Network data analysis function node and method
The NWDAF node automates application discovery by receiving and analyzing data from network function nodes, reducing 5GC load and improving detection efficiency and billing accuracy through reverse DNS lookup, addressing the challenges of manual discovery and high data processing costs.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NEC CORP
- Filing Date
- 2024-04-15
- Publication Date
- 2026-06-02
Smart Images

Figure 0007868630000001 
Figure 0007868630000002 
Figure 0007868630000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to communication systems. The present disclosure is particularly related to, but not exclusively related to, wireless communication systems and devices operating according to 3GPP (3rd Generation Partnership Project) standards or their equivalents or derivatives. The present disclosure is particularly related to, but not exclusively related to, data analysis and application detection in so-called "5G" (or next-generation) systems.
Background Art
[0002] <Abbreviations and Terms> 3GPP 3rd Generation Partnership Project 5GC 5G Core Network 5GS 5G System 5G-AN 5G Access Network ADC Application Detection and Control AF Application Function AMF Access and Mobility Management Function AN Access Network CC Country Code DL Downlink DNN Data Network Name DNS Domain Name System ]EIR Equipment Identity Register FQDN Fully Qualified Domain Name gNB Next Generation NodeB GPS Global Positioning System GPSI Generic Public Subscription Identifier IMEI International Mobile Equipment Identity IMEI SV International Mobile Equipment Identity Software Version IMSI International Mobile Subscriber Identity IP Internet Protocol MCC Mobile Country Code MM Mobility Management MT Machine Terminated MNC Mobile Network Code MNO Mobile Network Operator MSISDN Mobile Station International Subscriber Directory Number NAI Network Access Identifier NAS Non-Access-Stratum NEF Network Exposure Function NF Network Function NG Next Generation NG-RAN Next Generation-Radio Access Network NR New Radio NRF Network Repository Function NSSAI Network Slice Selection Assistance Information NWDAF Network Data Analytics Function OAM Operations, Administration and Maintenance OS Operating System OTA Over the Air OTT Over the Top PCC Policy and Charging Control PCF Policy Control Function PDB Packet Delay Budget PDU Protocol Data Unit PDR Packet Detection Rule PFD Packet Flow Description PEI Permanent Equipment Identifier PER Packet Error Rate PLMN Public Land Mobile Network RAN Radio Access Network RAT Radio Access Technologies RRC Radio Resource Control SBA Service-based Architecture SM Session Management SMF Session Management Function SMS Short Message Service S-NSSAI Single Network Slice Selection Assistance Information SUPI Subscription Permanent Identifier UE User Equipment UDM Unified Data Management UDR User Data Repository UPF User Plane Function UL Uplink URL Uniform Resource Locator URR Usage Reporting Rule
[0003] <Definition> For the purposes of this specification, the terms and definitions given in 3GPP TR (Technical Report) 21.905 (Non-Patent Document 1) and below apply. The terms defined in this specification take precedence over the definitions of the same terms in 3GPP TR 21.905 (Non-Patent Document 1).
[0004] <Background> The 3GPP working group is currently defining the 5G system. 3GPP TSG SA WG2 (SA2) specifies the 5G system architecture in 3GPP TS (Technical Specification) 23.501 (Non-Patent Document 2) and specifies the procedures in 3GPP TS 23.502 (Non-Patent Document 3). To provide network data analysis in the 5G network, a network function (NF) called the Network Data Analytics Function (NWDAF) is specified by SA2 in 3GPP TS 23.288 (Non-Patent Document 5).
[0005] Recently, for new use cases, new research has been proposed in SA2 to identify new types of outputs provided by the NWDAF. 3GPP TR 23.700-91 (Non-Patent Document 6) captures the latest results of this research.
Prior Art Documents
Non-Patent Documents
[0006]
Non-Patent Document 1
Non-licensed Document 4
Non-licensed Document 5
Non-licensed Document 6
Non-licensed Document 7
[0007] <Description of the assignment> The number of applications or services available on the market is continuously increasing, and the rate of new application releases is also accelerating very rapidly. Discovering and managing all applications using manually provisioned rules is time-consuming and costly.
[0008] To detect newly released applications, NWDAF needs to collect all necessary data from data plane nodes and perform data analysis according to NWDAF's current role in the 3GPP system. For example, target user data needs to be transferred from a user data processing entity, such as UPF or RAN, to NWDAF to detect traffic characteristics and provide new analysis for application discovery information.
[0009] However, this approach does not seem feasible. Firstly, NWDAF is designed as a control signaling node and should not process user data. Secondly, a huge amount of user data would need to be transmitted within 5GC, which would have a cost impact on 5GC.
[0010] An efficient mechanism is needed to automate application discovery while maintaining basic function assignments to each 3GPP logical node. [Means for solving the problem]
[0011] A network data analysis function (NWDAF) node according to one embodiment, A means for receiving a request from a network function node to detect a new application, including an indication with the value "New Application Analysis," UE (User Equipment) information, detection start and end times, and PFD (Packet Flow Description) information. A means for subscribing to data collection related to the new application to the SMF (session management function) node, Means for receiving the data related to the new application, including DNN (data network name), S-NSSAI (single-network slice selection assistance information), and a 3-tuple, from a UPF (user plane function) node via the SMF node, The system includes means for notifying the network function node of the analysis results, which include the DNN, the S-NSSAI, a 3-tuple added to the PFD information, a portion of the matching URL (Unified Resource Locator), domain name matching criteria, and information on applicable protocols. The aforementioned 3-tuple includes the server-side IP (Internet Protocol) address and port number.
