METHODS, EQUIPMENT, AND SYSTEMS FOR MONITORING AND PREVENTING NETWORK PERFORMANCE ABNORMALITIES USING ADVANCED DATA COLLECTION FOR NETWORK DATA ANALYSIS FUNCTIONALITY

VN126557APending Publication Date: 2026-07-01INTERDIGITAL PATENT HOLDINGS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
VN · VN
Patent Type
Applications
Current Assignee / Owner
INTERDIGITAL PATENT HOLDINGS INC
Filing Date
2024-10-30
Publication Date
2026-07-01

AI Technical Summary

Technical Problem

Existing mechanisms for mitigating signaling storms in mobile networks are mostly passive and react only after the overload has occurred, negatively impacting user experience.

Method used

A method implemented in a network anomaly monitoring function module that receives configuration information for monitoring network anomalies, selects relevant network function elements, and requests statistics to detect and prevent signaling storms proactively.

Benefits of technology

The solution enables proactive detection and prevention of signaling storms, improving network performance and user experience by anticipating and mitigating overload situations before they impact service.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure VN1202602864_0
    Figure VN1202602864_0
Patent Text Reader

Abstract

According to the invention scheme, the method implemented in the Network Anomaly Monitoring Function Module (NAMF) comprises the following steps: the NAMF module receives configuration information for the Network Anomaly Monitoring Strategy indicator; based on the Network Anomaly Monitoring Strategy, identifies network anomalies to be monitored within a network region; selects at least one network function element of the network associated with that network region; transmits to the selected network function element a statistical request message related to that network region, based on the Network Anomaly Monitoring Strategy; and receives the requested statistics from the selected network function element.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS, APPARATUSES AND SYSTEMS FOR ABNORMAL NETWORK PERFORMANCE MONITORING AND PREVENTING USING ENHANCED DATA COLLECTION FOR NETWORK DATA ANALYTICS FUNCTIONCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] The present application claims the benefit of US Provisional Patent Application No. 63 / 546,803 filed November 1st, 2023, which is incorporated herein by reference.FIELD OF THE INVENTION

[0002] The present disclosure is generally directed to abnormal network performance monitoring and preventing. More particularly, the present disclosure relates to methods for abnormal network performance monitoring and preventing using Artificial Intelligence / Machine Learning, (AI / ML), based frameworkBACKGROUND

[0003] Leveraging AI / ML technology to detect, prevent and mitigate abnormal behaviors in mobile networks has become a focus in wireless industry and standards development organization SDOs (e.g., 3 GPP). One example of abnormal network behavior is what is known as signaling storm in Mobile networks. Mobile networks rely on control plane signaling for managing the execution of all kinds of System operations.

[0004] “Signaling storm”, a term that is used when the intensity of the control signaling overwhelms the network resources and compromises the smooth network operations and sometimes even causes service outage, has been a concerning issue in today’s mobile networks across the world. There are many various reasons that may cause a signaling storm. The ever- increasing population of mobile users, popular social network applications, mobile device’s frequent switching between IDLE / dormant state to connected state for the purpose of power saving, etc. may all contribute to the intensity of the network signaling. In addition to regular mobile users, signaling storm may be caused by attacks conducted by malicious actors.

[0005] There are some existing mechanisms that may help mitigate the network signaling overload or congestion. For example, Unified Access Control mechanism allows the network to prevent some user equipment from accessing the network using barring parameters that depend on the user equipment access identity and access category. For another example, network overload and congestion control mechanism may allow the network to reject or defer some connection request to reduce the signaling load. However, these existing mechanisms are mostly passive reaction to the signaling overload issue after it has already happened and user experience is negatively impacted when these mechanisms kick in.

[0006] There is a need to improve reaction to the signaling overload issue.SUMMARY

[0007] In an embodiment, a method, implemented in a network anomaly monitoring function, NAMF, module, may comprise a step of receiving, by the NAMF module, configuration information indicating a network anomaly monitoring strategy. The method may further comprise a step of determining to monitor, based on the network anomaly monitoring strategy, a network anomaly in a network area. The method may further comprise a step of selecting at least one network function element of the network related to the network area. The method may further comprise a step of transmitting, to the selected network function element, a message indicating a request for statistics related to the network area, based on the network anomaly monitoring strategy; and a step of receiving, from the selected network function element, the requested statistics.

[0008] In an embodiment, a method, implemented in a network function module, may comprise a step of receiving a first message comprising configuration information indicating a network anomaly monitoring strategy. The method may further comprise a step of monitoring, based on the network anomaly monitoring strategy, a network anomaly in a network area. The method may further comprise a step of selecting at least one network function element of a network related to the network area. The method may further comprise a step of transmitting, to the selected network function element, a second message indicating a request for statistics related to the network area, based on the network anomaly monitoring strategy; and a step of receiving, from the selected network function element, said statistics.

[0009] The network area may comprise at least one network interface. The network area may comprise one or more control plane interfaces. The selected network function element may be an access and mobility management function element of the network. The statistics may comprise any of a number of non-access stratum, NAS, connections, rate of increment / decrement of number of NAS connections, number of control plane signals in a unit time, size of control plane signals, and bandwidth occupancy ratio. The second message further comprises an event identifier associated with an event filter for the statistics. The event identifier may indicate one or more event of control plane interface signal loads, and wherein the event filter comprises any of a type of control plane, a type of statistics to be generated by the selected network function element, and a type or name of service operation subscribed by the network function element. The selection of at least one network function element may comprise any of selecting at least one network function element responsible for monitoring the network area; and selecting at least one network function element based on the network anomaly.

