A method for predicting and / or detecting control signaling that poses a risk of at least partially overloading a mobile communications network.

JP7904993B2Active Publication Date: 2026-08-13NTT DOCOMO INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2026-08-13

Smart Images

  • Figure 0007904993000001
    Figure 0007904993000001
  • Figure 0007904993000002
    Figure 0007904993000002
  • Figure 0007904993000003
    Figure 0007904993000003
Patent Text Reader

Abstract

According to one embodiment, a method for predicting and / or detecting control signaling that has a risk of at least partially overloading a mobile communication network is described, comprising the steps of collecting metrics related to control plane traffic between a first mobile communication network component and one or more second mobile communication network components of the mobile communication network, receiving a notification that the first mobile communication network component has detected an anomalous behavior pattern, and, in response to receiving the notification, using the metrics to predict and / or determine whether control signaling is present that has a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a method for detecting control signaling having a risk of at least partially overloading a mobile communication network.

Background Art

[0002] The signaling load in a mobile communication system can vary drastically. A spike in the signaling load, a so-called (control plane) signaling storm, can be caused by errors (e.g., errors introduced in a policy), attacks, or other exceptional events such as when a batch of, for example, Internet of Things (IoT) devices are deployed, where a large number of devices (e.g., IoT devices) are connected simultaneously. Such events can lead to an overload of part of the mobile communication network, which can result in service disruptions, outages, and thus, for example, a bad user experience and service level agreement (SLA) penalties for the network operator. Therefore, in order to minimize or, ideally, avoid service downtime, an effective approach for predicting and detecting in advance control signaling having a risk of at least partially overloading a mobile communication network and, in some cases, mitigating it is desired.

Summary of the Invention

[0003] According to one embodiment, a method is provided for predicting and / or detecting control signaling that poses a risk of at least partially overloading a mobile communications network, comprising the steps of: collecting metrics relating to control plane traffic between a first mobile communications network component and one or more second mobile communications network components of the mobile communications network; receiving a notification that the first mobile communications network component has detected an exceptional operating pattern; and, in response to receiving the notification, using the metrics to predict and / or determine whether there is control signaling that poses a risk of overloading the first mobile communications network component and / or one or more second mobile communications network components. [Brief explanation of the drawing]

[0004] In the drawings, similar reference numerals generally indicate the same parts across different drawings. The drawings are not necessarily to scale, and rather the emphasis is on illustrating the principles of the invention. Various embodiments are described below with reference to the following drawings. [Figure 1] This refers to a mobile communication system, specifically a 5G communication system in this example. [Figure 2] This shows the signaling storm on the N1 reference point regarding the registration operation. [Figure 3] This shows a signaling storm on the N11 reference point regarding the operation of the Protocol Data Unit (PDU) session establishment service. [Figure 4] This shows a signaling storm on the N33 reference point regarding the operation of the public service. [Figure 5] This shows a signaling storm on the N4 reference point regarding the operation of the session refresh service. [Figure 6] A flowchart illustrating the prediction and / or detection and mitigation of abnormal signaling patterns is shown. [Figure 7]Figure 6 shows the flow for detecting a User Equipment (UE) registration signaling storm (corresponding to Figure 2). [Figure 8] Figure 6 shows the flow for detecting a PDU establishment signaling storm (corresponding to Figure 3). [Figure 9] Figure 6 shows the flow for detecting an Application Function (AF) request signaling storm (corresponding to Figure 4). [Figure 10] Two alternative examples of how mitigation mechanisms may be triggered by various embodiments are presented. [Figure 11] A flowchart illustrating a method for detecting control signaling that poses a risk of at least partially overloading a mobile communications network is shown. [Modes for carrying out the invention]

[0005] The following detailed description refers to the accompanying drawings illustrating specific details and embodiments of the present disclosure in which the present invention may be carried out. Other embodiments may be used without departing from the scope of the present invention, and structural, logical, and electrical modifications may be made. Since some embodiments of the present disclosure may be combined with one or more other embodiments of the present disclosure to form new embodiments, the various embodiments of the present disclosure are not necessarily mutually exclusive.

[0006] Various examples corresponding to the aspects of this disclosure are described below.

