Communication device and communication management device
The communication device addresses security threats by detecting synchronization accuracy degradation and switching to higher-priority time sources, ensuring robust communication quality and efficiency in wireless networks.
Patent Information
- Application Number
- JP2024552549
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-25
- Publication Date
- 2025-07-02
- Estimated Expiration
- 2042-10-25
AI Technical Summary
Existing wireless communication networks are vulnerable to security threats such as DoS attacks that can degrade the accuracy of time synchronization, leading to decreased communication quality and efficiency, as conventional methods fail to notify other nodes of a decrease in synchronization accuracy.
A communication device with a detection unit that identifies a decrease in time synchronization accuracy due to DoS attacks, transmitting threat information to a communication management device, which calculates an optimal path and recommends alternative ports or time sources for improved synchronization.
The solution mitigates the influence of degraded time synchronization by allowing nodes to switch to higher-priority time sources, thereby maintaining communication quality and efficiency.
Smart Images

Figure 0007701671000001 
Figure 0007701671000002 
Figure 0007701671000003
Abstract
Description
Technical Field
[0001] The present invention relates to a communication device and a communication management device for wireless communication.
Background Art
[0002] A wireless communication network is composed of a plurality of communication devices. For example, a radio access network (RAN) includes a DU (Distributed Unit) and an RU (Radio Unit). The DU provides radio link control (RLC), media access control (MAC), and PHY-High functions, etc. That is, the DU processes signals of the upper layer. The RU provides PHY-Low functions and RF processing, etc. Also, the RU can accommodate wireless terminals.
[0003] In a wireless access network, in many cases, time synchronization is established between communication devices. For example, in the O-RAN (Open RAN) architecture defined by the O-RAN Alliance, time synchronization is established between an O-DU (O-RAN DU) and an O-RU (O-RAN RU) using the PTP (Precision Time Protocol).
[0004] In PTP, a synchronization signal is transmitted between a master node and a slave node. In the O-RAN architecture, the O-DU may operate as a master node and the O-RU may operate as a slave node. Then, the slave node calculates the offset between the clock of the master node and the clock of the slave node using the synchronization signal. Thereby, the slave node can establish time synchronization with the master node. Note that methods for establishing time synchronization using a synchronization signal are described in, for example, Patent Documents 1 to 2.
Prior Art Documents
Patent Documents
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2022-040947 [Patent Document 2] Japanese Patent Application Laid-Open No. 2021-507613 [Non-Patent Document]
[0006] [Non-Patent Document 1] O-RAN.WG4.CUS.0-v09.00, Control, User and Synchronization Plane Specification [Non-Patent Document 2] O-RAN.SFG.Threat-Model-v03.00 O-RAN Security Threat Modeling and Remediation Analysis [Non-Patent Document 3] O-RAN.SFG.Security-Requirements-Specifications-v03.00 O-RAN Security Requirements Specifications [Summary of the Invention] [Problems to be Solved by the Invention]
[0007] There are various security threats on the network, and PTP communication for time synchronization in a wireless access network may be attacked. For example, when a node performing PTP communication is subjected to a DoS (Denial of service) attack, the processing of the synchronization signal may be delayed. Also, a slave node may not be able to receive a synchronization signal from a master node. And in these cases, the accuracy of time synchronization will decrease.
[0008] Here, when PTP communication is redundant, each node can select the best-quality time source from among multiple time sources. However, the conventional synchronization method does not have a function to notify other nodes of a decrease in the accuracy of time synchronization when the accuracy of time synchronization decreases due to a DoS attack or the like. For this reason, when the accuracy of time synchronization decreases at the master node, the slave node may not be able to select a high-quality time source. In such a case, communication is performed with low accuracy of time synchronization, so the communication quality or communication efficiency may decrease.
[0009] An object according to one aspect of the present invention is to mitigate the influence caused by a decrease in the accuracy of time synchronization in a wireless access network.
Means for Solving the Problem
[0010] A communication device according to one embodiment of the present invention is implemented in a first node among the plurality of nodes in a communication system in which communication between a plurality of time sources and the plurality of nodes constituting a wireless access network is redundant. This communication device includes a first port that receives a signal related to a first time source among the plurality of time sources, a second port that receives a signal related to a second time source among the plurality of time sources, a selection unit that selects the first port or the second port, a time synchronization unit that executes time synchronization processing using a signal received via the port selected by the selection unit, a detection unit that detects an event that degrades the accuracy of the time synchronization processing by the time synchronization unit, and a transmission unit that transmits information related to a threat to the time synchronization processing to a communication management device that manages the plurality of nodes when the detection unit detects the event, and a reception unit that receives information recommending the first port or the second port from the communication management device. When the reception unit receives information recommending the first port or the second port from the communication management device, the selection unit selects the first port or the second port based on the priority of the first time source, the priority of the second time source, and the information received from the communication management device.
Effect of the Invention
[0011] According to the above aspect, the influence caused by the degradation of time synchronization accuracy in the radio access network is alleviated.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
[0013] FIG. 1 shows an example of a communication system according to an embodiment of the present invention. In this example, the communication system 1000 includes a CU (Central Unit), a DU, an RU, and a wireless terminal. The DU and the RU constitute a radio access network as described above. That is, the RU provides a PHY-Low function and RF processing, etc., and can accommodate wireless terminals. The DU provides a radio link control, a media access control, and a PHY-High function, etc., and processes the signals of the RU at a higher layer. Note that a plurality of RUs can be connected to the DU. That is, the DU can process the signals of a plurality of RUs. The CU is provided between the core network and the DU, and further processes the signals of the DU at a higher layer. The wireless terminal is not particularly limited, but is, for example, a UE (User Equipment).
[0014] The DU and the RU are connected to each other by a known interface. For example, the interface between the DU and the RU is a fronthaul interface (or, Open Fronthaul) defined by the O-RAN alliance.
