Method for high performance signaling analysis and proof handling in a mobile communication network

By utilizing channelized devices and a pipelined data processing framework in mobile communication networks, efficient processing of signaling data in OTN and SDH signals is achieved, solving the problems of small signaling processing bandwidth and insufficient parallel processing capability in existing technologies, and improving the performance and functionality of signaling data processing.

CN122138131APending Publication Date: 2026-06-02TIANJIN JADE BIRD COMMUNICATION TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TIANJIN JADE BIRD COMMUNICATION TECHNOLOGY CO LTD
Filing Date
2026-02-24
Publication Date
2026-06-02

Smart Images

  • Figure CN122138131A_ABST
    Figure CN122138131A_ABST
Patent Text Reader

Abstract

This invention discloses a high-performance signaling analysis and verification processing method in mobile communication networks, belonging to the field of mobile communication. The system includes: accessing OTN and SDH signals using channelization equipment, performing polling analysis to identify and extract signaling data streams from the signals, encapsulating the signaling data streams as E1 data streams, automatically aggregating and tracing the source, and outputting them to a signal processing device; the signaling analysis and verification processing service is deployed as a backend service on multiple computing blades of the signal analysis and processing device; the signaling analysis and verification processing service employs a cascaded E1 data stream parallel acquisition module, an E1 data analysis module, an SS7 signaling data analysis module, and an information matching verification module, performing signaling analysis and verification processing on the E1 data streams through a pipelined data processing framework. The system of this invention can improve data access bandwidth and efficient parallel processing capabilities, enhancing the completeness and comprehensiveness of signaling data processing functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of mobile communication technology, specifically to a high-performance signaling analysis and verification method in mobile communication networks. Background Technology

[0002] In current mobile communication networks, the SS7 (Signaling System No. 7) system plays a core role. SS7 is applicable to public terrestrial mobile networks such as 2G and 3G through the MAP (Mobile Application Part) and CAP (CAMEL Application Part) protocols. SS7 provides local, long-distance, and international telephone call services, as well as related mobile services such as SMS, and also supports intelligent network services.

[0003] The SS7 protocol layered structure includes components such as MTP (Message Transfer Part), SCCP (Signaling Connection Control Part), and TCAP (Transaction Capabilities Application Part), as well as the functions of MAP, ISUP (ISDN User Part), and OMAP (Open Multimedia Applications Platform). ISUP is used in call connection control, establishing, managing, and releasing trunk circuits for voice or video calls between exchanges. SS7 was initially designed for fixed-line telephone networks, but later, through the introduction of protocols such as MAP, it became the core of 2G and 3G mobile networks. With the IP-ization of networks, the SIGTRAN protocol stack emerged, enabling SS7 signaling to be transmitted over IP networks. Therefore, there is still a certain demand for processing and analyzing signaling data carrying SS7 in mobile communication networks. However, the current equipment for processing SS7 signaling generally uses a single E1 rate interface with small processing bandwidth. Furthermore, signal access and signaling verification data processing cannot be uniformly managed and processed in a pipelined, high-performance parallel manner. In addition, there are currently few devices that simultaneously possess the functions of analyzing signaling data structure and verifying signaling data.

[0004] In mobile communication networks, signaling-related data is still encapsulated and transmitted as E1 data streams within OTN (Optical Transport Network) and SDH (Synchronous Digital Hierarchy) optical signals. The processing performance and access bandwidth of equipment analyzing and processing the SS7 signaling data carried in this E1 data stream are limited by the pure E1 interface. Furthermore, its processing performance cannot achieve horizontal scalability compatibility based on the increasing aggregation access bandwidth. Currently, there are few devices that integrate SS7 signaling data processing and extraction with signaling authentication functions. Summary of the Invention

[0005] The purpose of this invention is to provide a high-performance signaling analysis and verification processing method in mobile communication networks, which improves data access bandwidth and efficient parallel processing capabilities, and enhances the completeness and comprehensiveness of signaling data processing functions.

[0006] To achieve the above objectives, the present invention provides a technical solution:

[0007] A high-performance signaling analysis and authentication processing method in a mobile communication network includes:

[0008] S1 utilizes a channelization device to access OTN and SDH signals, performs polling analysis to identify and extract signaling data streams from the signals, encapsulates the signaling data streams as E1 data streams, automatically aggregates and traces and marks them, and outputs them to the signal processing device; the signaling analysis and processing verification service is deployed in a backend service mode on multiple computing blades of the signal analysis and processing device.

[0009] S2, the signaling analysis and verification service employs a cascaded E1 data stream parallel acquisition module, an E1 data analysis module, an SS7 signaling data analysis module, and an information matching and verification module. A pipelined data processing framework is used to perform signaling analysis and verification processing on the E1 data stream, including:

[0010] S21, the E1 data stream parallel acquisition module uses the source tracing and tagging information to perform load balancing scheduling of the aggregated E1 data stream in multiple soft queues.

[0011] S22, the E1 data analysis module performs SS7 overall structure verification, HDLC overall structure verification and SS7 timeslot data analysis on the load-balanced E1 data stream to extract and verify the SS7 signaling data in the E1 data stream and store it in the pcap packet;

[0012] S23, the SS7 signaling data analysis module performs SS7 data packet structure analysis on the pcap packet to obtain multi-layer structure information of MTP2, MTP3 and ISUP, extracts message types and key information carried in each message type, identifies the time nodes of call establishment and hanging up, associates relevant tracing information, and outputs communication information table and parsing information.