[0007] Example 1 is a method for predicting and / or detecting control signaling that poses a risk of at least partially overloading a mobile communications network, The steps include: collecting metrics relating to control plane traffic between a first mobile communication network component and one or more second mobile communication network components of a mobile communication network; The first mobile communication network component receives a notification that it has detected an exceptional operating pattern, - In response to receiving a notification, the system uses metrics to predict and / or determine whether there is a control signaling that poses a risk of overloading a first mobile communication network component and / or one or more second mobile communication network components. This method includes [something].

[0008] Example 2 is the method of Example 1, and the exceptional operating pattern is the exceptional operating pattern of the first mobile communication network component.

[0009] Example 3 is the method of Example 1 or 2, and the exceptional operating pattern includes an exceptional pattern of the internal operation of the first mobile communication network component.

[0010] Example 4 is one of the methods in Examples 1-3, and the exceptional operating pattern includes an exceptional signaling pattern of signaling between one or more second mobile communication network components and a first mobile communication network component.

[0011] Example 5 is one of the methods in Examples 1-4, where the first mobile communication network component is a core network function of the core network of the mobile communication network, and / or one or more second mobile communication network components are core network functions of the core network of the mobile communication network.

[0012] Example 6 is one of the methods in Examples 1-4, where the first mobile communications network component is a core network function of the core network of the mobile communications network, and / or one or more second mobile communications network components are one or more components of the radio access network of the mobile communications network.

[0013] Example 7 is any one of Examples 1 to 6, and includes the step of predicting and / or determining, by a machine learning model, whether there is control signaling having a risk of overloading a first mobile communication network component and / or one or more second mobile communication network components.

[0014] Example 8 is the method of Example 7, and the machine learning model receives a metric as input.

[0015] Example 9 is the method of Example 7 or 8, the notification includes information on an exceptional operating state, and the machine learning model receives information on the exceptional operating state as input.

[0016] Example 10 is any one of Examples 1 to 9, and includes the step of triggering a mitigation mechanism configured to reduce the load of a first mobile communication network component and / or one or more second mobile communication network components when it is predicted and / or determined that there is control signaling having a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components.

[0017] Example 11 is any one of Examples 1 to 10, and the metric includes one or more of the number and / or rate of request messages, the number and / or rate of response messages, the number and / or rate of subscribe messages, the number and / or rate of notification messages, and the number and / or rate of request rejections.

[0018] Example 12 is any one of Examples 1 to 11, and the exceptional operating state is · the number and / or rate of messages received by a first mobile communication network component from one or more second mobile communication network components exceeding a predetermined signaling threshold, · the load of the first mobile communication network component exceeding a predetermined load threshold, · The number of service - providing instances of the first mobile communication network component for one or more second mobile communication network components exceeds a predetermined service - providing threshold. · The message buffer level of the first mobile communication network component exceeds a predetermined buffer level. · The rate of memory allocation of the first mobile communication network component exceeds a predetermined memory - allocation threshold. · The rate of packet discard experienced by the first mobile communication network component exceeds a predetermined packet - discard threshold. · The rate of thread and / or process creation of the first mobile communication network component exceeds a predetermined thread / process - creation threshold. · The mass - storage input / output latency of the first mobile communication network component exceeds a predetermined input / output latency threshold. · The number of sockets of the Transmission Control Protocol and / or User Datagram Protocol exceeds a predetermined socket threshold is at least one or more of the above.

[0019] Example 13 is an overload detection and mitigation system for a mobile communication network configured to execute any one of the methods of Examples 1 - 12.

[0020] Example 14 is the overload detection and mitigation system of Example 13, configured to perform collection of metrics, reception of notifications, and prediction and / or determination of whether there is control signaling having a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components, and configured to notify the first communication network component, one or more second communication network components, and / or a fourth communication network component about the result of the prediction and / or determination.

[0021] Example 15 is an overload detection and mitigation system of Example 14, wherein a first communication network component, one or more second communication network components, and / or a fourth communication network component are configured to trigger a mitigation mechanism configured to reduce the load on the first mobile communication network component and / or one or more second mobile communication network components when it is predicted and / or determined that there is control signaling that poses a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components.