[0015] On the other hand, the standardization of the O-RAN architecture that introduces the RIC (RAN Intelligent Controller) based on the specifications of 3GPP (registered trademark) (Third Generation Partnership Project) is being discussed. The RIC is provided outside the CU and / or DU and can provide various intelligent decision-making functions. By connecting the RIC and the O-CU (O-RAN CU) / O-DU (O-RAN DU) with a standard interface, value-added services using AI / ML (Artificial Intelligence, Machine Learning), etc. are provided in a multi-vendor environment.
[0016] Figure 2 shows the configuration of the O-RAN architecture. In the configuration example shown in Figure 2, the CU includes the O-CU-UP and the O-CU-CP. The O-CU-UP processes the user plane signals, and the O-CU-CP processes the control plane signals. Note that the O-CU-UP and the O-CU-CP are connected by an E1 interface. The O-CU-UP and the O-DU are connected by an F1-u interface, and the O-CU-CP and the O-DU are connected by an F1-c interface. The O-DU and the O-RU are connected by an open front-haul interface.
[0017] SMO (Service Management and Orchestration) is a higher-level monitoring and control system that manages each device or function within the O-RAN architecture. The SMO is connected to the O-CU (O-CU-UP, O-CU-CP), the O-DU, and the O-RU via the O1 interface. Also, the SMO may manage the O-eNB, which is a fourth-generation base station. Furthermore, the SMO is also connected to the O-Cloud via the O2 interface.
[0018] The RIC is implemented within the SMO and provides services to each device or each function within the O-RAN architecture. However, the RIC implemented within the SMO is a non-real-time RIC (Non-RT RIC) with a low processing cycle in this configuration example. Therefore, a real-time RIC (Near-RT RIC) with a high processing cycle is provided outside the SMO. The non-real-time RIC and the real-time RIC are connected by an A1 interface. The real-time RIC is connected to the O-CU (O-CU-UP, O-CU-CP) and the O-DU via the E2 interface. Note that in the following description, the non-real-time RIC and the real-time RIC may be referred to as "RIC" without distinction.
[0019] In the open fronthaul interface between the O-DU and the O-RU, a control plane (C-Plane), a user plane (U-Plane), and a synchronization plane (S-Plane) are defined. The control plane is a protocol for transmitting control information. The user plane is a protocol for transmitting user data. The synchronization plane is a protocol for establishing time synchronization, and PTP (Precision Time Protocol) is used in the O-RAN architecture. And, for example, in Non-Patent Document 1, a configuration for establishing time synchronization between the time source (PRTC: Primary Reference Time Clock) and the O-DU / O-RU has been proposed. Note that this configuration is based on LLS (Lower Layer Split) which represents the split method of the communication layer of the open fronthaul.
[0020] Figures 3 and 4 show the configuration for establishing time synchronization in the fronthaul. Here, time synchronization is established using PTP. Note that the time source PRTC generates a reference clock. Assume that the accuracy of the reference clock is sufficiently high.
[0021] In the configuration (LLS-C1) shown in Fig. 3(a), the O-DU is synchronized with the time source PRTC. Then, PTP communication is directly performed between the O-DU and the O-RU. In this PTP communication, the O-DU operates as the master node and the O-RU operates as the slave node. That is, the O-RU synchronizes its local clock with the clock of the O-DU.
[0022] Fig. 5 shows an example of time synchronization using PTP. Here, the master node and the slave node each have their own clock. Then, by transmitting PTP messages between the master node and the slave node, the slave node synchronizes its clock with the clock of the master node.
[0023] Specifically, time synchronization is established by the following procedure. The master node transmits a Sync message to the slave node. The Sync message represents the time (t1) when the master node transmits the Sync message. The slave node records the time (t2) when the Sync message arrives at the slave node. Depending on the PTP mode, a FollowUp message may be transmitted after the Sync message. The slave node transmits a DelayReq message to the master node. At this time, the slave node records the time (t3) when the DelayReq message is transmitted. When the master node receives the DelayReq message, it transmits a DelayResp message to the slave node. The DelayResp message represents the time (t4) when the DelayReq message arrives at the master node. Then, the slave node calculates the average transmission delay between the master node and the slave node, and the offset between the clock of the master node and the clock of the slave node based on t1, t2, t3, and t4. Specifically, the average transmission delay and the offset are calculated by the following formulas. Average transmission delay = ((t2 - t1) + (t4 - t3)) / 2 Offset = t2 - t1 - average transmission delay
[0024] In the example shown in FIG. 5, t1, t2, t3, and t4 are 100, 82, 86, and 108 respectively. In this case, the average transmission delay is "2" and the offset is "-20". Then, the slave node adjusts its clock based on this offset value. As a result, the clock of the slave node synchronizes with the clock of the master node.
[0025] Note that the PTP procedure shown in FIG. 5 is executed, for example, at a predetermined time interval. That is, the master node periodically sends Sync messages. And each time a Sync message is sent from the master node, the slave node calculates the above-mentioned average transmission delay and offset. Thereby, accurate time synchronization is always achieved between the master node and the slave node.
[0026] In the configurations shown in FIGS. 3(b), 4(a), and 4(b), a plurality of time sources PRTC are provided. Also, redundancy is provided between the plurality of time sources PRTC and the plurality of nodes (O-DU / O-RU) constituting the radio access network.
[0027] In the configuration (LLS-C2) shown in FIG. 3(b), each O-DU is synchronized with the corresponding time source PRTC. Also, PTP communication between the O-DU and the O-RU is performed via an L2 switch network. The L2 switch network includes one or more front hole multiplexers FHM. The front hole multiplexer FHM is realized, for example, by an L2 switch device. In the PTP communication between the O-DU and the front hole multiplexer FHM, the O-DU operates as the master node and the front hole multiplexer FHM operates as the slave node. In the PTP communication between the front hole multiplexer FHM and the O-RU, the front hole multiplexer FHM operates as the master node and the O-RU operates as the slave node.
[0028] In the configuration (LLS-C3) shown in Fig. 4(a), a time source PRTC is provided inside the front hall. That is, the front hall multiplexer FHM is synchronized with the time source PRTC inside the front hall. In the PTP communication between the front hall multiplexer FHM and the O-DU, the front hall multiplexer FHM operates as the master node and the O-DU operates as the slave node. Similarly, in the PTP communication between the front hall multiplexer FHM and the O-RU, the front hall multiplexer FHM operates as the master node and the O-RU operates as the slave node.