[0010] The method may comprise a step of receiving periodically the statistics. The method may comprise a step of determining at least one network anomaly based on the received statistics. The method may comprise a step of determining network anomaly prevention based on the received statistics. The network function module may be a network data analytics function module. The method may comprise a step of transmitting, to a network function node, a signaling storm notification comprising information indicating a cause of a signaling load and a source network node of the signaling load.

[0011] In an embodiment, a network function module comprising a processor, a transceiver unit and a storage unit, may be configured to receive, by the network function module, a first message comprising configuration information indicating a network anomaly monitoring strategy. The network function module may be further configured to monitor, based on the network anomaly monitoring strategy, a network anomaly in a network area. The network function module may be further configured to select at least one network function element of a network related to the network area. The network function module may be further configured to transmit, to the selected network function element, a second message indicating a request for statistics related to the network area, based on the network anomaly monitoring strategy; and to receive, from the selected network function element, said statistics.

[0012] In an embodiment, a method, implemented in a network anomaly monitoring function, NAMF, module, may comprise a step of receiving, from a network node element, a first message comprising a request for restriction recommendations, the first message further comprising information indicating current network conditions and the network node element load target. The method may further comprise a step of determining restriction recommendations based on the information of the first message; and a step of transmitting, to the network node element, a second message comprising information including the determined restriction recommendations.

[0013] The network node may be an access and mobility management network node element. The information including the determined restriction recommendation may include radio resource control, RRC, connection requested to be restricted or nonaccess stratum, NAS, connection requests to be restricted. The determined restriction recommendations may include a percentage recommendation corresponding to a percentage of RRC connection requests and NAS connection request.

[0014] The method may further comprise, based on the first message, collecting information from one or more other network node elements part of the same slice of the network node element; and further determining the restriction recommendation based on the collected information.

[0015] The first message further may comprise information indicating a request for result predictions from the NAMF module, the method further comprising determining the resultpredictions based on the determined restriction recommendations. The determined result predictions comprise a prediction of the network node element load change based on the determined restriction recommendations. The first message may further comprise information indicating a service area to the NAMF module, and the method may further comprise a step of determining a restricted service area based on the determined restriction recommendations.

[0016] The restricted service area may be any of a set of cell identities, tracking area identities, and geographical area over which the determined restriction recommendations apply.

[0017] The second message may further comprise information including adjusted unified access control barring parameters.BRIEF DESCRIPTION OF THE DRAWINGS

[0018] A more detailed understanding may be had from the detailed description below, given by way of example in conjunction with drawings appended hereto. Figures in such drawings, like the detailed description, are examples. As such, the Figures (FIGs.) and the detailed description are not to be considered limiting, and other equally effective examples are possible and likely. Furthermore, like reference numerals ("ref.") in the FIGs. indicate like elements, and wherein:

[0019] FIG. 1 A is a system diagram illustrating an example communications system;

[0020] FIG. IB is a system diagram illustrating an example wireless transmit / receive unit (WTRU) that may be used within the communications system illustrated in FIG. 1 A;

[0021] FIG. 1C is a system diagram illustrating an example radio access network (RAN) and an example core network (CN) that may be used within the communications system illustrated in FIG. 1A;

[0022] FIG. ID is a system diagram illustrating a further example RAN and a further example CN that may be used within the communications system illustrated in FIG. 1 A;

[0023] FIG. 2 is an example of a message sequence chart of a control plane signaling load data collection;

[0024] FIG. 3 is an example of a message sequence chart of a direct network data analytics function (NWDAF)-controlled unified access control (UAC) parameters adjustment signaling;

[0025] FIG. 4 is an example of a message sequence chart of a NWDAF assisted overload mitigation signaling;

[0026] FIG. 5 is an example of a message sequence chart of a NWDAF assisted barring configuration signaling;

[0027] FIG. 6 is a flow chart diagram illustrating an example of a method implemented in a network anomaly monitoring function module according to an embodiment;

[0028] FIG. 7 is a flow chart diagram illustrating an example of another method implemented in a network anomaly monitoring function module according to another embodiment; and

[0029] FIG. 8 is a flow chart diagram illustrating an example of a method implemented in a network function module according to an embodiment.DETAILED DESCRIPTION

[0030] In the following detailed description, numerous specific details are set forth to provide a thorough understanding of embodiments and / or examples disclosed herein. However, it will be understood that such embodiments and examples may be practiced without some or all of the specific details set forth herein. In other instances, well-known methods, procedures, components and circuits have not been described in detail, so as not to obscure the following description. Further, embodiments and examples not specifically described herein may be practiced in lieu of, or in combination with, the embodiments and other examples described, disclosed or otherwise provided explicitly, implicitly and / or inherently (collectively "provided") herein. Although various embodiments are described and / or claimed herein in which an apparatus, system, device, etc. and / or any element thereof carries out an operation, process, algorithm, function, etc. and / or any portion thereof, it is to be understood that any embodiments described and / or claimed herein assume that any apparatus, system, device, etc. and / or any element thereof is configured to carry out any operation, process, algorithm, function, etc. and / or any portion thereof.

[0031] Hereinafter, ‘a’ and ‘an’ and similar phrases are to be interpreted as ‘one or more’ and ‘at least one’ . Similarly, any term which ends with the suffix ‘(s)’ is to be interpreted as ‘one or more’ and ‘at least one’. The term ‘may’ is to be interpreted as ