Information supervision method, network element, equipment, medium and product
By mirroring and replicating the extended reality service flow and generating a second service flow, the problem of low service flow propagation efficiency in the existing technology is solved, and the identification of image frames that are not suitable for propagation is realized without affecting the service flow transmission efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-22
- Publication Date
- 2026-04-14
AI Technical Summary
In the process of XR application platforms transmitting service streams to users, if the video message carries image frames that are not suitable for transmission, existing technologies require identification of each frame, which reduces the efficiency of service stream transmission.
The extended reality service flow is mirrored and copied by the first network element to generate the first service flow. The software toolkit identifier corresponding to the traffic characteristics is obtained to generate the second service flow, which is sent to the protocol analysis device for information monitoring and identification of key frames.
It improves the efficiency of business flow propagation, ensures that the original business flow is transmitted to the user without being affected, and enables the identification of image frames that are not suitable for propagation.
Smart Images

Figure CN121864655A_ABST
Abstract
Description
Technical Field
[0001] This application relates to core network technology, and more particularly to an information supervision method, network element, equipment, medium, and product. Background Technology
[0002] Extended Reality (XR) services are entering a phase of rapid development with the support of 5G-A networks, and are widely used in fields such as virtual performances, large-scale cultural tourism, industrial remote collaboration, and education and training. XR video streams generally use high compression ratio encoding and decoding such as H.265 and AV1, and their keyframes (I-frames) carry complete image information, which are the core of content review, quality control, and security supervision.
[0003] In related technologies, the XR application platform sends video packets to the UPF network element, which then forwards the video packets to the user through the base station. During this process, if the video packet contains image frames that are not suitable for transmission, those image frames will also be transmitted to the user. Alternatively, identifying the unsuitable image frames in the video requires parsing the video packet and identifying each frame in it. This can affect the service flow transmitted from the XR application platform to the user, thus reducing the efficiency of service flow transmission. Summary of the Invention
[0004] This application provides an information monitoring method, network element, device, medium, and product that can improve the efficiency of business flow propagation.
[0005] The technical solution of this application embodiment is implemented as follows: This application provides an information supervision method applied to a first network element, the method comprising: Receive extended reality service streams sent by the application device; If the extended reality service flow is determined to be a service flow to be monitored based on the traffic identification strategy, the extended reality service flow is mirrored to obtain a first service flow; and the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy is obtained. A second service flow is generated based on the first service flow and the software toolkit identifier; The second service flow is sent to the protocol analysis device so that the protocol analysis device can perform information monitoring based on the second service flow.
[0006] This application embodiment provides another information monitoring method applied to a protocol analysis device, the method comprising: Receive the second service flow sent by the first network element; Obtain the software toolkit identifier from the second business flow; The corresponding software toolkit is determined based on the preset correspondence and the software toolkit identifier; The second service stream is decoded based on the software toolkit to obtain the keyframes in the second service stream; The keyframe is reported to the monitoring device.
[0007] This application provides a first network element, characterized in that the first network element includes: The first receiving unit is used to receive extended reality service streams sent by the application device; The replication unit is used to mirror the extended reality service flow to obtain a first service flow when the extended reality service flow is determined to be a service flow to be monitored based on the traffic identification strategy. The first acquisition unit is used to acquire the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy; A generation unit is configured to generate a second service flow based on the first service flow and the software toolkit identifier; The sending unit is used to send the second service flow to the protocol analysis device so that the protocol analysis device can perform information monitoring based on the second service flow.
[0008] This application provides a protocol analysis device, characterized in that the protocol analysis device includes: The second receiving unit is used to receive the second service flow sent by the first network element; The second acquisition unit is used to acquire the software toolkit identifier from the second business flow; The determining unit is used to determine the corresponding software toolkit based on a preset correspondence and the software toolkit identifier; The decoding unit is used to decode the second service stream based on the software toolkit to obtain key frames in the second service stream; The reporting unit is used to report the key frame to the monitoring equipment.
[0009] This application embodiment provides a first network element, the first network element comprising: The first memory is used to store computer-executable instructions or computer programs; The first processor is configured to execute computer-executable instructions or computer programs stored in the first memory to implement the information monitoring method applied to the first network element provided in the embodiments of this application.
[0010] This application embodiment provides a protocol analysis device, the protocol analysis device comprising: Secondary memory is used to store computer-executable instructions or computer programs; The second processor, when executing computer-executable instructions or computer programs stored in the second memory, implements the information monitoring method for a protocol analysis device provided in the embodiments of this application.
[0011] This application provides a computer-readable storage medium storing a computer program or computer-executable instructions, which, when executed by a first processor, implements the information monitoring method provided in this application for a first network element, and when executed by a second processor, implements the information monitoring method provided in this application for a protocol analysis device.
[0012] This application provides a computer program product, including a computer program or computer-executable instructions. When the computer program or computer-executable instructions are executed by a first processor, they implement an information monitoring method applied to a first network element provided in this application. When the computer program or computer-executable instructions are executed by a second processor, they implement an information monitoring method applied to a protocol analysis device provided in this application.
