Information processing system, information processing method, and program

The system addresses the challenge of linking C-Plane and U-Plane packets across distributed data centers by using session indexes, facilitating efficient data analysis and reducing processing load, thus enabling comprehensive communication condition assessment in complex 5G networks.

JP2025098840AActive Publication Date: 2025-07-02SOFTBANK CORPORATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023215233
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-07-02
Estimated Expiration
2043-12-20

AI Technical Summary

Technical Problem

In the 5G era, the distribution of servers handling U-Plane and C-Plane processing across different data centers complicates the linking of data related to the same user's communication, leading to high processing loads and limitations in analyzing key performance indicators (KPIs) due to the separation of C-Plane and U-Plane packet extraction points.

Method used

An information processing system that acquires C-Plane and U-Plane packets, extracts source and destination addresses, and TEIDs from their payloads, and links them using session indexes generated from these identifiers, eliminating the need for a table associating provisional IDs and reducing processing load.

Benefits of technology

Enables timely acquisition and analysis of large amounts of data to understand communication conditions, even in complex core networks, without the need for high-speed dedicated optical fiber cables and reduces processing load by avoiding table updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025098840000001_ABST
    Figure 2025098840000001_ABST
Patent Text Reader

Abstract

To provide a technique capable of acquiring, in a timely manner and large volumes, the data necessary to grasp communication conditions even when the core network configuration becomes complex.SOLUTION: An information processing system comprises: an acquisition unit which acquires a C-plane packet and an U-plane packet from a core network; an extraction unit which extracts a source address, a destination address, and a TEID from the U-plane packet acquired by the acquisition unit, and also extracts the source address, destination address, and TEID of the U-plane packet from the information stored in the payload of the C-plane packet acquired by the acquisition unit; and an association unit which associates the C-plane packet with the U-plane packet on the basis of the source address, destination address, and TEID extracted by the extraction unit.SELECTED DRAWING: Figure 11
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information processing system, an information processing method, and a program, and more particularly to an information processing system, an information processing method, and a program that can timely acquire large amounts of data necessary to understand communication conditions even if the core network configuration becomes complex. [Background technology]

[0002] The quality of communication is evaluated by analyzing packets flowing through the network and calculating KPIs, etc. In marketing activities using RTB, packets flowing through the network are also analyzed.

[0003] For example, in LTE, C-Plane packets and U-Plane packets are extracted from reference point S11 relating to the connection between MME and S-GW, and reference point S1-U relating to the connection between eNodeB (a base station) and S-GW, respectively. By linking the extracted C-Plane packets and U-Plane packets, data relating to the communication of the same user can be identified, and information necessary for analyzing the communication status can be obtained.

[0004] In addition, a technology has been proposed in which a packet analysis unit that analyzes received packets refers to flow information to classify the received packets into flows and assigns packets a flow ID, which is an identifier for the flow corresponding to the packets, thereby improving traffic control units and traffic control methods (see, for example, Patent Document 1). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent Publication No. 2022-090476 Summary of the Invention [Problem to be solved by the invention]

[0006] In the initial release of LTE, the location where packets were taken out from the C-Plane and the U-Plane were taken out were concentrated within a single data center.

[0007] On the other hand, in the CUPS (C·U-Plane Separate) architecture defined in the later release of LTE and 5G (hereinafter, sometimes referred to as "5G compatible and later"), servers that handle network functions such as the UPF related to U-Plane processing have come to be distributed. For example, in order to improve the performance of the core network, servers that function as UPFs are often placed in data centers near base stations.

[0008] For this reason, after the 5G era, the data center that extracts the C-Plane packets and the data center that extracts the U-Plane packets are often different, making it difficult to link data related to the communication of the same user. On the other hand, for example, Cited Document 1 does not take into consideration that the extraction position of the C-Plane packets and the extraction position of the U-Plane packets are located in different data centers.

[0009] In addition, in the past, data related to the same user's communications was linked using a table that associates IDs provisionally assigned to the traffic of each user with unique IDs. For this reason, the processing load of the past linking process was high, and the number of users for which data linking was possible was limited, making it impossible to perform sufficient analysis of, for example, key performance indicators (KPIs).

[0010] One aspect of the present invention aims to realize a technology that can acquire large amounts of data required to understand communication conditions in a timely manner, even if the core network configuration becomes complex. [Means for solving the problem]

[0011] An information processing system according to one embodiment of the present invention includes an acquisition unit that acquires C-Plane packets and U-Plane packets from a core network, an extraction unit that extracts a source address, a destination address, and a TEID (Tunnel Endpoint Identifier) ​​from the U-Plane packets acquired by the acquisition unit, and extracts the source address, destination address, and TEID of the U-Plane packets from information stored in the payload of the C-Plane packets acquired by the acquisition unit, and a linking unit that links the C-Plane packets and U-Plane packets based on the source address, destination address, and TEID extracted by the extraction unit.

[0012] An information processing method according to one embodiment of the present invention includes the steps of acquiring C-Plane packets and U-Plane packets from a core network, extracting a source address, a destination address, and a TEID from the acquired U-Plane packets, and extracting the source address, destination address, and TEID of the U-Plane packets from information stored in the payload of the acquired C-Plane packets, and linking the C-Plane packets and U-Plane packets based on the extracted source address, destination address, and TEID.

[0013] Each aspect of the present invention may be realized by a computer. In this case, a program that causes a computer to execute each step of the above-described method, and a computer-readable recording medium having the program recorded thereon, also fall within the scope of the present invention. Effect of the Invention

[0014] According to one aspect of the present invention, even if the configuration of the core network becomes complex, it is possible to obtain a large amount of data required to grasp the communication situation in a timely manner. [Brief description of the drawings]

[0015]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

MODE FOR CARRYING OUT THE INVENTION

[0016] Hereinafter, embodiments of the present invention will be described with reference to the drawings. First, problems of the prior art will be described.

[0017] Conventionally, communication quality evaluation has been performed by analyzing packets flowing through a network and calculating KPIs.

[0018] FIG. 1 is a diagram for explaining a conventional packet analysis system related to analysis of communication status. As shown in the figure, in a fourth-generation mobile communication system (LTE), a UE (User Equipment) is connected to an LTE core network 30 via an eNodeB which is a base station. The core network 30 includes network functional units such as an MME (Mobility Management Entity), an S-GW (Serving Gateway), and a P-GW (PDN Gateway). Further, the UE is connected to an external network such as the Internet via an IP network used for providing a carrier service configured by a base station, a core network, and a CGN (Carrier Grade NAT), etc. The IP network for carrier service, the Internet, etc. may be collectively referred to as a DN (Data Network).

[0019] (Network configuration: LTE) In addition, FIG. 1 shows a packet analysis system 50 corresponding to an LTE core network. The packet analysis system 50 extracts C-Plane packets and U-Plane packets from a reference point related to the connection between the MME and the S-GW and a reference point (Reference point) related to the connection between the eNodeB and the S-GW, respectively. That is, C-Plane packets are acquired from S11, which is a reference point related to the connection between the MME and the S-GW, and U-Plane packets are acquired from S1-U, which is a reference point related to the connection between the eNodeB and the S-GW.

[0020] Note that C-Plane packets are packets related to communication for performing control such as which terminal is communicating with which base station. U-Plane packets are packets mainly related to the communication of data of the content itself, such as a website browsed by a user or voice data during a call.

[0021] The packet analysis system 50 identifies data related to the communication of the same user by associating the acquired C-Plane packets and U-Plane packets, and acquires information necessary for analyzing the communication status. By inputting such information into, for example, a monitor device (not shown) and performing analysis of the communication status, it is possible to calculate, for example, index values related to KPIs.

[0022] (Schematic configuration of the system) FIG. 2 is a diagram showing a schematic internal configuration example of the packet analysis system 50 in FIG. 1. As shown in the figure, the C-Plane packets acquired from S11 and the U-Plane packets acquired from S1-U are supplied to a packet identifier 51. In this example, C-Plane packets and U-Plane packets related to Sub (representing Subscriber) 1, Sub2, and Sub3 indicating individual users are supplied to the packet identifier 51.