[0029] In the configuration (LLS-C4) shown in Fig. 4(b), each O-DU operates in synchronization with the corresponding time source PRTC. Also, each O-RU operates in synchronization with the corresponding time source PRTC. Therefore, there is no need to perform PTP communication between the O-DU and the O-RU.
[0030] In recent years, the virtualization of network devices has been progressing. For example, a configuration for realizing a synchronization plane by implementing a virtualized DU (vDU: virtual DU) on a cloud platform has been studied.
[0031] Fig. 6 shows an example of a configuration for establishing time synchronization of a radio access network using a cloud platform. In the example shown in Fig. 6, a synchronization plane is realized based on LLS-C3 shown in Fig. 4(b). Therefore, a time source PRTC is provided inside the front hall.
[0032] In the configuration shown in Fig. 6(a), a PTP clock manager is implemented inside the cloud site. In this configuration, the PTP clock manager operates as a slave node of PTP communication. Also, the cloud platform has a timestamp function and a system clock. Then, the PTP clock manager synchronizes the system clock with the time source PRTC by performing the PTP procedure shown in Fig. 5 with the time source PRTC.
[0033] One or more virtualized DUs (vDUs) are implemented on a cloud platform. Each vDU is realized by a processor executing program code that describes the functions of an O-DU. Note that the vDUs can be implemented for each cell, each slice, or each vendor. And the vDUs operate using a system clock corrected by a PTP clock manager. As a result, each vDU operates in synchronization with the time source PRTC.
[0034] Each RU operates as a slave node for PTP communication. That is, each RU synchronizes its clock with the time source PRTC by performing the PTP procedure shown in FIG. 5 with the time source PRTC.
[0035] In the configuration shown in FIG. 6(b), an L2 packet switch is implemented on the cloud platform. Also, the PTP clock manager relays PTP packets between the time source PRTC and the DU / RU. That is, the PTP clock manager operates as a slave node with respect to the time source PRTC and as a master node with respect to the DU / RU. Specifically, the PTP clock manager synchronizes the system clock with the time source PRTC by performing the PTP procedure shown in FIG. 5 as a slave node with respect to the time source PRTC. Also, the PTP clock manager performs the PTP procedure shown in FIG. 5 as a master node with respect to the DU / RU. As a result, the clocks of each DU / RU are synchronized with the system clock of the cloud site. As a result, the clocks of each DU / RU are synchronized with the time source PRTC.
[0036] By the way, in a conventional radio access network, a dedicated closed network is configured to cope with security threats. In contrast, in the architecture recommended by the O-RAN Alliance, without assuming a dedicated closed network, secure communication between O-RUs / O-DUs / O-CUs is realized using port-based network access control (IEEE802.1X-2020). That is, a zero-trust-based approach is required.
[0037] In an environment premised on zero trust, various security threats are also a concern in PTP communication for establishing time synchronization. For example, Non-Patent Document 2 examines the following security threats.
[0038] (1) DoS attack on the master clock (2) Spoofing of the master clock (3) Illegal PTP instance (Man-in-the-middle) (4) Sniffing and deletion of PTP packets (5) Packet delay operation
[0039] On the other hand, countermeasures against these security threats are being considered. For example, Non-Patent Document 3 examines the following items required for PTP communication in the O-RAN architecture.
[0040] (1) Support multi-PTP domains and provide multiple grand masters simultaneously (2) Assign multiple grand masters to physically different PTP ports (3) The PTP communication path supports topological resiliency. (4) Authentication / authorization of the synchronization plane is realized by port-based network access control (IEEE802.1X-2020). (5) Encryption of PTP messages (MACsec)
[0041] Thus, various security threats also exist for the synchronization plane of the radio access network, but countermeasures have been prepared for many security threats. However, when a DoS attack occurs, the accuracy of time synchronization may decrease.
[0042] For example, in the configuration shown in Fig. 6(a), when a DoS attack occurs on the cloud site where the vDU is implemented, it is possible to detect the DoS attack by analyzing the received packets. However, if a large number of resources (such as processors and memories) of the cloud site are consumed to detect the DoS attack, there may be insufficient resources for executing the PTP procedure. Here, as described above, the PTP procedure is executed periodically. And when there are insufficient resources for executing the PTP procedure, the calculation of the average transmission delay and offset may be delayed or become impossible. Therefore, when a DoS attack occurs, the accuracy of time synchronization may decrease. This problem is not limited to the configuration shown in Fig. 6(a), and may also occur in other configurations (for example, the configuration shown in Fig. 6(b)).
[0043] Note that even when no DoS attack is occurring, if there are insufficient resources for executing the PTP procedure, the calculation of the average transmission delay and offset may be delayed or become impossible, and the accuracy of time synchronization may decrease. For example, in the configuration shown in Fig. 6(a) or Fig. 6(b), in the case where a process operating on the cloud platform runs wild, or in the case where high-load communication is executed, there may be insufficient resources.
[0044] <Embodiment> Fig. 7 shows an example of a network system that performs time synchronization in an embodiment of the present invention. In this example, the communication system includes a communication management device SMO and a plurality of PTP nodes. The PTP nodes have a function of establishing time synchronization by executing the PTP procedure shown in Fig. 5. In this example, the PTP nodes include a time source PRTC, an O-DU, a front-haul multiplexer FHM, and an O-RU.
[0045] In PTP communication, the T-GM (Telecom Grand Master) operates as a time source. The T-TSC (Telecom Time Slave Clock) is implemented in communication devices that require time synchronization (in a radio access network, for example, O-DU and O-RU). Also, a plurality of T-BC (Telecom Boundary Clock) are provided within the fronthaul. In the example shown in FIG. 7, n T-BC are provided. And the T-BC relays PTP communication between the T-GM and the T-TSC. The T-BC is implemented, for example, in the fronthaul multiplexer FHM.