[0013] The embodiments of this application have the following beneficial effects: When the first network element receives an extended reality service flow sent by the application device, it identifies the extended reality service flow based on the traffic identification strategy. If the extended reality service flow is determined to be a service flow to be monitored, it mirrors the extended reality service flow to obtain a first service flow and obtains the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy. Based on the first service flow and the software toolkit identifier, a second service flow is generated. The second service flow is then sent to the protocol analysis device, which uses the protocol analysis device to determine the key frames in the extended reality service flow based on the second service flow and sends them to the monitoring device. This allows the monitoring device to identify whether there are image frames in the extended reality service flow that are not suitable for propagation. This process does not affect the transmission of the extended reality service flow to the user, thereby improving the efficiency of service flow propagation. Attached Figure Description
[0014] Figure 1 This application provides an information supervision method process. Figure 1 ; Figure 2 This is an exemplary second service flow diagram provided in an embodiment of this application; Figure 3 This application provides an information supervision method process. Figure 2 ; Figure 4 This is a schematic diagram of an exemplary information supervision structure provided in an embodiment of this application; Figure 5This is a flowchart illustrating an exemplary information supervision method provided in an embodiment of this application; Figure 6 This is a schematic diagram of the composition structure of a first network element provided in an embodiment of this application. Figure 1 ; Figure 7 This is a schematic diagram of the composition structure of a first network element provided in an embodiment of this application. Figure 2 ; Figure 8 This is a schematic diagram of the composition structure of a protocol analysis device provided in an embodiment of this application. Figure 1 ; Figure 9 This is a schematic diagram of the composition structure of a protocol analysis device provided in an embodiment of this application. Figure 2 .
[0015] It should be noted that the terms "first" and "second" mentioned above are only used to distinguish between different options and do not represent the degree of superiority or inferiority of the options or their priority in the implementation process. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0017] This application provides an information monitoring method, which is applied to a first network element. Figure 1 An information supervision method flow provided for embodiments of this application Figure 1 ,like Figure 1 As shown, information supervision methods may include: S101, Receive extended reality service stream sent by the application device.
[0018] The information monitoring method provided in this application embodiment is applicable to scenarios where extended reality service flows sent by application devices are monitored.
[0019] In this embodiment of the application, the first network element can be a User Plane Function (UPF) network element, or it can be other network elements. The specific first network element can be determined according to the actual situation, and this embodiment of the application does not limit it.
[0020] In this embodiment of the application, the application device can be an XR application platform, or it can be other devices. The specific application device can be determined according to the actual situation, and this embodiment of the application does not limit it.
[0021] In this embodiment of the application, a data transmission interface is provided between the application device and the first network element, and the first network element can receive the extended reality service flow sent by the application device through the data transmission interface.
[0022] For example, the application device is an XR application platform, the data transmission interface is an N6 interface, and the first network element can receive the extended reality service flow sent by the XR application platform through the N6 interface.
[0023] In this embodiment, extended reality business flows include business flows in the education and training field, business flows in the virtual performance field, business flows in the cultural tourism field, etc. The specific extended reality business flows can be determined according to the actual situation, and this embodiment does not limit them.
[0024] It should be noted that the extended real-world business flow is a video stream.
[0025] In this embodiment, before the first network element receives the extended reality service flow sent by the application device, it also establishes a control information channel with the application device; receives policy configuration information sent by the application device based on the control information channel; and generates a traffic identification policy based on the policy configuration information.
[0026] It should be noted that the policy configuration information includes traffic characteristics and the software toolkit identifier corresponding to the traffic characteristics.
[0027] It should also be noted that traffic characteristics are feature information for accurately identifying extended reality business flows, including but not limited to: source IP address, destination IP address (or address range), source port, destination port, transport layer protocol (such as UDP), possible DSCP markers, application layer features (such as SNI, ALPN - if identifiable), etc. Specific feature information can be determined according to the actual situation, and this application embodiment does not limit it.
[0028] It should also be noted that the software toolkit identifier can be SDKID, which is a unique identifier of a software toolkit (Software Development Kit, SDK) registered on the XR protocol analysis platform that is capable of handling this specific extended reality business flow (i.e., its corresponding protocol and encryption method).
[0029] In this embodiment of the application, the traffic identification policy generated based on policy configuration information also includes traffic characteristics.
[0030] In this embodiment, the first network element and the application device can agree on a fixed TCP / UDP port to establish a control information channel, and the UPF listens for messages from the application device on this port. The first network element can also establish a control information channel with the application device in other ways; the specific way the first network element establishes a control information channel with the application device can be determined according to the actual situation, and this embodiment does not limit this.
[0031] It should be noted that the first network element and the application device can also communicate using the existing service interfaces of the 5G core network (such as NEF), i.e., the control information channel.
[0032] In this embodiment, when the first network element receives policy configuration information sent by the application device, it parses the policy configuration information and configures the corresponding traffic identification policy locally according to the parsed policy configuration information (the matching condition is traffic characteristics). It then associates the traffic identification policy with a software toolkit identifier, thus establishing a correspondence between the traffic identification policy and the software toolkit identifier. This allows the software toolkit identifier corresponding to the traffic identification policy to be obtained later based on this correspondence.
[0033] In this embodiment of the application, when the first network element receives an extended reality service flow sent by the application device, it obtains a traffic identification policy and uses the traffic identification policy to determine whether the extended reality service flow is a service flow to be monitored.
[0034] In this embodiment, the first network element establishes a control information channel with the application device before acquiring the traffic identification policy; receives policy configuration information sent by the application device based on the control information channel; and generates a traffic identification policy based on the policy configuration information.
