Information processing system, information processing method, and program

The system addresses the challenge of associating C-Plane and U-Plane packets in complex core networks by using session indexes to link packets, enhancing data acquisition and analysis efficiency.

JP2025099001AActive Publication Date: 2025-07-02SOFTBANK CORPORATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025006235
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-07-02
Estimated Expiration
2043-12-20

AI Technical Summary

Technical Problem

In complex core networks, such as those in 5G communication systems, associating C-Plane and U-Plane packets from different data centers becomes challenging, leading to high processing loads and limitations in data association, which hinders effective communication status analysis.

Method used

An information processing system that extracts source and destination addresses, along with TEIDs, from both C-Plane and U-Plane packets, and uses these to link the packets based on generated session indexes, eliminating the need for tables and reducing processing load.

Benefits of technology

Enables timely and efficient data acquisition for communication status analysis, even in complex core networks, by associating C-Plane and U-Plane packets without the need for dedicated optical fiber connections and reducing processing overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025099001000001_ABST
    Figure 2025099001000001_ABST
Patent Text Reader

Abstract

To provide a technique capable of acquiring, in a timely manner and large volumes, the data necessary to grasp communication conditions even when the core network configuration becomes complex.SOLUTION: An information processing system comprises: an acquisition unit which acquires a C-plane packet and an U-plane packet from a core network; an extraction unit which extracts a source address, a destination address, and a TEID (Tunnel Endpoint Identifier) from the U-plane packet acquired by the acquisition unit, and also extracts the source address, destination address, and TEID of the U-plane packet corresponding to the C-PLANE packet from the information stored in the payload of the C-plane packet; and an association unit which associates the C-plane packet with the U-plane packet on the basis of the source address, destination address, and TEID extracted by the extraction unit.SELECTED DRAWING: Figure 11
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system, an information processing method, and a program, and more particularly to an information processing system, an information processing method, and a program capable of timely and massively acquiring data necessary for grasping communication status even when the configuration of a core network becomes complex.

Background Art

[0002] Communication quality evaluation is performed by analyzing packets flowing through a network and calculating KPIs. Also, in marketing activities utilizing RTB and the like, analysis of packets flowing through a network is being performed.

[0003] For example, in LTE, C-Plane packets and U-Plane packets were respectively extracted from the reference point S11 related to the connection between the MME and the S-GW, and the reference point S1-U related to the connection between the base station eNodeB and the S-GW. By associating the extracted C-Plane packets and U-Plane packets, data related to the communication of the same user is specified, and information necessary for analyzing the communication status and the like is acquired.

[0004] Also, a technique has been proposed in which a packet analysis unit that analyzes received packets classifies the received packets into flows with reference to flow information and assigns a flow ID, which is an identifier of the flow corresponding to the packet, to improve traffic control units and traffic control methods (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] In the initial release of LTE, the extraction positions of C-Plane packets and U-Plane packets were aggregated within one data center.

[0007] On the other hand, in the CUPS (C·U-Plane Separate) architecture defined in the later release of LTE and in 5G (hereinafter sometimes referred to as "after 5G compliance"), servers responsible for network function units typified by UPF related to U-Plane processing are distributed and arranged. For example, in order to improve the performance of the core network, servers functioning as UPF are often arranged in a data center near the base station.

[0008] Therefore, after 5G compliance, the data centers for extracting C-Plane packets and the data centers for extracting U-Plane packets are often different, making it difficult to associate data related to the communication of the same user. On the other hand, for example, in Citation Document 1, the situation where the extraction positions of C-Plane packets and U-Plane packets are arranged in different data centers respectively is not considered.

[0009] Also, the association of data related to the communication of the same user in the past was performed using a table or the like for associating an ID temporarily assigned to the traffic of each user with a uniquely determined ID. For this reason, the conventional association process has a high processing load, and the number of users for which data association is possible is limited. For example, sufficient analysis of Key Performance Indicator (KPI) etc. could not be performed.

[0010] One aspect of the present invention aims to realize a technology that can acquire a large amount of data necessary for grasping the communication situation in a timely manner even when the configuration of the core network becomes complex.

Means for Solving the Problem

[0011] An information processing system according to one embodiment of the present invention includes an acquisition unit that acquires C-Plane packets and U-Plane packets from a core network, (i) an extraction unit that extracts a source address, a destination address, and a TEID (Tunnel Endpoint Identifier) ​​from the U-Plane packets acquired by the acquisition unit, and (ii) an extraction unit that extracts a source address, a destination address, and a TEID of a U-Plane packet corresponding to the C-Plane packet from information stored in the payload of the C-Plane packet acquired by the acquisition unit, and a linking unit that links the C-Plane packets and U-Plane packets based on the source address, destination address, and TEID extracted by the extraction unit.

[0012] An information processing method according to one embodiment of the present invention includes the steps of: (i) acquiring a C-Plane packet and a U-Plane packet from a core network; (i) extracting a source address, a destination address, and a TEID from the acquired U-Plane packet; and (ii) extracting a source address, a destination address, and a TEID of a U-Plane packet corresponding to the C-Plane packet from information stored in the payload of the acquired C-Plane packet; and linking the C-Plane packet and the U-Plane packet based on the extracted source address, destination address, and TEID.

[0013] Each aspect of the present invention may be realized by a computer. In this case, a program that causes a computer to execute each step of the above-described method, and a computer-readable recording medium having the program recorded thereon, also fall within the scope of the present invention. Effect of the Invention

[0014] According to one aspect of the present invention, even if the configuration of the core network becomes complex, it is possible to obtain a large amount of data required to grasp the communication situation in a timely manner. [Brief description of the drawings]

[0015]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Embodiments for Carrying Out the Invention

[0016] Hereinafter, embodiments of the present invention will be described with reference to the drawings. First, problems of the prior art will be described.

[0017] Conventionally, communication quality evaluation has been performed by analyzing packets flowing through a network and calculating KPIs.

[0018] FIG. 1 is a diagram for explaining a conventional packet analysis system related to analysis of communication status. As shown in the figure, in a fourth-generation mobile communication system (LTE), a UE (User Equipment) is connected to an LTE core network 30 via an eNodeB which is a base station. The core network 30 includes network function units such as an MME (Mobility Management Entity), an S-GW (Serving Gateway), and a P-GW (PDN Gateway). Further, the UE is connected to an external network such as the Internet via an IP network used for providing a carrier service constituted by a base station, a core network, and a CGN (Carrier Grade NAT), etc. The IP network for carrier service, the Internet, etc. are collectively referred to as a DN (Data Network) in some cases.

[0019] (Network Configuration: LTE) In addition, FIG. 1 shows a packet analysis system 50 corresponding to an LTE core network. From the reference points related to the connection between the MME and the S-GW, and the reference points (Reference point) related to the connection between the eNodeB and the S-GW, the C-Plane packets and the U-Plane packets are respectively extracted. That is, the C-Plane packets are acquired from S11, which is the reference point related to the connection between the MME and the S-GW, and the U-Plane packets are acquired from S1-U, which is the reference point related to the connection between the eNodeB and the S-GW.

[0020] Note that the C-Plane packets are, for example, packets related to communication for performing control such as which terminal is communicating with which base station. The U-Plane packets are, for example, packets related to the communication of mainly the data of the content itself, such as the Web sites browsed by the user and the voice data during a call.

[0021] The packet analysis system 50 identifies the data related to the communication of the same user by associating the acquired C-Plane packets and U-Plane packets, and acquires information necessary for the analysis of the communication situation. By inputting such information into, for example, a monitor device (not shown) and performing the analysis of the communication situation, it is possible to calculate, for example, the index values related to KPIs.

[0022] (Schematic Configuration of the System) FIG. 2 is a diagram showing a schematic internal configuration example of the packet analysis system 50 in FIG. 1. As shown in the figure, the C-Plane packets acquired from S11 and the U-Plane packets acquired from S1-U are supplied to a packet identifier 51. In this example, the C-Plane packets and U-Plane packets related to Sub (representing Subscriber) 1, Sub2, and Sub3 indicating individual users are supplied to the packet identifier 51.