[0023] The packet identifier 51 refers to a table described later, associates C-Plane packets and U-Plane packets, and supplies them to DPI servers 52-1 to 52-3. For example, the packet identifier 51 associates the C-Plane packet "S11(Sub1)" related to user Sub1 with the U-Plane packet "S1-U(Sub1)" and supplies them to DPI server 52-1. Similarly, the packet identifier 51 associates "S11(Sub2)" and "S1-U(Sub2)" related to user Sub2 and supplies them to DPI server 52-2, and associates "S11(Sub3)" and "S1-U(Sub3)" related to user Sub3 and supplies them to DPI server 52-3.

[0024] At this time, in order to associate C-Plane packets and U-Plane packets related to the same user, the packet identifier 51 uses a table that associates IMSI (International Mobile Subscriber Identity) and TEID (Tunnel Endpoint Identifier). Note that the IMSI is an ID assigned to each user in advance. Also, the TEID is an ID used in the tunneling protocol (GTP) and is assigned at the start of communication.

[0025] (Table for association) Figure 3 is a diagram showing an example of a table that associates IMSI and TEID used in the packet analysis system 50 of the figure. In the example of the figure, IMSI "44020xxxxxxxxxx01" is associated with TEID "teid1", and IMSI "44020xxxxxxxxxx02" is associated with TEID "teid2". In the table of Figure 3, each IMSI is associated with a TEID in this way.

[0026] Since the IMSI is included in the C-Plane packet, the packet identifier 51 can identify the TEID corresponding to the IMSI by referring to the table in FIG. 3. Then, the packet identifier 51 can identify the U-Plane packet to be associated with each C-Plane packet by referring to the TEID included in the U-Plane packet.

[0027] In the DPI servers 52-1 to 52-3, the data of the associated C-Plane packet and U-Plane packet are analyzed to generate information necessary for analyzing the communication status and the like. The generated information is supplied to, for example, a traffic monitor (not shown) and the communication status is analyzed.

[0028] (Network Configuration: 5G) Analysis of the communication status of each user in this way needs to continue even when the core network becomes the fifth-generation mobile communication system (5G). FIG. 4 is a diagram showing an example of applying a conventional packet analysis system to a 5G core network. As shown in the figure, the 5G core network 40 includes network functional units such as an AUSF (Authentication Server Function), an AMF (Access and Mobility Management Function), an NSSF (Network Slice Selection Function), an SMF (Session Management Function), a UDM (Unified Data Management), a PCF (Policy Control Function), and a UPF (User Plane Function).

[0029] The functions of the MME in the LTE core network 30 are mainly assigned to the AMF in the 5G core network 40. The functions of the S-GW in the LTE core network 30 are mainly assigned to the SMF and the UPF in the 5G core network 40. Therefore, in the 5G core network 40, the U-Plane packets may be obtained from N3, which is a reference point related to the connection between the base station gNodeB and the UPF. On the other hand, in the 5G core network 40, the C-Plane packets may be obtained, for example, from N11, which is a reference point related to the connection between the AMF and the SMF to which the gNodeB is connected.

[0030] On the other hand, after the 5G compatibility compared with the initial LTE release, the network function unit that executes the processing related to the C-Plane and the network function unit that executes the processing related to the U-Plane are clearly separated. Therefore, after the 5G compatibility, it is possible to separately arrange the network function unit that executes the processing related to the U-Plane from the network function unit that executes the processing related to the C-Plane.

[0031] For example, the UPF requires a higher processing capacity compared with the SMF. Therefore, when providing a low-latency communication service, the functions of the UPF can also be implemented in a distributed manner on multiple devices. In particular, when providing a low-latency communication service, the server on the DN that undertakes the processing related to such a service is arranged at a physically close distance to the user (or UE). Therefore, in order to improve the performance of the connection from the UE to the DN, it is preferable that the UPF be distributed and arranged near the base station.

[0032] Therefore, in an actual 5G core network, for example, a configuration may be adopted in which a plurality of UPFs are arranged corresponding to a gNodeB. In this case, for example, the UPF will be arranged in a data center different from the data center where AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged. As an example, for example, all network function parts of the 5G core network 40 are arranged in the Tokyo data center, and the UPF is arranged in the Sapporo data center, the Nagoya data center, and the Osaka data center.

[0033] In this case, the reference point N3 related to the connection between the gNodeB, which is a base station, and the UPF will exist within the Tokyo data center, the Sapporo data center, the Nagoya data center, and the Osaka data center. Therefore, in order to associate the C-Plane packets and the U-Plane packets related to the same user, for example, it is necessary to transfer the U-Plane packets obtained in the Sapporo data center, the Nagoya data center, and the Osaka data center to the packet identifier 51 in the Tokyo data center at high speed.

[0034] When the packet identifier 51 and the reference point N3 are arranged within the same data center, for example, by laying a dedicated optical fiber cable, etc., the U-Plane packets obtained at the reference point N3 can be transferred to the packet identifier 51 at high speed. However, when the packet identifier 51 and the reference point N3 are arranged in different data centers, laying a dedicated optical fiber cable is unrealistic.

[0035] Also, for example, when generating a table as shown in FIG. 3 to associate the C-Plane packets and the U-Plane packets related to the same user, for example, it is necessary to update the table so as to associate it with the IMSI each time a TEID is assigned. Therefore, the load becomes high due to the processing related to table update, and high processing capabilities are required for the packet identifier 51. Furthermore, since the size of the table that can be stored is also limited, the number of C-Plane packets and U-Plane packets that can be associated is also limited.

[0036] <First Embodiment> Next, a first embodiment of the present invention will be described. In the first embodiment, a session index is generated to associate a C-Plane packet and a U-Plane packet. The session index is generated based on information included in each of the C-Plane packet and the U-Plane packet, and is assigned to each of the C-Plane packet and the U-Plane packet. By combining the C-Plane packet and the U-Plane packet so that the session indexes match, it becomes possible to associate the C-Plane packet and the U-Plane packet related to the same UE. In this case, for example, a table as shown in FIG. 3 becomes unnecessary.

[0037] With reference to FIGS. 5 to 9, a method for generating a session index will be described. Note that the session index is identification information attached to each packet.

[0038] (U-Plane Packet) FIG. 5 is a diagram showing the components of a U-Plane packet. In this example, the U-Plane packet 300 includes an Ethernet header 301, an IP (outer) header 302, a UDP (outer) header 303, a tunneling protocol (GTPv1) header 304, an IP (inner) header 305, a UDP (inner) header 306, and a payload 307.

[0039] In the figure, “(outer)” and “(inner)” are used to distinguish the headers used in the tunneling protocol. “(inner)” means the header of the packet encapsulated by the tunneling protocol, and “(outer)” means the header of the packet storing the encapsulated packet. For example, the header of “(outer)” is used for communication inside the core network of the encapsulated packet, and the header of “(inner)” is used for communication between the UE and the DN of the packet of the U-Plane.

[0040] In the case of the U-Plane packet, for example, GTP (General Packet Radio Service (GPRS) Tunnelling Protocol) v1 is used as the tunneling protocol.

[0041] (C-Plane Packet) Figure 6 is a diagram showing the components of a C-Plane packet corresponding to the LTE core network and obtainable at the reference point S11. In this example, the C-Plane packet 330 includes an Ethernet header 331, an IP header 332, a UDP header 333, a tunneling protocol (GTPv2) header 334, and a payload 337. The payload 377 is also referred to as a GTP-C message.

[0042] In the case of the C-Plane packet, for example, GTPv2 is used as the tunneling protocol.

[0043] The session index is generated based on the source IP (source (src) IP) address, the destination IP (destination (dst) IP) address, and the TEID included in each of the U-Plane packet and the C-Plane packet.

[0044] FIG. 7 is a diagram showing components of a C-Plane packet corresponding to a 5G core network and obtainable at reference point N2. In the communication between the gNodeB and the AMF, the NGAP (Next Generation Application Protocol) is used. Details of the NGAP are specified in, for example, 3GPP standard TS.38.412 in detail.

[0045] In this example, the C-Plane packet 350 includes an Ethernet header 351, an IP header 352, an SCTP header 353, an NGAP header 354, and a payload 355. Note that the NGAP header 354 and the payload 355 are also referred to as the NGAP Message.

[0046] FIG. 8 is a diagram showing components of a C-Plane packet corresponding to a 5G core network and obtainable at reference point N12. In the communication between the AMF and the AUSF, HTTP (Hypertext Transfer Protocol) / 2 is used. Details of HTTP / 2 are specified in, for example, 3GPP standard TS.29.500 in detail.

[0047] In this example, the C-Plane packet 370 includes an Ethernet header 371, an IP header 372, a TCP header 373, an HTTP / 2 header 374, and a payload 375. Note that the payload 375 is also referred to as the Application.

[0048] (Information required for generating the session index) FIG. 9 is a diagram for explaining an example of information necessary for generating a session index. In the figure, “(uplink)” and “(downlink)” indicate the direction in which a packet is transmitted. “(uplink)” indicates an uplink direction, that is, a packet from a UE or a base station to a core network, and “(downlink)” indicates a downlink direction, that is, a packet from a core network to a UE or a base station.

[0049] As shown in the figure, the information necessary for generating a session index is the source IP address, the destination IP address, and the TEID in both the U-Plane and the C-Plane cases. However, depending on the direction in which the packet is transmitted, the nodes that assign the source, destination, and TEID are different.

[0050] (In the case of U-Plane) As shown in the figure, in the case of a U-Plane (uplink) packet, the source IP address means the IP address of the eNodeB or gNodeB. The destination IP address means the IP address of the S-GW, UPF, or SMF. The TEID means the TEID assigned by the S-GW, UPF, or SMF.

[0051] Also, in the case of a U-Plane (downlink) packet, the source IP address means the IP address of the S-GW or UPF. The destination IP address means the IP address of the eNodeB or gNodeB. The TEID means the TEID assigned by the eNodeB or gNodeB.

[0052] In the case of a U-Plane packet, the source IP address and the destination IP address are stored in the IP (outer) header 302 of FIG. 5, and the TEID is stored in the GTPv1 header 304 of FIG. 5.

[0053] (In the case of C-Plane) In the case of C-Plane (uplink) packets, similar to the case of U-Plane (uplink) packets, the source IP address means the IP address of the eNodeB or gNodeB. The destination IP address means the IP address of the S-GW, UPF, or SMF. The TEID means the TEID assigned by the S-GW, UPF, or SMF. That is, the payload of the C-Plane (uplink) packet stores the source IP address and destination IP address of the U-Plane (uplink) packet, as well as the TEID, and a session index is generated using these.

[0054] Also, in the case of C-Plane (downlink) packets, similar to the case of U-Plane (downlink) packets, the source IP address means the IP address of the S-GW or UPF. The destination IP address means the IP address of the eNodeB or gNodeB. The TEID means the TEID assigned by the eNodeB or gNodeB. That is, the payload of the C-Plane (downlink) packet stores the source IP address and destination IP address of the U-Plane (downlink) packet, as well as the TEID, and a session index is generated using these.

[0055] (Packets obtainable at S11) In the case of C-Plane packets obtainable at the reference point S11, the source IP address, destination IP address, and TEID are stored in the payload 337 of FIG. 6. That is, in the case of C-Plane packets obtainable at the reference point S11, the source IP address and destination IP address of the U-Plane packet, as well as the TEID, are stored in the information transmitted by the GTPv2 protocol.

[0056] The source IP address, destination IP address, and TEID are stored in the "Fully Qualified Tunnel Endpoint Identifier" IE (Information Element) with an IE Type Value of 87 within the payload 337. Note that the storage locations of each piece of information in the IE with an IE Type Value of 87 are described in detail in 3GPP standard TS 129 274 8.22 Fully Qualified TEID (F-TEID).

[0057] Figure 10 is a diagram for explaining the encoding format of the F-TEID defined in standard TS 129 274 8.22. The source IP address and destination IP address required for generating the session index are stored in "IPv4 address" or "IPv6 address" in Figure 10. Also, the TEID required for generating the session index is stored in "TEID / GRE Key" in Figure 10.

[0058] (Packets obtainable at N2) In the case of C-Plane packets obtainable at reference point N2, the source IP address, destination IP address, and TEID are stored in payload 355 in Figure 7. That is, in the case of C-Plane packets obtainable at reference point N2, the source IP address, destination IP address, and TEID are stored in the information transmitted by the NGAP protocol.

[0059] (Packets obtainable at N12) In the case of C-Plane packets obtainable at reference point N12, the source IP address, destination IP address, and TEID are stored in payload 375 in Figure 8. That is, in the case of C-Plane packets obtainable at reference point N12, the source IP address, destination IP address, and TEID are stored in the information transmitted by the HTTP / 2 protocol.

[0060] Also, in 5G, various security measures are adopted from the perspective of countermeasures against security threats. Specifically, for example, the SUPI (Subscription Permanent Identifier), which is the subscriber ID in 5G, is transmitted from the UE to the network as the SUCI (Subscription Concealed Identifier), which is information encrypted by a predetermined public key. Thus, in 5G, the subscriber ID is anonymized. Therefore, even if the C-Plane packet is obtained from the reference point N2, the relationship with the user or UE that transmitted the packet cannot be grasped. Therefore, the SUCI is obtained from the packet related to the authentication process transmitted and received between the AMF and the AUSF, which is the C-Plane packet that can be obtained at the reference point N12, and the SUPI and KSEAF are respectively obtained from the response packet for the request. Thereby, for example, in a monitoring device or the like, the SUPI can be derived from the SUCI included in the C-Plane packet.

[0061] Note that the SUPI, SUCI, and KSEAF are respectively stored in the payload part of the packet transmitted and received by the HTTP / 2 protocol. For a business operator who designs the network so as not to perform the above-described encryption, since there is no need to derive the SUPI from the SUCI, for such a business operator, it is not essential to obtain the C-Plane packet at the reference point N12.

[0062] (Packet Association by Session Index) For communications related to the same user, the source IP address and destination IP address stored in the IE with an IE Type Value of 87 in the payload 337 of the C-Plane (uplink) packets that can be obtained at reference point S11 are the same as the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (uplink) packets, respectively. And the TEID stored in the IE with an IE Type Value of 87 in the payload 337 of the C-Plane (uplink) packets is the same as the TEID stored in the tunneling protocol header 304 of the U-Plane (uplink) packets.

[0063] Similarly, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 355 of the C-Plane (uplink) packets that can be obtained at reference point N2 are the same as the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (uplink) packets and the TEID stored in the tunneling protocol header 304, respectively.

[0064] Furthermore, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 375 of the C-Plane (uplink) packets that can be obtained at reference point N12 are the same as the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (uplink) packets and the TEID stored in the tunneling protocol header 304, respectively.

[0065] Also, for communications related to the same user, the source IP address and destination IP address stored in the IE with IE Type Value of 87 in the payload 337 of the C-Plane (downlink) packets that can be obtained at reference point S11 are the same as the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (downlink) packets, respectively. And the TEID stored in the IE with IE Type Value of 87 in the payload 337 of the C-Plane (downlink) packets is the same as the TEID stored in the tunneling protocol header 304 of the U-Plane (downlink) packets.

[0066] Similarly, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 355 of the C-Plane (downlink) packets that can be obtained at reference point N2 are the same as the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (downlink) packets, and the TEID stored in the tunneling protocol header 304, respectively.

[0067] Furthermore, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 375 of the C-Plane (downlink) packets that can be obtained at reference point N12 are the same as the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (downlink) packets, and the TEID stored in the tunneling protocol header 304, respectively.

[0068] Therefore, for example, by extracting the source IP address, destination IP address, and TEID from each packet and using their hash values as the session index of the packet, packets related to the same user can be identified. That is, by identifying the C-Plane packets having the same session index as the session index of the U-Plane packets, the C-Plane packets and U-Plane packets related to the same user can be associated with each other.

[0069] By analyzing the information stored in the payload 307 of the U-Plane packets, the data transmitted and received between the UE and the DN can be identified. Then, by analyzing the information stored in the payloads 337, 355, and 375 of the C-Plane packets associated with the U-Plane packets, the UE can be identified or the behavior of the UE (e.g., handover, etc.) can be identified. In this way, if the communication content of each user can be identified, it becomes possible to perform a detailed analysis of the communication situation.

[0070] Here, an example of calculating the hash values of the source IP address, destination IP address, and TEID stored in each packet and using them as the session index of the packet has been described. However, the session index may be generated by a different operation. That is, a session index may be generated by performing a predetermined operation on the source IP address, destination IP address, and TEID stored in each packet. Specifically, for example, the value obtained by adding up the source IP address, destination IP address, and the value of the TEID may be used as the session index.

[0071] (Configuration example of packet analysis system) FIG. 11 is a block diagram showing a configuration example of a packet analysis system 200 according to the present embodiment. The packet analysis system 200 shown in the figure is a system that acquires packets in a core network and analyzes the communication status. As shown in the figure, the packet analysis system 200 includes an analysis device 201A and an analysis device 201B.

[0072] (Analysis Device) The analysis device 201A and the analysis device 201B may be arranged in different data centers, for example. Also, the connection between the analysis device 201A and the analysis device 201B may be made using a dedicated line provided by a telecommunications carrier, for example.

[0073] The analysis device 201A is a device that mainly executes processing related to C-Plane packets. The analysis device 201A includes an acquisition unit 221A, a session identification unit 222A, and a linking unit 223A.

[0074] The analysis device 201B is a device that mainly executes processing related to U-Plane packets. The analysis device 201B includes an acquisition unit 221B and a session identification unit 222B.

[0075] The acquisition unit 221A and the session identification unit 222A may be functional blocks having the same configuration as the acquisition unit 221B and the session identification unit 222B. For example, when the acquisition unit of a certain analysis device is connected to a reference point for acquiring C-plane packets, it functions as the acquisition unit 221A for acquiring C-Plane packets, and the session identification unit of that analysis device may function as the session identification unit 222A. Also, when a certain analysis device is connected to a reference point for acquiring U-plane packets, it functions as the acquisition unit 221B for acquiring U-Plane packets, and the session identification unit of that analysis device may function as the session identification unit 222B.

[0076] Hereinafter, unless otherwise distinguished, the acquisition unit 221A and the acquisition unit 221B are collectively referred to as the acquisition unit 221, the session identification unit 222A and the session identification unit 222B are collectively referred to as the session identification unit 222, and the linking unit 223A is referred to as the linking unit 223. Similarly, unless otherwise distinguished, the analysis device 201A and the analysis device 201B are collectively referred to as the analysis device 201.

[0077] (Acquisition Unit) The acquisition unit 221 acquires C-Plane packets and U-Plane packets at a position corresponding to a predetermined reference point in the core network. The packets acquired by the acquisition unit 221 are supplied to the session identification unit 222.

[0078] (Session Identification Unit) The session identification unit 222 extracts the source address, destination address, and TEID from the C-Plane packets and U-Plane packets acquired by the acquisition unit 221, and extracts the source address, destination address, and TEID of the U-Plane packets from the information stored in the payload of the C-Plane packets acquired by the acquisition unit 221. Then, the session identification unit 222 generates identification information for identifying packets related to the communication by each of a plurality of users based on the extracted source address, destination address, and TEID. Here, the identification information generated by the session identification unit 222 may be the above-described session index.

[0079] The session index may be generated by performing a predetermined operation on the source IP address and destination IP address stored in each packet, as well as the TEID. As an example, a session index including the hash values of the source IP address, destination IP address, and TEID may be generated.

[0080] That is, the session identification unit 222A of the analysis device 201A extracts the source address, destination address, and TEID from the payload 227 in FIG. 6 in the C-Plane packet acquired by the acquisition unit 221A and generates a session index. Further, the session identification unit 222B of the analysis device 201B extracts the source IP address and destination IP address from the IP (outer) header 302 in FIG. 5 in the U-Plane packet acquired by the acquisition unit 221B, and extracts the TEID from the tunneling protocol header 304 to generate a session index.

[0081] The session identification unit 222 supplies, for example, the generated identification information (session index) to the association unit 223 after attaching it to the C-Plane packet and U-Plane packet acquired by the acquisition unit 221.

[0082] Here, depending on the operation status of the core network and the packet analysis system 200, there may be U-Plane packets that cannot be associated with C-Plane packets. Specifically, for example, during maintenance of the analysis device 201A, there may be a period when C-Plane packets cannot be acquired. In such a case, since the core network is operating normally and the UE can establish a connection with the DN, the acquisition unit 221B of the analysis device 201B acquires U-Plane packets as usual. In such a case, since there are no C-Plane packets on the packet analysis system 200, U-Plane packets that cannot be associated with C-Plane packets are generated.

[0083] For example, when there are no C-Plane packets (that is, a session index cannot be generated), the analysis device 201B may prevent the U-Plane packets acquired by the acquisition unit 221B from being transmitted to the analysis device 201A.

[0084] In the example of FIG. 11, the information output from the session identification unit 222B of the analysis device 201B is configured to be supplied to the linking unit 223A of the analysis device 201A together with the information output from the session identification unit 222A of the analysis device 201A.

[0085] (Linking unit) The linking unit 223 links the C-Plane packets and the U-Plane packets based on the session index. That is, the linking unit 223 links the U-Plane to which the same session index as the session index assigned to the C-Plane packet is assigned. Thereby, it becomes possible to specify data related to the communication of the same UE and obtain information necessary for analyzing the communication situation.

[0086] As will be described later, the recording device 202 records by associating order information with each set of the C-Plane packet and the U-Plane packet linked by the linking unit 223. The order information may be, for example, the transmission time or reception time of the packet, or the sequence number of the packet. In short, information for specifying the order in which the packets are transmitted and received may be associated with each set of the C-Plane packet and the U-Plane packet.

[0087] The monitor device 203 refers to each set of the C-Plane packet and the U-Plane packet associated with the order information and executes a detailed analysis of the communication situation. Thereby, for example, calculation of index values related to KPIs, index values related to the degree of improvement in user satisfaction, etc. is performed.

[0088] Note that the recording device 202 may be configured to be integrated with the analysis device 201A, for example, or may be configured to be integrated with the monitor device 203.

[0089] Note that in the above example, it was described that the session identification unit 222 generates a session index based on the extracted source address, destination address, and TEID. However, the session identification unit 222 may not generate a session index. In this case, the session identification unit 222 may supply the C-Plane packets and U-Plane packets acquired by the acquisition unit 221 to the association unit 223 together with the source address, destination address, and TEID. Then, the association unit 223 may associate the C-Plane packets and U-Plane packets based on the source address, destination address, and TEID.

[0090] 。 Here, when associating C-Plane packets and U-Plane packets, there may be a case where there is an overlap in the source address, destination address, and TEID among packets acquired from different UEs. More specifically, for example, when performing association at once for packets collected over a certain period, there may be an overlap in the source address, destination address, and TEID among packets acquired from different UEs. According to the 3GPP standard regulations, in one network function (NE), processing is performed so that TEIDs do not overlap. However, when a user or UE that was using one TEID ends communication, the TEID may be reused by other users or UEs. Therefore, when performing association at once for packets collected over a certain period, in addition to the source address, destination address, and TEID, by referring to the order information, it is possible to determine whether the packets are packets of the same user or packets of different users.

[0091] (Arrangement of analysis device) In the example of FIG. 11, one analysis device 201B is installed for one analysis device 201A. However, in practice, a plurality of analysis devices 201B may be installed for one analysis device 201A. That is, a plurality of combinations of an acquisition unit 221B and a session identification unit 222B related to U-Plane packets may be provided for the combination of the acquisition unit 221A and the session identification unit 222A related to C-Plane packets.

[0092] For example, in a 5G core network, when providing a low-latency communication service, the functions of the UPF can also be implemented in a distributed manner among multiple devices. In particular, when providing a low-latency communication service, in order to improve the performance of the connection from the UE to the DN, the UPF is preferably distributed and arranged near the base station. Also, depending on the network operation mode and service provision mode, the UPF may be arranged near the server on the DN.

[0093] Therefore, in an actual 5G core network, for example, a configuration in which a plurality of UPFs are arranged corresponding to a gNodeB or a plurality of servers on the DN can be adopted. For example, the UPF can be arranged in a data center different from the data center where the AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged.

[0094] In this case, the analysis device 201A may be arranged in the data center where the AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged, and the analysis device 201B may be arranged in the data center where the UPF is arranged.

[0095] And, as described above, when a plurality of UPFs are arranged in correspondence with a gNodeB or a server on the DN, a plurality of data centers may be prepared in the vicinity of each of the plurality of gNodeBs (base stations) or the servers on the DN, and the analysis device 201B may be arranged in these plurality of data centers together with the UPF. That is, the acquisition unit 221B and the session identification unit 222B related to the U-Plane packets may be arranged close to the base station.

[0096] On the other hand, for example, when the packet analysis system 200 according to the present embodiment is used in an LTE core network, when the MME and the S-GW are arranged in the same data center, the analysis device 201A and the analysis device 201B may be arranged in the same data center. Similarly, even when the packet analysis system 200 according to the present embodiment is used in a 5G core network, when the UPF is also arranged in the data center where the AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged, the analysis device 201A and the analysis device 201B may be arranged in the same data center.

[0097] When the analysis device 201A and the analysis device 201B are arranged in the same data center, the connection between the analysis device 201A and the analysis device 201B may be performed by, for example, an optical fiber cable (it is not necessary to use a dedicated line provided by a telecommunications carrier).

[0098] (Packet acquisition location: LTE) FIG. 12 is a diagram for explaining an example of the acquisition location of C-Plane packets corresponding to the LTE core network and the acquisition location of U-Plane packets in the present embodiment. In the figure, each network function unit and base station of the core network are displayed by rectangles, and the reference points related to the packet acquisition location are displayed as characters and numerical values surrounded by circles.

[0099] In the example of FIG. 12, at reference point S11 between the MME and the S-GW, the analysis device 201A acquires C-Plane packets. Also, at reference point S1-U between the eNodeB and the S-GW, the analysis device 201B acquires U-Plane packets.

[0100] That is, when the core network is the core network in the LTE communication network, the acquisition unit 221 acquires C-Plane packets from reference point S11 and acquires U-Plane packets from reference point S1-U.

[0101] Note that in FIG. 12, the analysis device 201A and the analysis device 201B may be aggregated and arranged in, for example, the same data center, or may be distributed and arranged in separate data centers or the like.

[0102] (Packet Classification by Message Type) Note that among the packets acquired at reference point S11, only those that satisfy a predetermined condition may be supplied to the session identification unit 222. For example, by referring to the message type of the C-Plane packets acquirable at reference point S11, only packets of a predetermined message type may be supplied to the session identification unit 222. Note that the message type is information stored in the tunneling protocol header 334.

[0103] FIG. 13 is a diagram showing a list of message types of packets to be supplied to the session identification unit 222. In the figure, a message type number and the message type corresponding to the message type number are shown. The message type is information indicating the behavior of the UE (e.g., handover, etc.), and by referring to the message type, it is possible to classify packets necessary for analyzing the communication status in the subsequent monitoring device 203 and unnecessary packets.

[0104] As shown in FIG. 13, packets in which the message type number stored in the tunneling protocol header 334 is any one of 32, 33, 34, ··· 171, 176, 177 are classified as packets necessary for analyzing the communication status in the subsequent monitor device 203. On the other hand, packets in which the message type number stored in the tunneling protocol header 334 is other than the message type numbers shown in FIG. 13 are classified as packets unnecessary for analyzing the communication status in the subsequent monitor device 203.

[0105] In this way, the acquisition unit 221 may classify the packets of the C-Plane acquired from the reference point S11 into the first type of packets (packets necessary for analyzing the communication status) and the second type of packets (unnecessary packets) with reference to the message type of the packets, and supply only the packets classified into the first type to the session identification unit 222.

[0106] (Packet Classification by IE) For packets of any message type shown in FIG. 13, necessary packets and unnecessary packets may be further classified by referring to the IE in the payload 337. FIG. 14 is a diagram showing a list of IEs referred to at this time. In the figure, the IE Type Value and the IE (Information Element) corresponding to the IE Type Value are shown.

[0107] For example, a list of values (or ranges) to be compared with the values stored in the respective IEs corresponding to IE Type Values 1, 2, 3, ··· 87, 93, 97 is created in advance. For example, a value to be compared with the value stored in the IE of IE Type Value 1 is set in advance. When the value stored in the IE of IE Type Value 1 matches, subsequent processing is executed as a necessary packet, and when they do not match, it is excluded from subsequent processing as an unnecessary packet. Note that each packet may be assigned a flag indicating necessary or unnecessary, or only necessary packets may be stored, etc., and unnecessary packets may be discarded.

[0108] Also, a range of values to be compared with the value stored in the IE of IE Type Value2 is preset. When the value stored in the IE of IE Type Value1 is within this range, subsequent processing is executed as a necessary packet, and when it is outside the range, it is excluded from subsequent processing as an unnecessary packet.

[0109] Similar processing is also executed for IE Type Value3, ··· 87, 93, 97, and it is determined whether the packet is a necessary packet or an unnecessary packet for analyzing the communication status in the subsequent monitor device 203.

[0110] In this way, the acquisition unit 221 may supply only those packets that satisfy a predetermined condition among the packets acquired at the reference point S11 to the session identification unit 222. That is, as described above, the acquisition unit 221 refers to the value of a predetermined IE (Information Element) stored in the packet classified into the first type by referring to the message type, and further classifies it into the third type of packet and the fourth type of packet, and may supply only the packets classified into the third type to the session identification unit 222.

[0111] Alternatively, the acquisition unit 221 may extract the values stored in the respective IEs corresponding to IE Type Value1, 2, 3, ··· 87, 93, 97 from the packets of any message type shown in FIG. 13 and supply them to the session identification unit 222 together with the packets. That is, each of the IEs shown in FIG. 14 may be supplied to the subsequent session identification unit 222 and monitor device 203 as information necessary for analyzing the communication status. In this case, it is not necessary to further classify the packets classified as necessary packets for analyzing the communication status by referring to the message type.

[0112] (Packet acquisition location: 5G) FIG. 15 is a diagram for explaining an example of the acquisition position of C-Plane packets and the acquisition position of U-Plane packets corresponding to a 5G core network in the present embodiment. In the figure, each network function part and base station of the core network are displayed by rectangles, and the reference points related to the packet acquisition positions are displayed as characters and numerical values surrounded by circles.

[0113] In the example of FIG. 15, at reference point N2 between the gNodeB and the AMF, and at reference point N12 between the AMF and the AUSF, the analysis device 201A acquires C-Plane packets. Also, at reference point N3 between the gNodeB and the UPF, the analysis device 201B acquires U-Plane packets.

[0114] In the case of a 5G core network, it is also possible to acquire C-Plane packets at reference point N11 between the AMF and the SMF. However, in the case of a 5G core network, a header compression method called HPACK is adopted for the communication between the AMF and the SMF.

[0115] In the case of communication adopting HPACK, for example, even when retransmission occurs due to packet loss or the like, the index number changes. Nodes other than the node that requested retransmission cannot determine which packet is the retransmitted packet. Therefore, if an attempt is made to restore the header compressed by HPACK according to the index number, there is a possibility that the header cannot be restored correctly. That is, since the analysis device 201A is not the node that requested retransmission, it may not be able to correctly restore the header compressed by HPACK. For this reason, in the present embodiment, the acquisition unit 221 does not acquire C-Plane packets at reference point N11, but acquires C-Plane packets at reference point N2.

[0116] In addition, in a 5G core network where HPACK is not adopted, C-Plane packets may be acquired at reference point N11. In this case, it is not necessary to acquire C-Plane packets at reference point N2.