[0035] In this embodiment of the application, when the first network element receives the extended reality service flow sent by the application device, it will also forward the extended reality service flow to the base station along the original path, and use the base station to send the extended reality service flow to the user.
[0036] S102. If the extended real-world business flow is determined to be the business flow to be monitored based on the traffic identification strategy, the extended real-world business flow is mirrored to obtain the first business flow; the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy is obtained.
[0037] In this embodiment of the application, after the first network element receives the extended reality service flow sent by the application device, if it determines that the extended reality service flow is a service flow to be monitored based on the traffic identification strategy, it performs a mirror copy of the extended reality service flow to obtain the first service flow; and obtains the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy.
[0038] In this embodiment of the application, the traffic identification strategy includes five-tuple (source IP address, destination IP address (or address range), source port, destination port, transport layer protocol (such as UDP)) information, which can be matched with the information in the extended real-world service flow. If they match, the extended real-world service flow is determined to be the service flow to be monitored; if they do not match, the extended real-world service flow is determined not to be the service flow to be monitored.
[0039] It should be noted that, in addition to the five-tuple information, the traffic identification strategy also includes possible DSCP markers, application layer features (such as SNI, ALPN - if identifiable), and other filtering conditions. Alternatively, all information in the traffic identification strategy can be matched with the extended real-world service flow. If a match is found, the extended real-world service flow is determined to be the service flow to be monitored; otherwise, it is determined not to be the service flow to be monitored. The specific method for determining the extended real-world service flow as the service flow to be monitored based on the traffic identification strategy can be determined according to the actual situation, and this application embodiment does not limit this.
[0040] In this embodiment of the application, the method of mirroring the extended reality business flow to obtain the first business flow can be determined according to the actual situation, and this embodiment of the application does not limit it.
[0041] In this embodiment, the policy configuration information carries traffic characteristics and a software toolkit identifier corresponding to the traffic characteristics. The software toolkit identifier corresponding to the traffic characteristics can be obtained from the received traffic configuration information; alternatively, the software toolkit identifier can be determined based on the established correspondence between the traffic identification policy and the software toolkit identifier. The specific method of obtaining the software toolkit identifier can be determined according to the actual situation, and this embodiment does not limit it.
[0042] In this embodiment of the application, when the UPF network element is forwarding downlink XR service flow (or uplink traffic that meets the policy) from the N6 interface, it matches the service flow that meets the conditions in real time according to the configured traffic identification policy, that is, determines the service flow to be monitored.
[0043] In this embodiment of the application, when the UPF network element determines that the extended reality service flow is the service flow to be monitored (i.e., the service flow to be monitored is matched), it copies the original packet (or specific layer data, such as a complete IP packet or transport layer PDU) of the extended reality service flow to generate a mirror flow and obtain the first service flow.
[0044] It should be noted that the operation of mirroring the original packets of the extended reality service flow is independent of the original forwarding path of the extended reality service flow, thereby ensuring that the original processing flow of the extended reality service flow is uninterrupted. That is, this application will not cause additional delay to the original processing flow of the extended reality service flow.
[0045] It should be noted that the first business flow is a copy of the extended real business flow, meaning that the information in the first business flow is the same as the information in the extended real business flow.
[0046] S103. Generate a second business flow based on the first business flow and the software toolkit identifier.
[0047] In this embodiment, the first network element mirrors the extended reality service flow to obtain the first service flow; and after obtaining the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy, it generates the second service flow based on the first service flow and the software toolkit identifier.
[0048] In this embodiment of the application, the process of the first network element generating a second service flow based on the first service flow and the software toolkit identifier includes: adding the software toolkit identifier to the first service flow to obtain the first service flow with the added identifier; and encapsulating the first service flow with the added identifier to obtain the second service flow.
[0049] In this embodiment, a software toolkit identifier can be added to the beginning of the header of the first service flow to obtain the first service flow with the identifier added. That is, the software toolkit identifier is appended to the beginning of the first service flow. Alternatively, the software toolkit identifier can be added to the first service flow in other ways to obtain the first service flow with the identifier added; the specific method of adding the software toolkit identifier to the first service flow can be determined according to the actual situation, and this embodiment does not limit this method.
[0050] In this embodiment, the first network element can encapsulate the added first service flow using a lightweight tunneling protocol (such as UDP, VXLAN, GTP-U, or dedicated encapsulation) to obtain the second service flow. Specifically, during the encapsulation process of the added first service flow, corresponding network layer and transport layer information such as source IP / port (UPF) and destination IP / port (XR protocol analysis platform) are set.
[0051] It should be noted that the first network element can encapsulate the packet header with the IP and port information of the first network element and the IP and port information of the protocol analysis device, and use the added first service flow as the new information body, thereby obtaining the second service flow by encapsulating the packet header and the new information body.
[0052] In this application embodiment, an exemplary second service flow is as follows: Figure 2 As shown: The header of the first service flow is the encapsulated message header, including the IP header and TCP header, and the new information body (i.e., the encapsulated message payload). The IP header and TCP header can be determined based on the IP and port information of the first network element and the IP and port information of the protocol analysis device. The new information body includes the Software Toolkit ID (SDKID) and the first information flow (i.e., the original user message after mirroring). This first information flow includes the original IP header, the original UDP / TCP header, and the original payload. It should be noted that the original IP header and the original UDP / TCP header are determined by the IP and port information of the application device and the base station; that is, they are determined based on the source IP, UDP / TCP and destination IP, UDP / TCP addresses of the extended real service flow.