[0012] A network function node in another form, A means for sending a request to an NWDAF (network data analytic function) node to detect a new application, including an indication with the value "New Application Analysis," UE (User Equipment) information, detection start and end times, and PFD (Packet Flow Description) information. The system includes means for receiving analysis results from the aforementioned NWDAF node, including DNN (data network name), S-NSSAI (single-network slice selection assistance information), a 3-tuple added to the PFD information, a portion of the matching URL (Unified Resource Locator), domain name matching criteria, and information on applicable protocols. The aforementioned 3-tuple includes the server-side IP (Internet Protocol) address and port number. The data related to the new application, including the DNN, the S-NSSAI, and the 3-tuple, is transmitted from the NWDAF node to the SMF (session management function) node via the UPF (user plane function) node when subscribing to data collection related to the new application.
[0013] A method for controlling a network data analytic function (NWDAF) node, according to another embodiment, The network function node receives a request to detect a new application, including an indication with the value "New Application Analysis," UE (User Equipment) information, detection start and end times, and PFD (Packet Flow Description) information. The SMF (session management function) node subscribes to data collection related to the new application, The UPF (user plane function) node receives the data related to the new application, including the DNN (data network name), S-NSSAI (single-network slice selection assistance information), and a 3-tuple, via the SMF node. This includes notifying the network function node of the analysis results, which include the DNN, the S-NSSAI, a 3-tuple added to the PFD information, a portion of the matching URL (Unified Resource Locator), domain name matching criteria, and information on applicable protocols. The aforementioned 3-tuple includes the server-side IP (Internet Protocol) address and port number.
[0014] A method for controlling a network function node in another aspect, Sending a request to the NWDAF (network data analytic function) node to detect a new application, including an indication with the value "New Application Analysis," UE (User Equipment) information, detection start and end times, and PFD (Packet Flow Description) information. The NWDAF node receives analysis results including DNN (data network name), S-NSSAI (single-network slice selection assistance information), a 3-tuple added to the PFD information, a portion of the matching URL (Unified Resource Locator), domain name matching criteria, and information on applicable protocols. The aforementioned 3-tuple includes the server-side IP (Internet Protocol) address and port number. The data related to the new application, including the DNN, the S-NSSAI, and the 3-tuple, is transmitted from the NWDAF node to the SMF (session management function) node via the UPF (user plane function) node when subscribing to data collection related to the new application. [Effects of the Invention]
[0015] The above-described embodiment may contribute to solving the above-described problem. [Brief explanation of the drawing]
[0016] [Figure 1] This timing (signaling) diagram schematically illustrates an exemplary procedure for new application detection in NWDAF, defining ADC rules. [Figure 2] This timing (signaling) diagram schematically illustrates an exemplary procedure for new application detection in NWDAF, defining ADC rules. [Figure 3] This is a timing (signaling) diagram illustrating an exemplary procedure for PCF that defines application detection related to PCC rules. [Figure 4] This is a timing (signaling) diagram illustrating an exemplary procedure for PCF that defines application detection related to PCC rules. [Figure 5] This figure schematically illustrates a mobile (cellular or wireless) communication system to which this embodiment can be applied. [Figure 6] Figure 5 is a block diagram showing the main components of a UE (Mobile Device). [Figure 7] Figure 5 is a block diagram showing the main components of an exemplary (R)AN node (base station). [Figure 8] Figure 5 is a block diagram showing the main components of a typical core network node (or function). [Modes for carrying out the invention]
[0017] <Detailed explanation> To address at least one of the above challenges, this disclosure describes two solutions.
[0018] ●Solution 1: NWDAF 11 defines Application Detection and Control (ADC) rules for new application detection. This provides operators with the flexibility to detect any specific application without requiring additional resources for user data processing.
[0019] ●Solution 2: PCF 12 defines PCC rules related to application discovery. This utilizes reverse DNS lookup, a DNS technique that determines domain names from IP addresses. NWDAF 11 can obtain URL and domain name information for packets from the IP addresses provided in the mismatched header packet report. This report reports packets in the default QoS flow that do not match either the packet filter or the PFD in the packet discovery rule. Therefore, UPF 10 does not need to send the entire user data to NWDAF 11 to extract the URL and domain name from the user data.
[0020] In this specification, the term "user data" may be interpreted as "user packet," "application data," or "application packet."
[0021] <Solution 1: NWDAF 11 defines ADC rules for new application discovery> The main idea of this solution is that NEF 14 requests NWDAF 11 to perform data analysis on new application detection accompanied by a search request. NWDAF 11 generates application detection and control (ADC) rules which are passed to PCF 12. PCF 12 generates new PCC rules which UPF 10 will use to detect new applications and reports them to NWDAF 11. NWDAF 11 performs data analysis and notifies the subscribed consumer (e.g., NEF 14) of the analysis results.
[0022] Figures 1 and 2 schematically show the timing (signaling) diagrams of an exemplary procedure for new application detection in NWDAF 11 that defines ADC rules.
[0023] Step 0: NEF 14 service consumers (e.g., SMF, OAM, AF) subscribe to the PFD management service.
