Method for packet-based network monitoring in an O-RAN system

The method for packet-based network monitoring in O-RAN systems addresses the limitations of current monitoring systems by capturing and analyzing data packets at lower protocol layers, enhancing network monitoring efficiency and reducing downtime through detailed packet-level insights and proactive error detection.

DE102023213194A1Pending Publication Date: 2025-06-26ROBERT BOSCH GMBH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102023213194
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Current network monitoring systems in O-RAN systems provide limited performance measurements, making troubleshooting difficult and costly, especially in safety-critical and cost-sensitive sectors like industrial and automotive, due to limited access to lower protocol stack information.

Method used

A method for packet-based network monitoring in O-RAN systems that captures, filters, and analyzes data packets using O-RAN service models, enabling detailed network monitoring and performance analysis at lower protocol layers, reducing the need for special measuring devices and improving error detection and traceability.

Benefits of technology

Enhances network monitoring efficiency by providing detailed packet-level insights, reducing downtime, and enabling proactive error detection and adjustment, thus improving overall application performance and reducing computational load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method (100) for packet-based network monitoring in an O-RAN system (6) to initiate a measure for adapting the network monitoring, comprising the following steps: - capturing (101) data packets at an interface (10) of the O-RAN system (6) using an O-RAN service model, - extracting (102) information relating to the respective data packet on the basis of a selection criterion for network monitoring, wherein the selection criterion is specific to a respective network monitoring task, - aggregating (103) the extracted information with respect to the respective data packet in order to analyze the data contained in the information, - analyzing (104) the data from the aggregated information on the basis of a predetermined analysis model, wherein the analysis model comprises an algorithm for evaluating the data, - Initiating (105) a measure to adapt the network monitoring based on the result of the analysis (104).
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to a method for packet-based network monitoring in an O-RAN system. The invention further relates to a network function, a computer program and a computer-readable storage medium for this purpose.Prior ArtFor applications with safety-critical and cost-sensitive effects, e.g. from the industrial or automotive sector, an underlying network infrastructure with reliable and highly deterministic transmission or forwarding capabilities represents an important basis. Communication technologies based on the 5G or 6G standard increasingly contain mechanisms such as methods for redundant transmission and highly configurable, synchronized traffic control.With the introduction of open radio access network (RAN) systems or also O-RAN systems, further functions can be used in a 5G / 6G communication network in order to control the data traffic within the communication network. An open radio access network (RAN) system is a telecommunication system that replaces the traditional architecture of mobile radio networks with a disaggregated and open structure. This system may include various components, interfaces, or functions, such as a radio unit (RU), a distributed unit (DU), a centralized unit (CU), and various interfaces between these components.Due to the limited access to information at a lower level of a protocol stack, today's network monitoring systems provide only a few performance measurements, e.g. with respect to a data packet rate, a data packet loss or cyclic redundancy checks. Endpoints in a communication network, such as a user equipment, on which an application can be operated, can be equipped with corresponding error counters for the aforementioned measurement purpose. An example of this is an industrial application that cyclically receives input data. If, in one case, too many successive data packet losses occur during the data transmission in a network, this application can be controlled in such a way that it transitions into a safe state. However, subsequent debugging based on analysis of the performance measurements may be difficult and cost valuable time.Disclosure of the InventionThe subject matter of the invention is a method with the features of claim 1, a network function with the features of claim 9, a computer program with the features of claim 10 and a computer-readable storage medium with the features of claim 11. Features and details which are described in connection with the method according to the invention naturally also apply in connection with the network function according to the invention, the computer program according to the invention and the computer-readable storage medium according to the invention, and vice versa, so that with regard to the disclosure reference is or can always be made to the individual aspects of the invention in a mutually alternating manner.The invention relates in particular to a method for packet-based network monitoring in an O-RAN system in order to initiate a measure for adapting the network monitoring, comprising the following steps:detecting data packets at an interface of the O-RAN system using an O-RAN service model,extracting information relating to the respective data packet on the basis of a selection criterion for the network monitoring, wherein the selection criterion is specific to a respective task for the network monitoring,aggregating the extracted information with respect to the respective data packet in order to analyze the data contained in the information,analyzing the data from the aggregated information on the basis of a predefined analysis model, wherein the analysis model comprises an algorithm for evaluating the data,initiating a measure for adapting the network monitoring on the basis of the result of the analysis.The method according to the invention makes it possible to provide a clearly more powerful and detailed network monitoring on the basis of an advantageous application of O-RAN technology. Furthermore, this has the advantage that detailed information about individual packets can be available not only at the end points, but can be tracked by the network infrastructure itself. Furthermore, the method according to the invention enables the performance of forwarding packets through the network or network (forwarding) to be analyzed better. A network may be a communication network such as a communication network according to a 3GPP standard such as 4G, 5G or 6G. In addition, it is advantageously possible to dispense with the costly use of special measuring devices in order to collect data or, for example, in order to debug errors. Furthermore, this has the advantage that the method according to the invention carries out the network monitoring on the basis of low-layer information in the network stack, which would normally not be available for software-based monitoring components in communication networks. In addition, the invention enables significantly better tracking of application errors during the post-processing of the monitoring data from the data packets. This advantageously reduces downtime and improves overall efficiency of the application.It may also be advantageous within the scope of the invention that the method comprises the following further step:selecting a respective data packet from the detected data packets depending on the selection criterion for the network monitoring.This enables the network monitoring according to the invention to filter out irrelevant data packets in an effective and efficient manner and thus advantageously only extract the respectively relevant information for the respective task of the network monitoring as a function of the selection criterion, in order to be computationally more efficient. Furthermore, this has the advantage that for a specific monitoring task only such data relating to the data packets of a specific application can be selected for the further analysis and / or processing.Advantageously, it can be provided within the scope of the invention that the detection comprises the following further step:acquiring data packets on the basis of at least one network layer information item, wherein the network layer information item is specific to an arbitrary protocol layer of a network protocol stack.This allows monitoring of the network and / or performance degradation to be advantageously detected at a lower layer of the communication stack or protocol stack. This has the advantage that any processing delays of data packets on each layer can be effectively visualized to identify technical problems regarding the transmission of data packets. The ability to track data packets of a particular application across the entire protocol stack, for example, and to determine whether retransmissions, packet segmentations, or out-of-order transmissions, etc., may have occurred for that application allows network problems to be detected for particular selected terminals.A network stack, also referred to as a protocol stack or a communication protocol stack, is a software architecture or collection of network protocols organized into layers to enable communication between various computers or devices on a network. Each layer in the network stack performs specific tasks and functions and operates in cooperation with the other layers to transmit and receive data between endpoints. The network stack, which may be organized according to the open systems interconnection (OSI) model, is a basic component of any network communication and plays an important role in ensuring smooth and efficient data transmission. Typical layers in such a network stack may be, for example, a physical layer (layer 1), a data link layer (layer 2), or a network layer (layer 3). The physical layer handles the physical transmission of data over the network medium. It defines the electrical, mechanical and functional properties of the connection between the devices. The data link layer is responsible for error detection and correction and control of access to the medium. Here, for example, MAC addresses are used to identify devices in a local area network. The network layer is responsible for forwarding data packets between different networks. It uses IP addresses to determine the path for data packets and make routing decisions. The network stack allows the interoperability of devices and applications in different networks because it ensures that data can be transmitted in a uniform format and according to the agreed rules. The use of layers also allows clear isolation of responsibilities and easier maintenance and expansion of network protocols.A further advantage can be achieved within the scope of the invention if the acquisition of data packets takes place in the form of a list of data packets, wherein the list comprises at least one indication with respect to a content of the respective data packet. This allows detailed analysis of the data packets in terms of causalities between application events and network performance. Furthermore, this has the advantage that more efficient transmission of information or data with respect to the content of the captured and / or extracted data packets can be ensured. In addition, this enables a significantly more efficient reduction in the calculation