[0053] S104. Send a second service flow to the protocol analysis device so that the protocol analysis device can perform information monitoring based on the second service flow.
[0054] In this embodiment of the application, after the first network element generates a second service flow based on the first service flow and the software toolkit identifier, it sends the second service flow to the protocol analysis device so that the protocol analysis device can perform information monitoring based on the second service flow.
[0055] In this embodiment, the protocol analysis device can be an XR protocol analysis platform, or it can be other devices. The specific protocol analysis device can be determined according to the actual situation, and this embodiment does not limit it.
[0056] In this embodiment of the application, a communication connection is established between the first network element and the protocol analysis device, and a second service flow can be sent to the protocol analysis device based on the communication connection.
[0057] In this embodiment, the protocol analysis device identifies key frames in the extended reality traffic flow from the second traffic flow and transmits these key frames to the monitoring device. The monitoring device then monitors the second traffic flow to determine whether there are any image frames in the extended reality traffic flow that are not suitable for propagation.
[0058] Understandably, when the first network element receives an Extended Reality (EV) service flow sent by the application device, it identifies the EV based on a traffic identification strategy. If the EV is determined to be a service flow to be monitored, it mirrors the EV to obtain a first service flow and obtains a software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy. Based on the first service flow and the software toolkit identifier, a second service flow is generated. The second service flow is then sent to a protocol analysis device, which uses this device to identify key frames in the EV based on the second service flow and sends them to a monitoring device. This allows the monitoring device to identify whether there are image frames in the EV that are not suitable for propagation. This process does not affect the transmission of the EV to the user, thus improving the efficiency of service flow propagation.
[0059] This application provides an information monitoring method, which is applied to a protocol analysis device. Figure 3 An information supervision method flow provided for embodiments of this application Figure 2 ,like Figure 3 As shown, information supervision methods may include: S201, Receive the second service flow sent by the first network element.
[0060] The information monitoring method provided in this application embodiment is applicable to scenarios where extended reality service flows sent by application devices are monitored.
[0061] In this embodiment of the application, the protocol analysis device can be an XR protocol analysis platform, or it can be other network elements. The specific protocol analysis device can be determined according to the actual situation, and this embodiment of the application does not limit it.
[0062] In this embodiment of the application, a communication connection is established between the first network element and the protocol analysis device, and the protocol analysis device can receive the second service flow sent by the first network element based on the communication connection.
[0063] In this embodiment of the application, the first network element can be a User Plane Function (UPF) network element, or it can be other network elements. The specific first network element can be determined according to the actual situation, and this embodiment of the application does not limit it.
[0064] In this embodiment, the second business flow includes business flows in the education and training field, business flows in the virtual performance field, business flows in the cultural tourism field, etc. The specific second business flow can be determined according to the actual situation, and this embodiment does not limit it.
[0065] It should be noted that the second service flow is a video stream.
[0066] S202. Obtain the software toolkit identifier from the second business flow.
[0067] In this embodiment of the application, after the protocol analysis device receives the second service flow sent by the first network element, it obtains the software toolkit identifier from the second service flow.
[0068] In this embodiment, the second service flow includes an IP header, a TCP header, and a new information body, which includes a software toolkit identifier and the first service flow. The protocol analysis device can obtain the software toolkit identifier from the second service flow.
[0069] In this embodiment of the application, the process by which the protocol analysis device obtains the software toolkit identifier from the second service flow includes: decapsulating the second service flow to obtain the added first service; and obtaining the software toolkit identifier from the added first service.
[0070] It should be noted that the protocol analysis device includes a protocol access adaptation layer and an SDK resource pool. The protocol access adaptation layer is used to decapsulate the second service flow to obtain the added first service flow, thereby obtaining the software toolkit identifier and the first service flow from the added first service flow.
[0071] S203. Determine the corresponding software toolkit based on the preset correspondence and the software toolkit identifier.
[0072] In this embodiment of the application, after the protocol analysis device obtains the software toolkit identifier from the second service flow, it determines the corresponding software toolkit based on the preset correspondence and the software toolkit identifier.
[0073] In this embodiment, the preset correspondence can be information configured in the protocol analysis device, information transmitted to the protocol analysis device by other devices, or information obtained by the protocol analysis device through other means. The specific way in which the protocol analysis device obtains the preset correspondence can be determined according to the actual situation, and this embodiment does not limit it.
[0074] It should be noted that the preset correspondence is a preset correspondence between multiple software toolkits and multiple software toolkit identifiers. Based on this preset correspondence, the corresponding software toolkit can be determined by the software toolkit identifier.
[0075] For example, the protocol access adaptation layer uses a predefined general interface (with the input parameters being SDKID (i.e., software toolkit identifier) and the original user message (i.e., the first service flow)) to call the SDK instance with the corresponding SDKID in the SDK resource pool. This determines the corresponding software toolkit by identifying the software toolkit identifier, and then uses the software toolkit to parse the original user message.
[0076] In this embodiment of the application, before the protocol analysis device determines the corresponding software toolkit based on the preset correspondence and the software toolkit identifier, it also receives multiple software toolkits sent by the application device; generates multiple software toolkit identifiers corresponding to the multiple software toolkits; deploys the multiple software toolkits in the resource pool, and establishes a preset correspondence between the multiple software toolkits and the multiple software toolkit identifiers.