[0024] Step 1: To obtain analytics information about new application discovery, an NWDAF consumer (e.g., NEF 14) invokes an analytics request procedure or any other relevant procedure, or sends an "Nnwdaf_AnalyticsInfo_request" message or any other relevant message to NWDAF 11 to request a new application discovery analytics report or notification from NWDAF 11.
[0025] The service consumer can be NEF 14.
[0026] This message from the NWDAF service consumer to NWDAF 11 includes the analysis ID, analysis filter information, information on traffic measurement and reporting, a list of PFDs, the target for analysis reporting, and the analysis target period. Parameters such as analysis filter information, information on traffic measurement and reporting, and the list of PFDs can be sent to NWDAF 11 in a separate message.
[0027] The analysis ID identifies the requested analysis, as described in 3GPP TS 23.288 (Non-Patent Literature 5). This solution uses the analysis ID to identify analyses related to new application detection. The analysis ID can have a new value, such as "new application detection".
[0028] In this disclosure, analysis filter information indicates the conditions that must be met to report analysis information and allows selection of the type of analysis information requested (e.g., a subset of all available analyses generated by NWDAF 11 for a given analysis ID), as described in 3GPP TS 23.288 (Non-Patent Literature 5). An example of analysis filter information is as follows: ●UE (GPSI / SUPI), or a list of UEs ● Home subscribers, visited subscribers, or visited subscribers with specific MCC and MNC. ● Information indicating an area of interest, which may include at least one of a cell ID, a list of cell IDs, a tracking area, a list of tracking areas, or a location object, as defined in IETF RFC RFC5580 (Non-Patent Literature 8). ● Access type, e.g., 3GPP access and / or non-3GPP access ● RAT type, e.g., NR, NB-IOT, unreliable non-3GPP, reliable non-3GPP, reliable IEEE 802.11 non-3GPP access, wired, wired cable, wired BBF. ● UPF address, or list of UPF addresses ● Number of sample PDU sessions to be tested ● A combination of the above information.
[0029] The analysis filter information can be called a search key.
[0030] The traffic measurement and reporting information indicates the target traffic measured by UPF 10. Furthermore, you can specify the measurement period, measurement thresholds, and report format. An example of traffic measurement and reporting information is as follows: ● Destination IPv4 address or range of destination IPv4 addresses ● Destination IPv6 address or range of destination IPv6 addresses ● An application identifier using wildcards or a list of application identifiers using wildcards (for example, the value may represent an application such as a URL or FQDN). ● DNN, S-NSSAI, combinations of DNN and S-NSSAI, list of DNNs, list of S-NSSAIs, list of combinations of DNN and S-NSSAI ● Measurement threshold ● Measurement time ● Amount of user data measured ● Number of identified target traffic ● Report format ● The volume of UL / DL packets of identified target traffic per specific period. For example, if a URL is specified for packet search and such a URL is assigned to a video content server, the total UL / DL packet count for video traffic will be reported for specific periods of time. ● The number of packets of identified target traffic for a specific period of time. For example, if a URL is specified for packet search, the number of URL matches is reported at specific intervals. Typically, URL matches are found in traffic for user DNS queries. ● A combination of the above information.
[0031] Information regarding traffic measurement and reporting can be called search criteria.
[0032] The PFD list is the complete set of the most recent PFDs available on the network. The PFD list is used by NWDAF 11 in step 13 to identify whether the reported traffic is existing or new.
[0033] The target of the analysis report indicates the object for which analysis information is requested. For example, the object may be a specific UE, a group of UEs, or all UEs, as described in 3GPP TS 23.288 (Non-Patent Literature 5). GPSI and SUPI can be used in the target of the analysis report.
[0034] The analysis target period is a specific time interval from the start time to the end time, as described in 3GPP TS 23.288 (Non-Patent Document 5).
[0035] Step 2: NWDAF 11 finds the relevant PCF 12 based on the search key or analysis filter information and sends the ADC rule. If the search key or analysis filter information includes SUPI, DNN, or S-NSSAI, NWDAF 11 issues Nbsf_Management_Discovery to find the relevant PCF 12.
[0036] NWDAF 11 can also find the relevant PCF 12 via NRF by calling the Nnrf_NFDiscovery_Request service with a TAI derived from the location of the preferred target NF or area of interest, as described in 3GPP TS 23.502 (Non-Patent Literature 3).
[0037] Step 3: NWDAF 11 generates ADC rules for new application discovery. ADC rules are generated based on analysis IDs, search criteria, or information regarding traffic measurement and reporting. ADC rules include rules related to application discovery and rules related to measurement and reporting.
[0038] Step 4: To collect information about the new application, NWDAF 11 invokes the New Application Discovery Information Subscription procedure or any other relevant procedure, or sends an “Npcf_EventExposure_Subscribe” message or any other message to the relevant PCF 12 to subscribe to new application discovery-related data. NWDAF 11 may send multiple messages to the PCF 12 based on search key or analysis filter information. The “Npcf_EventExposure_Subscribe” message or any other message to the relevant PCF 12 to subscribe to new application discovery-related data may include generated ADC rules to install the ADC rules in the PCF 12.
[0039] This message includes the event ID, event filter, event report target, notification target address (and notification correlation ID), event target duration, event report mode, DNN, and NSSAI. The event ID may contain the new value "ADC rule for new application detection".
[0040] The Event ID identifies the type of event being subscribed to (e.g., PDU session release), as described in 3GPP TS 23.502 (Non-Patent Document 3). In this message, the Event ID identifies the type of event related to the ADC rule for new application discovery.