[0023] The packet identifier 51 refers to a table described later, associates C-Plane packets and U-Plane packets, and supplies them to DPI servers 52-1 to 52-3. For example, the packet identifier 51 associates the C-Plane packet "S11(Sub1)" related to user Sub1 with the U-Plane packet "S1-U(Sub1)" and supplies them to DPI server 52-1. Similarly, the packet identifier 51 associates "S11(Sub2)" and "S1-U(Sub2)" related to user Sub2 and supplies them to DPI server 52-2, and associates "S11(Sub3)" and "S1-U(Sub3)" related to user Sub3 and supplies them to DPI server 52-3.

[0024] At this time, in order to associate C-Plane packets and U-Plane packets related to the same user, the packet identifier 51 uses a table that associates IMSI (International Mobile Subscriber Identity) and TEID (Tunnel Endpoint Identifier). Note that the IMSI is an ID assigned to each user in advance. Also, the TEID is an ID used in the tunneling protocol (GTP) and is assigned at the start of communication.

[0025] (Table for association) Figure 3 is a diagram showing an example of a table that associates IMSI and TEID used in the packet analysis system 50 of the figure. In the example of the figure, IMSI "44020xxxxxxxxxx01" is associated with TEID "teid1", and IMSI "44020xxxxxxxxxx02" is associated with TEID "teid2". In the table of Figure 3, each IMSI is thus associated with a TEID.

[0026] Since the IMSI is included in the C-Plane packet, the packet identifier 51 can identify the TEID corresponding to the IMSI by referring to the table in FIG. 3. Then, by referring to the TEID included in the U-Plane packet, the packet identifier 51 can identify the U-Plane packet to be associated with each C-Plane packet.

[0027] In the DPI servers 52-1 to 52-3, the data of the associated C-Plane packet and U-Plane packet are analyzed to generate information necessary for analyzing the communication status and the like. The generated information is supplied to, for example, a traffic monitor (not shown), and the communication status is analyzed.

[0028] (Network Configuration: 5G) Analysis of the communication status of each user like this needs to continue even when the core network becomes the 5th generation mobile communication system (5G). FIG. 4 is a diagram showing an example when a conventional packet analysis system is applied to a 5G core network. As shown in the figure, the 5G core network 40 includes network functional units such as an AUSF (Authentication Server Function), an AMF (Access and Mobility Management Function), an NSSF (Network Slice Selection Function), an SMF (Session Management Function), a UDM (Unified Data Management), a PCF (Policy Control Function), and a UPF (User Plane Function).

[0029] The functions of the MME in the LTE core network 30 are mainly assigned to the AMF in the 5G core network 40. The functions of the S-GW in the LTE core network 30 are mainly assigned to the SMF and the UPF in the 5G core network 40. Therefore, in the 5G core network 40, the U-Plane packets may be obtained from N3, which is a reference point related to the connection between the base station gNodeB and the UPF. On the other hand, in the 5G core network 40, the C-Plane packets may be obtained from, for example, N11, which is a reference point related to the connection between the AMF and the SMF to which the gNodeB is connected.

[0030] On the other hand, compared with the initial LTE release, after the 5G compatibility, the network function unit that executes the processing related to the C-Plane and the network function unit that executes the processing related to the U-Plane are clearly separated. Therefore, after the 5G compatibility, it is possible to separately arrange the network function unit that executes the processing related to the U-Plane from the network function unit that executes the processing related to the C-Plane.

[0031] For example, the UPF requires a higher processing capacity compared to the SMF. Therefore, when providing a low-latency communication service, the functions of the UPF can also be implemented in a distributed manner on multiple devices. In particular, when providing a low-latency communication service, the server on the DN that undertakes the processing related to such a service is arranged at a physically close distance to the user (or UE). Therefore, in order to improve the performance of the connection from the UE to the DN, it is preferable that the UPF be distributed and arranged near the base station.

[0032] Therefore, in an actual 5G core network, for example, a configuration in which a plurality of UPFs are arranged corresponding to a gNodeB may be adopted. In this case, for example, the UPFs will be arranged in a data center different from the data center where AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged. As an example, for example, all network function parts of the 5G core network 40 are arranged in the Tokyo data center, and the UPFs are arranged in the Sapporo data center, the Nagoya data center, and the Osaka data center.

[0033] In this case, the reference point N3 related to the connection between the gNodeB, which is a base station, and the UPF will exist within the Tokyo data center, within the Sapporo data center, within the Nagoya data center, and within the Osaka data center. Therefore, in order to associate the C-Plane packets and the U-Plane packets related to the same user, for example, it is necessary to transfer the U-Plane packets obtained within the Sapporo data center, within the Nagoya data center, and within the Osaka data center to the packet identifier 51 in the Tokyo data center at high speed.

[0034] When the packet identifier 51 and the reference point N3 are arranged within the same data center, for example, by laying a dedicated optical fiber cable, etc., the U-Plane packets obtained at the reference point N3 can be transferred to the packet identifier 51 at high speed. However, when the packet identifier 51 and the reference point N3 are arranged in different data centers, laying a dedicated optical fiber cable is unrealistic.

[0035] Also, for example, when generating a table as shown in FIG. 3 to associate the C-Plane packets and the U-Plane packets related to the same user, for example, each time a TEID is assigned, it is necessary to update the table so as to associate it with the IMSI. Therefore, the load becomes high due to the processing related to table update, and a high processing capacity is required for the packet identifier 51. Furthermore, since the size of the table that can be stored is also limited, the number of C-Plane packets and U-Plane packets that can be associated is also limited.

[0036] <First Embodiment> Next, a first embodiment of the present invention will be described. In the first embodiment, a session index is generated to associate C-Plane packets and U-Plane packets. The session index is generated based on information included in each of the C-Plane packet and the U-Plane packet, and is assigned to each of the C-Plane packet and the U-Plane packet. By combining the C-Plane packet and the U-Plane packet so that the session indexes match, it becomes possible to associate the C-Plane packet and the U-Plane packet related to the same UE. In this case, for example, a table as shown in FIG. 3 becomes unnecessary.

[0037] With reference to FIGS. 5 to 9, a method for generating a session index will be described. Note that the session index is identification information attached to each packet.

[0038] (U-Plane Packet) FIG. 5 is a diagram showing components of a U-Plane packet. In this example, the U-Plane packet 300 includes an Ethernet header 301, an IP (outer) header 302, a UDP (outer) header 303, a tunneling protocol (GTPv1) header 304, an IP (inner) header 305, a UDP (inner) header 306, and a payload 307.

[0039] In the figure, “(outer)” and “(inner)” are used to distinguish the headers used in the tunneling protocol. “(inner)” means the header of the packet encapsulated by the tunneling protocol, and “(outer)” means the header of the packet storing the encapsulated packet. For example, the header of “(outer)” is used for communication inside the core network of the encapsulated packet, and the header of “(inner)” is used for communication between the UE and the DN of the packet of the U-Plane.

[0040] In the case of the U-Plane packet, for example, GTP (General Packet Radio Service (GPRS) Tunnelling Protocol) v1 is used as the tunneling protocol.

[0041] (C-Plane Packet) Figure 6 shows the components of the C-Plane packet corresponding to the LTE core network and obtainable at the reference point S11. In this example, the C-Plane packet 330 includes an Ethernet header 331, an IP header 332, a UDP header 333, a tunneling protocol (GTPv2) header 334, and a payload 337. The payload 377 is also referred to as a GTP-C message.

[0042] In the case of the C-Plane packet, for example, GTPv2 is used as the tunneling protocol.

[0043] The session index is generated based on the source IP (source (src) IP) address, the destination IP (destination (dst) IP) address, and the TEID included in each of the U-Plane packet and the C-Plane packet.

[0044] FIG. 7 is a diagram showing components of a C-Plane packet corresponding to a 5G core network and obtainable at reference point N2. In the communication between the gNodeB and the AMF, the NGAP (Next Generation Application Protocol) is used. Details of the NGAP are specified in, for example, 3GPP standard TS.38.412 in detail.

[0045] In this example, the C-Plane packet 350 includes an Ethernet header 351, an IP header 352, an SCTP header 353, an NGAP header 354, and a payload 355. Note that the NGAP header 354 and the payload 355 are also referred to as an NGAP Message.