[0077] It should be noted that a communication connection is established between the protocol analysis device and the user device, and multiple software toolkits sent by the application device can be received based on this communication connection.
[0078] In this embodiment, the application device can be an XR application platform / service provider, and the protocol analysis device can receive multiple SDKs (Software Toolkits) sent by the application device. It should be noted that the core function of each SDK is to decrypt and decode the protocol stack of XR packets pushed by itself, which use a specific protocol (possibly including custom protocols) and encryption methods. The input to the SDK is the original network packet (i.e., extended reality service flow), and the output is the decoded video keyframe (I-Frame) image data.
[0079] It should be noted that when the protocol analysis device receives multiple software toolkits, it deploys these multiple software toolkits to the SDK resource pool and generates a globally unique identifier (UUID) for each of the multiple software toolkits, thus obtaining multiple software toolkit identifiers (i.e., obtaining multiple SDKIDs).
[0080] In this embodiment of the application, the protocol analysis device records and maintains the mapping relationship between SDK and SDKID (i.e., the preset correspondence between multiple software toolkits and multiple software toolkit identifiers), and manages the lifecycle of SDK (loading, activation, uninstallation).
[0081] In this embodiment of the application, after the protocol analysis device establishes a preset correspondence between multiple software toolkits and multiple software toolkit identifiers, it will also send the preset correspondence to the application device.
[0082] It should be noted that a communication connection is established between the protocol analysis device and the user device, and a preset mapping relationship can be sent to the application device based on this communication connection. Preset mapping relationships can also be sent to the application device in other ways; the specific method of sending the preset mapping relationship to the application device can be determined according to the actual situation, and this application embodiment does not limit this.
[0083] S204. Decode the second service stream using the software toolkit to obtain the key frames in the second service stream.
[0084] In this embodiment of the application, after the protocol analysis device determines the corresponding software toolkit based on the preset correspondence and the software toolkit identifier, it decodes the second service flow based on the software toolkit to obtain the key frames in the second service flow.
[0085] In this embodiment of the application, the process of the protocol analysis device obtaining the software toolkit identifier from the second service flow includes: decapsulating the second service flow to obtain the added first service; obtaining the software toolkit identifier from the added first service; correspondingly, the process of decoding the second service flow based on the software toolkit to obtain key frames in the second service flow includes: decoding the added first service based on the software toolkit to obtain key frames.
[0086] In this embodiment of the application, the second service flow can be decapsulated using the protocol access adaptation layer to obtain the added first service flow, thereby obtaining the software toolkit identifier and the first service flow from the added first service flow.
[0087] In this embodiment, the process of decoding the added first service stream using a software toolkit to obtain keyframes includes using the software toolkit to perform multi-layer decoding on the first service stream according to its implementation logic (e.g., TLS / DTLS decryption -> QUIC / WebRTC / private protocol parsing -> RTP unpacking -> RTP payload parsing -> container format (e.g., FMP4) decapsulation -> video stream extraction). Then, keyframes (I-Frames) are identified in the parsed video stream.
[0088] In this embodiment of the application, the added first service can also be decoded in other ways to obtain key frames; the specific implementation method can be determined according to the actual situation, and this embodiment of the application does not limit it.
[0089] S205, Report keyframes to the monitoring equipment.
[0090] In this embodiment of the application, the protocol analysis device decodes the second service flow based on the software toolkit, obtains the key frames in the second service flow, and then reports the key frames to the monitoring device.
[0091] In this embodiment of the application, once a keyframe is determined, the keyframe can be output or reported to the monitoring device.
[0092] For example, if keyframes are output, the identified keyframes can be decoded into image data formats (such as RGB / YUV data blocks or image files) suitable for subsequent processing. If keyframes are reported to the monitoring device, the decoded keyframe image data can be reported to the content monitoring platform using the protocol access adaptation layer. The reported content may include keyframe data, associated business flow identifiers (such as the 5-tuple in the first business flow), timestamps (including the timestamp when the keyframe is reported to the monitoring device, or the timestamp when the second business flow is received), and other information.
[0093] For example, such as Figure 4 As shown: The UPF network element (first network element) establishes a control information channel with the XR application platform (application device). The first network element receives policy configuration information (issuing identification policies) sent by the application device based on the control information channel, and generates a traffic identification policy based on the policy configuration information. The XR application platform sends video packets (extended reality service flows) to the UPF network element, and the first network element receives the extended reality service flows sent by the application device. If the extended reality service flow is determined to be the service flow to be monitored based on the traffic identification policy, the extended reality service flow is mirrored to obtain the first service flow (i.e., the original packet). The software toolkit identifier corresponding to the traffic characteristics in the traffic identification policy is obtained. Based on the first service flow and the software toolkit identifier (SDKID), a second service flow (i.e., the mirrored packet, including the original packet and the SDKID) is generated. Then, the second service flow is sent to the protocol analysis device (XR protocol analysis platform). The protocol analysis device receives a second service flow sent by the first network element; the protocol access adaptation layer in the protocol analysis device obtains the software toolkit identifier from the second service flow; based on the preset correspondence and the software toolkit identifier, it determines the corresponding software toolkit (SDK); it calls the software toolkit from the SDK resource pool (supporting hot loading and hot updating, the SDK resource pool includes SDK1, SDK2, ..., SDKN), and decodes the second service flow based on the software toolkit to obtain the key frames in the second service flow (calling the SDK to parse the key frames); it reports the key frames (i.e., the key frames obtained after decoding) to the monitoring device (monitoring platform). In this case, when the first network element receives an extended reality service flow sent by the application device, it will also forward the extended reality service flow to the base station along the original path, and the user will be transmitted through the base station.