[0046] The communication system with the above configuration includes a plurality of time sources in order to reduce security threats to time synchronization. In the example shown in FIG. 7, two time sources (T-GM1, T-GM2) are provided. And the PTP communication paths between the time sources and each T-TSC (for example, O-DU and O-RU) are made redundant.
[0047] For example, the PTP messages generated by the time source T-GM1 are sent to T-BC1 and T-BC2. Also, the PTP messages generated by the time source T-GM2 are sent to T-BC1 and T-BC2. Note that the PTP message is a message transmitted in the PTP procedure and includes the Sync message, FollowUp message, DelayReq message, and DelayResp message shown in FIG. 5. The PTP message also includes an announce message for notifying control information and management information.
[0048] Then, T-BC1 receives PTP messages transmitted from time source T-GM1 and PTP messages from time source T-GM2. Here, each PTP node supports T-BMCA (Telecom Best Master Clock Algorithm). T-BMCA is an algorithm that selects the best quality time source from among multiple time sources. At this time, the PTP node may select the best quality time source based on the announce messages transmitted from each time source (i.e., each T-GM). Therefore, T-BC1 selects a good quality time source from among time source T-GM1 and time source T-GM2. Also, T-BC2 selects a good quality time source from among time source T-GM1 and time source T-GM2. Similarly, each T-BC selects the best quality time source.
[0049] Each T-TSC receives PTP messages from multiple T-BCs. For example, T-TSC1 receives PTP messages from T-BCn-1 and T-BCn. Then, T-TSC1 selects the best quality time source based on the received PTP messages. Similarly, T-TSC2 also selects the best quality time source.
[0050] Here, the algorithm for selecting the best quality time source from among multiple time sources (i.e., T-BMCA) will be briefly described. In PTP communication, each time source periodically transmits an announce message. The announce message includes the following parameters related to the priority of the time source.
[0051] (1) Priority 1 (any value) (2) Clock Class (3) Clock Accuracy (device-specific accuracy index) (4) Clock Variance (oscillator accuracy) (5) Priority 2 (any value)
[0052] Then, the PTP node selects the best-quality time source by comparing the contents of the announce messages sent from each time source. For example, the time source with the highest priority is selected. If the priorities are the same, the time source with the highest priority is selected by comparing other parameters.
[0053] However, if the priorities of each time source are different from each other, the accuracy of the clock may decrease when a failure occurs. Therefore, in many cases, the priorities of each time source are the same.
[0054] When the priorities of each time source are the same, the PTP node selects the time source based on, for example, the number of the port that receives the PTP message. For example, when receiving a PTP message sent from time source T-GM1 via port P1 and a PTP message sent from time source T-GM2 via port P2, the PTP node may select the port with the smaller number value. In this case, since port P1 is selected, this PTP node selects time source T-GM1. If the announce message contains identification information (e.g., MAC address) that uniquely identifies the time source, the PTP node may select the time source based on that identification information.
[0055] The communication management device SMO manages the devices or functions within the O-RAN architecture. In PTP communication, the communication management device SMO manages the communication devices implemented in each PTP node.
[0056] FIG. 8 is a functional block diagram of a PTP node. In this example, the PTP node 100 corresponds to one of the communication devices among a plurality of communication devices constituting a radio access network. That is, the PTP node 100 corresponds to an O-DU, a fronthaul multiplexer FHM, or an O-RU. Further, the PTP node 100 includes a virtual platform 110. The virtual platform 110 is realized by, for example, hardware including a processor and a memory, and software including an OS (Operating System). Then, various programs are executed on the virtual platform 110.
[0057] The PTP node 100 includes a RAN device 121, a PTP clock manager 122, a DoS attack detection unit 123, a resource monitoring unit 124, a local clock 125, a plurality of NW ports, and an OAM (Operations, Administration and Management) port. However, the PTP node 100 may include other functions or devices not shown in FIG. 8. Also, programs not shown in FIG. 8 may be executed on the virtual platform 110.
[0058] The RAN device 121 provides the functions of a communication device constituting a radio access network. In the example shown in FIG. 8, the RAN device 121 provides the functions of an O-DU. That is, the RAN device 121 operates as an O-vDU.
[0059] The PTP clock manager 122 executes the PTP procedure shown in FIG. 5 to establish time synchronization. Here, the PTP clock manager 122 can operate as a master of PTP communication and can also operate as a slave of PTP communication. For example, when the PTP node 100 is the T-BC(1) shown in FIG. 7, the PTP clock manager 122 operates as a slave with respect to T-GM1 and T-GM2. Also, the PTP clock manager 122 operates as a master with respect to T-BC(n-1) and T-BC(n).
[0060] The PTP clock manager 122 includes a T-BMCA switch 122a. The T-BMCA switch 122a selects the best-quality time source from among a plurality of time sources. At this time, the T-BMCA switch 122a selects the best-quality time source based on, for example, announcement messages transmitted from the plurality of time sources respectively. Then, the PTP clock manager 122 performs time synchronization based on PTP messages from the time source selected by the T-BMCA switch 122a. For example, if the PTP node 100 is the T-BC(1) shown in FIG. 7 and the T-BMCA switch 122a selects the time source T-GM1, the PTP clock manager 122 performs time synchronization based on the PTP messages transmitted from the time source T-GM1. Note that, as will be described in detail later, the T-BMCA switch 122a can also select a time source in response to an instruction from the communication management device SMO shown in FIG. 7.
[0061] The DoS attack detection unit 123 detects a DoS attack against the PTP node 100. The DoS attack is detected, for example, by analyzing the header of the received packet. The resource monitoring unit 124 monitors the resource utilization rate of the PTP node 100. At this time, the resource monitoring unit 124 may monitor the utilization rate of the processor and / or the memory implemented in the PTP node 100. Also, the resource monitoring unit 124 may monitor the utilization rate of the resources allocated to PTP communication. Then, the resource monitoring unit 124 outputs an alarm when the resource utilization rate exceeds a predetermined threshold value. The threshold value is, for example, a utilization rate at which a delay is assumed to occur in the processing related to PTP communication, and is determined in advance based on simulations or measurements or the like.