[0041] The event filter specifies the conditions that must be met to notify of subscribed event IDs, and includes the event-related parameters to match and their values. The event filter is event ID dependent, as described in 3GPP TS 23.502 (Non-Patent Literature 3).
[0042] The target of an event report indicates a specific UE, a group of UEs, or all UEs, as described in 3GPP TS 23.502 (Non-Patent Literature 3). GPSI and SUPI can be used to identify specific UEs within the target of an event report.
[0043] The target of the event report can be the same as the target of the analysis report.
[0044] Using the notification target address (and notification correlation ID), notifications received from an event provider can be correlated with a service consumer's subscription, as described in 3GPP TS 23.502 (Non-Patent Document 3).
[0045] The analysis target period is a specific time interval from the start time to the end time.
[0046] The event reporting mode is a mode for event reporting. For example, as described in 3GPP TS 23.502 (Non-Patent Literature 3), reports can be made for each event up to a maximum number of times, periodically, or for a maximum period of time.
[0047] Step 5: PCF 12 stores the ADC rules received from NWDAF 11. Based on the ADC rules, PCF 12 updates the existing PCC rules to add new application detection and control functions. These new rules relate to packet detection and usage information collection and reporting, and the purpose of these PCC rules is to detect new applications and measure and report the detected new applications. Usage information collection and reporting includes usage information reporting criteria and usage information measurement. The added new rules may also include information on new packet detection rules and new usage reporting rules. The new packet detection rules may include at least one piece of information related to packet filters and PFDs. The new usage reporting rules may include information on reporting criteria (or more criteria).
[0048] Step 6: PCF 12 communicates the new PCC rules to SMF 13, as described in 3GPP TS23.502 (Non-Patent Document 3).
[0049] Step 7: PCF 12 invokes the new application detection procedure or any other related procedure, or sends an Nsmf_EventExposure_Subscribe message to SMF 13 to subscribe to data related to the new application detection. The data related to the new application detection is detected, measured, and reported based on the new PCC rules for the new application detection.
[0050] Steps 6 and 7 can be performed in a single step.
[0051] Step 8: Based on the new PCC rules for new application detection received from PCF 12, SMF 13 generates new packet detection rules and new usage reporting rules and instructs UPF 10 to detect, measure, and report application traffic using the new packet detection rules and new usage reporting rules using the N4 session change procedure as described in TS23.502. The new packet detection rules may include at least one piece of information regarding packet filters and PFDs. The new usage reporting rules may include information on reporting criteria (or more criteria).
[0052] Step 9: UPF 10 performs packet inspection to detect, measure, and report new application traffic based on the new packet detection rules and new usage reporting rules received in Step 8. If a packet in the default QoS flow does not match either the packet filter or PFD in the new packet detection rule, it is detected, measured, and reported by UPF 10.
[0053] Step 10: When the reporting criteria indicated by the new usage reporting rules received in Step 8 are met, UPF 10 sends an application discovery report to SMF 13.
[0054] This application discovery report lists packets that do not have an application ID and do not match any of the packet filters in the default QoS flow of the packet discovery rules.
[0055] For each detected packet, this application discovery report includes at least one parameter: DNN, S-NSSAI, 3-tuple, and destination FQDN. The 3-tuple contains the protocol ID of the protocol above IP, the destination IP address, and the destination port number.
[0056] Step 11: SMF 13 reports the application discovery report received from UPF 10 by sending an Nsmf_EventExposure_Notify message or any other relevant message to PCF 12.
[0057] Step 12: PCF 12 forwards the Npcf_EventExposure_Notify message or any other message to NWDAF 11 to report the application discovery report received from SMF 13.
[0058] Step 13: Based on the application discovery report received from PCF 12, NWDAF 11 performs data analysis and generates analysis results regarding new application discovery.
[0059] The analysis results for detecting new applications include at least one of the following: DNN, S-NSSAI, a list of new PFDs recommended for new applications, a list of new 3-tuples recommended for addition to existing PFDs, and a list of 3-tuples recommended for removal from existing PFDs.
[0060] The list of recommended new PFDs for new applications includes a 3-tuple (containing the protocol, server-side IP address, and port number), a key part of the URL to be matched, domain name matching criteria, and information about applicable protocols, along with at least one of the following parameters.
[0061] The list of new 3-tuples that are recommended to be added to existing PFDs should include a 3-tuple (containing the protocol, server-side IP address, and port number), and at least one of the following parameters: a key part of the URL to match, domain name matching criteria, and information about applicable protocols.
[0062] The list of 3-tuples that are recommended to be removed from existing PFDs includes at least one of the following parameters: a 3-tuple (including protocol, server-side IP address and port number), a key part of the URL to match, domain name matching criteria, and information about applicable protocols.
[0063] Step 14: Based on the results of the data analysis, NWDAF 11 notifies the relevant service consumer of the analysis results by calling a new application discovery notification procedure or any other relevant procedure, or sends an Nnwdaf_AnalyticsInfo_Notify message or any other message to the relevant service consumer (e.g., NEF 14) to report / notify the analysis results regarding the new application discovery. This message includes notification correlation information and the analysis results regarding the new application discovery.
[0064] The analysis results may include the following information: ● New PFD recommended for new applications ● New 3-tuples recommended for addition to existing PFDs ● 3-tuples that are recommended to be removed from existing PFDs
[0065] Notification correlation information is a notification target address (and notification correlation ID) that allows notifications received from NWDAF 11 to be correlated with a service consumer's subscription, as described in 3GPP TS 23.288 (Non-Patent Document 5). Notification correlation information can be used instead of the optional parameters analysis ID and analysis filter in the above message.
[0066] Step 15: NEF 14 notifies the Nnef_PFDManagement service consumer of the latest PFD list. This list is updated based on NWDAF 11's analysis results regarding new application detection.
[0067] The service consumer can be SMF 13, OAM, or AF.
[0068] <Solution 2: PCF 12 defines application discovery rules> The main idea of this solution is for PCF 12 to communicate new application detection-related PCC rules to SMF 13. NEF 14 subscribes to the NWDAF 11 service to detect new applications, and NWDAF 11 subscribes to SMF 13's reports on packets from new application traffic. SMF 13 instructs UPF 10 to report packets that do not have an application ID and do not match any packet filters in the default QoS flows of PDR and URR. UPF 10 performs packet inspection and reports new application packets. NWDAF 11 analyzes the mismatched packet header reports, generates a list of corresponding PFD IDs, and provides the NEF 14 with a list of corresponding PFDs. NEF 14 assigns an official PFD ID to each new PFD, assigns an application ID for the new PFD, and sends the list of PFD IDs along with the corresponding application IDs to SMF 13. SMF 13 sends the updated PDR to UPF10 for application detection.
[0069] Figures 3 and 4 schematically show the timing (signaling) diagrams of an exemplary procedure in PCF 12 that defines application detection-related PCC rules.
[0070] Step 1: NEF 14 subscribes to an application discovery policy change that includes an event ID with the new value "Application Discovery Policy Change" by calling the event subscription procedure or any other procedure, or by sending the "Npcf_EventExposure_Subscribe" message or any other message to PCF 12.
[0071] Step 2: In response to the new event ID, PCF 12 transmits new application detection-related PCC rules to SMF 13 using similar procedures described in TS23.502 (Non-Patent Document 3) and TS23.503 (Non-Patent Document 4). The new application detection-related PCC rules relate to packet detection and usage information collection and reporting, and the purpose of these PCC rules is to detect new application packets that do not have an application ID and do not match any packet filter in the default QoS flow, and to measure and report the detected new applications. Usage information collection and reporting includes usage information reporting criteria and usage information measurement.
[0072] Step 3: PCF 12 notifies NEF 14 of the policy change regarding application discovery via an Npcf_EventExposure_Notify message containing an event ID with the new value "Policy change regarding application discovery".
[0073] Step 4: To obtain analytics information about new application discovery, the NWDAF consumer (e.g., NEF 14) invokes the analytics request procedure or any other procedure, or sends the "Nnwdaf_AnalyticsInfo_request" message or any other message to NWDAF 11 to request a new application discovery analytics report or notification from NWDAF 11.
[0074] Consumers can use NEF 14.
[0075] This message includes the analysis ID, a list of existing application IDs, a list of existing PFDs, areas of interest, analysis filter information, the target of the analysis report, and the target analysis period.
[0076] The analysis ID identifies the requested analysis, as described in 3GPP TS 23.288 (Non-Patent Document 5). The analysis ID is used to identify analyses relating to new application detection. The analysis ID may have a new value, such as "new application detection".
[0077] The analysis filter information indicates the conditions that must be met in order to report the analysis information, and allows the selection of the type of analysis information requested (e.g., a subset of all available analyses generated by NWDAF 11 for a given analysis ID), as described in 3GPP TS 23.288 (Non-Patent Literature 5).
[0078] The list of existing application IDs is the complete set of applications recognized on the network. UPF 10 uses the list of existing PFDs to identify whether an inspected packet is from a known application or a new application.
[0079] The list of existing PFDs is the complete set of the most recent PFDs available on the network. NWDAF 11 uses the list of existing PFDs to identify whether the reported traffic is existing or new.
[0080] The target of the analysis report indicates the object for which analysis information is requested. For example, the object may be a specific UE, a group of UEs, or any UE (i.e., all UEs), as described in 3GPP TS 23.288 (Non-Patent Literature 5). GPSI and SUPI can be used in the target of the analysis report.
[0081] The analysis target period is a specific time interval from the start time to the end time.
[0082] Step 5: NWDAF 11 subscribes to data related to the new application discovery by calling a new application discovery procedure or any other procedure, or by sending an Nsmf_EventExposure_Subscribe message or any other message to SMF 13. The data related to the new application discovery is discovered, measured, and reported based on the new PCC rules for the new application discovery. The message may include an event ID with a new value, "The packet does not match any packet filter."
[0083] Step 6: Based on the application detection-related PCC rules received from PCF 12 in Step 2 and the new event ID received in Step 5, SMF 13 generates new packet detection rules and new usage reporting rules and instructs UPF 10 to detect, measure, and report application traffic as described in 3GPP TS 23.503 (Non-Patent Literature 4) and 3GPP TS 29.244 (Non-Patent Literature 7).
[0084] Step 7: SMF 13 sends an N4 session change request message or any other message to UPF 10 to communicate new application detection (i.e., usage reporting rules for measurement and reporting (inconsistent packet headers)).
[0085] Step 8: UPF 10 performs packet inspection to detect, measure, and report new application traffic based on the new packet detection rules and new usage reporting rules, and to examine the packet header. If a packet does not have an application ID and does not match any packet filter in the default QoS flow of the packet detection rule, it is detected, measured, and reported.