[0022] It should be noted that one or more features of any of the above examples may be combined with any one of the other examples. In particular, the examples described for apparatus are equally valid for methods.

[0023] In a further embodiment, a computer program and computer-readable medium are provided that, when executed by a computer, include instructions causing the computer to perform any one of the methods described above.

[0024] The following provides a more detailed explanation of various examples.

[0025] Figure 1 shows a mobile communication system 100, which in this example is a 5G communication system.

[0026] The mobile communication system 100 includes multiple UE101 (on the terminal side), and on the network side • Multiple (wireless) access networks 102 • Core network 103 including the following (core) network function (NF) ○ Access and Mobility Management Function (AMF) 104 ○Session Management Function (SMF) 105 ○ Unified Data Management (UDM) 106 ○Network Slice Selection Function (NSSF) 107 ○ Authentication Server Function (AUSF) 108 ○Policy Control Function (PCF) 109 ○Application Function (AF) 110 ○User Plane Function (UPF) 111 ○Network Exposure Function (NEF) 112 ○Network Slice Admission Control Function (NSACF) 113 ○ Network slice-specific authentication and authorization functions 114 ○Network Data Analytics Function (NWDAF) 115 (shown here without connections to other core network functions for simplicity, but in reality, it can be connected to most of the above).

[0027] • Data Network 116 Includes.

[0028] The core network functions are connected to each other via reference points (N11, N7, N30, etc.). Furthermore, RAN102 is connected to AMF104 (or to each AMF104 individually) via reference point N2, and mobile terminal 101 is connected to AMF104 via reference point N1 (through RAN102).

[0029] In a communication system like the one shown in Figure 1, a so-called signaling storm can occur, which is a large amount of control signaling that can overload the components.

[0030] Figure 2 shows the signaling storm on the N1 reference point for the registration operation.

[0031] There are a very large number of UE registration requests (for example, those resulting from Internet of Things (IoT) device registration), which can lead to the AMF104 becoming overloaded.

[0032] Figure 3 shows the signaling storm on the N11 reference point (between AMF104 and SMF105) for the Protocol Data Unit (PDU) session establishment service operation.

[0033] There are a very large number of PDU establishment requests (for example, caused by many IoT devices reporting events), which leads to the SMF105 becoming overloaded.

[0034] Figure 4 shows the signaling storm on the N33 reference point (between AF110 and NEF112) regarding the operation of the public service.

[0035] There are a very large number of AF requests, which leads to the NEF112 becoming overloaded.

[0036] Figure 5 shows the signaling storm on the N4 reference point (between SMF105 and UPF111) regarding the operation of the session refresh service.

[0037] There are a very large number of session updates by SMF105 (for example, caused by an abnormal PCF109 creating a malformed policy update that signals SMF105), which leads to UPF111 becoming overloaded.

[0038] For mobile network operators (MNOs), it is generally desirable to be able to handle (i.e., predict and avoid) signaling storms. Ideally, this should be done in such a way that the downtime of components affected by the signaling storm is within minutes or seconds rather than hours, resulting in little to no service disruption and interruption (which can be caused by overload).

[0039] In consideration of the above, various embodiments and methods can be used to proactively protect mobile communications network components (or “entities”), particularly on the network side (e.g., within the core network), against signaling storms; that is, to predict signaling storms and take countermeasures before they actually occur (or at least mitigate their impact when they do occur). According to various embodiments, this is done using a Network Data Analytics Function (NWDAF) 115 that has (or aggregates or collects) and / or stores information to enable appropriate prediction (or judgment).