[0062] The local clock 125 generates a clock signal using an oscillator having a predetermined frequency. The clock signal may be a numerical value that is incremented by one each time. In this case, the local clock 125 includes a counter.
[0063] Note that in the embodiment shown in FIG. 8, a DoS attack detection unit 123, a resource monitoring unit 124, and a local clock 125 are implemented in the virtual platform 110, but the embodiments of the present invention are not limited to this configuration. For example, the DoS attack detection unit 123 or the resource monitoring unit 124 may be realized by a software program executed on the virtual platform 110. Also, the local clock 125 may be provided outside the virtual platform 110.
[0064] The NW port provides an interface with other PTP nodes. In this embodiment, the PTP node 100 includes four NW ports P1 to P4. Here, for example, when the PTP node 100 is the T-BC(1) shown in FIG. 7, the NW port P1 is connected to the T-GM1, and the NW port P2 is connected to the T-GM2. In this case, the NW ports P1 and P2 are each used as slave ports. The NW port P3 is connected to the T-BCn-1, and the NW port P4 is connected to the T-BCn. In this case, the NW ports P3 and P4 are each used as master ports.
[0065] The OAM port provides an interface with the communication management device SMO shown in FIG. 2 or FIG. 7. When the DoS attack detection unit 123 detects a DoS attack, the OAM port transmits information indicating that the PTP node 100 has been subjected to a DoS attack to the communication management device SMO. Also, when the resource monitoring unit 124 outputs an alarm, the OAM port transmits information indicating that the resource utilization rate of the PTP node 100 has exceeded the threshold to the communication management device SMO. The OAM port also receives a notification related to the setting of the T-BMCA switch 122a from the communication management device SMO.
[0066] In this way, in addition to the function of executing the PTP procedure, the PTP node 100 has a function of transmitting information related to threats to time synchronization processing to the communication management device SMO. Further, the PTP node 100 has a function of receiving a notification related to the setting of the T-BMCA switch 122a from the communication management device SMO. Note that threats to time synchronization processing include security threats such as DoS attacks and states where the resource utilization rate exceeds a threshold. Hereinafter, mainly security threats will be described.
[0067] FIG. 9 is a flowchart showing an example of a method by which the PTP node 100 notifies the SMO of a security threat. The processing of this flowchart is executed, for example, periodically.
[0068] In S1, the DoS attack detection unit 123 monitors a DoS attack on the PTP node 100. When a DoS attack is detected, in S2, the DoS attack detection unit 123 notifies the communication management device SMO of PTP threat information (here, information indicating the detection of a DoS attack) via the OAM port.
[0069] In S3, the resource monitoring unit 124 monitors the resource utilization rate of the PTP node 100. When the resource utilization rate exceeds a predetermined threshold, the resource monitoring unit 124 notifies the communication management device SMO of PTP threat information (here, information indicating that the resource utilization rate has exceeded the threshold) via the OAM port.
[0070] FIG. 10 is a functional block diagram of the communication management device SMO. In this embodiment, the communication management device (SMO) 200 includes a topology information storage unit 201, a threat information acquisition unit 202, an optimal path calculation unit 203, and a recommended port notification unit 204. Note that the communication management device (SMO) 200 may include other functions or devices not shown in FIG. 10.
[0071] The topology information storage unit 201 stores topology information representing the topology of a network that performs PTP communication. The topology information represents the connections between PTP nodes. Specifically, the topology information represents the connections between PTP ports.
[0072] The threat information acquisition unit 202 collects PTP threat information from each PTP node. The PTP threat information corresponds to information related to threats to the time synchronization process, which was described with reference to FIG. 8 or FIG. 9.
[0073] When the threat information acquisition unit 202 acquires PTP threat information, the optimal path calculation unit 203 calculates the optimal path for PTP communication with reference to the topology information stored in the topology information storage unit 201. At this time, the optimal path calculation unit 203 calculates an optimal path that does not pass through PTP nodes where security threats have been detected, between each T-GM and each T-TSC (O-DU / O-RU). When a new optimal path is calculated, the recommended port notification unit 204 determines the recommended port for performing PTP communication for each PTP node. Then, the recommended port notification unit 204 notifies the determined recommended port to the corresponding one or more PTP nodes.
[0074] FIG. 11 is a flowchart related to an example of the processing of the communication management device (SMO) 200. Note that the flowchart shown in FIG. 11 shows only the processing related to the control of PTP communication.
[0075] In S11, the communication management device (SMO) 200 collects information representing the connections between nodes from each PTP node 100. Then, the communication management device (SMO) 200 creates topology information based on the collected information. The created topology information is stored in the topology information storage unit 201. After this, the processing of S12 to S17 is repeatedly executed at a predetermined time interval.
[0076] In S12, the communication management device (SMO) 200 collects port selection information from each PTP node 100. Here, each NW port of the PTP node 100 is associated with a master node. For example, in the embodiment shown in FIG. 8, NW port P1 is associated with PTP master 1, and NW port P2 is associated with PTP master 2.
[0077] In S13 to S14, the threat information acquisition unit 202 collects PTP threat information from each PTP node 100. Here, the PTP threat information is transmitted, for example, when a threat to PTP communication occurs in the PTP node 100. In this example, the PTP threat information is transmitted when a DoS attack is detected and when the resource utilization rate of the PTP node exceeds a threshold.
[0078] When receiving the PTP threat information (S14: Yes), in S15, the optimal path calculation unit 203 calculates the optimal path for PTP communication. At this time, the optimal path calculation unit 203 calculates, for example, an optimal path that does not pass through the PTP node where a threat to PTP communication is detected.
[0079] In S16, the recommended port notification unit 204 determines whether the newly calculated optimal path is the same as the current path. Then, when the newly calculated optimal path is different from the current path, the recommended port notification unit 204 determines, for each PTP node, whether the port connected to the new optimal path is the same as the currently used port. Then, when the port connected to the new optimal path is different from the currently used port, the recommended port notification unit 204 determines, in S17, the port connected to the new optimal path as the "recommended port". The recommended port represents a port that is preferably used for PTP communication. Then, the recommended port notification unit 204 notifies the determined port to the corresponding PTP node. The PTP node 100 that receives the notification of the recommended port determines whether to switch the PTP port.