[0013] S24, the information matching and verification module performs signaling matching and verification based on the communication information table and parsing information, reverse-engineers the time slot information corresponding to the PCM voice stream from the circuit identification code (CIC) value, maps the start and end offsets of the data stream transmission using the communication establishment and hang-up time nodes, extracts the corresponding call data stream in the PCM voice stream according to the offset position as the verification call data, and associates it with the source information.

[0014] Furthermore, in S1, the channelization device is configured with multiple high-order cards and one low-order card, wherein the low-order output port of the high-order card is connected to the input port of the low-order card.

[0015] The high-order card receives the original OTN and SDH signals. After automatically polling and analyzing the input OTN and SDH signals, it automatically aggregates the low-order signals input to the high-order card to the low-order output port for output.

[0016] The low-order card extracts and analyzes low-order input signals through an automatic polling analysis mechanism, aggregates and outputs time slots containing E1 data from the signals, and connects the output end of the low-order card to the input end of multiple high-performance computing blades of the signal analysis device. The aggregated E1 data stream is encapsulated in an Ethernet structure and connected to the 10GE optical port of the computing blade for reception and processing.

[0017] Furthermore, in S2, the device network management system is used to control the operation status of the pipeline data processing framework. By issuing Socket communication commands, the system controls the business process and triggers the start, end, and termination of the signaling analysis and processing of the certificate service.

[0018] Further, in S21, the E1 data stream parallel acquisition module checks whether the current E1 data stream has been allocated a soft queue in the historical traceability and tagging information. If it has been allocated, the current E1 data stream is directly queued into the soft queue according to the allocated soft queue number, and the amount of data enqueued in the current soft queue is updated. If it has not been allocated, an idle soft queue is searched from all soft queues to serve as the input soft queue for the current E1 data stream, and the amount of data enqueued in the current soft queue is updated, as well as the soft queue number corresponding to the current E1 traceability information.

[0019] Further, in S22, the E1 analysis module scans and reads unanalyzed files in the E1 data acquisition file disk directory. After reading the file, it determines whether byte order reversal is required. If so, it reverses the high and low bits of each byte of the E1 data and stores it.

[0020] First, the E1 data stream is subjected to SS7 overall structure verification, including: frame-fixing the E1 data stream and verifying it using the polynomial CRC16 check algorithm, and extracting the data payload that passes the verification and storing it in the pcap packet.

[0021] If the SS7 overall structure verification fails, the E1 data stream will undergo HDLC overall structure verification; for the data that passes the HDLC overall structure verification, HDLC overall structure analysis will be performed, and the data payload that passes the verification will be extracted and stored in a pcap packet.

[0022] For data that fails the HDLC overall structure verification, perform SS7 timeslot data analysis, use the delimiter byte 0x7e to identify and extract the valid data stream, perform CRC16 verification calculation on the SS7 timeslot data, and if it passes, store the timeslot data payload in the pcap packet.

[0023] Furthermore, in S23, the SS7 signaling data analysis module reads the pcap packets, obtains the data content of each packet, first analyzes the MTP2 structure according to the SS7 protocol structure, and then obtains the starting position of the MTP3 structure according to the characteristics and length of the MTP2 structure.

[0024] Perform MTP3 structure parsing, extract source point code, destination point code and circuit identification code according to the length occupied by each field, and store them as communication information.

[0025] Furthermore, in S23, when the MTP3 structure service type indicator field identifies that the next layer structure carries ISUP protocol information, the next layer structure undergoes ISUP protocol structure parsing, including:

[0026] The system acquires and caches the source address code, destination address code, circuit selection code, calling number, called number, call start time, and call end time. Using the source address code, destination address code, and circuit selection code as unique call identifiers (Sessions), it iterates through all message type data packets to identify the continuity of call signaling. When the process from Initial Address Message (IAM) to Address Complete Message (ACM) to Answer Message (ANM) is captured, the call initiation time of this unique call identifier Session is recorded. When the process from Release Message (REL) to Release Complete Message (RLC) is captured, the hang-up time of this unique call identifier Session is recorded. The system obtains the communication information table corresponding to this unique call identifier Session, writes the communication information table to a file for storage, and also imports it into the database.

[0027] Furthermore, in S24, the timeslot information corresponding to the PCM voice stream obtained by the information matching and verification module includes: the E1 link number corresponding to the PCM voice path and the corresponding 64k timeslot number.

[0028] Extracting the TS timeslot data stream where the PCM voice stream is located based on the E1 link number and the corresponding 64k timeslot number includes: finding the corresponding E1 data stream from the collected E1 data stream, performing frame detection on the E1 data stream, normalizing the data into 32 TS timeslot data streams, and extracting the corresponding TS timeslot stream based on the 64k timeslot number corresponding to the PCM voice path.

[0029] Furthermore, the extracted call data stream is associated with the corresponding source information, including: associated wavelength division multiplexing channel number, task number, high-order timeslot number, low-order timeslot number and 64k timeslot number.

[0030] Furthermore, the signaling analysis and verification service is further connected to the voice generation output module at the output end of the information matching verification module. The voice generation output module maps and associates the verification call data extracted by the information matching verification module with relevant traceability information to achieve the splicing of traceability information in the WAV file name, and stores the voice stream in the audio file according to the WAV file format in the corresponding storage path.

[0031] Compared with the prior art, the beneficial effects of the present invention are:

[0032] This invention provides a high-performance signaling analysis and verification processing method for mobile communication networks. It utilizes front-end channelization equipment to aggregate and output SS7 signaling data carried in OTN and SDH. The aggregated data is then connected to an integrated signal processing device for high-performance parallel execution of signaling verification services. This completes the pipeline functions of high-capacity signal access, aggregation, and integrated high-performance data processing, outputting signaling verification voice data. The signaling processing bandwidth can be horizontally expanded in a stacked manner according to the access and aggregation volume, enabling better centralized processing of signaling verification data services. This invention can meet the current signaling data access and processing requirements of mobile communication networks, improve data access bandwidth and efficient parallel processing capabilities, and enhance the completeness and comprehensiveness of signaling data processing functions.

[0033] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0034] Figure 1 This is a structural diagram of the high-performance signaling analysis and verification processing method in mobile communication networks according to the present invention;

[0035] Figure 2 This is an architecture diagram of the signal processing circuitry of the present invention;

[0036] Figure 3 This is a schematic diagram of the data processing pipeline model of the present invention;

[0037] Figure 4 This is a flowchart of the E1 data stream parallel acquisition module of the present invention;

[0038] Figure 5 This is a flowchart of the E1 data analysis module of the present invention;

[0039] Figure 6 This is a flowchart of the SS7 signaling data analysis module of the present invention;

[0040] Figure 7 This is a flowchart of the signaling matching and verification module of the present invention. Detailed Implementation

[0041] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0042] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0043] This invention proposes a high-performance signaling analysis and verification processing method for mobile communication networks. This method enables efficient processing of signaling data carried in OTN and SDH signals in mobile communication networks, which can improve the bandwidth and capacity of signaling data processing, increase the depth of signaling parsing results, and provide integrated output verification results for signaling verification services.

[0044] Reference Figure 1 As shown, this disclosure provides a high-performance signaling analysis and verification processing method in a mobile communication network, including:

[0045] S1 utilizes channelization equipment to access OTN and SDH signals, performs polling analysis to identify and extract signaling data streams from the signals, encapsulates the signaling data streams as E1 data streams, automatically aggregates and traces and marks them, and outputs them to the signal processing equipment; the signaling analysis and processing verification service is deployed on multiple computing blades of the signal analysis and processing equipment in a backend service mode.

[0046] Specifically, the efficient signaling verification processing method based on computing blades involves using a front-end integrated device channelization device on a high-performance computing blade with an x86 architecture to aggregate and output the E1 data stream to an ATCA-type 6U architecture computing blade, and then performing overall analysis and signaling verification operations on the aggregated E1 data stream.

[0047] In this invention, optical signals can be accessed into the channelization device using a multi-path parallel access method.

[0048] Because the channelization equipment supports 100G / 10GOTN, 10G / 2.5G / 622M / 155MSDH access, and can aggregate and output E1 data streams from SDH signals encapsulated in OTN signals or directly accessed SDH signals, and add traceability tagging information, the E1 data streams are uniformly aggregated and output through the channelization equipment and then connected to the high-performance computing blades of the ATCA architecture for unified processing. The signal connection topology architecture can be horizontally expanded in terms of the number of boards according to the number of signal accesses, and the overall analysis and processing architecture has scalability.

[0049] refer to Figure 2 As shown, the wiring architecture of the channelization equipment and signal processing equipment is as follows:

[0050] The channelization device is configured with multiple high-level cards and one low-level card, wherein the low-level output port of the high-level card is connected to the input port of the low-level card.

[0051] Specifically, the high-order card receives the original OTN and SDH signals, automatically polls and analyzes the input OTN and SDH signals, and then automatically aggregates the low-order signals input to the high-order card to the low-order output port of the high-order card for output.

[0052] The low-order card extracts and analyzes low-order input signals through an automatic polling analysis mechanism, aggregates the time slots containing E1 data in the signal, and outputs them. The output of the low-order card is connected to the input of multiple high-performance computing blades of the signal analysis equipment, encapsulates the aggregated E1 data stream into an Ethernet structure, and connects to the 10GE optical port of the high-performance computing blade for reception and processing.

[0053] It should be noted that the current line wiring processing architecture can plan the ratio of high-order and low-order cards of the channelization equipment according to the specific high-order and low-order signal quantities that need to be processed, and plan the ratio of high-performance computing blades of the signal processing equipment through the low-order output E1 signal quantities. It has the feature of horizontally expanding the architecture to improve processing capabilities according to the signal input volume.

[0054] This invention utilizes the high-bandwidth access and polling analysis capabilities of channelized devices for OTN and SDH signals to identify and extract the signaling data streams contained within them. These streams are then encapsulated in E1 data streams within an Ethernet structure and aggregated for output to signal analysis equipment for high-performance signaling analysis and verification. The E1 data stream encapsulation within the Ethernet structure defines relevant traceability and tagging formats, facilitating the tracing and correlation of subsequent signaling analysis and verification results. This data cabling networking scheme allows for horizontal stacking expansion to meet the increased service access bandwidth demands.

[0055] S2, the signaling analysis and verification service adopts a cascaded E1 data stream parallel acquisition module, E1 data analysis module, SS7 signaling data analysis module, information matching and verification module, and voice generation and output module. The pipelined data processing framework performs signaling analysis and signaling verification processing on the E1 data stream.

[0056] like Figure 3 As shown, after the E1 signal (i.e., the E1 data stream) is processed and aggregated by the front-end channelization equipment, the high-performance computing blade on the signal analysis equipment performs signaling verification processing on the E1 signal, realizing a pipeline-style data processing framework for signaling data processing.