[0117] Also, in the case of a 5G core network, the IMSI in the C-Plane packet is encrypted, and it is necessary to decrypt the encrypted IMSI for analyzing the communication status in the subsequent monitoring device 203. For this reason, in the present embodiment, the acquisition unit 221 acquires C-Plane packets at reference point N12 between the AMF and the AUSF. At reference point N12, packets corresponding to scheme 2, scheme 7, scheme 12, and scheme 14 among the schemes defined in / nausf-auth / v1 / ue-authentications are acquired by the acquisition unit 221.

[0118] In this way, when the core network is the core network in a 5G communication network, the acquisition unit 221 acquires C-Plane packets from reference point N2 and reference point N12, and acquires U-Plane packets from reference point N3.

[0119] Note that in FIG. 15, the analysis devices 201A and 201B may be aggregated and arranged in, for example, the same data center, or may be distributed and arranged in separate data centers or the like.

[0120] (Classification of Packets by Procedure Code) Among the packets acquired at reference point N2, only those that satisfy a predetermined condition may be supplied to the session identification unit 222. For example, by referring to the Procedure Code of the C-Plane packets that can be acquired at N2, only packets with a predetermined Procedure Code may be acquired. The Procedure Code is information stored in the payload 355 of FIG. 7.

[0121] FIG. 16 is a diagram showing a list of Procedure Codes of packets to be supplied to the session identification unit 222. In the figure, the Procedure Code and the Code Name corresponding to the Procedure Code are shown. The Procedure Code is information indicating the behavior of the UE, similar to the message type in FIG. 13. By referring to the Procedure Code, it is possible to classify packets necessary for analyzing the communication status in the subsequent monitoring device 203 and unnecessary packets.

[0122] As shown in FIG. 16, each of the packets with a Procedure Code of 4, 11, 12, ··· 41, 42, 46 is classified as a packet necessary for analyzing the communication status in the subsequent monitoring device 203. On the other hand, packets with a Procedure Code other than the Procedure Code shown in FIG. 16 are classified as unnecessary packets for analyzing the communication status in the subsequent monitoring device 203.

[0123] In this way, the acquisition unit 221 may classify the C-Plane packets acquired from the reference point N2 into a first type of packet (packets necessary for analyzing the communication status) and a second type of packet (unnecessary packets) by referring to the Procedure Code, and supply only the packets classified into the first type to the session identification unit 222.

[0124] (Packet acquisition location: 5G interworking) FIG. 17 is a diagram for explaining another example of the acquisition location of C-Plane packets corresponding to the 5G core network and the acquisition location of U-Plane packets in the present embodiment. In the figure, each network function unit and base station of the core network are displayed as rectangles, and the reference points related to the packet acquisition locations are displayed as characters and numerical values surrounded by circles.

[0125] In the case of FIG. 17, different from the example of FIG. 15, the acquisition location related to a 5G core network having an interworking function between 5GC and EPC (Evolved Packet Core) will be described. Such a configuration of the 5G core network is shown in the 3GPP standard TS 123 501 4.3, “Interworking with EPC”.

[0126] In the example of FIG. 17, in addition to the configuration of FIG. 15, an MME and an eNodeB are included. Also, in the case of a 5G core network having an interworking function between 5GC and EPC, the functions of the S-GW and the P-GW are implemented in a server responsible for the functions of the SMF or the UPF. In the example of FIG. 17, it is assumed that the function of the S-GW is implemented in a server responsible for the function of the UPF.

[0127] In the example of FIG. 17, at the reference point N2 between the gNodeB and the AMF, at the reference point N12 between the AMF and the AUSF, and further at the reference point N26 between the MME and the AMF, C-Plane packets are acquired by the analysis device 201A. Further, at the reference point S11 between the MME and the UPF, C-Plane packets are acquired by the analysis device 201A. Note that the UPF described in FIG. 17 is a server responsible for the function of the UPF and implements the function of the S-GW. Therefore, it can be said that the reference point S11 related to the acquisition of C-Plane packets is actually a reference point between the MME and the S-GW.

[0128] Also, in the example of FIG. 17, at the reference point N3 between the gNodeB and the UPF, U-Plane packets are acquired by the analysis device 201B. Further, at the reference point S1-U between the eNodeB and the UPF (actually the S-GW), U-Plane packets are acquired by the analysis device 201B.

[0129] Regarding the reference point S11 and the reference point S1-U, it is the same as the case described above with reference to FIG. 12. Regarding the reference point N2, the reference point N12, and the reference point N3, it is the same as the case described above with reference to FIG. 15.

[0130] In mobile communications such as LTE and 5G, information is encrypted during communication. For example, consider a case where a UE is connected to a gNodeB, then handed over to an eNodeB, and then handed over again to be connected to the gNodeB. In this case, since the encryption key changes when connected to the eNodeB, when reconnecting to the gNodeB, the encryption key used immediately before must be obtained from the MME. Therefore, at the reference point N26, it is necessary for the analysis device 201A to acquire the C-Plane packets.

[0131] In FIG. 17, the analysis device 201A and the analysis device 201B may be aggregated and arranged in, for example, the same data center, or may be distributed and arranged in separate data centers.

[0132] (Packet Analysis Processing) Next, an example of packet analysis processing by the packet analysis system 200 in FIG. 11 will be described. FIG. 18 is a flowchart for explaining an example of the flow of packet analysis processing.

[0133] In step S101, the acquisition unit 221A of the analysis device 201A acquires C-Plane packets. At this time, when the core network is the core network in the LTE communication network, as described above with reference to FIG. 12, C-Plane packets are acquired at the reference point S11 between the MME and the S-GW.

[0134] Also, when the core network is the core network in the 5G communication network, as described above with reference to FIG. 15, C-Plane packets are acquired from the reference points N2 and N12 between the gNodeB and the AMF. Note that at the reference point N12, packets corresponding to scheme 2, scheme 7, scheme 12, and scheme 14 among the schemes defined in / nausf-auth / v1 / ue-authentications are acquired by the acquisition unit 221.

[0135] Furthermore, when the core network is a core network in a 5G communication network and has an interworking function between 5GC and EPC, as described above with reference to FIG. 17, at reference point N2, reference point N12, and reference point N26 between MME and AMF, C-Plane packets are acquired. Furthermore, at reference point S11 between MME and UPF (actually S-GW), C-Plane packets are acquired.

[0136] The packets acquired by the acquisition unit 221 in step S101 are supplied to the session identification unit 222.

[0137] Note that, as described above with reference to FIG. 13, only the packets that satisfy a predetermined condition among the packets acquired at reference point S11 may be supplied to the session identification unit 222. For example, by referring to the Message Type of the C-Plane packets that can be acquired at S11, only the packets of a predetermined message type may be supplied to the session identification unit 222. Also, as described above with reference to FIG. 14, further, by referring to the IE in the payload 337, the packets are further classified so that only the packets that satisfy a predetermined condition among the packets acquired at reference point S11 are supplied to the session identification unit 222.

[0138] Also, as described above with reference to FIG. 16, only the packets that satisfy a predetermined condition among the packets acquired at reference point N2 may be supplied to the session identification unit 222. For example, by referring to the Procedure Code of the C-Plane packets that can be acquired at N2, only the packets of a predetermined Procedure Code may be supplied to the session identification unit 222.

[0139] In step S102, the acquisition unit 221B of the analysis device 201B acquires U-Plane packets. At this time, when the core network is the core network in the LTE communication network, as described above with reference to FIG. 12, U-Plane packets are acquired at the reference point S1-U between the eNodeB and the S-GW.

[0140] Also, when the core network is the core network in the 5G communication network, as described above with reference to FIG. 15, U-Plane packets are acquired by the acquisition unit 221B of the analysis device 201B at the reference point N3 between the gNodeB and the UPF.

[0141] Furthermore, when the core network is the core network in the 5G communication network and has an interworking function between the 5GC and the EPC, as described above with reference to FIG. 17, U-Plane packets are acquired by the analysis device 201B at the reference point N3 and the reference point S1-U.