[0046] FIG. 8 is a diagram showing components of a C-Plane packet corresponding to a 5G core network and obtainable at reference point N12. In the communication between the AMF and the AUSF, HTTP (Hypertext Transfer Protocol) / 2 is used. Details of HTTP / 2 are specified in, for example, 3GPP standard TS.29.500 in detail.

[0047] In this example, the C-Plane packet 370 includes an Ethernet header 371, an IP header 372, a TCP header 373, an HTTP / 2 header 374, and a payload 375. Note that the payload 375 is also referred to as an Application.

[0048] (Information required for generating a session index) FIG. 9 is a diagram for explaining an example of information necessary for generating a session index. In the figure, “(uplink)” and “(downlink)” indicate the direction in which a packet is transmitted. “(uplink)” indicates an uplink direction, that is, a packet from a UE or a base station to a core network, and “(downlink)” indicates a downlink direction, that is, a packet from a core network to a UE or a base station.

[0049] As shown in the figure, the information necessary for generating a session index is the source IP address, the destination IP address, and the TEID in both the U-Plane and the C-Plane cases. However, depending on the direction in which the packet is transmitted, the nodes that assign the source, destination, and TEID are different.

[0050] (In the case of the U-Plane) As shown in the figure, in the case of a U-Plane (uplink) packet, the source IP address means the IP address of the eNodeB or gNodeB. The destination IP address means the IP address of the S-GW, UPF, or SMF. The TEID means the TEID assigned by the S-GW, UPF, or SMF.

[0051] Also, in the case of a U-Plane (downlink) packet, the source IP address means the IP address of the S-GW or UPF. The destination IP address means the IP address of the eNodeB or gNodeB. The TEID means the TEID assigned by the eNodeB or gNodeB.

[0052] In the case of a U-Plane packet, the source IP address and the destination IP address are stored in the IP (outer) header 302 of FIG. 5, and the TEID is stored in the GTPv1 header 304 of FIG. 5.

[0053] (In the case of the C-Plane) In the case of C-Plane (uplink) packets, similar to the case of U-Plane (uplink) packets, the source IP address means the IP address of the eNodeB or gNodeB. The destination IP address means the IP address of the S-GW, UPF, or SMF. The TEID means the TEID assigned by the S-GW, UPF, or SMF. That is, the payload of the C-Plane (uplink) packet stores the source IP address and destination IP address of the U-Plane (uplink) packet, as well as the TEID, and a session index is generated using these.

[0054] Also, in the case of C-Plane (downlink) packets, similar to the case of U-Plane (downlink) packets, the source IP address means the IP address of the S-GW or UPF. The destination IP address means the IP address of the eNodeB or gNodeB. The TEID means the TEID assigned by the eNodeB or gNodeB. That is, the payload of the C-Plane (downlink) packet stores the source IP address and destination IP address of the U-Plane (downlink) packet, as well as the TEID, and a session index is generated using these.

[0055] (Packets obtainable at S11) In the case of C-Plane packets obtainable at the reference point S11, the source IP address, destination IP address, and TEID are stored in the payload 337 of FIG. 6. That is, in the case of C-Plane packets obtainable at the reference point S11, the source IP address and destination IP address of the U-Plane packet, as well as the TEID, are stored in the information transmitted by the GTPv2 protocol.

[0056] The source IP address, destination IP address, and TEID are stored in the IE (Information Element) of "Fully Qualified Tunnel Endpoint Identifier" with an IE Type Value of 87 within the payload 337. Note that the storage locations of each piece of information in the IE with an IE Type Value of 87 are described in detail in 3GPP standard TS 129 274 8.22 Fully Qualified TEID (F-TEID).

[0057] Figure 10 is a diagram for explaining the encoding format of the F-TEID defined in standard TS 129 274 8.22. The source IP address and destination IP address required for generating the session index are stored in "IPv4 address" or "IPv6 address" in Figure 10. Also, the TEID required for generating the session index is stored in "TEID / GRE Key" in Figure 10.

[0058] (Packets obtainable at N2) In the case of C-Plane packets obtainable at reference point N2, the source IP address, destination IP address, and TEID are stored in payload 355 in Figure 7. That is, in the case of C-Plane packets obtainable at reference point N2, the source IP address, destination IP address, and TEID are stored in the information transmitted by the NGAP protocol.

[0059] (Packets obtainable at N12) In the case of C-Plane packets obtainable at reference point N12, the source IP address, destination IP address, and TEID are stored in payload 375 in Figure 8. That is, in the case of C-Plane packets obtainable at reference point N12, the source IP address, destination IP address, and TEID are stored in the information transmitted by the HTTP / 2 protocol.

[0060] Also, in 5G, various security measures are adopted from the perspective of countermeasures against security threats. Specifically, for example, the SUPI (Subscription Permanent Identifier), which is the subscriber ID in 5G, is transmitted from the UE to the network as the SUCI (Subscription Concealed Identifier), which is information obtained by encrypting the SUPI with a predetermined public key. Thus, in 5G, the subscriber ID is anonymized. Therefore, even if the C-Plane packets are obtained from the reference point N2, the relationship with the user or UE that transmitted the packets cannot be grasped. Then, the SUCI is obtained from the packets related to the authentication process transmitted and received between the AMF and the AUSF, which are the C-Plane packets that can be obtained at the reference point N12, and the SUPI and KSEAF are respectively obtained from the response packets for the request. Thereby, for example, in a monitoring device or the like, the SUPI can be derived from the SUCI included in the C-Plane packets.

[0061] Note that the SUPI, SUCI, and KSEAF are respectively stored in the payload part of the packets transmitted and received by the HTTP / 2 protocol. For operators who design the network so as not to perform the above-described encryption, since there is no need to derive the SUPI from the SUCI, for such operators, it is not essential to obtain the C-Plane packets at the reference point N12.

[0062] (Packet Association by Session Index) For communications related to the same user, the source IP address and destination IP address stored in the IE with an IE Type Value of 87 within the payload 337 of the C-Plane (uplink) packets that can be obtained at reference point S11 are identical to the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (uplink) packets, respectively. And the TEID stored in the IE with an IE Type Value of 87 within the payload 337 of the C-Plane (uplink) packets is identical to the TEID stored in the tunneling protocol header 304 of the U-Plane (uplink) packets.

[0063] Similarly, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 355 of the C-Plane (uplink) packets that can be obtained at reference point N2 are identical to the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (uplink) packets, and the TEID stored in the tunneling protocol header 304, respectively.

[0064] Furthermore, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 375 of the C-Plane (uplink) packets that can be obtained at reference point N12 are identical to the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (uplink) packets, and the TEID stored in the tunneling protocol header 304, respectively.

[0065] Also, for communications related to the same user, the source IP address and destination IP address stored in the IE with an IE Type Value of 87 in the payload 337 of the C-Plane (downlink) packets that can be obtained at reference point S11 are the same as the source IP address and destination IP address stored in the IP (outer) header 302 of the U-Plane (downlink) packets, respectively. And the TEID stored in the IE with an IE Type Value of 87 in the payload 337 of the C-Plane (downlink) packets is the same as the TEID stored in the tunneling protocol header 304 of the U-Plane (downlink) packets.

[0066] Similarly, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 355 of the C-Plane (downlink) packets that can be obtained at reference point N2 are the same as the source IP address, destination IP address stored in the IP (outer) header 302 of the U-Plane (downlink) packets, and the TEID stored in the tunneling protocol header 304, respectively.

[0067] Furthermore, for communications related to the same user, the source IP address, destination IP address, and TEID stored in the payload 375 of the C-Plane (downlink) packets that can be obtained at reference point N12 are the same as the source IP address, destination IP address stored in the IP (outer) header 302 of the U-Plane (downlink) packets, and the TEID stored in the tunneling protocol header 304, respectively.

[0068] Therefore, for example, by extracting the source IP address, destination IP address, and TEID from each packet and using their hash values as the session index of the packet, packets related to the same user can be identified. That is, by identifying C-Plane packets having the same session index as the session index of U-Plane packets, the C-Plane packets and U-Plane packets related to the same user can be associated with each other.