[0057] The pipeline-style data processing framework consists of five modules: an E1 data stream parallel acquisition module, an E1 data analysis module, an SS7 signaling data analysis module, an information matching and verification module, and a voice generation and output module. These five modules are cascaded and interconnected, meaning the output of one module serves as the input for the next, completing the pipeline processing model in a chain-like manner.

[0058] This invention utilizes channelization equipment to access high-capacity OTN and SDH signals, and polls and analyzes the signaling service traffic contained therein. Channels with signaling services are automatically cross-aggregated to specific output ports. The signal analysis equipment uses stacked, scalable access channelization equipment to aggregate and output signaling service traffic. Leveraging the high-performance computing blades within the signal analysis equipment, the current signaling service traffic is processed in real-time and in parallel. Using an E1 data stream parallel acquisition module, an E1 data analysis module, an SS7 signaling data analysis module, an information matching and verification module, and a voice generation and output module, a controllable signaling data processing service pipeline model is formed. This outputs the signaling analysis results, verification results, and verification files that users are interested in, for users to view and download for playback.

[0059] In this invention, a device network management system is used to control the operation of the pipeline-style data processing framework. By issuing Socket communication commands, the system controls the business process and triggers control signaling analysis and processing to control the start, end, and termination of the certificate business.

[0060] S21, the E1 data stream parallel acquisition module uses source tracing and tagging information to load balance and schedule the aggregated E1 data streams across multiple soft queues.

[0061] The E1 data stream parallel acquisition module uses a traffic load balancing algorithm to schedule the aggregated E1 data streams based on source tracing and tagging information, thereby achieving balanced concurrent processing of traffic across multiple cores and threads. The E1 data stream parallel acquisition module employs the DPDK high-performance data plane development kit to implement a network data reception and acquisition service development model, thus achieving high-performance parallel acquisition and reception of aggregated E1 data traffic.

[0062] like Figure 4 As shown, the E1 data stream parallel acquisition module achieves parallel acquisition through a high-performance data acquisition framework deployed in the high-performance computing blade, and uses traceability and tagging information to sort and store the E1 data stream.

[0063] 1) The E1 data stream carried in 10GE Ethernet packets is input to the 10G network port of the high-performance computing blade of the signal processing equipment. The 10G network port uses the DPDK high-performance data development framework to capture and receive high-performance data streams. By leveraging the features of DPDK, the Linux kernel is bypassed to reduce multiple data copies, achieving zero-copy of the data stream to user space for processing. The user space application efficiently captures the data stream on the network port as input for subsequent processing modules.

[0064] 2) After the E1 data stream is received and captured by the DPDK framework, the E1 data stream parallel acquisition module performs load balancing processing on the data packets, designs a load balancing algorithm, and uses the specification of encapsulating the E1 data stream in the Ethernet packet to extract information such as the high and low order timeslot numbers representing E1 traceability.

[0065] The E1 data stream parallel acquisition module checks the historical E1 source information to see if the current E1 data stream has been assigned to a known soft queue. If it has, the current E1 data stream is directly enqueued into the soft queue according to the assigned soft queue number, and the amount of data enqueued in the current soft queue is updated. If it has not been assigned, an idle soft queue (i.e., the soft queue with the least amount of data received) is searched from all soft queues. This soft queue with the least amount of data is used as the input soft queue for the current E1 data stream, and the amount of data enqueued in the current soft queue is updated, as well as the soft queue number corresponding to the current E1 source information.

[0066] The load balancing algorithm used in this invention can ensure that the same E1 data flows into the same soft queue, while ensuring that the data flow transmitted in the soft queue remains balanced, thereby ensuring the task parallelism of the storage thread for subsequent data flows.

[0067] For example, if the source information 1 in the E1 data stream is found to have an enqueue soft queue number of 1, then the E1 data stream of the source information 1 is enqueued into soft queue 1; if no enqueue soft queue number is found, then the soft queue pool is searched to find the soft queue 2 with the fewest enqueue data, then the E1 data stream of the source information 1 is enqueued into soft queue 2.

[0068] 3) After receiving the E1 data stream, different soft queues perform dequeue operations on different cores. For example, the data dequeue operation for soft queue 1 is performed on core 1, the data dequeue operation for soft queue 2 is performed on core 2, the data dequeue operation for soft queue 3 is performed on core 3, the data dequeue operation for soft queue 4 is performed on core 4, and so on.

[0069] 4) After dequeuing E1 data streams on different cores, the source identifier of the E1 data stream is parsed, and the corresponding storage descriptor is found based on the source identifier. If the storage descriptor does not exist, it is created. The corresponding cache block is checked to see if it is full and data needs to be written. If it is full, the data is written to the E1 data file. Different cores correspond to their respective E1 data storage threads. For example, dequeued data from core 1 corresponds to E1 data storage thread 1, dequeued data from core 2 corresponds to E1 data storage thread 2, and so on.

[0070] S22, the E1 data analysis module performs SS7 overall structure verification, HDLC overall structure verification, and SS7 timeslot data analysis on the load-balanced E1 data stream to extract and verify the SS7 signaling data in the E1 data stream and store it in a pcap (PacketCapture) packet.

[0071] The E1 data analysis module performs framing and frame structure processing on E1 data. It uses a data processing polynomial CRC check algorithm and a delimiter byte 0x7e identification and extraction algorithm to verify and extract SS7 signaling data from E1 data.

[0072] like Figure 5 As shown, the E1 analysis module performs parallel analysis and processing on the E1 data stored in the E1 data stream parallel acquisition module, executing processes such as E1 data frame synchronization, decapsulation, and data extraction, and outputting relevant SS7 data pcap packets.

[0073] 1) The E1 analysis module scans and reads unanalyzed files in the E1 data acquisition file disk directory. After reading the file, it determines whether byte order reversal is required. If so, it reverses the high and low bits of each byte of the E1 data and stores the reversed data, then performs the SS7 overall structure verification. If reversal is not required, it directly performs the SS7 overall structure verification.

[0074] 2) Perform SS7 overall structure verification on the E1 data stream, including: First, perform a synchronization bit search to frame the E1 data stream. After framing, the data is regularized into a data matrix of 32 64k time slot streams. Excluding the first synchronization time slot, the remaining 31 time slots are used as the overall data stream for a 0x7e search. The data between two 0x7e values ​​undergoes a bitwise operation of removing one 0 from five 1s, converting the resulting data bits into bytes. According to the SS7 data structure specification, the data must satisfy the CRC16 polynomial check. The bytes in the data payload, excluding the last two bytes, are then subjected to CRC16 checksum calculation.

[0075] If the CRC16 calculation result is equal to the last two bytes of the data payload, the current byte stream is determined to conform to the overall SS7 structure. The data that passes the verification is then parsed using the overall SS7 structure; that is, the verified data payload is extracted and stored in a pcap packet, and the source information of the data is marked in the filename of the pcap packet.

[0076] 3) If the SS7 overall structure check fails, perform HDLC (High-Level Data Link Control) overall structure check on the E1 data stream. This includes: searching the entire data stream for 0x7e bits, performing a bitwise operation (removing one 0 from five 1s) on the data between two 0x7e bits, and converting the resulting data bits into bytes. According to the HDLC data structure specification, the data payload must meet the HDLC CRC16 polynomial check. After removing the last two bytes of the data payload, perform the HDLC CRC16 check calculation.

[0077] If the CRC16 calculation result is equal to the last two bytes of the data payload, the current byte stream is determined to conform to the overall HDLC structure. The verified data is then parsed using the overall HDLC structure; that is, the verified data payload is extracted and stored in a pcap packet, and the source information of the data is marked in the pcap packet file name.

[0078] 4) Perform SS7 timeslot data analysis on data that fails the HDLC overall structure verification, including: performing SS7 timeslot data analysis on the data, framing the data and then normalizing it into 32 timeslots to obtain the data stream for each timeslot, performing a 0x7e search on the independent data stream for each timeslot from 1 to 31, extracting the data in 0x7e, and performing a bitwise operation of removing one 0 from five 1s to obtain the payload data, converting the obtained payload data into bytes, and performing SS7 CRC16 checksum calculation. If the checksum passes, the timeslot data payload is stored in a pcap packet, with the pcap packet name indicating the current tracing information and the timeslot number of the current 64k.

[0079] It should be noted that the CRC16 verification methods for SS7 and HDLC structures are different. If the CRC16 verification fails for SS7, it will be calculated according to the CRC16 verification method for HDLC to see if it meets the CRC16 verification standard. If it does, it is determined to be an HDLC package.

[0080] S23, the SS7 signaling data analysis module performs SS7 data packet structure analysis on the pcap packets, obtains multi-layer structure information of the reliable transport layer MTP2, the routing layer MTP3, and the call control layer ISUP, extracts message types and key information carried in each message type, identifies the time nodes of call establishment and termination, associates relevant tracing information, and outputs communication information table and parsing information.

[0081] The SS7 signaling data analysis module parses and processes the SS7 data structure in E1, analyzes the multi-layer structure information of SS7 such as MTP2, MTP3, and ISUP, extracts message types and key information carried in each message type, and derives the IAM, ACM, ANM, RLC, and REL message types, as well as the source point code, destination point code, circuit identification code, calling number, and called number contained in each message type. It identifies the time nodes of call establishment and termination, associates relevant tracing information, and outputs the communication information table and parsing information.

[0082] like Figure 6 As shown, the SS7 signaling data analysis module performs SS7 data packet structure analysis on the pcap packets output from the E1 analysis module, focusing on parsing the ISUP protocol, extracting information such as source point code, destination point code, and circuit identification code, identifying and statistically analyzing the call flow, and outputting call communication related information by combining the extracted calling number, called number, and call initiation and hang-up time.

[0083] 1) The SS7 signaling data analysis module reads the pcap packets output from the E1 analysis module and obtains the data content of each packet. It analyzes the MTP2 structure based on the SS7 protocol structure, and then determines the starting position of the MTP3 structure based on the characteristics and length of the MTP2 structure.

[0084] 2) Perform MTP3 structure parsing, including: According to the protocol specification, the MTP3 structure contains source code, destination code, and circuit identification code. Based on the length of each field, extract the source code, destination code, and circuit identification code content and store them as partial information fields of the communication information. The MTP3 structure service type indicator field can identify the protocol information type carried by the next layer structure. If the protocol information type carried by the next layer structure is identified as ISUP protocol, then the next layer structure is parsed using the ISUP protocol structure.

[0085] 3) Perform ISUP structure parsing, including: extracting message types from the ISUP protocol structure according to the protocol specification. If the message type is IAM Initial Address message, enter the call initiation state, parse the protocol structure, and obtain the calling and called numbers. When the message type is ACM Address Full message, enter the call setup state, and ringing begins when there is free time. When the message type is ANM Answer message, enter the called party answering state, and the call actually begins; record the current call start time. When the message type is REL Release message, enter the one-party hang-up state, and the call ends; record the current call end time. When the message type is RLC Release Complete message, enter the connection fully released state, indicating that the current call resources have been released.

[0086] 4) The source code, destination code, circuit selection code, calling number, called number, call start time, and call end time obtained during ISUP protocol parsing are cached and associated with line-related information, including wavelength division multiplexing (WDM) channel number, higher-order timeslot number, lower-order timeslot number, and 64k timeslot number. A unique call identifier for each session is the source code, destination code, and circuit selection code, which forms the Session. All message type data packets are traversed to identify the continuity of call signaling. When the flow from Initial Address Message (IAM) to Address Complete Message (ACM) to Response Message (ANM) is captured, the call initiation time of this unique call identifier Session is recorded. When the flow from Release Message (REL) to Release Complete Message (RLC) is captured, the hang-up time of this unique call identifier Session is recorded. This yields the communication information table corresponding to this unique call identifier Session. The communication information table is written to a file for storage and then added to the database.

[0087] S24, the information matching and verification module performs signaling matching and verification based on the communication information table and parsing information, reverse-engineers the time slot information corresponding to the PCM voice stream from the circuit identification code (CIC) value, uses the communication establishment and hanging-up time nodes to map the start and end offsets of the data stream transmission, extracts the corresponding call data stream from the PCM voice stream according to the offset position as the verification call data, and associates it with the source information.

[0088] The information matching and verification module performs a signaling matching and verification process based on the parsed information and communication information table obtained from the SS7 signaling data analysis module. It uses a reverse algorithm to calculate the E1 time slot and 64k time slot number of the PCM voice stream by using the communication establishment and hanging-up time nodes to map the start and end offsets of the data stream transmission. Based on the offset position, it extracts the corresponding call data stream from the PCM voice stream.

[0089] like Figure 7 As shown, the information matching and verification module performs information matching and verification on the communication process information captured and analyzed by the SS7 signaling analysis module. It identifies the unique call identifier of the communication information and verifies the time slot of the corresponding voice PCM stream. Based on the Circuit Identifier (CIC) value in the unique call identifier, it uses an encoding algorithm to deduce the lower-order time slot number and the 64k time slot number of the corresponding voice PCM, thus obtaining the time slot stream where the PCM voice resides. The module maps the corresponding bit stream position of the voice based on the call initiation and hang-up times and then extracts the data stream.

[0090] 1) The information matching and verification module uses the CIC encoding reverse algorithm to calculate the corresponding time slot information of the PCM. The CIC uniquely identifies the physical (or logical) circuit (a time slot in the trunk line) carrying the call. In the SS7 network, a trunk group can contain multiple E1 links. Each E1 link has an initial CIC value, and then circuit identification codes (CICs) are assigned sequentially.

[0091] For example, suppose a trunk group consists of n E1 links. In the first E1 link, CIC 1 corresponds to TS1, CIC2 corresponds to TS2, ..., CIC 15 corresponds to TS15, and CIC 31 corresponds to TS31. In the second E1 link, CIC 33 corresponds to TS1, CIC 34 corresponds to TS2, ... and so on. Therefore, the encoding reverse derivation steps are as follows: extract the high 7 bits and low 5 bits of CIC, calculate the E1 link number: e1_index = cic / 32 + 1 [the first E1 link is numbered 1], and calculate the slot index within this E1 link: slot_index = relative_cic % 32. This yields the E1 link number and the corresponding 64k slot number for the PCM call path corresponding to this call link.

[0092] 2) The timeslot information corresponding to the PCM voice stream obtained by the information matching and verification module includes: the E1 link number and the corresponding 64k timeslot number corresponding to the PCM voice path.

[0093] The information matching and verification module extracts the TS timeslot data stream where the PCM voice stream is located based on the E1 link number and the corresponding 64k timeslot number obtained above. This includes: finding the corresponding data stream from the collected E1 data stream, performing frame detection on the E1 data stream, normalizing the data into 32 TS timeslot data streams, and extracting the corresponding TS timeslot stream based on the 64k timeslot number in the E1 corresponding to the PCM voice stream.

[0094] 3) The information matching and verification module finds the offset start position of the current stream corresponding to the call start time and the offset end position of the current stream corresponding to the end time based on the call start time and end time in the communication information table, and extracts the voice stream of the corresponding call period from the PCM voice stream extracted above.

[0095] 4) Associate the extracted audio stream with the corresponding source information, mainly associating the wavelength division multiplexing channel number, task number, high-order time slot number, low-order time slot number and 64k time slot number, so as to facilitate the audio storage module to concatenate file names.

[0096] refer to Figure 3The signaling analysis and processing verification service further connects to the voice generation output module at the output end of the information matching verification module. The voice generation output module maps and associates the verification call data extracted by the information matching verification module with relevant traceability information to achieve the concatenation of traceability information in the WAV file name. The voice stream is stored in the audio file according to the WAV file format under the corresponding storage path to complete the WAV file output and provide FTP service for access and download.

[0097] Specifically, the voice generation and output module stores the verification call data extracted by the signaling matching and verification module, and concatenates the traceability information of the WAV file name.