[0094] It is understood that the entire identification process of the information supervision method in this application is based on mirrored streams, requiring no decryption, modification, or deep detection operations on the original service flow path, thus ensuring service performance and security. This application innovatively solves the technical challenge of keyframe identification for encrypted or proprietary protocol XR streams at the 5G core network user plane (UPF) level, filling a gap in existing technology. The analysis using mirrored streams is completely independent of the original service flow forwarding path. The original stream requires no decryption, unpacking, or DPI, therefore introducing no additional latency, jitter, or interruption risk to the XR service itself (zero intrusion), ensuring a high-real-time XR service user experience. By authorizing the use of the vendor-provided SDK as the sole component for decryption and decoding, keyframe information is legally obtained without cracking encrypted content, solving the problem of encrypted stream identification while complying with privacy protection and compliance requirements. Simultaneously, the SDK mechanism naturally supports the parsing of various non-standard / proprietary protocols. The plug-in SDK framework allows new XR applications / service providers to quickly integrate, simply by providing their SDK and registering with the platform. It supports new protocols and encryption methods without requiring a complete upgrade, offering excellent compatibility and scalability. By accurately identifying keyframes, it provides core capabilities for building an end-to-end XR service supervision loop (transmission -> identification -> review -> handling), significantly improving network operators' management capabilities for XR services in terms of content security, compliance, and copyright protection—something existing wireless or direct-connection management solutions cannot achieve. It offloads computationally intensive protocol parsing and decoding to a dedicated XR protocol analysis platform, avoiding excessive burden on the core network UPF and optimizing core network resource utilization.
[0095] For example, such as Figure 5As shown: The XR application platform (application network element) submits a dedicated SDK (i.e., multiple software toolkits, each containing private protocols / encryption / decoding capabilities) to the XR protocol analysis platform (protocol analysis device). The protocol analysis device receives the multiple software toolkits sent by the application device; generates multiple software toolkit identifiers corresponding to the multiple software toolkits (the protocol analysis device uses this to build a pluggable SDK framework (multi-protocol compatible), generate unique SDKs, and register them in the resource pool); deploys the multiple software toolkits in the resource pool and establishes a preset correspondence between the multiple software toolkits and their identifiers. The protocol analysis device sends the preset correspondence to the application device (returning the SDKID (UUID bound to the protocol type)). The UPF network element (first network element) establishes a control information channel with the application device (establishing a control channel (TCP / UDP port or NEF interface)); the first network element dynamically binds service flows and decoding capabilities, and receives policy configuration information sent by the application device based on the control information channel (issuing policies (traffic characteristics + SDKID)); and generates traffic identification policies based on the policy configuration information (configuring traffic identification rules (five-tuple matching)). The XR application platform issues XR service flows. The first network element receives the extended reality service flow (i.e., XR service flow (encrypted / private protocol)) sent by the application device. If the extended reality service flow is determined to be a service flow to be monitored based on the traffic identification policy, the extended reality service flow is mirrored to obtain the first service flow (matching traffic rules and copying the mirror flow, i.e., lossless mirroring (zero business intrusion)). The software toolkit identifier corresponding to the traffic characteristics in the traffic identification policy is obtained. Based on the first service flow and the software toolkit identifier (inserting SDKID header + VXLAN encapsulation), the second service flow is generated. The second service flow is sent to the XR protocol analysis platform (protocol analysis device) (sending the mirror flow with SDKID). The protocol analysis device receives the second service flow sent by the first network element; decapsulates the second service flow to obtain the added first service; obtains the software toolkit identifier from the added first service (stripping the encapsulation, extracting the SDKID and the first service flow (original packet)); calls the DSK resource pool, and determines the corresponding software toolkit based on the preset correspondence in the SDK resource pool and the software toolkit identifier; decodes the added first service based on the software toolkit (multi-layer decoding, such as TLS / DTLS decryption -> QUIC / WebRTC / private protocol parsing -> RTP unpacking -> RTP payload parsing -> container format (such as FMP4) decapsulation -> video stream extraction), obtaining keyframes (extracting keyframe image data); and reports the keyframes to the content supervision platform (supervisory device) (reporting keyframe data + service metadata). The supervision device performs content review / QoS optimization / security handling, and performs southbound blocking or northbound alarms.
[0096] Understandably, when the protocol analysis device receives the second service flow sent by the first network element, it obtains the software toolkit identifier from the second service flow and determines the corresponding software toolkit based on the preset correspondence and the software toolkit identifier. This allows it to decode the second service flow based on the software toolkit, obtain the key frame in the second service flow, and send the key frame to the monitoring device. The monitoring device can then use the key frame to identify whether there are image frames in the extended reality service flow that are not suitable for propagation. This process does not affect the transmission of the extended reality service flow to the user, thereby improving the efficiency of service flow propagation.