[0069] By analyzing the information stored in the payload 307 of U-Plane packets, the data transmitted and received between the UE and the DN can be identified. Then, by analyzing the information stored in the payloads 337, 355, and 375 of the C-Plane packets associated with the U-Plane packets, the UE can be identified or the behavior of the UE (e.g., handover, etc.) can be identified. Thus, if the communication content of each user can be identified, it becomes possible to perform a detailed analysis of the communication situation.

[0070] Here, an example has been described in which the hash values of the source IP address, destination IP address, and TEID stored in each packet are calculated and used as the session index of the packet. However, the session index may be generated by a different operation. That is, a session index may be generated by performing a predetermined operation on the source IP address, destination IP address, and TEID stored in each packet. Specifically, for example, the value obtained by adding up the source IP address, destination IP address, and the value of the TEID may be used as the session index.

[0071] (Configuration example of packet analysis system) FIG. 11 is a block diagram showing a configuration example of the packet analysis system 200 according to the present embodiment. The packet analysis system 200 shown in the figure is a system that acquires packets in the core network and analyzes the communication status. As shown in the figure, the packet analysis system 200 includes an analysis device 201A and an analysis device 201B.

[0072] (Analysis device) The analysis device 201A and the analysis device 201B may be arranged in different data centers, for example. Also, the connection between the analysis device 201A and the analysis device 201B may be made using a dedicated line provided by a telecommunications carrier, for example.

[0073] The analysis device 201A is a device that mainly executes processing related to C-Plane packets. The analysis device 201A includes an acquisition unit 221A, a session identification unit 222A, and a linking unit 223A.

[0074] The analysis device 201B is a device that mainly executes processing related to U-Plane packets. The analysis device 201B includes an acquisition unit 221B and a session identification unit 222B.

[0075] The acquisition unit 221A and the session identification unit 222A may be functional blocks having the same configuration as the acquisition unit 221B and the session identification unit 222B. For example, when the acquisition unit of a certain analysis device is connected to a reference point for acquiring C-plane packets, it functions as the acquisition unit 221A for acquiring C-Plane packets, and the session identification unit of that analysis device may function as the session identification unit 222A. Also, when a certain analysis device is connected to a reference point for acquiring U-plane packets, it functions as the acquisition unit 221B for acquiring U-Plane packets, and the session identification unit of that analysis device may function as the session identification unit 222B.

[0076] Hereinafter, unless otherwise distinguished, the acquisition unit 221A and the acquisition unit 221B are collectively referred to as the acquisition unit 221, the session identification unit 222A and the session identification unit 222B are collectively referred to as the session identification unit 222, and the linking unit 223A is referred to as the linking unit 223. Similarly, unless otherwise distinguished, the analysis device 201A and the analysis device 201B are collectively referred to as the analysis device 201.

[0077] (Acquisition Unit) The acquisition unit 221 acquires C-Plane packets and U-Plane packets at a position corresponding to a predetermined reference point in the core network. The packets acquired by the acquisition unit 221 are supplied to the session identification unit 222.

[0078] (Session Identification Unit) The session identification unit 222 extracts the source address, destination address, and TEID from the C-Plane packets and U-Plane packets acquired by the acquisition unit 221, and extracts the source address, destination address, and TEID of the U-Plane packets from the information stored in the payload of the C-Plane packets acquired by the acquisition unit 221. Then, the session identification unit 222 generates identification information for identifying packets related to the communication by each of a plurality of users based on the extracted source address, destination address, and TEID. Here, the identification information generated by the session identification unit 222 may be the session index described above.

[0079] The session index may be generated by performing a predetermined operation on the source IP address and destination IP address stored in each packet, as well as the TEID. As an example, a session index including the hash values of the source IP address, destination IP address, and TEID may be generated.

[0080] That is, the session identification unit 222A of the analysis device 201A extracts the source address, destination address, and TEID from the payload 227 in FIG. 6 in the C-Plane packet acquired by the acquisition unit 221A and generates a session index. Also, the session identification unit 222B of the analysis device 201B extracts the source IP address and destination IP address from the IP (outer) header 302 in FIG. 5 and extracts the TEID from the tunneling protocol header 304 in the U-Plane packet acquired by the acquisition unit 221B and generates a session index.

[0081] The session identification unit 222, for example, attaches the generated identification information (session index) to the C-Plane packets and U-Plane packets acquired by the acquisition unit 221 and supplies them to the association unit 223.

[0082] Here, depending on the operating conditions of the core network and the packet analysis system 200, there may be U-Plane packets that cannot be associated with C-Plane packets. Specifically, for example, during maintenance of the analysis device 201A, there may be a period when C-Plane packets cannot be acquired. In such a case, since the core network is operating normally and the UE can establish a connection with the DN, the acquisition unit 221B of the analysis device 201B acquires U-Plane packets as usual. In such a case, since there are no C-Plane packets on the packet analysis system 200, U-Plane packets that cannot be associated with C-Plane packets are generated.

[0083] For example, when there are no C-Plane packets (that is, a session index cannot be generated), the analysis device 201B may prevent the U-Plane packets acquired by the acquisition unit 221B from being transmitted to the analysis device 201A.

[0084] In the example of Fig. 11, the information output from the session identification unit 222B of the analysis device 201B is configured to be supplied to the association unit 223A of the analysis device 201A together with the information output from the session identification unit 222A of the analysis device 201A.

[0085] (Association unit) The association unit 223 associates the C-Plane packets and the U-Plane packets based on the session index. That is, the association unit 223 associates the U-Plane with the same session index as the session index assigned to the C-Plane packet. Thereby, it becomes possible to identify the data related to the communication of the same UE and obtain information necessary for analyzing the communication status.

[0086] As will be described later, the recording device 202 records by associating order information with each set of the C-Plane packet and the U-Plane packet associated by the association unit 223. The order information may be, for example, the transmission time or reception time of the packet, or the sequence number of the packet. In short, information for specifying the order in which the packets are transmitted and received may be associated with each set of the C-Plane packet and the U-Plane packet.

[0087] The monitor device 203 refers to each set of the C-Plane packet and the U-Plane packet associated with the order information and performs a detailed analysis of the communication status. Thereby, for example, calculation of index values related to KPIs, index values related to the degree of improvement in user satisfaction, etc. is performed.

[0088] Note that the recording device 202 may be configured to be integrated with the analysis device 201A, for example, or may be configured to be integrated with the monitor device 203.

[0089] Note that in the above example, it was described that the session identification unit 222 generates a session index based on the extracted source address, destination address, and TEID. However, the session identification unit 222 may not generate a session index. In this case, the session identification unit 222 may supply the C-Plane packets and U-Plane packets acquired by the acquisition unit 221 to the association unit 223 together with the source address, destination address, and TEID. Then, the association unit 223 may associate the C-Plane packets and U-Plane packets based on the source address, destination address, and TEID.

[0090] 。 Here, when associating C-Plane packets and U-Plane packets, there may be a case where there is an overlap in the source address, destination address, and TEID among packets acquired from different UEs. More specifically, for example, when performing association at once for packets collected over a certain period, there may be an overlap in the source address, destination address, and TEID among packets acquired from different UEs. According to the 3GPP standard regulations, in one network function (NE), the processing is such that the TEID does not overlap. However, when a user or UE that was using one TEID ends the communication, the TEID may be reused by another user or UE. Therefore, when performing association at once for packets collected over a certain period, in addition to the source address, destination address, and TEID, by referring to the order information, it is possible to determine whether the packets are from the same user or different users.

[0091] (Arrangement of the analysis device) In the example of FIG. 11, one analysis device 201B is installed for one analysis device 201A, but actually, a plurality of analysis devices 201B may be installed for one analysis device 201A. That is, a plurality of combinations of an acquisition unit 221B and a session identification unit 222B related to U-Plane packets may be provided for the combination of the acquisition unit 221A and the session identification unit 222A related to C-Plane packets.

[0092] For example, in a 5G core network, when providing a low-latency communication service, the functions of the UPF can also be implemented in a distributed manner across multiple devices. In particular, when providing a low-latency communication service, in order to improve the performance of the connection from the UE to the DN, the UPF is preferably distributed and arranged near the base station. Also, depending on the network operation mode and service provision mode, the UPF may be arranged near the server on the DN.