[0040] In particular, various embodiments provide NWDAF-based signaling storm prediction and detection (and possibly mitigation), including:

[0041] 1) Use of one or more machine learning (ML) models for anomaly prediction and detection. 2) Determining the signaling patterns (e.g., request rate, response rate, etc.) of control plane communication (e.g., service operation request / response or subscribe / notification patterns) between mobile network (i.e., network-side) components, interpreting detected anomalies in the signaling patterns (e.g., by one of the ML models) as indicators of a (disruptive or already occurring) signaling storm, i.e., treating abnormal control plane signaling patterns as indicators of a signaling storm. 3) Mobile network components (e.g., NFs) monitor control plane signaling to report metrics (e.g., measurements), detect specific operating patterns (of their own), and in some cases detect control plane signaling patterns as well. For example, an ML model is trained (by NWDAF115) to predict and / or detect an unusual control plane signaling pattern at a specific reference point between two mobile network components (e.g., between two NFs in core network 103 (e.g., 5GC)) based on control plane signaling (i.e., control signaling traffic) metrics and unexpected (i.e., exceptional) signaling pattern notifications provided by one or both (or the other) of the mobile network components. The two mobile network components (one acting as a service producer (or "producer") and the other as a service consumer) and other entities in the mobile communication system (e.g., Operation, Administration and Maintenance (OAM) or Service Communication Proxy (SCP)), which are not shown in Figure 1 but may be part of the communication system, may subscribe to the analysis provided by NWDAF115. If NWDAF115 predicts and / or detects an abnormal signaling pattern, it notifies the subscribed entity, which can then take appropriate mitigation actions (for example, those that are conventionally present in the communication system).

[0042] Therefore, according to various embodiments, the NWDAF115 performs analysis to predict and / or detect anomalous control plane signaling patterns by an ML model trained on metrics of signaling traffic, in addition to unexpected pattern notifications provided by one or more mobile network components (e.g., NFs) (optionally).

[0043] Therefore, NWDAF115 can detect or predict early on abnormal signaling (or communication) patterns, i.e., anomalies in control plane signaling (e.g., request / subscribe and response / notification messages) between two mobile network components. For this anomaly prediction and / or detection problem, NWDAF115 uses one or more ML models to provide analysis for control plane signaling patterns of service behavior at a reference point (e.g., a newly introduced analysis ID is assigned). These analyses can then trigger mitigation actions by various entities, for example (e.g., initiated by NWDAF115 or by notification of the analysis to another component).

[0044] • Service producers may use mitigation mechanisms such as request throttling, backpressure, and connection pooling. • Service consumers may use mitigation mechanisms such as request throttling or NF reselection. • OAM, for example, uses horizontal / vertical scaling as a mitigation mechanism. • SCPs, for example, use mitigation mechanisms such as request throttling, back pressure, and connection pooling. • RAN, for example, uses mitigation mechanisms such as NF reselection and access restriction. In the following, we assume, for example, that one or more mobile network components (e.g., NFs) involved in a possible signaling storm can measure and report metrics related to control plane traffic (related to their corresponding service operations), such as the number of requests / subscribes sent / received within a time window, the number of responses / notifications sent / received within a time window, service / response timing information, and error counts such as the number of rejected requests and the number of timeout requests, and that they can detect specific (particularly unexpected) behavioral patterns (for example, with respect to their service operations, the number of messages, service-providing instances, buffer levels, load levels, memory allocation rates, packet drop rates, thread / process creation rates, (disk) I / O operation latency, the number of TCP / UDP sockets, etc., exceeding their respective predetermined thresholds, where the thresholds are determined, for example, as defining the range of values ​​for normal operation, i.e., when a signaling storm is not present).

[0045] NWDAF115 trains an ML model to detect anomalies in signaling patterns between mobile network components. Specifically, it collects information on the (primary) service and entities of multiple considered reference points between two entities (mobile network components), and optionally requests each of them (or at least some) to activate an internal behavior pattern detection mechanism, i.e., a pattern of information (e.g., values ​​or behavioral metrics) regarding the internal behavior of the mobile network components. This information regarding the internal behavior of the mobile network components could be, for example, • Information regarding the number of requests / subscribes, the number of responses / notifications within a time window, the service / response rate, service / response timing information, and error counts such as the number of rejected requests and the number of timeout requests. • Number of active (ongoing) requests / subscribers (i.e., generally active (i.e., currently being processed) service-providing instances) Operational metrics such as load information, buffer level, load level, memory allocation rate, packet drop rate, thread / process creation rate, (disk) I / O operation latency, and number of TCP / UDP sockets. Includes one or more of the following.

[0046] When a mobile network component detects an unexpected behavioral pattern, it notifies the NWDAF115.