[0086] Step 9: Once the reporting criteria are met, UPF 10 sends a mismatched packet header report to SMF 13. The mismatched packet header report is called an application discovery report, and its purpose is to report packets that do not have an application ID and do not match any packet filters in the default QoS flow of the packet discovery rule.
[0087] This report includes at least one of the following parameters for the detected packets: DNN, S-NSSAI, 3-tuple, and destination FQDN. The 3-tuple contains the protocol ID of the protocol above IP, the destination IP address, and the destination port number.
[0088] Step 10: SMF 13 sends an Nsmf_EventExposure_Notify message or any other message to NWDAF 11 to report the mismatched packet header report received from UPF 10.
[0089] Step 11: Based on the application discovery report received from SMF 13, NWDAF 11 performs data analysis and generates analysis results regarding new application discovery.
[0090] Step 12: Based on the data analysis results, NWDAF 11 notifies the relevant service consumer of the analysis results by calling a new application discovery notification procedure or any other procedure, or sends an Nnwdaf_AnalyticsInfo_Notify message or any other message to NEF 14 to report / notify the analysis results regarding the new application discovery. This message includes notification correlation information and analysis results.
[0091] The analysis results include at least one of the following parameters: DNN, S-NSSAI, a list of new PFDs recommended for new applications, a list of new 3-tuples recommended to be added to existing PFDs, and a list of 3-tuples recommended to be removed from existing PFDs. The list of new PFDs recommended for new applications includes at least one of the following parameters: 3-tuples (including protocol, server-side IP address, and port number), key parts of the URL to be matched, domain name matching criteria, and information on applicable protocols.
[0092] The list of new 3-tuples that are recommended to be added to existing PFDs should include a 3-tuple (containing the protocol, server-side IP address, and port number), and at least one of the following parameters: a key part of the URL to match, domain name matching criteria, and information about applicable protocols.
[0093] The list of 3-tuples that are recommended to be removed from existing PFDs includes at least one of the following parameters: a 3-tuple (including protocol, server-side IP address and port number), a key part of the URL to match, domain name matching criteria, and information about applicable protocols.
[0094] Notification correlation information is a notification target address (and notification correlation ID) that allows notifications received from NWDAF 11 to be correlated with a service consumer's subscription, as described in 3GPP TS 23.288 (Non-Patent Document 5). Notification correlation information can be used instead of the optional parameters analysis ID and analysis filter in the above message.
[0095] Step 13: NEF 14 assigns a PFD ID to each new PFD and associates it with an Application ID. If possible, NEF 14 contacts AF to obtain the Application ID. Otherwise, NEF 14 assigns a unique Application ID without AF's assistance.
[0096] Steps 14-16: NEF 14 notifies UDR 15 to update the corresponding PFD.
[0097] Step 17: NEF 14 notifies consumers of the Neff PFD management service of the latest PFD list. This list is updated based on NWDAF 11's analysis results regarding new application detection.
[0098] The service consumer can be SMF 13, OAM, or AF.
[0099] <Summary> Beneficial in nature, the above embodiments include, but are not limited to, one or more of the following functions:
[0100] 1) In the existing scheme, packet inspection is performed in NWADF 11, which generates a large amount of traffic between UPF 10 and NWDAF 11. This increases signaling overhead and exhausts the capacity of the associated NF. In the proposed solution, packet inspection is performed in UPF 10, which sends only application discovery reports to NWDAF 11, rather than all packets. This significantly reduces traffic between UPF 10 and NWDAF 11.
[0101] 2) Two new solutions have been proposed for detecting new applications. One new solution is for NWDAF 11 to define ADC rules for new application detection, which will give operators the flexibility to detect any specific application, improve resource allocation, and make billing more accurate. The other solution is for PCF 12 to define application detection rules that utilize reverse DNS lookups. In this way, NWDAF 11 can obtain the URL and domain name information of packets from the IP addresses provided in the mismatched header packet report. Therefore, UPF 10 does not need to send the entire application packet to NWDAF 11 in order to extract the URL and domain name from the packet.
[0102] 3) It is proposed that new parameter search keys and search conditions be provided to NWDAF 11 in order to generate ADC rules for application detection.
[0103] 4) Based on the new PCC rules for new packet detection, SMF 13 derives new packet detection rules and usage reporting rules.
[0104] 5) UPF 10 performs packet inspection and generates an application detection report based on the new packet detection rules and usage reporting rules.
[0105] 6) After detecting a new packet header, UPF 10 sends a mismatched packet header report for packets that do not have an application ID and do not match any packet filter in the default QoS flow.
[0106] To provide these functions, the above embodiments describe an exemplary method that includes at least some of the following steps:
[0107] 1) NEF 14 subscribes to the NWDAF service to detect new applications. 2) PCF 12 transmits new application detection-related PCC rules to SMF 13. 3) SMF 13 instructs UPF 10 to report packets according to the new application detection rules and usage reporting rules. 4) UPF 10 performs packet inspection and reports to SMF 13 if the reporting criteria are met. 5) SMF 13 sends a new application detection report to NWDAF 11. 6) NWDAF 11 performs data analysis on the new application detection report and generates analysis results that derive the corresponding PFD. 7) NWDAF 11 notifies NEF 14 of the analysis results.
[0108] <Benefits> New methods have been proposed for detecting new application traffic. These solutions allow networks to automatically detect new application traffic without placing a significant signaling load on the network.