[0093] Therefore, in an actual 5G core network, for example, a configuration in which a plurality of UPFs are arranged corresponding to a gNodeB or a plurality of servers on the DN can be adopted. For example, the UPF can be arranged in a data center different from the data center where the AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged.

[0094] In this case, the analysis device 201A may be arranged in the data center where the AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged, and the analysis device 201B may be arranged in the data center where the UPF is arranged.

[0095] Then, as described above, when a plurality of UPFs are arranged in correspondence with a gNodeB or a server on the DN, a plurality of data centers may be prepared in the vicinity of each of the plurality of gNodeBs (base stations) or the server on the DN, and the analysis device 201B may be arranged together with the UPFs in these plurality of data centers. That is, the acquisition unit 221B and the session identification unit 222B related to the U-Plane packets may be arranged close to the base station.

[0096] On the other hand, for example, when the packet analysis system 200 according to the present embodiment is used in an LTE core network, when the MME and the S-GW are arranged in the same data center, the analysis device 201A and the analysis device 201B may be arranged in the same data center. Similarly, even when the packet analysis system 200 according to the present embodiment is used in a 5G core network, when the UPF is also arranged in the data center where the AUSF, AMF, NSSF, SMF, UDM, PCF, etc. are arranged, the analysis device 201A and the analysis device 201B may be arranged in the same data center.

[0097] When the analysis device 201A and the analysis device 201B are arranged in the same data center, the connection between the analysis device 201A and the analysis device 201B may be made, for example, by an optical fiber cable (it is not necessary to use a dedicated line provided by a telecommunications carrier).

[0098] (Packet acquisition location: LTE) FIG. 12 is a diagram for explaining an example of the acquisition location of C-Plane packets corresponding to the LTE core network and the acquisition location of U-Plane packets in the present embodiment. In the figure, each network function unit and base station of the core network are displayed by rectangles, and the reference points related to the packet acquisition locations are displayed as characters and numerical values surrounded by circles.

[0099] In the example of FIG. 12, at reference point S11 between the MME and the S-GW, the analysis device 201A acquires C-Plane packets. Also, at reference point S1-U between the eNodeB and the S-GW, the analysis device 201B acquires U-Plane packets.

[0100] That is, when the core network is the core network in the LTE communication network, the acquisition unit 221 acquires C-Plane packets from reference point S11 and acquires U-Plane packets from reference point S1-U.

[0101] Note that in FIG. 12, the analysis device 201A and the analysis device 201B may be aggregated and arranged in, for example, the same data center, or may be distributed and arranged in separate data centers or the like.

[0102] (Packet Classification by Message Type) Note that only those packets among the packets acquired at reference point S11 that satisfy a predetermined condition may be supplied to the session identification unit 222. For example, by referring to the message type of the C-Plane packets acquirable at reference point S11, only packets of a predetermined message type may be supplied to the session identification unit 222. Note that the message type is information stored in the tunneling protocol header 334.

[0103] FIG. 13 is a diagram showing a list of message types of packets to be supplied to the session identification unit 222. In the figure, the message type number and the message type corresponding to the message type number are shown. The message type is information indicating the behavior of the UE (for example, handover, etc.), and by referring to the message type, it is possible to classify packets necessary for analyzing the communication status in the subsequent monitoring device 203 and unnecessary packets.

[0104] As shown in FIG. 13, packets in which the message type number stored in the tunneling protocol header 334 is any one of 32, 33, 34, ··· 171, 176, 177 are classified as packets necessary for analyzing the communication status in the subsequent monitor device 203. On the other hand, packets in which the message type number stored in the tunneling protocol header 334 is other than the message type numbers shown in FIG. 13 are classified as packets unnecessary for analyzing the communication status in the subsequent monitor device 203.

[0105] In this way, the acquisition unit 221 may classify the packets of the C-Plane acquired from the reference point S11 into the first type of packets (packets necessary for analyzing the communication status) and the second type of packets (unnecessary packets) with reference to the message type of the packets, and supply only the packets classified into the first type to the session identification unit 222.

[0106] (Packet Classification by IE) For packets of any message type shown in FIG. 13, necessary packets and unnecessary packets may be further classified by referring to the IE in the payload 337. FIG. 14 is a diagram showing a list of IEs referred to at this time. In the figure, the IE Type Value and the IE (Information Element) corresponding to the IE Type Value are shown.

[0107] For example, a list of values (or ranges) to be compared with the values stored in the respective IEs corresponding to IE Type Values 1, 2, 3, ··· 87, 93, 97 is created in advance. For example, a value to be compared with the value stored in the IE of IE Type Value 1 is set in advance. When the value stored in the IE of IE Type Value 1 matches, subsequent processing is executed as a necessary packet, and when it does not match, it is excluded from subsequent processing as an unnecessary packet. Note that each packet may be assigned a flag indicating necessary or unnecessary, or only necessary packets may be stored, etc., and unnecessary packets may be discarded.

[0108] In addition, a range of values to be compared with the value stored in the IE of IE Type Value2 is preset. When the value stored in the IE of IE Type Value1 is within this range, subsequent processing is executed as necessary packets, and when it is outside the range, it is excluded from subsequent processing as unnecessary packets.

[0109] Similar processing is also executed for IE Type Value3, ··· 87, 93, 97, and it is determined whether the packet is a necessary packet or an unnecessary packet for analyzing the communication status in the subsequent monitor device 203.

[0110] In this way, the acquisition unit 221 may supply only those packets that satisfy a predetermined condition among the packets acquired at the reference point S11 to the session identification unit 222. That is, as described above, the acquisition unit 221 refers to the value of a predetermined IE (Information Element) stored in the packet classified into the first type by referring to the message type, and further classifies it into the third type of packet and the fourth type of packet, and may supply only the packets classified into the third type to the session identification unit 222.

[0111] Alternatively, the acquisition unit 221 may extract the values stored in the respective IEs corresponding to IE Type Value1, 2, 3, ··· 87, 93, 97 from the packets of any message type shown in FIG. 13 and supply them to the session identification unit 222 together with the packets. That is, each of the IEs shown in FIG. 14 may be supplied to the subsequent session identification unit 222 and monitor device 203 as information necessary for analyzing the communication status. In this case, there is no need to further classify the packets classified as necessary packets for analyzing the communication status by referring to the message type.

[0112] (Packet acquisition location: 5G) FIG. 15 is a diagram for explaining an example of the acquisition position of C-Plane packets and the acquisition position of U-Plane packets corresponding to a 5G core network in the present embodiment. In the figure, each network function part and base station of the core network are displayed by rectangles, and the reference points related to the packet acquisition positions are displayed as characters and numerical values surrounded by circles.

[0113] In the example of FIG. 15, at reference point N2 between the gNodeB and the AMF, and at reference point N12 between the AMF and the AUSF, the C-Plane packets are acquired by the analysis device 201A. Also, at reference point N3 between the gNodeB and the UPF, the U-Plane packets are acquired by the analysis device 201B.

[0114] In the case of a 5G core network, it is also possible to acquire C-Plane packets at reference point N11 between the AMF and the SMF. However, in the case of a 5G core network, a header compression method called HPACK is adopted for the communication between the AMF and the SMF.

[0115] In the case of communication adopting HPACK, for example, even when retransmission occurs due to packet loss or the like, the index number changes. Nodes other than the node that requested retransmission cannot determine which packet is the retransmitted packet. Therefore, when trying to restore the header compressed by HPACK according to the index number, there is a possibility that the header cannot be restored correctly. That is, since the analysis device 201A is not the node that requested retransmission, it may not be able to correctly restore the header compressed by HPACK. For this reason, in the present embodiment, the acquisition unit 221 does not acquire C-Plane packets at reference point N11, but acquires C-Plane packets at reference point N2.

[0116] In addition, in a 5G core network where HPACK is not adopted, C-Plane packets may be acquired at reference point N11. In this case, it is not necessary to acquire C-Plane packets at reference point N2.

[0117] Also, in the case of a 5G core network, the IMSI in the C-Plane packet is encrypted, and it is necessary to decrypt the encrypted IMSI for analyzing the communication status in the subsequent monitoring device 203. Therefore, in this embodiment, the acquisition unit 221 acquires C-Plane packets at reference point N12 between the AMF and the AUSF. At reference point N12, packets corresponding to scheme 2, scheme 7, scheme 12, and scheme 14 among the schemes defined in / nausf-auth / v1 / ue-authentications are acquired by the acquisition unit 221.

[0118] Thus, when the core network is the core network in a 5G communication network, the acquisition unit 221 acquires C-Plane packets from reference point N2 and reference point N12, and acquires U-Plane packets from reference point N3.

[0119] Note that in FIG. 15, the analysis devices 201A and 201B may be aggregated and arranged in, for example, the same data center, or may be distributed and arranged in separate data centers.

[0120] (Classification of Packets by Procedure Code) Among the packets acquired at reference point N2, only those that satisfy a predetermined condition may be supplied to the session identification unit 222. For example, by referring to the Procedure Code of the C-Plane packets that can be acquired at N2, only packets with a predetermined Procedure Code may be acquired. The Procedure Code is the information stored in the payload 355 of FIG. 7.

[0121] FIG. 16 is a diagram showing a list of Procedure Codes of packets to be supplied to the session identification unit 222. In the figure, the Procedure Code and the Code Name corresponding to the Procedure Code are shown. The Procedure Code is information indicating the behavior of the UE, similar to the message type in FIG. 13. By referring to the Procedure Code, it is possible to classify packets necessary for analyzing the communication status in the subsequent monitor device 203 and unnecessary packets.

[0122] As shown in FIG. 16, each of the packets whose Procedure Code is any one of 4, 11, 12, ··· 41, 42, 46 is classified as a packet necessary for analyzing the communication status in the subsequent monitor device 203. On the other hand, packets whose Procedure Code is other than the Procedure Code shown in FIG. 16 are classified as packets unnecessary for analyzing the communication status in the subsequent monitor device 203.

[0123] In this way, the acquisition unit 221 may refer to the Procedure Code of the C-Plane packets acquired from the reference point N2 and classify them into the first type of packets (packets necessary for analyzing the communication status) and the second type of packets (unnecessary packets), and supply only the packets classified into the first type to the session identification unit 222.

[0124] (Packet acquisition location: 5G interworking) FIG. 17 is a diagram for explaining another example of the acquisition location of C-Plane packets corresponding to the 5G core network and the acquisition location of U-Plane packets in the present embodiment. In the figure, each network function unit and base station of the core network are displayed by rectangles, and the reference points related to the packet acquisition locations are displayed as characters and numerical values surrounded by circles.

[0125] In the case of Fig. 17, different from the example in Fig. 15, the acquisition position related to a 5G core network having an interworking function between 5GC and EPC (Evolved Packet Core) will be described. Such a configuration of the 5G core network is shown in 3GPP standard TS 123 501 4.3, "Interworking with EPC".

[0126] In the example of Fig. 17, in addition to the configuration of Fig. 15, an MME and an eNodeB are included. Also, in the case of a 5G core network having an interworking function between 5GC and EPC, the functions of S-GW and P-GW are implemented in a server responsible for the functions of SMF or UPF. In the example of Fig. 17, it is assumed that the function of S-GW is implemented in a server responsible for the function of UPF.

[0127] In the example of Fig. 17, at the reference point N2 between gNodeB and AMF, at the reference point N12 between AMF and AUSF, and further at the reference point N26 between MME and AMF, C-Plane packets are acquired by the analysis device 201A. Further, at the reference point S11 between MME and UPF, C-Plane packets are acquired by the analysis device 201A. Note that the UPF described in Fig. 17 is a server responsible for the function of UPF and implements the function of S-GW. Therefore, it can be said that the reference point S11 related to the acquisition of C-Plane packets is actually the reference point between MME and S-GW.

[0128] Also, in the example of Fig. 17, at the reference point N3 between gNodeB and UPF, U-Plane packets are acquired by the analysis device 201B. Further, at the reference point S1-U between eNodeB and UPF (actually S-GW), U-Plane packets are acquired by the analysis device 201B.

[0129] Regarding the reference point S11 and the reference point S1-U, it is the same as the case described above with reference to Fig. 12. Regarding the reference point N2, the reference point N12, and the reference point N3, it is the same as the case described above with reference to Fig. 15.

[0130] In mobile communications such as LTE and 5G, information is encrypted during communication. For example, consider a case where a UE is connected to a gNodeB, then handed over and connected to an eNodeB, and further handed over and connected to the gNodeB again. In this case, since the encryption key changes when connected to the eNodeB, when reconnecting to the gNodeB, the encryption key used immediately before must be obtained from the MME. Therefore, at the reference point N26, it is necessary for the analysis device 201A to acquire C-Plane packets.

[0131] In addition, in FIG. 17, the analysis device 201A and the analysis device 201B may be aggregated and arranged in, for example, the same data center, or may be distributed and arranged in separate data centers.

[0132] (Packet Analysis Processing) Next, an example of packet analysis processing by the packet analysis system 200 in FIG. 11 will be described. FIG. 18 is a flowchart for explaining an example of the flow of packet analysis processing.

[0133] In step S101, the acquisition unit 221A of the analysis device 201A acquires C-Plane packets. At this time, when the core network is the core network in the LTE communication network, as described above with reference to FIG. 12, C-Plane packets are acquired at the reference point S11 between the MME and the S-GW.

[0134] Also, when the core network is the core network in the 5G communication network, as described above with reference to FIG. 15, C-Plane packets are acquired from the reference points N2 and N12 between the gNodeB and the AMF. Note that at the reference point N12, packets corresponding to scheme 2, scheme 7, scheme 12, and scheme 14 among the schemes defined in / nausf-auth / v1 / ue-authentications are acquired by the acquisition unit 221.

[0135] Furthermore, when the core network is a core network in a 5G communication network and has an interworking function between 5GC and EPC, as described above with reference to FIG. 17, at reference point N2, reference point N12, and reference point N26 between MME and AMF, C-Plane packets are acquired. Furthermore, at reference point S11 between MME and UPF (actually S-GW), C-Plane packets are acquired.

[0136] The packets acquired by the acquisition unit 221 in step S101 are supplied to the session identification unit 222.

[0137] As described above with reference to FIG. 13, only the packets that satisfy a predetermined condition among the packets acquired at reference point S11 may be supplied to the session identification unit 222. For example, by referring to the Message Type of the C-Plane packets that can be acquired at S11, only the packets of a predetermined message type may be supplied to the session identification unit 222. Also, as described above with reference to FIG. 14, further, by referring to the IE in the payload 337, the packets are further classified so that only the packets that satisfy a predetermined condition among the packets acquired at reference point S11 are supplied to the session identification unit 222.

[0138] Also, as described above with reference to FIG. 16, only the packets that satisfy a predetermined condition among the packets acquired at reference point N2 may be supplied to the session identification unit 222. For example, by referring to the Procedure Code of the C-Plane packets that can be acquired at N2, only the packets of a predetermined Procedure Code may be supplied to the session identification unit 222.

[0139] In step S102, the acquisition unit 221B of the analysis device 201B acquires U-Plane packets. At this time, when the core network is the core network in the LTE communication network, as described above with reference to FIG. 12, U-Plane packets are acquired at the reference point S1-U between the eNodeB and the S-GW.

[0140] Also, when the core network is the core network in the 5G communication network, as described above with reference to FIG. 15, U-Plane packets are acquired by the acquisition unit 221B of the analysis device 201B at the reference point N3 between the gNodeB and the UPF.

[0141] Furthermore, when the core network is the core network in the 5G communication network and has an interworking function between the 5GC and the EPC, as described above with reference to FIG. 17, U-Plane packets are acquired by the analysis device 201B at the reference points N3 and S1-U.

[0142] In step S103, the session identification unit 222 extracts the source address, destination address, and TEID from the C-Plane packets and U-Plane packets acquired by the acquisition unit 221.