load and / or the processing time for the analysis to be achieved.It may further be possible that the acquisition of data packets is performed using an E2 service model for an E2 interface and / or an E2 service model for the power measurement for an E2 interface. This allows, on the one hand, detailed information about individual data packets to be available not only at the end points, but to be tracked by the network infrastructure itself. This has the advantage that the performance of forwarding data packets within the communication network can be analyzed better and more quickly. On the other hand, this allows that no special measurement equipment needs to be used to collect data regarding network monitoring.Furthermore, it can be provided that the initiation of the measure comprises at least one of the following further steps:initiating an adaptation of a configuration of a network in order to avoid a power loss of a network service, in particular a forwarding of data packets, or a fault within the network,initiating an adaptation of an application to avoid a power drop of a network service or a fault within the O-RAN system,initiating an adaptation of a property of the network and / or an application on the basis of a predefined task for the network monitoring.This has the advantage that, based on the results of the analysed data packets and / or on the basis of the respective network monitoring task, the behavior of the network or of the network or of the applications can be adapted to the respective end points in order to increase the network performance or to detect faults at an early stage. Furthermore, it makes it possible that a corresponding adaptation of the network monitoring can be adapted in such a way that it is ensured in a significantly more effective and / or more efficient manner.Advantageously, it can be provided within the scope of the invention that at least a part of the method is assigned as a subfunction to a monitoring function of an x application, i.e. xApp and / or an r application, i.e. rApp. This enables more efficient monitoring of the data packets to be ensured. Furthermore, this has the advantage that the method according to the invention can become an integral component of the communication network, wherein an integral component can be understood as a function implemented permanently or permanently in a communication system. It is thus further conceivable that implementing the method according to the invention as an xApp / rApp makes it more advantageous for the function to be able to be installed and / or executed on each O-RAN system.A further advantage can be achieved within the scope of the invention if an orchestration function calculates a division of the method into at least two sub-functions as a function of a temporal and / or a resource-related condition. This allows a significantly more powerful and detailed network monitoring to be provided, taking into account the time constraints and / or the available network resources.The invention likewise relates to a network function for network monitoring in an O-RAN system, which is set up to carry out the method according to the invention. Thus, the network function according to the invention provides the same advantages as have been described in detail with reference to a method according to the invention.The invention also relates to a computer program comprising instructions which, when the computer program is executed by a network function, cause the computer program to execute the method according to the invention. Thus, the computer program according to the invention brings with it the same advantages as have been described in detail with reference to the method according to the invention.The invention also relates to a computer-readable storage medium comprising instructions which, when executed by a network function, cause the latter to carry out the steps of the method according to the invention. Thus, the computer-readable storage medium according to the invention brings the same advantages as have been described in detail with reference to the method according to the invention.In addition, the method according to the invention can also be embodied as a computer-implemented method.Further advantages, features and details of the invention will become apparent from the following description, in which exemplary embodiments of the invention are described in detail with reference to the drawings. The features mentioned in the claims and in the description can be essential to the invention individually or in any combination. The following are shown: FIG. 1 shows a schematic visualization of a method, a device, a storage medium and a computer program according to exemplary embodiments of the invention. FIG. 2 shows a schematic illustration from the prior art, FIG. 3 shows a schematic illustration according to exemplary embodiments of the invention, FIG. 4 shows a further schematic illustration according to exemplary embodiments of the invention, FIG. 5 shows a further schematic illustration according to exemplary embodiments of the invention, FIG. 6 shows a further schematic illustration according to exemplary embodiments of the invention.In the following figures, the identical reference numerals are also used for the same technical features of different exemplary embodiments.The invention describes a new process flow which enables improved online monitoring of the network and / or detection of performance degradations even at the lower layers of a communication stack. This allows relevant changes to be detected before an actual failure of applications occurs. Based on a prediction of potential failures, appropriate countermeasures may be taken, such as replacing defective components during the next maintenance window or reconfiguring the network to adjust end-to-end performance. Such countermeasures may thus relate to adaptations of the network or the application if information about monitoring and prediction is provided in a suitable manner, or both of the network and the application in a more complex scenario. Moreover, the invention enables better trace of application errors to a cause in the network during post-processing of the monitoring data. This reduces downtime and improves overall application efficiency.On the basis of the interfaces and services available into the mobile communication systems by the O-RAN technology, a clearly more powerful and detailed network monitoring can be provided with the methods according to the invention. The present invention may use the O-RAN service models E2SM-NI and E2SM-KPM to directly detect packets and relevant power measurements at the network interfaces.Thus, detailed information about individual packets may be available not only at the endpoints, but may be tracked by the network infrastructure itself. Furthermore, the network monitoring according to the invention does not follow a black channel approach in which only the end-to-end performance can be considered, but the method according to the invention enables the performance of forwarding packets through the network to be analyzed. Furthermore, it is advantageously possible to dispense with the costly use of special measuring devices in order to collect data or, for example, in order to debug the system after a fault has already occurred.FIG. 1 schematically illustrates a method 100, a network function 60, a storage medium 55 and a computer program 50 according to exemplary embodiments of the invention. FIG. 1 illustrates, according to embodiments of the invention, a method for packet-based network monitoring in an O-RAN system in order to initiate a measure for adapting the network monitoring, with the following steps:In step 101, data packets are acquired at an interface of the O-RAN system using an O-RAN service model. According to step 102, information relating to the respective data packet is extracted on the basis of a selection criterion for the network monitoring, wherein the selection criterion is specific to a respective task of the network monitoring. In step 103, the information relating to the respective data packet is aggregated in order to analyze the data contained in the information. In step 104, the data from the aggregated information is then analyzed on the basis of a predefined analysis model. The analysis model includes an algorithm for evaluating the data. In step 105, a measure for adapting the network monitoring on the basis of the result of the analysis is initiated.Furthermore, FIG. 1 shows a network function 60 which comprises a computer-readable storage medium 55. The storage medium 55 comprises a computer program 50.FIG. 2 shows, by way of example, various components of a known O-RAN system 6 from the prior art. The O-RAN system 6 comprises an intelligent RAN controller for near-real-time applications 4 (Near-RT RIC), which enables control and optimization of O-RAN nodes or E2 nodes 1, 2, 3 (e.g. CU, DU, eNB, gNB) and resources in near-real-time. Further depicted in FIG. 2 is a non-real-time smart RAN controller 5 (non-RT RIC) that functions to support smart RAN optimization by providing policy-based guidance, ML model management, and enhancement information to the near-RT RIC function. In addition, FIG. 2 shows a so-called xApp 20 and a rApp 25. The xApp 20 and rApp 25 are applications hosted on and capable of providing value added services to near RT RIC 4 and non RT RIC 5, respectively. xApp 20 stands for xAppli and refers to applications running in the open RAN architecture. These applications can perform various functions within the RAN operation, such as network optimization, resource control, or user experience enhancement. rApp 25 stands for rAppli, and specifically refers to applications executing in the non-RT RIC 5 that interact with the radio access network components in an open RAN environment 6. These applications may help improve the performance and efficiency of the radio communication.The radio unit 1 or (engl.) Radio Unit 1 (RU) is the hardware component responsible for signal transmission. It contains transmitters and receiver antennas as well as the processing units for signal processing. The processing unit 2 or (or) the distributed unit 2 (DU) is a component placed in the vicinity of the radio unit 1. This component 2 performs signal processing tasks to minimize latencies and optimize performance. The central unit 3 or also (engl.) Centralized unit 3 (CU) is another component of the open RAN system and may include various central control and management functions. The central unit 3 coordinates and controls all RU and DU units 1, 2 in the network.Furthermore, an E2 interface 10 is shown in FIG. 2. The E2 interface 10 is an interface between the E2 nodes 1, 2, 3, such as DU 2, CU 3 and the near RT RIC 4. The E2 interface 10 enables messaging, such as exchange of control messages and measurements, or policy setting, which is a set of rules used to manage and control the state of managed objects in the RAN on the E2 nodes 2, 3 between these components. There are also interface-related application protocols with a series of defined procedures to standardize the communication messages between the E2 nodes 2, 3 and the near RT RIC 4. In addition, there are so-called service models, also called service models (E2SMs), which define the content of the communication messages via the E2 interface 10. There are, for example, the following E2SMs:E2SM-NI: This is a service model that can be exposed via the E2 interface 10. For example, the E2NB-NI provides a network interface and allows modification of incoming and outgoing network interface message contents. The E2 nodes 1, 2, 3 can use these E2 indication messages of the REPORT type to send messages.E2SM-KPM: A further service model which can be provided via the E2 interface 10. It can forward the available performance metrics from E2 nodes to the xApp(s) on near RT RIC 4. The E2 nodes 1, 2, 3 can use these E2 indication messages of the REPORT type to send messages.The E2 nodes 1, 2, 3 may comprise RAN functions supporting one or more RIC services, i.e. services provided on an E2 node 1, 2, 3 to allow access to messages and measurements and to allow control of the E2 node 1, 2, 3 from the near RT RIC 4. The following RIC service, the so-called REPORT, can be used, for example. The REPORT is an RIC service provided by an E2 node 1, 2, 3, which can be used by the near RT RIC 4. According to a subscription model, an E2 node 2, 3 may send a message to the RIC 4 based on an event trigger.FIG. 3 shows a schematic illustration according to exemplary embodiments of the invention. FIG. 3 illustrates, by way of example, possible steps of an exemplary embodiment of the method according to the invention. In particular, FIG. 3 illustrates how network monitoring could be implemented depending on the data actually to be processed and the task to be fulfilled.In step 301, data packets transmitted in a network are captured by an interface 10 and made available to the control and management level.Optionally, it is possible that the captured data packets are captured, for example, as a list of data packets, wherein the list comprises details and / or details, e.g. about the source and destination of the data packets, the network protocol used, the arrival time, or the payload.According to step 302, the captured data packets are filtered or selected because not all data packets captured by the monitoring interface 10 are relevant to a particular monitoring task. In such a case, data packets that are not to be taken into account can be discarded or not selected, so that they do not have to be further processed.In step 303, information relevant to the predefined network monitoring is extracted from the captured data packets. In the case of the detection of data packets in the form of the above-mentioned data. The processing of all these details can increase the computational load of the monitoring function, so that only information relevant to the respective monitoring task should be extracted from the list. This in turn depends on how the monitoring function is to be used. For example, for time analysis, arrival time is of great importance, while the payload may not be needed.In step 305, the extracted data may be aggregated so that not every packet yields a single sample. Instead, information or data from multiple data packets may be aggregated to derive a statistical representation or distribution. For example, minimum, average and / or maximum values may be derived and / or an aggregated sample per time interval may be viewed. The statistical representation may be, for example, a probability density function (pdf) and / or any quantity (e.g., percentiles) derived from the function. This function (pdf) can also change over time (time variant), which can be taken into account in a possible optimization of the system. To track evolution over time, the monitoring function must time stamp the samples. In one implementation, these timestamps may be synchronized with other network components to correlate to the events in the components.In step 306, the aggregated monitoring data is used as input to processing and analysis functions suitable for the respective monitoring task. The selection of possible evaluation models or algorithms for the analysis of the data can be varied. In addition to simple analysis and / or evaluation models for determining whether the forwarding capabilities of the network are within an expected range, there may also be more complex algorithms for statistical analyses, for recognition of change points and / or for classification.In step 307, further measures can be initiated on the basis of the results according to step 306. Thus, for example, adaptations of the network or of the application can be initiated in order, for example, to avoid a power loss of a network service, in particular a forwarding of data packets, or in order to optimize the performance of the network. In step 308, it is shown that the process flow according to this exemplary embodiment of the method according to the invention can be repeated. The various steps of the above-described exemplary embodiment of the method according to the invention can be subject to individual time restrictions and computing effort. This may be highly dependent on the rate of the incoming packets, the complexity of the algorithms, the size of the data sets to be processed, and the time required to respond to a network event. For example, a very high arrival rate of packets associated with limited computational resources for performing the supervisory function may result in buffer overflows if the processing of the captured packets is slower than the arrival of new packets. For this, according to step 304, a query is carried out with regard to the buffer or the size of the batch, i.e. the predefined size of the task packet. If the maximum permissible size has been reached, this means according to step 304 that a maximum number of extracted data or information from the captured data packets has been reached and the further processing according to step 305 takes place. If capacities for further data were still available, it would be decided in step 304 that further data packets can be detected and data relating to the respective task for the network monitoring can be extracted until the maximum is reached. Similarly, if the monitoring function is used to predict potential application errors based on the observed network behavior (e.g., by