[0109] <System Overview> Figure 5 schematically shows a mobile (cellular or wireless) communication system 1 to which the above embodiment can be applied.
[0110] In this network, users of mobile devices 3 (UE) can communicate with each other and with other users via base stations 5 and the core network 7 using appropriate 3GPP RATs, such as E-UTRA and / or 5G RAT (radio access technology). It will be understood that several base stations 5 form a (R)AN ((radio) access network). As those skilled in the art will understand, one mobile device 3 and one base station 3 (RAN) are shown in Figure 5 for illustrative purposes, but the system, if implemented, typically includes other base stations and mobile devices (UEs).
[0111] Each base station 5 controls one or more associated cells (directly or via other nodes such as home base stations, relays, remote radio heads, and distributed units). A base station 5 that supports the E-UTRA protocol to mobile devices 3 may be called an "ng-eNB," and a base station 5 that supports next-generation protocols to mobile devices 3 may be called a "gNB." It will be understood that some base stations 5 may be configured to support both 4G and 5G and / or any other 3GPP or non-3GPP communication protocols.
[0112] Mobile device 3 and its serving base station 5 are connected via appropriate air interfaces (e.g., so-called "Uu" interfaces). Adjacent base stations 5 are connected to each other via appropriate base station-to-base station interfaces (e.g., so-called "X2" interfaces, "Xn" interfaces). Base stations 5 / access networks are also connected to core network nodes via appropriate interfaces (e.g., so-called "NG-U" interfaces (for the user plane), so-called "NG-C" interfaces (for the control plane)).
[0113] The core network 7 typically includes logical nodes (or "functions") to support communications in the communication system 1. Typically, for example, the core network 7 of a "next-generation" / 5G system includes, among other functions, a control plane function (CPF) and a user plane function (UPF). The core network 7 may also include, among other things, a Network Data Analytics Function (NWDAF) 11, a Policy Control Function (PCF) 12, a Session Management Function (SMF) 13, and a Network Exposure Function (NEF) 14. Although not shown in Figure 5, the core network 7 may also be connected to at least one application function (AF) / application server (AS). The core network 7 also provides connectivity to an external IP network / data network 20 (such as the Internet).
[0114] The components of this system 1 are configured to perform one or more of the above embodiments for the purpose of discovering data analysis support applications.
[0115] <User Equipment (UE)> Figure 6 is a block diagram showing the main components of the UE (Mobile Device 3) shown in Figure 5. As illustrated, the UE 3 includes a transceiver circuit 31 capable of transmitting and receiving signals to and from connected nodes via one or more antennas 33. Although not necessarily shown in Figure 6, the UE 3 of course has all the usual functions of a conventional mobile device (such as a user interface 35), which may be provided by any one or any combination of hardware, software, and firmware as needed. The controller 37 controls the operation of the UE 3 according to software stored in memory 39. The software may be pre-installed in memory 39 and / or downloaded via the communication system 1 or from an RMD (removable data storage device). The software includes, among other things, an operating system 41 and a communication control module 43. The communication control module 43 is responsible for processing (generating / transmitting / receiving) signaling messages and uplink / downlink data packets between the UE 3 and other nodes, including the (R)AN node 5, AF, and core network nodes. Such signaling includes well-formatted requests and responses related to the discovery of data analysis support applications.
[0116] <(R)AN node> Figure 7 is a block diagram showing the main components of an exemplary (R)AN node 5 (base station) as shown in Figure 5. As illustrated, the (R)AN node 5 includes a transceiver circuit 51 that can transmit and receive signals to and from a connected UE 3 via one or more antennas 53, and to and from other network nodes (directly or indirectly) via a network interface 55. The network interface 55 typically includes a suitable base station-to-base station interface (e.g., X2 / Xn) and a suitable base station-to-core network interface (e.g., NG-U / NG-C). The controller 57 controls the operation of the (R)AN node 5 according to software stored in memory 59. The software may be pre-installed in memory 59 and / or downloaded via the communication system 1 or from an RMD (removable data storage device). The software includes, among other things, an operating system 61 and a communication control module 63. The communication control module 63 is responsible for handling (generating / transmitting / receiving) signaling between the (R)AN node 5 and other nodes such as UE 3 and core network nodes. Such signaling includes appropriately formatted requests and responses related to the discovery of data analysis support applications.
[0117] <Core Network Node> Figure 8 is a block diagram showing the main components of a typical core network node (or function) as shown in Figure 5, e.g., UPF 10, NWDAF 11, PCF 12, SMF 13, and NEF 14. As shown, the core network node includes a transceiver circuit 71 capable of transmitting and receiving signals to and from other nodes (including UE 3 and (R)AN node 5) via a network interface 75. A controller 77 controls the operation of the core network node according to software stored in memory 79. The software may be pre-installed in memory 79 and / or downloaded via communication system 1 or from an RMD (removable data storage device). The software includes, among other things, an operating system 81 and at least a communication control module 83. The communication control module 83 is responsible for handling (generating / transmitting / receiving) signaling between the core network node and other nodes such as UE 3, (R)AN node 5, and other core network nodes. Such signaling includes appropriately formatted requests and responses related to data analysis support application discovery.
[0118] <Changes and Alterations> Detailed embodiments are described above. As those skilled in the art will understand, many modifications and substitutions can be made to the above embodiments while still benefiting from the inventions embodied therein. Only a few of these substitutions and modifications are described here as examples.
[0119] For the sake of clarity, the above description assumes that UE 3, (R)AN node 5, and core network node 7 have several separate modules (such as a communication control module). These modules may thus be provided for specific applications, for example, if an existing system is modified to implement the above embodiments, or for other applications, for example, a system designed from the outset with the functionality of the present invention in mind. However, because these modules are integrated into the operating system or the entire code, they may not be recognized as separate entities. These modules may also be implemented in software, hardware, firmware, or a combination thereof.
[0120] Each controller may include any suitable form of processing circuitry, including, but not limited to, one or more hardware-implemented computer processors, microprocessors, CPUs (central processing units), ALUs (arithmetic logic units), I / O (input / output) circuits, internal memory / cache (programs and / or data), processing registers, communication buses (e.g., control buses, data buses and / or address buses), DMA (direct memory access) functions, hardware or software-implemented counters, pointers, and / or timers.
[0121] In the above embodiments, several software modules have been described. As those skilled in the art will understand, the software modules may be provided in compiled or uncompiled form, or supplied to UE 3, (R)AN node 5, and core network node 7 as signals on a computer network or on a recording medium. Furthermore, the functions performed by some or all of this software may be performed using one or more dedicated hardware circuits. However, the use of software modules is preferred because it facilitates the updating of UE 3, (R)AN node 5, and core network node 7 in order to update their functions.
[0122] The above embodiments can also be applied to "non-mobile" or generally fixed user devices.
[0123] While the present invention has been specifically shown and described with reference to its exemplary embodiments, the invention is not limited to these embodiments. Those skilled in the art will understand that various modifications, as formally and in detail described herein, can be made without departing from the spirit and scope of the invention as defined by the claims.
[0124] This application claims priority based on European Provisional Patent Application No. 20187246.2, filed on 22 July 2020, and incorporates all of its disclosures herein. [Explanation of Symbols]
[0125] 1. Mobile (cellular or wireless) communication system 3. Mobile Devices (UE) 5. Base Station ((R)AN Node) 7 Core Network 10 UPF (USER PLANE FUNCTION) 11 NWDAF(NETWORK DATA ANALYTICS FUNCTION) 12 PCF(POLICY CONTROL FUNCTION) 13 SMF(SESSION MANAGEMENT FUNCTION) 14 NEF(NETWORK EXPOSURE FUNCTION) 15. UDR (USER DATA REPOSITORY) 20 External IP Network 31 Transceiver Circuit 33 Antennas 35 User Interface 37 Controllers 39 memory 51 Transceiver Circuit 53 Antenna 55 Network Interfaces 57 Controllers 59 memory 61 Operating Systems 63 Communication control module 71 Transceiver Circuit 75 Network Interfaces 77 Controllers 79 memory 81 Operating Systems 83 Communication control module
Claims
1. A network data analysis function node used in a communication system, A means for receiving a first message from a consumer node, which includes an analysis identifier (ID) that identifies the analysis of the application, A means for receiving the aforementioned analysis ID and sending a second message to the session management node toward the user plane function node, including an event ID that identifies the event corresponding to the analysis indicated by the aforementioned analysis ID, A means for receiving a third message, which includes, as data corresponding to the event reported by the user plane function node, information indicating a protocol ID, an Internet Protocol (IP) address, a port number, and information regarding a domain name. A means for deriving information regarding the analysis of a PFD, which includes a list of Packet Flow Description (PFD) information that is recommended for the application in response to the analysis of the data, and which includes at least one of the following: a 3-tuple containing the protocol ID, the IP address, and the port number, and information regarding the domain name, by receiving the protocol ID, the IP address, and the port number, and information regarding the domain name, The system includes means for transmitting a fourth message to the consumer node, which includes a list of PFD information and information relating to the analysis of the PFD. Network data analysis function node.
2. The aforementioned network data analysis function node includes a Network Data Analytics Function (NWDAF). A network data analysis function node according to claim 1.
3. The consumer node is equipped with a Network Exposure Function (NEF). A network data analysis function node according to claim 1 or 2.
4. The aforementioned user plane function node includes a User Plane Function (UPF), A network data analysis function node according to claim 1 or 2.
5. A method for a network data analysis function node used in a communication system, The consumer node receives a first message containing an analysis identifier (ID) that identifies the analysis related to the application. Upon receiving the aforementioned analysis ID, the session management node sends a second message to the user plane function node, which includes an event ID that identifies the event corresponding to the analysis indicated by the aforementioned analysis ID. A third message is received, which, as data corresponding to the event reported by the user plane function node, includes information indicating the protocol ID, the Internet Protocol (IP) address, the port number, and information regarding the domain name. By receiving information indicating the protocol ID, the IP address, and the port number, and information regarding the domain name, the analysis of the data derives information regarding the analysis of a PFD, which comprises a list of Packet Flow Description (PFD) information that is recommended for the application in response to the analysis and includes at least one of the following: a 3-tuple containing the protocol ID, the IP address, and the port number, and information regarding the domain name. A fourth message is sent to the consumer node, which includes information relating to the analysis of the PFD, comprising a list of the PFD information. method.
6. The aforementioned network data analysis function node includes a Network Data Analytics Function (NWDAF). The method according to claim 5.
7. The consumer node is equipped with a Network Exposure Function (NEF). The method according to claim 5 or 6.
8. The aforementioned user plane function node includes a User Plane Function (UPF), The method according to claim 5 or 6.