[0143] That is, the session identification unit 222A of the analysis device 201A extracts the source address, destination address, and TEID from the C-Plane packets acquired by the acquisition unit 221A.

[0144] At this time, when the acquisition unit 221A acquires a C-Plane packet from the reference point S11, the source IP address, destination IP address, and TEID are extracted from the IE with an IE Type Value of 87 in the payload 337 of FIG. 6. Also, when the acquisition unit 221A acquires a C-Plane packet from the reference point N2, the source IP address, destination IP address, and TEID stored in the payload 355 of FIG. 7 are extracted. Further, when the acquisition unit 221A acquires a C-Plane packet from the reference point N12, the source IP address, destination IP address, and TEID stored in the payload 375 of FIG. 8 are extracted.

[0145] Also, the session identification unit 222B of the analysis device 201B extracts the source address, destination address, and TEID from the U-Plane packet acquired by the acquisition unit 221B. At this time, as described above, the source IP address and destination IP address are extracted from the IP (outer) header 302 of FIG. 5, and the TEID is extracted from the tunneling protocol header 304.

[0146] In step S104, the session identification unit 222 generates a session index, which is identification information for identifying packets related to communication by each of a plurality of users, based on the source address, destination address, and TEID extracted in the process of step S103. That is, the session identification unit 222A of the analysis device 201A generates a session index for the C-Plane packet acquired by the acquisition unit 221A, and the session identification unit 222B of the analysis device 201B generates a session index for the U-Plane packet acquired by the acquisition unit 221B.

[0147] The session index may be generated by performing a predetermined operation on the source IP address, destination IP address, and TEID stored in each packet. As an example, a session index including the hash values of the source IP address, destination IP address, and TEID is generated.

[0148] The session identification unit 222 supplies the C-Plane packets and U-Plane packets acquired by the acquisition unit 221 to the association unit 223 together with the generated session index.

[0149] In step S105, the association unit 223 associates the C-Plane packets and the U-Plane packets based on the session index.

[0150] At this time, for example, the session index of the C-Plane packet supplied from the session identification unit 222A of the analysis device 201A is compared with the session index of the U-Plane packet supplied from the session identification unit 222B of the analysis device 201B. Then, the U-Plane packet having the same session index as the session index of the C-Plane packet is associated with the C-Plane packet. Thereby, it becomes possible to specify data related to the communication of the same user and obtain information necessary for analyzing the communication situation.

[0151] In step S106, the recording device 202 records by associating order information with each set of the C-Plane packet and the U-Plane packet associated by the process of step S105. The order information may be, for example, the transmission time or reception time of the packet, or the sequence number of the packet.

[0152] In step S107, the monitor device 203 refers to each set of the C-Plane packet and the U-Plane packet with which the order information is associated by the process of step S106 and performs a detailed analysis of the communication situation. Thereby, for example, calculation of index values related to KPIs is performed.

[0153] In this way, the packet analysis process is executed.

[0154] (Effect of the Embodiment) According to this embodiment, for example, even when a configuration is adopted in which a plurality of UPFs are arranged corresponding to a gNodeB which is a base station, information etc. necessary for analyzing the communication situation can be obtained efficiently.

[0155] In this embodiment, as described above, the C-Plane packet and the U-Plane packet are associated by a session index. Therefore, for example, even if N3, which is a reference point related to the connection between the gNodeB and the UPF, is distributed and present in different data centers, laying a dedicated optical fiber cable etc. for transferring the U-Plane packet obtained at N3 at high speed is not necessary.

[0156] Also, in this embodiment, for example, a table for associating the TEID and the IMSI etc. is not necessary either, so it is also possible to reduce the processing load of the device. Furthermore, since the number of C-Plane packets and U-Plane packets that can be associated is not limited by the size of the table, it is possible to analyze the communication situation using a large amount of data.

[0157] In this way, according to this embodiment, even if the configuration of the core network becomes complex, it is possible to obtain a large amount of data necessary for grasping the communication situation in a timely manner.

[0158] <Second Embodiment> In the example of FIG. 11, the configuration in which the analysis device 201A has the acquisition unit 221A, the session identification unit 222A, and the association unit 223A, and the analysis device 201A has the acquisition unit 221B and the session identification unit 222B was described. However, the analysis device 201A and the analysis device 201B may be devices having the same configuration.

[0159] For example, the analysis device 201B may be provided with an association unit 223B which is a functional block having the same configuration as the association unit 223A. That is, a plurality of analysis devices 201 having the same configuration may be prepared, and one of them may be used as the analysis device 201A and the others may be used as the analysis device 201B.

[0160] In this case, the linking unit 223B of the analysis device 201B may be left unoperated, and the linking unit 223A of the analysis device 201A may link the C-Plane packets and the U-Plane packets. <Third Embodiment>

[0161] In the above-described embodiment, it was explained that the linking of the C-Plane packets and the U-Plane packets is performed in the linking unit 223A of the analysis device 201A. By performing the linking in the analysis device 201A that is centrally arranged rather than the analysis device 201B that can be distributedly arranged, the maintainability of the entire packet analysis system 200 can be improved.

[0162] However, the linking of the C-Plane packets and the U-Plane packets may be performed in the linking unit 223B of the analysis device 201B. For example, the linking unit 223B of the analysis device 201B may be operated, and the linking unit 223A of the analysis device 201A may not be operated. Alternatively, only the analysis device 201B may have the linking unit B, and the analysis device 201A may not be provided with the linking unit.

[0163] The C-Plane packets are packets related to the control of the UE on the network, etc., and the U-Plane packets are packets including Web sites browsed by the user, voice data during a call, etc. Therefore, generally, the U-Plane packets are larger in data size than the C-Plane packets. Here, if the linking is performed in the analysis device 201B, the C-Plane packets with a relatively small data size may be transferred from the analysis device 201A to the analysis device 201B, and the communication load between the analysis device 201A and the analysis device 201B can be suppressed. <Other Embodiments> In the above-described embodiments, examples in which one analysis device 201B is mainly installed for one analysis device 201A and examples in which a large number of analysis devices 201B are installed for one analysis device 201A have been described, but the present invention is not limited thereto. For example, it is also possible to install a large number of analysis devices 201A for one analysis device 201B.

[0164] <Example of software implementation> The above-described analysis device 201 is a program for causing a computer to function, and can be realized by a program for causing a computer to function as the analysis device 201. In this case, the analysis device 201 includes a computer having at least one control device (for example, a processor) and at least one storage device (for example, a memory) as hardware for executing the above program. An example of such a computer is shown in FIG. 19.

[0165] The computer 500 includes at least one processor 501 and at least one memory 502. A program 520 for operating the computer 500 as the analysis device 201 is recorded in the memory 502. In the computer 500, the processor 501 reads and executes this program 520, whereby each function of the analysis device 201 is realized.

[0166] As the processor 501, for example, a CPU (Central Processing Unit), a GPU (Graphic Processing Unit), a DSP (Digital Signal Processor), an MPU (Micro Processing Unit), an FPU (Floating point number Processing Unit), a PPU (Physics Processing Unit), a microcontroller, or a combination thereof can be used.

[0167] As the memory 502, for example, a flash memory, an HDD (Hard Disk Drive), an SSD (Solid State Drive), or a combination thereof can be used.

[0168] Note that the computer 500 may further include a RAM (Random Access Memory) for expanding the program 520 during execution and temporarily storing various data. Further, the computer 500 may further include a communication interface for transmitting and receiving data to and from other devices. Further, the computer 500 may further include an input / output interface for connecting input / output devices such as a keyboard, a mouse, a display, and a printer.

[0169] Also, the program 520 for operating the computer 500 as the analysis device 201 can be recorded on a non-transitory tangible recording medium 530 readable by the computer 500. As such a recording medium 530, for example, a tape, a disk, a card, a semiconductor memory, or a programmable logic circuit can be used. The computer 500 can acquire the program 520 via such a recording medium 530.

[0170] Also, the program 520 for operating the computer 500 as the analysis device 201 can be transmitted via a transmission medium. As such a transmission medium, for example, a communication network or a broadcast wave can be used. The computer 500 can also acquire the program 520 via such a transmission medium.