[0142] In step S103, the session identification unit 222 extracts the source address, destination address, and TEID from the C-Plane packets and U-Plane packets acquired by the acquisition unit 221.

[0143] That is, the session identification unit 222A of the analysis device 201A extracts the source address, destination address, and TEID from the C-Plane packets acquired by the acquisition unit 221A.

[0144] At this time, when the acquisition unit 221A acquires a C-Plane packet from the reference point S11, the source IP address, destination IP address, and TEID are extracted from the IE with an IE Type Value of 87 in the payload 337 of FIG. 6. Further, when the acquisition unit 221A acquires a C-Plane packet from the reference point N2, the source IP address, destination IP address, and TEID stored in the payload 355 of FIG. 7 are extracted. Furthermore, when the acquisition unit 221A acquires a C-Plane packet from the reference point N12, the source IP address, destination IP address, and TEID stored in the payload 375 of FIG. 8 are extracted.

[0145] In addition, the session identification unit 222B of the analysis device 201B extracts the source address, destination address, and TEID from the U-Plane packet acquired by the acquisition unit 221B. At this time, as described above, the source IP address and destination IP address are extracted from the IP (outer) header 302 of FIG. 5, and the TEID is extracted from the tunneling protocol header 304.

[0146] In step S104, the session identification unit 222 generates a session index, which is identification information for identifying packets related to communication by each of a plurality of users, based on the source address, destination address, and TEID extracted in the process of step S103. That is, the session identification unit 222A of the analysis device 201A generates a session index for the C-Plane packet acquired by the acquisition unit 221A, and the session identification unit 222B of the analysis device 201B generates a session index for the U-Plane packet acquired by the acquisition unit 221B.

[0147] The session index may be generated by performing a predetermined operation on the source IP address, destination IP address, and TEID stored in each packet. As an example, a session index including the hash values of the source IP address, destination IP address, and TEID is generated.

[0148] The session identification unit 222 supplies the C-Plane packets and U-Plane packets acquired by the acquisition unit 221 to the association unit 223 together with the generated session index.

[0149] In step S105, the association unit 223 associates the C-Plane packets and the U-Plane packets based on the session index.

[0150] At this time, for example, the session index of the C-Plane packet supplied from the session identification unit 222A of the analysis device 201A is compared with the session index of the U-Plane packet supplied from the session identification unit 222B of the analysis device 201B. Then, the U-Plane packet having the same session index as the session index of the C-Plane packet is associated with the C-Plane packet. Thereby, it becomes possible to identify data related to the communication of the same user and obtain information necessary for analyzing the communication status.

[0151] In step S106, the recording device 202 records by associating order information with each set of the C-Plane packet and the U-Plane packet associated by the process of step S105. The order information may be, for example, the transmission time or reception time of the packet, or the sequence number of the packet.

[0152] In step S107, the monitor device 203 refers to each set of the C-Plane packet and the U-Plane packet with which the order information is associated by the process of step S106 and performs a detailed analysis of the communication status. Thereby, for example, calculation of index values related to KPIs is performed.

[0153] In this way, the packet analysis process is executed.

[0154] (Effect of the Embodiment) According to this embodiment, even if a configuration is adopted in which multiple UPFs are deployed corresponding to a base station, gNodeB, for example, information necessary for analyzing communication conditions can be efficiently obtained.

[0155] In this embodiment, as described above, the C-Plane packet and the U-Plane packet are linked by the session index. Therefore, even if N3, which is a reference point related to the connection between the gNodeB and the UPF, is distributed in different data centers, there is no need to lay a dedicated optical fiber cable for transferring the U-Plane packet acquired by N3 at high speed.

[0156] In addition, in this embodiment, for example, a table for associating TEID with IMSI is not required, so that the processing load of the device can be reduced. Furthermore, the number of C-Plane packets and U-Plane packets that can be linked is not limited by the size of the table, so that the communication status can be analyzed using a large amount of data.

[0157] As described above, according to this embodiment, even if the configuration of the core network becomes complicated, it is possible to timely acquire a large amount of data required to grasp the communication situation.

[0158] Second Embodiment 11, a configuration has been described in which analysis device 201A has acquisition unit 221A, session identification unit 222A, and linking unit 223A, and analysis device 201B has acquisition unit 221B and session identification unit 222B. However, analysis device 201A and analysis device 201B may be devices with the same configuration.

[0159] For example, analysis device 201B may include linking unit 223B, which is a functional block having the same configuration as linking unit 223A. In other words, a plurality of analysis devices 201 having the same configuration may be prepared, and one of them may be used as analysis device 201A and the others may be used as analysis device 201B.

[0160] In this case, the associating unit 223B of the analysis device 201B may be deactivated, and the associating unit 223A of the analysis device 201A may associate the C-Plane packets and the U-Plane packets. <Third Embodiment>

[0161] In the above-described embodiment, it has been described that the association between the C-Plane packets and the U-Plane packets is performed in the associating unit 223A of the analysis device 201A. By performing the association in the analysis device 201A that is centrally arranged instead of the analysis device 201B that can be distributedly arranged, the maintainability of the entire packet analysis system 200 can be improved.

[0162] However, the association between the C-Plane packets and the U-Plane packets may be performed in the associating unit 223B of the analysis device 201B. For example, the associating unit 223B of the analysis device 201B may be activated and the associating unit 223A of the analysis device 201A may be deactivated. Alternatively, only the analysis device 201B may have the associating unit B, and the analysis device 201A may not be provided with the associating unit.

[0163] The C-Plane packets are packets related to the control of the UE on the network, etc., and the U-Plane packets are packets including Web sites browsed by the user, voice data during a call, etc. Therefore, generally, the U-Plane packets are larger in data size than the C-Plane packets in many cases. Here, if the association is performed in the analysis device 201B, the C-Plane packets with a relatively small data size may be transferred from the analysis device 201A to the analysis device 201B, and the communication load between the analysis device 201A and the analysis device 201B can be suppressed. <Other Embodiments> In addition, in the above-described embodiments, examples where one analysis device 201B is mainly installed for one analysis device 201A and examples where a large number of analysis devices 201B are installed for one analysis device 201A have been described, but the present invention is not limited thereto. For example, it is also possible to install a large number of analysis devices 201A for one analysis device 201B.

[0164] <Example of software implementation> The above-described analysis device 201 is a program for causing a computer to function, and can be realized by a program for causing a computer to function as the analysis device 201. In this case, the analysis device 201 includes, as hardware for executing the above program, a computer having at least one control device (for example, a processor) and at least one storage device (for example, a memory). An example of such a computer is shown in FIG. 19.

[0165] The computer 500 includes at least one processor 501 and at least one memory 502. A program 520 for operating the computer 500 as the analysis device 201 is recorded in the memory 502. In the computer 500, the processor 501 reads and executes this program 520 from the memory 502, thereby realizing each function of the analysis device 201.

[0166] As the processor 501, for example, a CPU (Central Processing Unit), a GPU (Graphic Processing Unit), a DSP (Digital Signal Processor), an MPU (Micro Processing Unit), an FPU (Floating point number Processing Unit), a PPU (Physics Processing Unit), a microcontroller, or a combination thereof can be used.

[0167] As the memory 502, for example, a flash memory, an HDD (Hard Disk Drive), an SSD (Solid State Drive), or a combination thereof can be used.

[0168] Note that the computer 500 may further include a RAM (Random Access Memory) for expanding the program 520 during execution or temporarily storing various data. Also, the computer 500 may further include a communication interface for transmitting and receiving data to and from other devices. Further, the computer 500 may further include an input / output interface for connecting input / output devices such as a keyboard, a mouse, a display, and a printer.

[0169] Also, the program 520 for operating the computer 500 as the analysis device 201 can be recorded on a non-transitory tangible recording medium 530 readable by the computer 500. As such a recording medium 530, for example, a tape, a disk, a card, a semiconductor memory, or a programmable logic circuit can be used. The computer 500 can acquire the program 520 via such a recording medium 530.