[0047] At least some of the mobile network components (e.g., one or both of the mobile network components connected by the reference point under consideration) that are involved in a possible signaling storm continuously monitor traffic (for metrics related to control signaling), and the NWDAF collects service control signaling metrics. The control signaling metrics (i.e., metrics related to control plane traffic) and (optionally) any unexpected pattern notifications provided by one or more of the mobile network components are given as input to an ML model to detect anomalous control signaling patterns.

[0048] NWDAF115 outputs, for example, at least some of the following (e.g., "for the control plane signaling pattern of service behavior at a reference point"):

[0049] • Sender / Destination NF • Reference points and service operations • Identify one of the following abnormalities (or exceptions): ○Too many demands.

[0050] ○Too many parallel requests (no response) ○ The response was too insufficient. ○The response is too slow. ○The response time is far too inconsistent. ○ Too many requests are being rejected. ○ Too many request timeouts ○ Unexpected message patterns NWDAF115 may also output information indicating that the exception has been resolved.

[0051] Exception identification is, for example, what an ML model (trained on a specific reference point) outputs regarding classifications within one of these classes (i.e., exceptions) and a further "no exceptions" class.

[0052] The service producers and service consumers of the reference points and / or other entities under consideration may have the ability to monitor control signaling traffic and detect operational patterns in their operation (e.g., message sequences, resource usage) through, for example, the following:

[0053] • Their internal logic (i.e., NF internal logic) • A set of configurations sent by OAM • The use of ML models trained by and shared with NWDAF115, i.e., mobile network components, may perform inference.

[0054] As described above, if a mobile network component detects an unexpected behavioral pattern, it sends a notification to the NWDAF115. This triggers ML-based signaling pattern detection in the NWDAF115 (using an ML model), and the notification (i.e., any information it contains, i.e., information about the unexpected behavioral pattern) may also be used as input to the ML model, i.e., the ML model is trained, according to one embodiment, to predict abnormal control signaling using behavioral information from one or more entities connected by reference points considered (among other input data). Thus, one or more notifications about an unexpected behavioral pattern may (or may include) supporting (input) data for abnormal signaling pattern detection.

[0055] Figure 6 shows a flowchart 600 illustrating the detection and mitigation of abnormal signaling patterns (i.e., signaling storms).

[0056] Service Consumer 601, Service Producer 602, NWDAF603, SCP604, and OAM605 are included in this flow.

[0057] In 606, 607, and 608, NWDAF603 performs data collection from service consumer 601, service producer 602, and SCP 603, respectively, and requests to be notified of any unexpected behavioral patterns of service consumer 601, service producer 602, and SCP604, respectively. In doing so, NWDAF603 indicates the reference points and service behaviors to be considered (for which it wishes to receive traffic data and be notified of any unexpected behavioral patterns).

[0058] In 609, NWDAF603 opts to collect data from OAM605 and be notified about the load on network functions (in particular, at least one of the service consumer 601 and service producer 602, or both if both are network functions).

[0059] In 610, NWDAF603 uses the collected data as training data to train an ML model to detect anomalous signaling patterns (e.g., one of the exceptions mentioned above).

[0060] In 611, 612, 613, and 614, service consumers 601, service producers 602, SCP 604, and OAM 605 subscribe to analysis in NWDAF 603 regarding reference points and service behavior (as they are shown in subscriptions), and are notified, for example, of predictions and / or detections of anomalous control signaling patterns. Detection of anomalous signaling patterns may mean that control (plane) signaling that is potentially overloading (i.e., at least partially overloading the communication network, i.e., has the risk of overloading one or more components of the communication network (particularly network functions)) is predicted and / or detected, i.e., that a (control) signaling storm is detected (when it already exists) or predicted (when it is not already existing but is imminent, i.e., when there is a risk of it occurring), and it should be noted that detection of anomalous signaling patterns may be considered a prediction of control signaling (storm) that overloads one or more components of the network.

[0061] In 615, the service consumer 601, service producer 602, NWDAF 603, and SCP 604 monitor traffic on the reference point (regarding the service behavior under consideration) and thus collect input data for the machine learning model.