detecting a trend toward a continuously decreasing data rate), the entire analysis may need to be completed so that there is sufficient time for countermeasures before the application fails.FIG. 4 shows a schematic illustration according to exemplary embodiments of the invention. FIG. 4 shows an exemplary system representation of the invention with regard to an example application case with two end points 30, 31 which exchange data in a communication network. The exchanged data can be enriched by means of an external enrichment function 70. Furthermore, FIG. 4 depicts an O-RAN system 6, which comprises, by way of example, the E2 nodes 1, 2, 3, a near-RT-RIC 4 and a non-RT-RIC 5.In this exemplary embodiment according to FIG. 4, given the respective technical capabilities of near-RT RIC 4 and non-RT RIC 5, specific subfunctions for network monitoring, as described with reference to FIG. 1 or 3, can be used as network function in an xApp 20 and / or in an rApp 25 or, on the basis of calculations and / or definitions, can be arranged accordingly in RIC 4 and / or in RIC 5. These sub-functions can be provided, for example, as virtualized functional units, such as, for example, as part of a monitoring function, which can be dynamically assigned to the near-RT RIC 4 or to the non-RT RIC 5. In such an assignment, an orchestration function (not shown) can optionally be used, which can check the time constraints and the computing effort, for example. The orchestrator, which can be provided, for example, as a guideline (software) or else as a component of the xApp 20 or the rApp 25 itself, calculates a suitable division and / or implementation of the sub-functions depending on the requirement for the network monitoring and assigns them in accordance with the two RIC components 4, 5.FIG. 5 illustrates another schematic system diagram according to embodiments of the invention. In this embodiment of Figure 5, a tighter interaction between a user application 32, 36 and the xApp 20 and / or rApp 25 is illustrated via direct and / or non-direct communication to allow more efficient monitoring of the transmitted data packets. Optionally, the following models or concepts are possible: 1) The application 32, 36 instructs and configures 500 the xApp / rApp monitoring processes entirely, or each application 32, 36 has its own monitoring xApp / rApp, or 2) the xApp / rApp monitoring function(s) can learn the monitoring configuration entirely based on established machine learning or artificial intelligence techniques. For example, a monitoring function may observe the traffic characteristics or identify and configure certain traffic markers accordingly 500, or 3) any combination of 1) and 2) in which configuration 500 occurs partially through application 32, 36 and partially through the self-learning capabilities of the monitoring functions.The configuration 500 of the monitoring xApp 20 / rApp 25 within the O-Ran system 6 may be performed in terms of various aspects, including such aspects aswhich type of packet is to be monitored,how often to monitor (e.g., each packet or only every 100th packet),which part of the statistics is to be evaluated (e.g. whole pdf, percentile or median),which application flow is to be monitored,configuring triggers for detailed network monitoring in the event of certain events or conditions of the application.Furthermore, the (auto)configured monitoring function should take into account the time constraints, the computational effort and the available resources.Further, it is shown in FIG. 5 that an application 32, 36 served via the network can interact directly with the SMO (Service Management and Orchestration) framework 40 of the communication network to configure 500 the monitoring process provided by the xApp 20 / rApp 25. This may be done either by the application 32, 36 itself being provided on endpoints on the UE site 30 or on edge servers 35. Regardless of whether application 32, 36 includes its own xApp 20 / rApp 25 that can be uploaded to RIC 4, 5, or whether it 32, 36 includes its own configuration for xApps 20 / rApps 25 already provided in RIC 4, 5, SMO framework 40 controls and controls provisioning on the network.FIG. 6 illustrates another schematic system diagram according to embodiments of the invention. In this embodiment illustrated in FIG. 6, neither app 1 32 nor app 2 36 may configure 600 xApp 20 and / or rApp 25 via SMO framework 40. In this embodiment, unlike the example of FIG. 5, a direct connection may be used for the configuration 600 of the application 32, 36 to the respective xApp 20 and / or rApp 25 provided on endpoints on the U E page 30 or on edge servers 35. Further, the information may be processed and analyzed from the aggregated data according to machine learning-based methods. This can comprise, for example, learning via causal dependencies and / or for optimizing the recognition scheme (cf. black box optimization) and / or for learning via relevant packet information. For example, the monitoring function may detect anomalies that were not known at the design time of the method. Further, the analysis model used for analyzing the data can be improved. Alternatively, the selection, extraction and aggregation of data packets according to the invention in this embodiment according to Fig. 6 may be optimized, for example, such that irrelevant packets are filtered out, only relevant information is extracted to be computationally efficient, or data from data packets aggregates such that they are most meaningful to the processing scheme.The foregoing explanation of the embodiments describes the present invention solely by way of examples. Of course, individual features of the embodiments can be freely combined with one another, insofar as technically expedient, without departing from the scope of the present invention.

