NFs (e.g., the first NF and the fifth NF) communicating with the second NF may fail in part of their communication with the second NF.
[0322] In this scenario, by performing an anomaly prediction process for the second NF, the first NWDAF, which has predicted / determined whether an anomaly (i.e., signaling storm) has occurred, can transmit the prediction result for the second NF to the first NF within the area of the first NWDAF, and can provide information for excluding the second NF (NF#2) as the required action.
[0323] Therefore, the first NF that has received the current prediction result can communicate with another NF (e.g., the third NF in place of the second NF) by performing a subsequent process as the required action.
[0324] The first NWDAF can obtain additional information from another NWDAF (e.g., the central NWDAF), or can receive prediction results for the second NF as the result of the execution in the central NWDAF.
[0325] In this scenario, the first NWDAF can re-predict / determine whether an anomalous state (i.e., signaling storm) has occurred in the second NF, transmit its prediction results to the first NF, and change the required actions.
[0326] Figure 14 An example is given of providing information as the required action to exclude the second NF (NF#2) and recommend the fourth NF (NF#4).
[0327] Therefore, the first NF, which has received the current prediction result, can communicate with the recommended fourth NF, which replaces the second NF, by performing subsequent processes as the required actions.
[0328] In this case, if necessary, the first NF can transmit the completion level (feedback / reward score) of the result of the corresponding subsequent process (action) to the first NWDAF, and the first NWDAF can identify the degree to which the action of the corresponding subsequent process has been performed and do so in a closed-loop manner.
[0329] Next, we will refer to Figure 15 Another implementation method is described.
[0330] Figure 15 An example of the implementation is as follows: A first NF, acting as a consumer NF, requests a first NWDAF to analyze and predict whether an abnormal state (e.g., signaling storm) has occurred, and the first NWDAF transmits a message to the first NF indicating that the transmission based on the analysis and prediction results (e.g., signaling storm information OUTPUT) is being delayed (expected delay = 300s).
[0331] In this scenario, the first NF can determine that a re-request (re-delegation) needs to be sent to an NWDAF other than the first NWDAF, and re-request the second NWDAF to analyze and predict whether an anomalous state (e.g., signaling storm) has occurred. The first NF can also transmit information about the expected time for the first NF to receive the prediction results (e.g., required response time = 100s).
[0332] Then, the second NWDAF can perform an abnormal state prediction process according to the request from the first NF, and transmit the prediction results (recommended actions, such as signaling storm prediction) obtained by analysis / prediction of NF (e.g., NF 2, NF 3, NF 4 or NF 5) to the first NF.
[0333] In this case, the first NF can perform subsequent procedures based on the received signaling storm prediction results to take the following actions: exclude NF 2 and NF 3 with a signaling storm prediction of 75% or higher during reselection, and only send SBI message requests to NF 4 and NF 5.
[0334] In this case, if necessary, the first NF can transmit the completion level (feedback / reward score) of the result of the corresponding subsequent process (action) to the first NWDAF, and the first NWDAF can identify the degree to which the action of the corresponding subsequent process has been performed and do so in a closed-loop manner.
[0335] Furthermore, the communication technology between multiple NF / NWDAFs according to this disclosure can be applied on a regional (analysis / prediction range) basis for communication between different core networks / clusters, and Figure 16 An example of its implementation is shown.
[0336] Figure 16 Communication between different core networks / clusters is illustrated by local / global roaming, NW slicing, NF sets, or UE / RAN locations, with corresponding examples of region A, region B, and region C.
[0337] exist Figure 16 In the implementation, the first NF belonging to region C can request the first NWDAF to analyze and predict whether an anomalous state (e.g., signaling storm) has occurred, and the request can be associated with an unspecified region (region: any (*)).
[0338] In this scenario, the first NWDAF can obtain the analysis and prediction results of the anomalous state (e.g., signaling storm) prediction process performed by the first NWDAF and the analysis and prediction results of the anomalous state (e.g., signaling storm) prediction process performed by the joint second NWDAF through joint learning among NWDAFs. Figure 16 The implementation examples illustrate cases where the corresponding accuracy is determined to be 55% and 43%.
[0339] The first NWDAF can transmit the prediction results of the first NWDAF and the second NWDAF to the first NF (each of the first NWDAF and the second NWDAF can transmit its prediction result to the first NF).
[0340] In this case, the first NF may not need to perform separate subsequent processes (actions) based on the required actions, because the accuracy of the currently received prediction results is relatively low, at 55% and 43%.
[0341] In this scenario, if necessary, the first NF can re-request the first NWDAF analysis and predict whether an anomalous state (e.g., signaling storm) has occurred to obtain highly accurate predictions and appropriate follow-up processes (actions), and this can be achieved by specifying a target region (e.g., region {A}). B) to execute the request.
[0342] Therefore, the first NWDAF can obtain the analysis and prediction results of the anomalous state (e.g., signaling storm) prediction process for only region A and region B through joint learning between NWDAFs as described above, transmit it to the first NF, and provide information for excluding region B as the required action.
[0343] In this scenario, the first NF in region C that has received the current prediction result can refuse to communicate with the NF in region B and only communicate with region A by performing a subsequent process as the required action.
[0344] As described above, according to the signaling control method performed by the NF of this disclosure, a specific technical configuration is implemented that enables the identification and response to normal / abnormal NFs (e.g., UENF, RANF, AMF, SMF, UPF, ...), normal / abnormal operation between NFs, signaling storms, etc., by implementing communication technology between the NF and NWDAF and the following communication technology between multiple NFs / NWDAFs (which is used to define a new analysis ID for predicting abnormal states (e.g., signaling storms) between NFs and using the ID to analyze / predict abnormal states such as signaling storms).
[0345] Therefore, this disclosure achieves the following effects: it is able to detect anomalies in NFs, abnormal operations between NFs, and signaling storms, and to respond to them optimally, thereby avoiding any potential degradation in communication and quality of customer experience.
[0346] The signaling control method according to embodiments of this disclosure can be implemented as program commands that can be executed by various computer devices and recorded in a computer-readable medium. The computer-readable medium may include program commands, data files, and data structures individually or in combination. The program commands recorded on the medium may be specifically designed and configured for this disclosure, or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, or magnetic tapes; optical media such as optical disc read-only memory (CD-ROM) or digital versatile disc (DVD); magneto-optical media such as floppy optical discs; and hardware devices such as ROM, random access memory (RAM), or flash memory specifically designed to store and execute program commands. Examples of program commands include not only machine code generated by a compiler but also high-level language code that can be executed by a computer using an interpreter, etc. The aforementioned hardware devices may be configured to operate as one or more software modules to perform the operations of this disclosure, and vice versa.
[0347] Although this disclosure has been described in detail with reference to various embodiments, it is not limited to the embodiments described above. Those skilled in the art will recognize that various changes and modifications can be made without departing from the scope of this disclosure as defined in the appended claims.
Claims
1. A Network Functions (NF) device, the NF device comprising: Memory, the memory including instructions; as well as A processor, configured to execute the instructions to transmit information to be analyzed to an NF configured to perform an anomaly prediction process through information analysis, and to request prediction results obtained by performing the anomaly prediction process, wherein the NF is a Network Data Analysis Function (NWDAF). The processor is configured to select a specific NWDAF from a plurality of NWDAFs based on the information to be transmitted, and to transmit the information to the specific NWDAF.
2. The NF device according to claim 1, wherein, The processor is configured to select the specific NWDAF based on at least one of the following: whether the information to be transmitted is real-time or non-real-time data, the estimated processing time consumed in analyzing the information, and the capacity required to analyze the information.
3. The NF device according to claim 1, wherein, The plurality of NWDAFs includes a first NWDAF located near the NF device and a second NWDAF configured to perform anomaly prediction processes by communicating with the plurality of first NWDAFs, the first NWDAFs being located locally on the NF device.
4. The NF device according to claim 1, wherein, The processor is configured to, upon receiving a prediction result from an abnormal state prediction process performed by analyzing transmitted information from the specific NWDAF, request a prediction result from another NWDAF among the plurality of NWDAFs based on the prediction result.
5. The NF device according to claim 4, wherein, The processor is configured to: The subsequent process is performed based on the prediction result transmitted from the specific NWDAF or the other NWDAF; and When it is determined that the execution of the subsequent process is impossible, a new prediction result for the execution of an alternative subsequent process is requested from the specific NWDAF or the other NWDAF.
6. A Network Data Analysis Function (NWDAF) device, the NWDAF device comprising: Memory, the memory including instructions; and A processor configured to execute the instructions to derive prediction results by performing an anomaly prediction process associated with a particular NF through analyzing information transmitted from each NF, and to transmit information to another NWDAF device or request additional information from another NWDAF device based on the prediction results.
7. The NWDAF device according to claim 6, wherein, The processor is configured to control the transmission of information to the other NWDAF device by using at least one of the accuracy, impact, and urgency of the prediction result as criteria.
8. The NWDAF device according to claim 6, wherein, The processor is configured to: Based on the prediction result, information is transmitted to the other NWDAF device to allow the information to be used in an anomaly prediction process, which derives a final prediction result for the specific NF, and this anomaly prediction process is performed by the other NWDAF device; or Based on the prediction results, additional information is requested from the other NWDAF device, and the final prediction result is derived by re-executing the abnormal state prediction process, in which even the additional information is analyzed.
9. The NWDAF device according to claim 6, wherein, The other NWDAF device is a centralized NWDAF configured to perform anomaly prediction processes by interworking with multiple local NWDAFs.
10. A signaling control method executed by a Network Function (NF) device, the signaling control method comprising the following steps: The information to be used for analysis is transmitted to an NF configured to perform an anomaly prediction process through information analysis, in order to request the prediction results obtained by performing the anomaly prediction process. This NF is a Network Data Analysis Function (NWDAF). The transmission step includes the following steps: selecting a specific NWDAF from multiple NWDAFs based on the information to be transmitted, and transmitting the information to the specific NWDAF.
11. A signaling control method executed by a Network Data Analysis Function (NWDAF) device, the signaling control method comprising the following steps: The prediction results are derived by performing an anomaly prediction process related to a specific NF by analyzing the information transmitted from each NF. as well as Based on the prediction results, information can be transmitted to another NWDAF device or additional information can be requested from another NWDAF device.
Citation Information
Patent Citations
Fluid pressure indicator for medical devices
KR1020230074196A