[0098] The WAV file name format is combined according to the format "Task ID_Line ID_Signal ID_Channel ID_Wave Division Number_Channel Number_OTN Channel Number_E1_VC12_High-order Time Slot_Low-order Time Slot_64k Time Slot Number-Time Stamp@CIC(dpc value-opc value-cic value)@Calling Number-Called Number-Packet Number.wav". The voice stream is stored in the audio file according to the WAV file format in the corresponding storage path.

[0099] In this invention, the signaling analysis and verification service has a service control interface, which controls the start, end, and termination of the service through a SOCKET. The E1 data stream parallel acquisition module, E1 data analysis module, SS7 signaling data analysis module, information matching and verification module, and voice generation and output module run on a high-performance computing blade as a data service processing service. Each function and related parsing and processing verification algorithms are implemented in C++ and Python.

[0100] refer to Figure 3 The E1 data stream parallel acquisition module, E1 data analysis module, SS7 signaling data analysis module, information matching and verification module, and voice generation and output module are deployed on multiple computing blades of the signal analysis device. Each computing blade has multiple 10G network ports to receive aggregated E1 traffic, more than 384G of memory space, and 48 cores of parallel processing capability. It can achieve high-performance computing of data processing streams for the E1 data stream parallel acquisition module, E1 data analysis module, SS7 signaling data analysis module, information matching and verification module, and voice generation and output module. The above modules are mainly developed and implemented in C++ and Python, and are combined into a data processing signaling verification backend service running on multiple computing blades.

[0101] The E1 data stream parallel acquisition module, E1 data analysis module, SS7 signaling data analysis module, information matching and verification module, and voice generation and output module are combined into a data processing pipeline. The operation status of the data processing pipeline is controlled by the device network management system, which controls the business process by issuing Socket communication commands.

[0102] When the task start instruction is received, the data processing signaling verification backend service will trigger the business. All data streams during the business operation time will enter the data processing pipeline to process and output intermediate data or intermediate results. Finally, the signaling verification data results and the signaling verification analysis correlation results in the database can be seen in the current task output directory.

[0103] When the service execution time is reached and a task termination instruction is received, all parallel processing threads are terminated, and E1 traffic reception stops. When the service execution time is not reached and a task abort instruction is received, the currently running parallel processing service is aborted, and E1 traffic reception stops.

[0104] The device network management interface can display the signaling verification results and the corresponding verification data WAV file output path. An FTP service is deployed on the data processing device to allow users to download the corresponding signaling verification data WAV file. Users can directly play the downloaded WAV file.

[0105] In summary, the high-performance signaling analysis and verification processing method for mobile communication networks proposed in this invention is a processing architecture that combines cascaded networking with channelization equipment. Through the front-end access of OTN and SDH optical signals via the channelization equipment, the E1 data streams contained therein are automatically aggregated, tagged, and traced, and output to multiple stacked computing blades of the signal processing equipment. The signal processing equipment achieves high-performance concurrent acquisition and reception of the E1 data streams, establishing a pipeline architecture for data processing. The aggregated input E1 data streams with traceability tags are processed in real time within the service processing cycle, and signaling analysis results and verification files are output. Users can immediately obtain relevant parsing results of signaling data in the current input signal, key information elements in transmission, call communication information tables, and signaling verification files. Furthermore, the analysis results output can be subscribed to and viewed, and the signaling verification files can be downloaded to local storage via FTP service for viewing and playback. The verification files and analysis results output have a traceability relationship, allowing users to easily understand the source information of the current verification results.

[0106] The signaling analysis and processing verification service is deployed as a backend service on the high-performance computing blades of the signal analysis and processing equipment. Leveraging the high-performance computing power of these blades, it enables parallel analysis of the aggregated E1 data streams. The signaling analysis and processing and verification services provide external control interfaces, allowing users to configure start, end, and abort commands according to their needs. This fulfills users' controllable requirements for the services. After the service ends or is aborted, users can view the analysis results and verification documents.

[0107] The signaling analysis and processing verification service provides detailed and rich analysis results on the signaling structure. It can extract key information from SS7 signaling data, perform signaling flow analysis and source tracing and correlation processing, and customize a set of source management tags. It can trace and correlate the final data output results and files to the original wavelength division multiplexing channel number, time slot number and other information of the signal, so as to facilitate users to track and associate them.

[0108] In the description of this invention, it should be understood that the indicated orientation or positional relationship is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing this invention and simplifying the description, and is not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this invention.

[0109] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0110] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A high-performance signaling analysis and verification processing method in a mobile communication network, characterized in that, include: S1 utilizes a channelization device to access OTN and SDH signals, performs polling analysis to identify and extract signaling data streams from the signals, encapsulates the signaling data streams as E1 data streams, automatically aggregates and traces and marks them, and outputs them to the signal processing device; the signaling analysis and processing verification service is deployed in a backend service mode on multiple computing blades of the signal analysis and processing device. S2, the signaling analysis and verification service employs a cascaded E1 data stream parallel acquisition module, an E1 data analysis module, an SS7 signaling data analysis module, and an information matching and verification module. A pipelined data processing framework is used to perform signaling analysis and verification processing on the E1 data stream, including: S21, the E1 data stream parallel acquisition module uses the source tracing and tagging information to perform load balancing scheduling of the aggregated E1 data stream in multiple soft queues. S22, the E1 data analysis module performs SS7 overall structure verification, HDLC overall structure verification and SS7 timeslot data analysis on the load-balanced E1 data stream to extract and verify the SS7 signaling data in the E1 data stream and store it in the pcap packet; S23, the SS7 signaling data analysis module performs SS7 data packet structure analysis on the pcap packet to obtain multi-layer structure information of MTP2, MTP3 and ISUP, extracts message types and key information carried in each message type, identifies the time nodes of call establishment and hanging up, associates relevant tracing information, and outputs communication information table and parsing information. S24, the information matching and verification module performs signaling matching and verification based on the communication information table and parsing information, reverse-engineers the time slot information corresponding to the PCM voice stream from the circuit identification code (CIC) value, maps the start and end offsets of the data stream transmission using the communication establishment and hang-up time nodes, extracts the corresponding call data stream in the PCM voice stream according to the offset position as the verification call data, and associates it with the source information.

2. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, In S1, the channelization device is configured with multiple high-order cards and one low-order card, wherein the low-order output port of the high-order card is connected to the input port of the low-order card. The high-order card receives the original OTN and SDH signals. After automatically polling and analyzing the input OTN and SDH signals, it automatically aggregates the low-order signals input to the high-order card to the low-order output port for output. The low-order card extracts and analyzes low-order input signals through an automatic polling analysis mechanism, aggregates and outputs time slots containing E1 data from the signals, and connects the output end of the low-order card to the input end of multiple high-performance computing blades of the signal analysis device. The aggregated E1 data stream is encapsulated in an Ethernet structure and connected to the 10GE optical port of the computing blade for reception and processing.

3. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, In S2, the device network management system controls the operation of the pipeline data processing framework, controls the business process by issuing Socket communication commands, and triggers the start, end and stop of the signaling analysis and processing of the certificate service.

4. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, In S21, the E1 data stream parallel acquisition module checks whether the current E1 data stream has been allocated to a soft queue in the source tracing and tagging information of the historical records. If it has been allocated, the current E1 data stream is directly queued into the soft queue according to the allocated soft queue number, and the amount of data enqueued in the current soft queue is updated. If no soft queue is allocated, a free soft queue is searched from all soft queues and used as the input soft queue for the current E1 data stream. The amount of data enqueued in the current soft queue is updated, and the soft queue number corresponding to the current E1 traceability information is updated.

5. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, In S22, the E1 analysis module scans and reads unanalyzed files in the E1 data acquisition file disk directory. After reading the file, it determines whether byte order reversal is required. If so, the high and low bits of each byte of E1 data are reversed and stored. First, the E1 data stream is subjected to SS7 overall structure verification, including: frame-fixing the E1 data stream and verifying it using the polynomial CRC16 check algorithm, and extracting the data payload that passes the verification and storing it in the pcap packet. If the SS7 overall structure verification fails, the E1 data stream will undergo HDLC overall structure verification; for the data that passes the HDLC overall structure verification, HDLC overall structure analysis will be performed, and the data payload that passes the verification will be extracted and stored in a pcap packet. For data that fails the HDLC overall structure verification, perform SS7 timeslot data analysis, use the delimiter byte 0x7e to identify and extract the valid data stream, perform CRC16 verification calculation on the SS7 timeslot data, and if it passes, store the timeslot data in the pcap packet.

6. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, In S23, the SS7 signaling data analysis module reads the pcap packets and obtains the data content of each packet. First, it analyzes the MTP2 structure according to the SS7 protocol structure, and then obtains the starting position of the MTP3 structure according to the characteristics and length of the MTP2 structure. It performs MTP3 structure parsing and extracts the source point code, destination point code, and circuit identification code according to the length occupied by each field, and stores them as communication information.

7. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 6, characterized in that, In S23, when the MTP3 structure service type indicator field identifies that the next layer structure carries ISUP protocol information, the next layer structure is parsed for ISUP protocol structure parsing, including: The system acquires and caches the source address code, destination address code, circuit selection code, calling number, called number, call start time, and call end time. Using the source address code, destination address code, and circuit selection code as unique call identifiers (Sessions), it iterates through all message type data packets to identify the continuity of call signaling. When the process from Initial Address Message (IAM) to Address Complete Message (ACM) to Answer Message (ANM) is captured, the call initiation time of this unique call identifier Session is recorded. When the process from Release Message (REL) to Release Complete Message (RLC) is captured, the hang-up time of this unique call identifier Session is recorded. The system obtains the communication information table corresponding to this unique call identifier Session, writes the communication information table to a file for storage, and also imports it into the database.

8. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, In S24, the timeslot information corresponding to the PCM voice stream obtained by the information matching and verification module includes: the E1 link number and the corresponding 64k timeslot number corresponding to the PCM voice path. Extracting the TS timeslot data stream where the PCM voice stream is located based on the E1 link number and the corresponding 64k timeslot number includes: finding the corresponding E1 data stream from the collected E1 data stream, performing frame detection on the E1 data stream, normalizing the data into 32 TS timeslot data streams, and extracting the corresponding TS timeslot stream based on the 64k timeslot number corresponding to the PCM voice path.

9. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, In S24, the extracted call data stream is associated with the corresponding source information, including: associated wavelength division multiplexing channel number, task number, high-order timeslot number, low-order timeslot number and 64k timeslot number.

10. The high-performance signaling analysis and verification processing method in a mobile communication network according to claim 1, characterized in that, The signaling analysis and verification service is further connected to the voice generation output module at the output end of the information matching verification module. The voice generation output module maps and associates the verification call data extracted by the information matching verification module with relevant traceability information to achieve the splicing of traceability information in the WAV file name, and stores the voice stream in the audio file according to the WAV file format in the corresponding storage path.