[0097] Based on the same inventive concept as the above-mentioned information supervision method, this application provides a first network element 1, corresponding to an information supervision method; Figure 6 A schematic diagram of the composition structure of a first network element provided in an embodiment of this application. Figure 1 The first network element 1 may include: The first receiving unit 11 is used to receive the extended reality service stream sent by the application device; The copying unit 12 is used to mirror copy the extended reality service flow to obtain a first service flow when the extended reality service flow is determined to be a service flow to be monitored based on the traffic identification strategy. The first acquisition unit 13 is used to acquire the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy; The first generation unit 14 is used to generate a second service flow based on the first service flow and the software toolkit identifier; The sending unit 15 is used to send the second service flow to the protocol analysis device so that the protocol analysis device can perform information monitoring based on the second service flow.
[0098] In some embodiments of this application, the first network element further includes an adding unit and an encapsulation unit; The adding unit is used to add the software toolkit identifier to the first business flow to obtain the first business flow after the addition; The encapsulation unit is used to encapsulate the added first service flow to obtain the second service flow.
[0099] In some embodiments of this application, the first network element further includes a first establishment unit; The first establishing unit is used to establish a control information channel with the application device; The first receiving unit 11 is configured to receive policy configuration information sent by the application device based on the control information channel; the policy configuration information includes traffic characteristics and a software toolkit identifier corresponding to the traffic characteristics; The first generation unit 14 is used to generate the traffic identification policy based on the policy configuration information.
[0100] It should be noted that, in practical applications, the first receiving unit 11, copying unit 12, first acquiring unit 13, first generating unit 14, and transmitting unit 15 can be implemented by the first processor 21 on the first network element, specifically by a CPU (Central Processing Unit), MPU (Microprocessor Unit), DSP (Digital Signal Processor), or FPGA (Field Programmable Gate Array), etc.; the data storage can be implemented by the first memory 22 on the first network element.
[0101] This application embodiment also provides a first network element, such as Figure 7 As shown, the first network element includes: a first processor 21, a first memory 22, and a first communication bus 23. The first memory 22 communicates with the first processor 21 through the first communication bus 23. The first memory 22 stores programs executable by the first processor 21. When the program is executed, the information monitoring method applied to the first network element as described above is executed through the first processor 21.
[0102] In practical applications, the first memory 22 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD) or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the first processor 21.
[0103] This application provides a computer-readable storage medium having a computer program thereon, which, when executed by a first processor 21, implements the information monitoring method as described above.
[0104] This application also provides a computer program product, including a computer program that can be executed by a first processor 21 in a first network element to complete the steps described in the aforementioned information supervision method.
[0105] Understandably, when the first network element receives an Extended Reality (EV) service flow sent by the application device, it identifies the EV based on a traffic identification strategy. If the EV is determined to be a service flow to be monitored, it mirrors the EV to obtain a first service flow and obtains a software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy. Based on the first service flow and the software toolkit identifier, a second service flow is generated. The second service flow is then sent to a protocol analysis device, which uses this device to identify key frames in the EV based on the second service flow and sends them to a monitoring device. This allows the monitoring device to identify whether there are image frames in the EV that are not suitable for propagation. This process does not affect the transmission of the EV to the user, thus improving the efficiency of service flow propagation.
[0106] Based on the same inventive concept as the above-mentioned information supervision method, this application provides a protocol analysis device 2, corresponding to an information supervision method; Figure 8 A schematic diagram of the composition structure of a protocol analysis device provided in this application embodiment. Figure 1 The protocol analysis device 2 may include: The second receiving unit 31 is used to receive the second service flow sent by the first network element; The second acquisition unit 32 is used to acquire the software toolkit identifier from the second service flow; Determining unit 33 is used to determine the corresponding software toolkit based on a preset correspondence and the software toolkit identifier; Decoding unit 34 is used to decode the second service stream based on the software toolkit to obtain key frames in the second service stream; The reporting unit 35 is used to report the key frame to the monitoring device.
[0107] In some embodiments of this application, the protocol analysis device further includes a deployment unit and a second establishment unit; The second receiving unit 31 is used to receive multiple software toolkits sent by the application device; The second generation unit is used to generate multiple software toolkit identifiers corresponding to the multiple software toolkits; The deployment unit is used to deploy the plurality of software toolkits in the resource pool; The second establishing unit is used to establish a preset correspondence between the plurality of software toolkits and the plurality of software toolkit identifiers.
[0108] In some embodiments of this application, the protocol analysis device further includes a second sending unit; The second sending unit is used to send the preset correspondence to the application device.
[0109] In some embodiments of this application, the protocol analysis device further includes a junction encapsulation unit; The decapsulation unit is used to decapsulate the second service flow to obtain the added first service; The second acquisition unit 32 is used to acquire the software toolkit identifier from the added first service; Correspondingly, the decoding unit 34 is used to decode the added first service based on the software toolkit to obtain the keyframe.
[0110] It should be noted that, in practical applications, the second receiving unit 31, the second acquiring unit 32, the determining unit 33, the decoding unit 34, and the reporting unit 35 can be implemented by the second processor 41 on the protocol analysis device, specifically by a CPU (Central Processing Unit), MPU (Microprocessor Unit), DSP (Digital Signal Processor), or FPGA (Field Programmable Gate Array), etc.; the data storage can be implemented by the second memory 42 on the protocol analysis device.
[0111] This application also provides a protocol analysis device, such as... Figure 9 As shown, the protocol analysis device includes: a second processor 41, a second memory 42, and a second communication bus 43. The second memory 42 communicates with the second processor 41 through the second communication bus 43. The second memory 42 stores programs executable by the second processor 41. When the program is executed, the information monitoring method applied to the protocol analysis device as described above is executed by the second processor 41.