[0080] Note that the recommended port notification unit 204 may determine, for each PTP node, whether the time source to be connected to the new optimal path is the same as the currently used time source. In this case, when the time source to be connected to the new optimal path is different from the currently used time source, the recommended port notification unit 204 may determine the time source to be connected to the new optimal path as the recommended time source. Then, the recommended port notification unit 204 notifies the corresponding PTP node of the new time source.
[0081] FIG. 12 is a flowchart showing an example of the processing of the PTP node 100 that has received the notification of the recommended port. Note that before receiving the notification of the recommended port, the PTP node 100 determines the port for receiving the PTP message based on the announce message transmitted from each time source (i.e., T-GM). Here, each NW port of the PTP node 100 is associated with a predetermined master node. That is, before receiving the notification of the recommended port, the time source to be used by each PTP node 100 is set based on the announce message.
[0082] In S21, the PTP clock manager 122 waits for the notification of the recommended port transmitted from the communication management device (SMO) 200. During the period of waiting for the notification of the recommended port, the PTP clock manager 122 selects the port for PTP communication based on the PTP message transmitted from each time source (T-GM). That is, the PTP clock manager 122 performs time synchronization using the PTP message received via the selected port.
[0083] When the PTP clock manager 122 receives a notification of a recommended port from the communication management device (SMO) 200, at S22, the PTP clock manager 122 compares the priority of the time source corresponding to the current port with the priority of the time source corresponding to the recommended port. When the priority of the time source corresponding to the current port is higher than the priority of the time source corresponding to the recommended port, the PTP clock manager 122 selects the current port at S23. On the other hand, when the priority of the time source corresponding to the current port is not higher than the priority of the time source corresponding to the recommended port, the PTP clock manager 122 selects the recommended port at S24. Therefore, when the priorities of the time source corresponding to the current port and the time source corresponding to the recommended port are the same, the recommended port is selected.
[0084] <Example> FIG. 13 shows an example of the configuration of a PTP network. In this example, the PTP network includes two time sources (PRTC1, PRTC2), two O-DUs (O-DU1, O-DU2), two front-haul multiplexers (FHM1, FHM2), and two O-RUs (O-RU1, O-RU2). Each time source PRTC, each O-DU, each front-haul multiplexer FHM, and each O-RU are realized by the PTP node 100. Also, each time source PRTC corresponds to a T-GM, each O-DU and each front-haul multiplexer FHM correspond to a T-BC, and each O-RU corresponds to a T-TSC.
[0085] In FIG. 13, "M" represents the master port of PTP communication, and "S" represents the slave node of PTP communication. And on the interface connecting the master port M and the slave port S, the PTP procedure shown in FIG. 5 is executed. Also, each O-DU, each front-haul multiplexer FHM, and each O-RU respectively correspond to the PTP node 100 shown in FIG. 8 and include a T-BMCA switch 122a.
[0086] FIG. 14 shows an example of a method for creating topology information. In this embodiment, each PTP node recognizes the PTP nodes adjacent to itself through negotiation or message exchange executed at startup. Then, each PTP node transmits adjacent node information representing the PTP nodes adjacent to itself to the communication management device (SMO) 200. In the embodiment shown in FIG. 14, adjacent node information is transmitted from the front hole multiplexer FHM1 and O-RU1, but actually adjacent node information is transmitted from all PTP nodes. Then, the communication management device (SMO) 200 creates topology information based on the adjacent node information received from each PTP node.
[0087] FIG. 15 shows an example of topology information representing the configuration of the PTP network shown in FIG. 13. The topology information represents, for each PTP node, the other PTP nodes adjacent to it. Note that FIG. 15(a) shows the topology information represented in matrix form, and FIG. 15(b) shows the topology information represented in list form, but the contents are the same.
[0088] In the adjacency matrix shown in FIG. 15(a), "1" represents the adjacent state, and "-" represents the non-adjacent state. For example, in the PTP network shown in FIG. 13, the PTP nodes adjacent to the time source PRTC1 are O-DU1 and O-DU2. Therefore, in the record corresponding to the time source PRTC1 in the adjacency matrix, "1" is set for O-DU1 and O-DU2 respectively. Also, the PTP nodes adjacent to O-DU1 are the time source PRTC1, the time source PRTC2, the front hole multiplexer FHM1, and the front hole multiplexer FHM2. Therefore, in the record corresponding to O-DU1 in the adjacency matrix, "1" is set for PRTC1, PRTC2, FHM1, and FHM2 respectively.
[0089] Note that, although not particularly limited, the topology information storage unit 201 stores the topology information in matrix form shown in Fig. 15(a). Also, in the interface between the PTP node and the communication management device (SMO) 200, the topology information in list form shown in Fig. 15(b) is transmitted.
[0090] Fig. 16 shows an example of the initial state of PTP communication. In Fig. 16, the ellipses drawn within each PTP node correspond to the NW ports shown in Fig. 8. M1 and M2 each represent a master port, and S1 and S2 each represent a slave port. Also, in Fig. 16, the paths connecting to the ports selected by the slave nodes are represented by thick solid lines. Also, the paths connecting to the ports not selected by the slave nodes are represented by thick dashed lines.
[0091] For example, the master port M1 of the time source PRTC1 is connected to the slave port S1 of O-DU1, the master port M2 of the time source PRTC1 is connected to the slave port S1 of O-DU2, the master port M1 of the time source PRTC2 is connected to the slave port S2 of O-DU1, and the master port M2 of the time source PRTC2 is connected to the slave port S2 of O-DU2. And in the initial state, O-DU1 selects the slave port S1, and O-DU2 selects the slave port S2. That is, O-DU1 selects the time source PRTC1, and O-DU2 selects the time source PRTC2.