[0171] Also, part or all of the functions of the analysis device 201 can also be realized by a logic circuit. For example, an integrated circuit in which a logic circuit functioning as each of the above control blocks is formed is also included in the scope of the present invention. In addition to this, for example, it is also possible to realize the functions of each of the above control blocks by a quantum computer.

[0172] According to each aspect of the present invention described above, by achieving the above-described effects, it is possible to contribute to the achievement of Goal 9, "Build the infrastructure for industry and innovation," of the Sustainable Development Goals (SDGs).

[0173] Note that the present invention is not limited to the above-described embodiments, and various modifications are possible within the scope indicated in the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention.

[0174] 〔Summary〕 The information processing system according to Aspect 1 of the present invention includes an acquisition unit that acquires C-Plane packets and U-Plane packets from a core network, an extraction unit that extracts a source address, a destination address, and a TEID (Tunnel Endpoint Identifier) from the U-Plane packets acquired by the acquisition unit, and extracts the source address, destination address, and TEID of the U-Plane packets from the information stored in the payload of the C-Plane packets acquired by the acquisition unit, and a linking unit that links the C-Plane packets and the U-Plane packets based on the source address, destination address, and TEID extracted by the extraction unit.

[0175] The information processing system according to Aspect 2 of the present invention is, in the above Aspect 1, wherein the core network is a core network in a 5G communication network, and the acquisition unit acquires C-Plane packets from reference points N2 and N12 and acquires U-Plane packets from reference point N3.

[0176] The information processing system according to Aspect 3 of the present invention is, in the above Aspect 2, wherein the acquisition unit further acquires C-Plane packets from reference point N26.

[0177] In the information processing system according to aspect 4 of the present invention, in the above aspect 2 or 3, the acquisition unit classifies the C-Plane packets acquired from the reference point N2 into a first type of packet and a second type of packet with reference to the Procedure Code of the packet, and supplies only the packets classified into the first type to the extraction unit.

[0178] In the information processing system according to aspect 5 of the present invention, in the above aspect 1, the core network is a core network in an LTE communication network, and the acquisition unit acquires C-Plane packets from the reference point S11 and acquires U-Plane packets from the reference point S1-U.

[0179] In the information processing system according to aspect 6 of the present invention, in the above aspect 5, the acquisition unit classifies the C-Plane packets acquired from the reference point S11 into a first type of packet and a second type of packet with reference to the message type of the packet, and supplies only the packets classified into the first type to the extraction unit.

[0180] In the information processing system according to aspect 7 of the present invention, in the above aspect 6, the acquisition unit further classifies the packets classified into the first type into a third type of packet and a fourth type of packet with reference to the value of a predetermined IE (Information Element) stored in the packet, and supplies only the packets classified into the third type to the extraction unit.

[0181] In the information processing system according to aspect 8 of the present invention, in the above aspects 1 to 7, the extraction unit generates identification information for identifying packets related to communications by each of a plurality of users based on the extracted source address, destination address, and TEID, and the association unit associates the C-Plane packets and the U-Plane packets based on the identification information.

[0182] The information processing system according to aspect 9 of the present invention is, in the above aspect 8, wherein the identification information includes a hash value of the source address, the destination address, and the TEID.

[0183] The information processing system according to aspect 10 of the present invention is, in the above aspects 1 to 9, provided with a first acquisition unit and a first extraction unit for packets of the C-Plane, and a second acquisition unit and a second extraction unit for packets of the U-Plane, and a plurality of combinations of the second acquisition unit and the second extraction unit are provided for one combination of the first acquisition unit and the first extraction unit, and the second acquisition unit and the second extraction unit are arranged close to the base station.

[0184] The information processing method according to aspect 11 of the present invention includes the steps of acquiring, from a core network, a packet of the C-Plane and a packet of the U-Plane; extracting a source address, a destination address, and a TEID from the acquired packet of the U-Plane; extracting the source address, the destination address, and the TEID of the packet of the U-Plane from the information stored in the payload of the acquired packet of the C-Plane; and associating the packet of the C-Plane and the packet of the U-Plane based on the extracted source address, destination address, and TEID.

[0185] The program according to aspect 12 of the present invention causes a computer to execute information processing including the steps of acquiring, from a core network, a packet of the C-Plane and a packet of the U-Plane; extracting a source address, a destination address, and a TEID from the acquired packet of the U-Plane; extracting the source address, the destination address, and the TEID of the packet of the U-Plane from the information stored in the payload of the acquired packet of the C-Plane; and associating the packet of the C-Plane and the packet of the U-Plane based on the extracted source address, destination address, and TEID.

Explanation of Signs

[0186] 200 Packet Analysis System 201 Analysis Device 202 Recording Device 203 Monitor Device 221 Acquisition Unit 222 Session Identification Unit 223 Linking Unit

Claims

1. an acquisition unit that acquires packets of a C-Plane and packets of a U-Plane from a core network; (a) extracting a source address, a destination address, and a TEID (Tunnel Endpoint Identifier) ​​from the U-Plane packet acquired by the acquisition unit, and (b) extracting a source address, a destination address, and a TEID of a U-Plane packet corresponding to the C-Plane packet from information stored in a payload of the C-Plane packet acquired by the acquisition unit; a linking unit that links the C-Plane packet with the U-Plane packet based on the source address, destination address, and TEID extracted by the extraction unit; An information processing system comprising:

2. The core network is a core network in a 5G communication network, The acquisition unit acquires packets of the C-Plane from reference point N2 and reference point N12, and acquires packets of the U-Plane from reference point N3. The information processing system according to claim 1 .

3. The acquisition unit further acquires packets of the C-Plane from a reference point N26. The information processing system according to claim 2 .

4. The acquisition unit classifies C-Plane packets acquired from the reference point N2 into first type packets and second type packets by referring to the procedure code of the packets, and supplies only the packets classified into the first type to the extraction unit. The information processing system according to claim 2 .

5. The core network is a core network in an LTE communication network, The acquisition unit acquires packets in the C-Plane from the reference point S11, and acquires packets in the U-Plane from the reference point S1-U. The information processing system according to claim 1 .

6. The acquisition unit classifies C-Plane packets acquired from the reference point S11 into a first type packet and a second type packet by referring to the message type of the packet, and supplies only the packets classified into the first type to the extraction unit.

6. The information processing system according to claim 5.

7. The acquisition unit further classifies the packets classified into the first type into packets of a third type and packets of a fourth type by referring to a value of a predetermined IE (Information Element) stored in the packets, and supplies only the packets classified into the third type to the extraction unit.

7. The information processing system according to claim 6.

8. the extraction unit generates identification information for identifying packets related to communications by each of a plurality of users based on the extracted source address, destination address, and TEID; The linking unit links the packets of the C-Plane and the packets of the U-Plane based on the identification information. The information processing system according to claim 1 .

9. The identification information includes a hash value of the source address, the destination address, and the TEID. The information processing system according to claim 8.

10. A first acquisition unit and a first extraction unit related to packets of the C-Plane; A second acquisition unit and a second extraction unit related to packets of the U-Plane, For one combination of the first acquisition unit and the first extraction unit, a plurality of combinations of the second acquisition unit and the second extraction unit are provided. The information processing system according to claim 7.

11. acquiring packets of a C-Plane and packets of a U-Plane from a core network; (a) extracting a source address, a destination address, and a TEID from the acquired U-Plane packet; and (b) extracting a source address, a destination address, and a TEID of a U-Plane packet corresponding to the C-Plane packet from information stored in the payload of the acquired C-Plane packet. linking the C-Plane packet with the U-Plane packet based on the extracted source address, destination address, and TEID; An information processing method comprising:

12. On the computer, acquiring packets of a C-Plane and packets of a U-Plane from a core network; (a) extracting a source address, a destination address, and a TEID from the acquired U-Plane packet; and (b) extracting a source address, a destination address, and a TEID of a U-Plane packet corresponding to the C-Plane packet from information stored in the payload of the acquired C-Plane packet. and executing information processing including a step of linking the C-Plane packet with the U-Plane packet based on the extracted source address, destination address, and TEID. program.

Citation Information

Patent Citations

  • Base station, control method, and program

    JP2022090476A