Claims

Method (100) for packet-based network monitoring in an O-RAN system (6) in order to initiate a measure for adapting the network monitoring, comprising the following steps: - acquiring (101) data packets at an interface (10) of the O-RAN system (6) using an O-RAN service model, - extracting (102) information relating to the respective data packet on the basis of a selection criterion for the network monitoring, wherein the selection criterion is specific for a respective task of the network monitoring, - aggregating (103) the extracted information relating to the respective data packet in order to analyze the data contained in the information, - analyzing (104) the data from the aggregated information on the basis of a predefined analysis model, wherein the analysis model comprises an algorithm for evaluating the data, - initiating (105) an action for adapting the network monitoring on the basis of the result of the analysis (104).Method (100) according to claim 1, characterized in that the method (100) comprises the further step of: - selecting a respective data packet from the detected data packets depending on the selection criterion for the network monitoring in order to extract the information relating to the respective data packet.Method (100) according to one of the preceding claims, characterized in that the capturing (101) comprises the following further step: - capturing data packets on the basis of at least one network layer information, wherein the network layer information is specific to an arbitrary protocol layer of a network protocol stack.Method (100) according to one of the preceding claims, characterized in that the acquisition (101) of data packets takes place in the form of a list of data packets, wherein the list comprises at least one indication with respect to a content of the respective data packet.Method (100) according to one of the preceding claims, characterized in that the acquisition (101) of data packets is carried out using an E2 service model for an E2 interface (E2SM-NI) and / or an E2 service model for the power measurement (E2SM-KPM) for an E2 interface.Method (100) according to one of the preceding claims, characterized in that the initiating (105) comprises at least one of the following further steps: - initiating an adaptation of a configuration of a network in order to avoid a power loss of a network service, in particular a forwarding of data packets, or a fault within the network, - initiating an adaptation of an application in order to avoid a power loss of a network service, or a fault within the O-RAN system, - initiating an adaptation of a property of the network and / or an application on the basis of a predefined task for the network monitoring.Method (100) according to one of the preceding claims, characterized in that at least part of the method (100) is assigned as a subfunction to a monitoring function to an xApp (20) and / or to an rApp (25).Method (100) according to one of the preceding claims, characterized in that an orchestration function calculates a division of the method (100) into at least two sub-functions as a function of a temporal and / or a resource-related condition.Network function (60) for network monitoring in an O-RAN system (6) configured to carry out the method (100) according to one of the preceding claims.A computer program (50) comprising instructions which, when the computer program (50) is executed by a network function (60), cause the latter to carry out the method (100) according to any one of claims 1 to 8.A computer readable storage medium (55) comprising instructions which, when executed by a network function (60), cause the latter to carry out the steps of the method (100) according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method and device for treating an anomaly in a communication network

    DE102018209407A1

  • Reinforcement Learning for Multi-Access Traffic Management

    DE102022200847A1

  • System and method using genetic algorithms for anomaly detection in a mobile network

    US20230396639A1