[0092] Note that each PTP node selects a port for PTP communication based on the parameters related to the priority described in the announce message transmitted from each time source PRTC as described above. However, when the priorities of each time source PRTC are the same as each other, the PTP node selects the time source PRTC based on, for example, the port number.
[0093] Also, each PTP node transmits selection information indicating the selected master node to the communication management device (SMO) 200. In the embodiment shown in FIG. 16, the selection information transmitted from the front hole multiplexer FHM1 indicates that O-DU1 is selected as the master node. Also, the selection information transmitted from O-RU1 indicates that FHM1 is selected as the master node. Therefore, the communication management device (SMO) 200 can recognize which master node each PTP node has selected.
[0094] FIG. 17 shows an example of a security threat to a PTP node. In this embodiment, a DoS attack has occurred on the front hole multiplexer FHM1, which is one of the PTP nodes. In this case, the DoS attack detection unit 123 of the front hole multiplexer FHM1 detects the DoS attack. Then, the DoS attack detection unit 123 transmits PTP threat information indicating that the front hole multiplexer FHM1 has been subjected to a DoS attack to the communication management device (SMO) 200 via the OAM port. In this embodiment, the PTP threat information is represented as "DOS Attack detected: True". Also, since the front hole multiplexer FHM1 is under a DoS attack, in the adjacent node information, the PTP nodes connected to the downstream side of the front hole multiplexer FHM1 are deleted.
[0095] When the communication management device (SMO) 200 receives the adjacent node information shown in FIG. 17, it updates the topology information. In this embodiment, the topology information is updated as shown in FIG. 18. Specifically, in the record corresponding to the front hole multiplexer FHM1, the PTP nodes (i.e., O-RU1 and O-RU2) connected to the downstream side of the front hole multiplexer FHM1 are deleted.
[0096] Also, when the communication management device (SMO) 200 receives the PTP threat information shown in FIG. 17, in S11 shown in FIG. 11, it calculates the optimal path for PTP communication. At this time, the optimal path calculation unit 203 calculates the optimal path between each time source (PRTC1, PRTC2) and the T-TSC (O-RU1, O-RU2) so as not to pass through the front hole multiplexer FHM1 which is the transmission source of the PTP threat information. Specifically, since the front hole multiplexer FHM1 is under a DoS attack, an optimal circuit that does not use the path between the front hole multiplexer FHM1 and the PTP node connected to its downstream side is calculated. That is, the optimal path is calculated with a configuration assuming that there is no path between the front hole multiplexer FHM1 and O-RU1 and no path between the front hole multiplexer FHM1 and O-RU2.
[0097] As a result, it is assumed that the optimal path shown in FIG. 19 is obtained. Specifically, the optimal path between the time sources (PRTC1, PRTC2) and O-RU1 is the path from the time source PRTC2 through O-DU2 and the front hole multiplexer FHM2 to O-RU1. That is, when PTP communication is performed via the newly calculated optimal path, O-RU1 will transmit and receive PTP messages using the slave port S2. On the other hand, O-RU1 is currently transmitting and receiving PTP messages using the slave port S1. Therefore, the communication management device (SMO) 200 determines in S16 of FIG. 11 that it is preferable to perform port switching. Then, the recommended port notification unit 204 transmits recommended port information recommending the use of the slave port S2 to O-RU1. In the example shown in FIG. 19, the recommended port information is represented as "PTP Master Recommendation: FHM2".
[0098] When O-RU1 receives recommended port information, it executes the processes of S22 to S24 shown in FIG. 12. At this time, when the priority of the time source (i.e., PRTC1) corresponding to the currently used port S1 is higher than the priority of the time source (i.e., PRTC2) corresponding to the recommended port S2, the PTP clock manager 122 continues to select the current port. That is, as shown in FIG. 17, O-RU1 performs PTP communication with the front-haul multiplexer FHM1. Here, the front-haul multiplexer FHM1 performs PTP communication with O-DU1, and O-DU1 performs PTP communication with the time source PRTC1. Therefore, O-RU1 performs time synchronization based on the time source PRTC1. That is, the time source used by O-RU1 does not change. In this case, although a security threat has occurred on the PTP communication path, the time source with a higher priority is continuously used.
[0099] On the other hand, when the priority of the time source (i.e., PRTC1) corresponding to the currently used port S1 is not higher than the priority of the time source (i.e., PRTC2) corresponding to the recommended port S2, the PTP clock manager 122 selects the recommended port. For example, when the priorities of the time sources PRTC1 and PRTC2 are the same, the PTP clock manager 122 selects the recommended port notified from the communication management device (SMO) 200. That is, as shown in FIG. 19, O-RU1 performs PTP communication with the front-haul multiplexer FHM2. Here, the front-haul multiplexer FHM2 performs PTP communication with O-DU2, and O-DU2 performs PTP communication with the time source PRTC2. Therefore, O-RU1 performs time synchronization based on the time source PRTC2. That is, the time source used by O-RU1 is changed from PRTC1 to PRTC2. In this case, since the priorities of the two time sources are the same, the time source connected to the PTP communication path where no security threat has occurred is selected.
[0100] As described above, when the PTP node according to the embodiment of the present invention detects an event that degrades the accuracy of time synchronization, it notifies the detection result to the communication management device (SMO) 200. Then, the communication management device (SMO) 200 determines and notifies the recommended ports to be used for PTP communication to one or more PTP nodes. Therefore, a decrease in the accuracy of time synchronization in each PTP node is suppressed.
[0101] <Hardware Configuration> FIG. 20(a) shows an example of the hardware configuration of the PTP node. Here, the PTP node 10 corresponds to the PTP node 100 shown in FIG. 8 and includes a processor 11, a memory 12, a storage device 13, and a communication interface circuit 14. When the PTP node is an O-RU, the PTP node 10 further includes a wireless circuit 15.