[0112] In practical applications, the second memory 42 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD) or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the second processor 41.
[0113] This application provides a computer-readable storage medium having a computer program thereon, which, when executed by a second processor 41, implements the information monitoring method as described above.
[0114] This application also provides a computer program product, including a computer program that can be executed by a second processor 41 in a protocol analysis device to complete the steps described in the aforementioned information monitoring method.
[0115] Understandably, when the protocol analysis device receives the second service flow sent by the first network element, it obtains the software toolkit identifier from the second service flow and determines the corresponding software toolkit based on the preset correspondence and the software toolkit identifier. This allows it to decode the second service flow based on the software toolkit, obtain the key frame in the second service flow, and send the key frame to the monitoring device. The monitoring device can then use the key frame to identify whether there are image frames in the extended reality service flow that are not suitable for propagation. This process does not affect the transmission of the extended reality service flow to the user, thereby improving the efficiency of service flow propagation.
[0116] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0117] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0118] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0119] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0120] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.
Claims
1. An information supervision method, characterized in that, Applied to the first network element, the method includes: Receive extended reality service streams sent by the application device; If the extended reality service flow is determined to be a service flow to be monitored based on the traffic identification strategy, the extended reality service flow is mirrored to obtain a first service flow; and the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy is obtained. A second service flow is generated based on the first service flow and the software toolkit identifier; The second service flow is sent to the protocol analysis device so that the protocol analysis device can perform information monitoring based on the second service flow.
2. The method according to claim 1, characterized in that, The step of generating a second service flow based on the first service flow and the software toolkit identifier includes: Add the software toolkit identifier to the first business flow to obtain the first business flow after addition; The added first service flow is encapsulated to obtain the second service flow.
3. The method according to claim 1, characterized in that, Before receiving the extended reality service stream sent by the application device, the method further includes: Establish a control information channel with the application device; Based on the control information channel, the application device sends policy configuration information; the policy configuration information includes traffic characteristics and a software toolkit identifier corresponding to the traffic characteristics; The traffic identification policy is generated based on the policy configuration information.
4. An information supervision method, characterized in that, Applied to a protocol analysis device, the method includes: Receive the second service flow sent by the first network element; Obtain the software toolkit identifier from the second business flow; The corresponding software toolkit is determined based on the preset correspondence and the software toolkit identifier; The second service stream is decoded based on the software toolkit to obtain the keyframes in the second service stream; The keyframe is reported to the monitoring device.
5. The method according to claim 4, characterized in that, Before determining the corresponding software toolkit based on the preset correspondence and the software toolkit identifier, the method further includes: Receive multiple software toolkits sent by the application device; Generate multiple software toolkit identifiers corresponding to the multiple software toolkits; The multiple software toolkits are deployed in a resource pool, and a preset correspondence is established between the multiple software toolkits and their identifiers.
6. The method according to claim 5, characterized in that, After establishing the preset correspondence between the plurality of software toolkits and the plurality of software toolkit identifiers, the method further includes: Send the preset correspondence to the application device.
7. The method according to claim 1, characterized in that, The step of obtaining the software toolkit identifier from the second business flow includes: The second service flow is decapsulated to obtain the first service after addition; Obtain the software toolkit identifier from the first service after it has been added; Accordingly, the step of decoding the second service stream based on the software toolkit to obtain keyframes in the second service stream includes: The keyframe is obtained by decoding the first service after it has been added, based on the software toolkit.
8. A first network element, characterized in that, The first network element includes: The first receiving unit is used to receive extended reality service streams sent by the application device; The replication unit is used to mirror the extended reality service flow to obtain a first service flow when the extended reality service flow is determined to be a service flow to be monitored based on the traffic identification strategy. The first acquisition unit is used to acquire the software toolkit identifier corresponding to the traffic characteristics in the traffic identification strategy; A generation unit is configured to generate a second service flow based on the first service flow and the software toolkit identifier; The sending unit is used to send the second service flow to the protocol analysis device so that the protocol analysis device can perform information monitoring based on the second service flow.
9. A first network element, characterized in that, The first network element includes: The first memory is used to store computer-executable instructions or computer programs; The first processor, when executing computer-executable instructions or computer programs stored in the first memory, implements the method according to any one of claims 1 to 3.
10. A protocol analysis device, characterized in that, The protocol analysis device includes: The second receiving unit is used to receive the second service flow sent by the first network element; The second acquisition unit is used to acquire the software toolkit identifier from the second business flow; The determining unit is used to determine the corresponding software toolkit based on a preset correspondence and the software toolkit identifier; The decoding unit is used to decode the second service stream based on the software toolkit to obtain key frames in the second service stream; The reporting unit is used to report the key frame to the monitoring equipment.
11. A protocol analysis device, characterized in that, The protocol analysis device includes: Secondary memory is used to store computer-executable instructions or computer programs; The second processor, when executing computer-executable instructions or computer programs stored in the second memory, implements the method according to any one of claims 4 to 7.
12. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the first processor, it implements the method according to any one of claims 1 to 3; when the computer program is executed by the second processor, it implements the method according to any one of claims 4 to 7.
13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the first processor, it implements the method according to any one of claims 1 to 3; when the computer program is executed by the second processor, it implements the method according to any one of claims 4 to 7.