[0170] Also, the program 520 for operating the computer 500 as the analysis device 201 can be transmitted via a transmission medium. As such a transmission medium, for example, a communication network or a broadcast wave can be used. The computer 500 can also acquire the program 520 via such a transmission medium.

[0171] Also, part or all of the functions of the analysis device 201 can also be realized by a logic circuit. For example, an integrated circuit in which a logic circuit functioning as each of the above control blocks is formed is also included in the scope of the present invention. In addition to this, for example, it is also possible to realize the functions of each of the above control blocks by a quantum computer.

[0172] According to each aspect of the present invention described above, by achieving the above-described effects, it is possible to contribute to the achievement of Goal 9, "Build the infrastructure for industry and innovation," of the Sustainable Development Goals (SDGs).

[0173] Note that the present invention is not limited to the above-described embodiments, and various modifications are possible within the scope indicated in the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention.

[0174] 〔Summary〕 The information processing system according to Aspect 1 of the present invention includes an acquisition unit that acquires C-Plane packets and U-Plane packets from a core network, an extraction unit that extracts a source address, a destination address, and a TEID (Tunnel Endpoint Identifier) from the U-Plane packets acquired by the acquisition unit, and extracts the source address, destination address, and TEID of the U-Plane packets from the information stored in the payload of the C-Plane packets acquired by the acquisition unit, and a linking unit that links the C-Plane packets and the U-Plane packets based on the source address, destination address, and TEID extracted by the extraction unit.

[0175] The information processing system according to Aspect 2 of the present invention is, in the above Aspect 1, the core network is a core network in a 5G communication network, and the acquisition unit acquires C-Plane packets from reference points N2 and N12 and acquires U-Plane packets from reference point N3.

[0176] The information processing system according to Aspect 3 of the present invention is, in the above Aspect 2, the acquisition unit further acquires C-Plane packets from reference point N26.

[0177] In the information processing system according to aspect 4 of the present invention, in the above aspect 2 or 3, the acquisition unit classifies the C-Plane packets acquired from the reference point N2 into a first type of packet and a second type of packet with reference to the Procedure Code of the packets, and supplies only the packets classified into the first type to the extraction unit.

[0178] In the information processing system according to aspect 5 of the present invention, in the above aspect 1, the core network is a core network in an LTE communication network, and the acquisition unit acquires C-Plane packets from the reference point S11 and acquires U-Plane packets from the reference point S1-U.

[0179] In the information processing system according to aspect 6 of the present invention, in the above aspect 5, the acquisition unit classifies the C-Plane packets acquired from the reference point S11 into a first type of packet and a second type of packet with reference to the message type of the packets, and supplies only the packets classified into the first type to the extraction unit.

[0180] In the information processing system according to aspect 7 of the present invention, in the above aspect 6, the acquisition unit further classifies the packets classified into the first type into a third type of packet and a fourth type of packet with reference to the value of a predetermined IE (Information Element) stored in the packets, and supplies only the packets classified into the third type to the extraction unit.

[0181] In the information processing system according to aspect 8 of the present invention, in the above aspects 1 to 7, the extraction unit generates identification information for identifying packets related to communications by each of a plurality of users based on the extracted source address, destination address, and TEID, and the association unit associates the C-Plane packets and the U-Plane packets based on the identification information.

[0182] The information processing system according to aspect 9 of the present invention is, in the above aspect 8, wherein the identification information includes a hash value of the source address, the destination address, and the TEID.

[0183] The information processing system according to aspect 10 of the present invention is, in the above aspects 1 to 9, provided with a first acquisition unit and a first extraction unit for the packet of the C-Plane, and a second acquisition unit and a second extraction unit for the packet of the U-Plane, and a plurality of combinations of the second acquisition unit and the second extraction unit are provided for one combination of the first acquisition unit and the first extraction unit, and the second acquisition unit and the second extraction unit are arranged close to the base station.

[0184] The information processing method according to aspect 11 of the present invention includes steps of acquiring a packet of the C-Plane and a packet of the U-Plane from a core network, extracting a source address, a destination address, and a TEID from the acquired packet of the U-Plane, and extracting a source address, a destination address, and a TEID of the packet of the U-Plane from information stored in a payload of the acquired packet of the C-Plane, and associating the packet of the C-Plane and the packet of the U-Plane based on the extracted source address, destination address, and TEID.

[0185] The program according to aspect 12 of the present invention causes a computer to execute information processing including steps of acquiring a packet of the C-Plane and a packet of the U-Plane from a core network, extracting a source address, a destination address, and a TEID from the acquired packet of the U-Plane, extracting a source address, a destination address, and a TEID of the packet of the U-Plane from information stored in a payload of the acquired packet of the C-Plane, and associating the packet of the C-Plane and the packet of the U-Plane based on the extracted source address, destination address, and TEID.

Description of Signs

[0186] 200 Packet Analysis System 201 Analysis Device 202 Recording Device 203 Monitor Device 221 Acquisition Unit 222 Session Identification Unit 223 Linking Unit

Claims

1. An acquisition unit that acquires C-Plane packets and U-Plane packets from a core network; An extraction unit that extracts a source address, a destination address, and a TEID (Tunnel Endpoint Identifier) from the U-Plane packet acquired by the acquisition unit, and extracts the source address, the destination address, and the TEID of the U-Plane packet from information stored in the payload of the C-Plane packet acquired by the acquisition unit; An association unit that associates the C-Plane packet and the U-Plane packet based on the source address, the destination address, and the TEID extracted by the extraction unit An information processing system comprising the above.

2. The core network is a core network in a 5G communication network, The acquisition unit acquires C-Plane packets from reference points N2 and N12, and acquires U-Plane packets from reference point N3 The information processing system according to Claim 1.

3. The acquisition unit further acquires C-Plane packets from reference point N26 The information processing system according to Claim 2.

4. The acquisition unit classifies the C-Plane packets acquired from reference point N2 into a first type of packet and a second type of packet with reference to the Procedure Code of the packet, and supplies only the packets classified into the first type to the extraction unit The information processing system according to Claim 2.

5. The core network is a core network in an LTE communication network, The acquisition unit acquires C-Plane packets from reference point S11, and acquires U-Plane packets from reference point S1-U The information processing system according to Claim 1.

6. The acquisition unit classifies the C-Plane packets acquired from reference point S11 into a first type of packet and a second type of packet with reference to the message type of the packet, and supplies only the packets classified into the first type to the extraction unit The information processing system according to Claim 5.

7. The acquisition unit further classifies the packets classified into the first type into third-type packets and fourth-type packets by referring to the value of a predetermined IE (Information Element) stored in the packets, and supplies only the packets classified into the third type to the extraction unit. The information processing system according to claim 6.

8. The extraction unit generates identification information for identifying packets related to communications by each of a plurality of users based on the extracted source address, destination address, and TEID. The association unit associates the C-Plane packets and the U-Plane packets based on the identification information. The information processing system according to claim 1.

9. The identification information includes hash values of the source address, the destination address, and the TEID. The information processing system according to claim 8.

10. a first acquisition unit and a first extraction unit related to the C-Plane packets; a second acquisition unit and a second extraction unit related to the U-Plane packets, wherein a plurality of combinations of the second acquisition unit and the second extraction unit are provided for one combination of the first acquisition unit and the first extraction unit. The information processing system according to claim 7.

11. acquiring C-Plane packets and U-Plane packets from a core network; extracting a source address, a destination address, and a TEID from the acquired U-Plane packets, and extracting a source address, a destination address, and a TEID of the U-Plane packets from information stored in a payload of the acquired C-Plane packets; associating the C-Plane packets and the U-Plane packets based on the extracted source address, destination address, and TEID An information processing method including.

12. In a computer, acquiring C-Plane packets and U-Plane packets from a core network; Extract the source address, destination address, and TEID from the obtained U-Plane packets, and extract the source address, destination address, and TEID of the U-Plane packets from the information stored in the payload of the obtained C-Plane packets; Execute information processing including a step of associating the C-Plane packets and the U-Plane packets based on the extracted source address, destination address, and TEID. Program.

Citation Information

Patent Citations

  • Base station, control method, and program

    JP2022090476A