[0102] The processor 11 controls the operation of the PTP node 10 by executing a communication program stored in the storage device 13. The communication program includes program codes describing procedures for PTP communication. Therefore, by the processor 11 executing this communication program, the functions of the PTP clock manager 122, the DoS attack detection unit 123, and the resource monitoring unit 124 may be provided. The memory 12 is used as a working area for the processor 11. The storage device 13 stores the above-described communication program and other programs. The communication interface circuit 14 includes the NW port and the OAM port shown in FIG. 8 and communicates with other PTP nodes and the communication management device (SMO) 200. The wireless circuit 15 includes a wireless transmitter that transmits signals to a wireless terminal and a wireless receiver that receives signals from the wireless terminal.
[0103] Figure 20(b) shows an example of the hardware configuration of the communication management device (SMO). Here, the communication management device (SMO) 20 corresponds to the communication management device (SMO) 200 shown in FIG. 10, and includes a processor 21, a memory 22, a storage device 23, and a communication interface circuit 24. That is, the configuration of the communication management device (SMO) 20 is substantially the same as that of the PTP node 10. However, the communication program executed by the processor 21 includes program codes describing the procedures of the flowchart shown in FIG. 11. Therefore, by the processor 21 executing this communication program, the functions of the threat information acquisition unit 202, the optimal path calculation unit 203, and the recommended port notification unit 204 are provided.
Explanation of Signs
[0104] 100 PTP node 110 Virtual platform 121 RAN device 122 PTP clock manager 122a T-BMCA switch 123 DoS attack detection unit 124 Resource monitoring unit 125 Local clock 200 Communication management device (SMO) 201 Topology information storage unit 202 Threat information acquisition unit 203 Optimal path calculation unit 204 Recommended port notification unit
Claims
1. In a communication system in which communication between a plurality of time sources and a plurality of nodes constituting a wireless access network is redundant, a communication device implemented in a first node among the plurality of nodes, comprising: a first port for receiving a signal related to a first time source among the plurality of time sources; a second port for receiving a signal related to a second time source among the plurality of time sources; a selection unit for selecting the first port or the second port; a time synchronization unit for performing time synchronization processing using a signal received via the port selected by the selection unit; a detection unit for detecting an event that degrades the accuracy of the time synchronization processing by the time synchronization unit; a transmission unit for transmitting information related to a threat to the time synchronization processing to a communication management device that manages the plurality of nodes when the detection unit detects the event; a reception unit for receiving information recommending the first port or the second port from the communication management device, and when the reception unit receives information recommending the first port or the second port from the communication management device, the selection unit selects the first port or the second port based on the priority of the first time source, the priority of the second time source, and the information received from the communication management device The communication device characterized by the above.
2. When the time synchronization unit is performing the time synchronization processing using the signal received via the first port, the reception unit receives information recommending the second port, and when the priority of the second time source is not higher than the priority of the first time source, the selection unit selects the second port The communication device according to claim 1, characterized by the above.
3. The detection unit includes an attack detection unit for detecting an attack on the communication device, and the transmission unit transmits the information related to the threat to the communication management device when the attack detection unit detects an attack on the communication device The communication device according to claim 1, characterized by the above.
4. The attack detection unit detects a DoS attack on the communication device The communication device according to claim 3, characterized by the above.
5. The detection unit includes a resource monitoring unit for monitoring the usage rate of resources of the communication device, and the transmission unit transmits the information related to the threat to the communication management device when the usage rate monitored by the resource monitoring unit exceeds a predetermined threshold value The communication device according to claim 1, characterized in that.
6. In a communication system in which redundancy is provided between a plurality of time sources and a plurality of communication devices constituting a radio access network, and each of the plurality of communication devices performs time synchronization processing using signals transmitted from the plurality of time sources, a communication management device for managing the plurality of communication devices, a storage unit that stores topology information representing connections between the plurality of time sources and the plurality of communication devices; an acquisition unit that acquires information related to a threat to the time synchronization processing from a first communication device among the plurality of communication devices; for each of the plurality of communication devices, a calculation unit that calculates a communication path for receiving a signal transmitted from any one of the plurality of time sources so as not to pass through the first communication device, using the topology information; for each of the plurality of communication devices, based on the communication path calculated by the calculation unit, a recommendation port for receiving a signal transmitted from any one of the plurality of time sources is determined, and information representing the determined recommendation port is notified to the corresponding communication device; a notification unit; A communication management device comprising:
7. a plurality of time sources; a plurality of communication devices constituting a radio access network; a communication management device for managing the plurality of communication devices, the communication paths between the plurality of time sources and the plurality of communication devices are redundant, each of the plurality of communication devices, a first port for receiving a signal related to a first time source among the plurality of time sources; a second port for receiving a signal related to a second time source among the plurality of time sources; a selection unit that selects the first port or the second port; a time synchronization unit that performs time synchronization processing using a signal received via the port selected by the selection unit; a detection unit that detects an event that degrades the accuracy of the time synchronization processing by the time synchronization unit; a transmission unit that transmits information related to a threat to the time synchronization processing to the communication management device when the detection unit detects the event; a reception unit that receives information recommending the first port or the second port from the communication management device; The communication management device, a storage unit that stores topology information representing connections between the plurality of time sources and the plurality of communication devices; an acquisition unit that acquires the information related to the threat from a first communication device among the plurality of communication devices; For each of the plurality of communication devices, a calculation unit that calculates a communication path for receiving a signal transmitted from any one of the plurality of time sources so as not to pass through the first communication device by using the topology information; For each of the plurality of communication devices, based on the communication path calculated by the calculation unit, a recommended port for receiving a signal transmitted from any one of the plurality of time sources is determined, and information representing the determined recommended port is notified to the corresponding communication device, and a notification unit; In a second communication device among the plurality of communication devices, when the receiving unit receives information recommending the first port or the second port from the communication management device, the selection unit determines the priority of the first time source, the priority of the second time source, and the information received from the communication management device, and selects the first port or the second port A communication system characterized by this.
Citation Information
Patent Citations
Ensuring operation of a communication network in case of an abnormal traffic condition
EP3591929A1
Time Synchronization for Wireless Communications
JP2021507613A
Wireless node
JP2022040947A
JPP7118324B
Clock synchronization in the presence of security threats
US20150236807A1