[0062] In 616, 617, or 618, when a service consumer 601, a service producer 602, or an SCP 604 notifies the NWDAF 603 of an unexpected behavioral pattern, in 619, the NWDAF 603 uses the collected input data (e.g., collected within a specific time window prior to the notification) to perform anomaly signaling pattern detection using a (trained) machine learning model.

[0063] In 620, 621, 622, and 623, the NWDAF 603 notifies the SCF 604, service consumer 601, service producer 602, and OAM 605, respectively, of the results of detecting an abnormal signaling pattern, i.e., an exceptional case, especially if an exceptional case exists. In doing so, it indicates the reference point and service operation to be considered and includes the IDs of the mobile network components (e.g., NFs) involved. Then, in 624, 625, 626, and 627, the SCF 604, service consumer 601, service producer 602, and OAM 605, respectively, may trigger mitigation mechanisms. In the case of OAM 605, this may include configuring the SCF 604, service consumer 601, and service producer 602 for mitigation in 628.

[0064] If the exception is resolved, NWDAF603 may also notify SCF604, service consumer 601, service producer 602, and OAM605. The mitigation mechanism is then reverted (i.e., deactivated) rather than being triggered.

[0065] The monitoring of item 615 in Figure 6 and the subsequent actions are performed repeatedly.

[0066] Below, three examples of the flow in Figure 6 are given for different pairs of service producers and service consumers, corresponding to the signaling storms shown in Figures 2, 3, and 4.

[0067] Figure 7 shows the flow of Figure 6 for detecting a UE registration signaling storm (corresponding to Figure 2).

[0068] SCP604 is not included in this example. The reference point considered is N1, and the service behavior considered is UE registration. The service consumer is RAN701, and the service producer is AMF702. In this example, RAN701 does not subscribe to the analysis.

[0069] In this case, the mitigation mechanism is as follows, for example:

[0070] • AMF scaling using OAM 705 • Request throttling (e.g., via NAS-level congestion control) by AMF 702 and N2 overload control (of RAN701) • RRC denial, RRC connection release, and access restriction via RAN701 Figure 8 shows the flow of Figure 6 for detecting a PDU establishment signaling storm (corresponding to Figure 3).

[0071] The reference point considered is N11, and the service behavior considered is the PDU session creation context. The service consumer is AMF801 (or multiple AMFs), and the service producer is SMF802.

[0072] In this case, the mitigation mechanism is as follows, for example:

[0073] • SMF scaling using OAM805 • Request throttling by SMF802 (Non-Access Stratum (NAS) level congestion control) • Request throttling and NF reselection via AMF801 (NAS-level congestion control) Figure 9 shows the flow of Figure 6 for detecting an AF request signaling storm (corresponding to Figure 4).

[0074] SCP604 is not included in this example. The reference point considered is N33 (no service operation in this example). The service is AF901 (or multiple AFs), and the service producer is NEF902.

[0075] In this case, the mitigation mechanism is as follows, for example:

[0076] • NEF scaling using OAM905 • Request throttling via NEF 902 • Throttling requested by AF 901, NF reselection Figure 10 shows two alternative examples of how the mitigation mechanism may be triggered.

[0077] In the first option (shown at the top of Figure 10), the NWDAF 1001 notifies a communication system component, such as the RAN 1002, one of the core entities (e.g., network function) 1003, the OAM 1004, or another, of the control signaling anomaly. Each component takes this information into consideration and decides whether to initiate an automatic mitigation (e.g., protection) mechanism, such as automatic congestion control.

[0078] Alternatively, in the second option (shown at the bottom of Figure 10), NWDAF1001 notifies OAM1004 of a control signaling anomaly, and OAM1004 takes this information into consideration and decides to initiate automatic mitigation, configuring one or more other entities, such as RAN1002, one of the core entities (e.g., network function)1003, or others to perform mitigation (e.g., protection) (see illustrative step 628 in Figure 6).

[0079] In summary, various embodiments provide a method as shown in Figure 11.

[0080] Figure 11 shows a flowchart 1100 illustrating a method for predicting and / or detecting control signaling (e.g., control plane signaling) that poses a risk of at least partially overloading a mobile communications network.

[0081] In 1101, metrics relating to control plane traffic between a first mobile communications network component and one or more second mobile communications network components of a mobile communications network (e.g., characterizing its volume or intensity) are collected (e.g., by monitoring or subscribing to one or more components that provide such metrics).

[0082] In 1002, a notification is received (for example, from the first mobile communication network component) that the first mobile communication network component has detected an exceptional (in other words, unexpected) operating pattern. Each of the one or more second mobile communication network components may similarly notify about its operating pattern.

[0083] In 1003, in response to the receipt of the notification, the metric is used to predict and / or determine whether there is a control signaling that poses a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components (e.g., whether there is an abnormal signaling pattern (e.g., of a particular service operation) that indicates a signaling storm (or an impending signaling storm)). This prediction and / or determination may be made by an appropriately trained ML model (to process the information contained in the notification regarding the metric and, if applicable, exceptional operational conditions, and to predict a particular control signaling (e.g., classifying control signaling into several classes, at least one of which poses an overload risk)). The ML model may be specifically trained for one pair of communication network components, i.e., for a particular reference point (e.g., N1, N11, N33, or N4 in the above example).

[0084] In other words, according to various embodiments, (control) signaling storm detection and / or prediction is performed based on metrics of control plane traffic and notifications from involved entities that have detected an unexpected operational state. Receiving such notifications triggers the actual detection / prediction process (e.g., inference by an ML model). Therefore, resources for the detection / prediction process are used only when there is an actual indication (i.e., notification of an unexpected operational state) that a signaling storm may be occurring or imminent. The method in Figure 11 enables early detection (or even prediction) of signaling storms, and thus can reduce service downtime. This can save resources and improve the user experience.

[0085] Exceptional operating patterns may include, for example, exceptional patterns of internal operation of the first mobile communication network component, and in particular may include internal information not exposed to the NWDAF, such as buffer size, time to retrieve information from database, memory allocation rate, packet discard rate, thread / process creation rate, (disk) I / O operation latency, and the number of TCP / UDP sockets.

[0086] For example, according to various embodiments, a communication system is provided which includes a first entity (e.g., NWDAF) that collects metrics of control plane request / response and / or subscribe / notification messages between a second entity and a third entity (e.g., two NFs) directly from the entities or from a fourth entity (e.g., SCP), and prompts the entities to activate an unexpected traffic detection mechanism. The first entity trains an ML model to predict / detect anomalies in control plane signaling between the second and third entities, with inputs being the collected metrics and unexpected behavior pattern notifications from the second, third, and fourth entities. The second, third, and fourth entities, as well as a fifth entity (e.g., OAM), subscribe to the first entity to be notified when an anomaly traffic pattern is detected. The second, third, and fourth entities monitor control plane traffic to generate unexpected behavior pattern notifications and measure metrics to be sent to the first entity, which are used as input for inference by the ML model. The first entity notifies other entities if it predicts / detects an unusual signaling pattern that would trigger mitigation actions in those entities.

[0087] Various embodiments provide a mobile communications network overload detection and mitigation system configured to perform a method for detecting control (plane) signaling that poses a risk of at least partially overloading the mobile communications network, according to any one of the examples and embodiments described herein. As described above, the overload detection and mitigation system includes, for example, an NWDAF (which performs the actual detection) and one or more other components (including a first communications network component, a second communications network component, or further communications network components), such as an OAM, SMF, AMF, etc., which are notified by the NWDAF and may trigger mitigation.

[0088] The components of a communication network component may be implemented by, for example, one or more circuits. “Circuit” may be understood as any kind of logic implementation entity, which may be a dedicated circuit or processor, firmware, or any combination thereof, that runs software stored in memory. Thus, “Circuit” may be a wired logic circuit or a programmable logic circuit such as a microprocessor. “Circuit” may also be software, such as a processor that runs any kind of computer program. Any other kind of implementation of any of the above functions may also be understood as “Circuit”.

[0089] While specific embodiments have been described, it should be understood by those skilled in the art that various modifications of form and detail may be made without departing from the spirit and scope of the embodiments of this disclosure as defined by the attached claims. Accordingly, such scope is indicated by the attached claims, and is therefore intended to encompass all modifications that fall within the meaning and scope of the equivalents of the claims.

Claims

1. A method for predicting and / or detecting control signaling that poses a risk of at least partially overloading a mobile communications network, A specific mobile communication network component collects metrics relating to control plane traffic between a first mobile communication network component and one or more second mobile communication network components of the mobile communication network. The steps include: receiving a notification from the aforementioned specific mobile communication network component that the first mobile communication network component has detected an exceptional operating pattern; In response to receiving the notification, the specific mobile network component predicts and / or determines, using the collected metrics relating to control plane traffic and the detected exceptional behavioral patterns of the received notification, whether there is control signaling that poses a risk of overloading the first mobile network component and / or one or more second mobile network components. Includes, The metric includes one or more of the following: the number and / or rate of request messages, the number and / or rate of response messages, the number and / or rate of subscribe messages, the number and / or rate of notification messages, and the number and / or rate of request rejections. The aforementioned exceptional operating pattern is, The number and / or rate of messages received by the first mobile communication network component from one or more second mobile communication network components exceeds a predetermined signaling threshold. The load on the first mobile communication network component exceeds a predetermined load threshold. The number of service provision instances of the first mobile communication network component for one or more second mobile communication network components exceeds a predetermined service provision threshold. The message buffer level of the first mobile communication network component exceeds a predetermined buffer level. The memory allocation rate of the first mobile communication network component exceeds a predetermined memory allocation threshold. The rate of packet loss experienced by the first mobile communication network component exceeds a predetermined packet loss threshold. The rate of thread and / or process creation of the first mobile communication network component exceeds a predetermined thread / process creation threshold. The mass storage input / output latency of the first mobile communication network component exceeds a predetermined input / output latency threshold, and The number of sockets for the transport control protocol and / or user datagram protocol exceeds a predetermined socket threshold. A method that is one or more of the following.

2. The method according to claim 1, wherein the exceptional operating pattern is an exceptional operating pattern of the first mobile communication network component.

3. The method according to claim 1, wherein the exceptional operating pattern includes an exceptional pattern of the internal operation of the first mobile communication network component.

4. The method according to claim 1, wherein the exceptional operating pattern includes an exceptional signaling pattern of signaling between one or more second mobile communication network components and the first mobile communication network component.

5. The method according to claim 1, wherein the first mobile communication network component is a core network function of the core network of the mobile communication network, and / or the one or more second mobile communication network components are core network functions of the core network of the mobile communication network.

6. The method according to claim 1, wherein the first mobile communications network component is a core network function of the core network of the mobile communications network, and / or the one or more second mobile communications network components are one or more components of the radio access network of the mobile communications network.

7. The method according to claim 1, further comprising the step of predicting and / or determining, by machine learning model, whether there is control signaling that poses a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components.

8. The method according to claim 7, wherein the machine learning model receives the metric as input.

9. The method according to claim 7, wherein the notification includes information relating to the exceptional behavior pattern, and the machine learning model receives the information relating to the exceptional behavior pattern as input.

10. The method according to claim 1, comprising the step of triggering a mitigation mechanism configured to reduce the load on the first mobile communication network component and / or the one or more second mobile communication network components if it is predicted and / or determined that there is a control signaling that poses a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components.

11. An overload detection and mitigation system for a mobile communications network, configured to perform the method described in any one of claims 1 to 10.

12. The overload detection and mitigation system according to claim 11, comprising the specific mobile communication network component as a third communication network component configured to collect the metrics, receive the notifications, and predict and / or determine whether there is control signaling that poses a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components, and to notify the first mobile communication network component, the one or more second mobile communication network components and / or the fourth communication network component of the results of the prediction and / or determination.

13. The overload detection and mitigation system according to claim 12, wherein the first mobile communication network component, the one or more second mobile communication network components, and / or the fourth communication network component are configured to trigger a mitigation mechanism configured to reduce the load on the first mobile communication network component and / or the one or more second mobile communication network components when it is predicted and / or determined that there is control signaling that poses a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components.

Citation Information

Patent Citations

  • 5G signaling storm prediction method and equipment based on grey prediction model, and medium

    CN117527612A

  • Core network node and method

    JP2022516933A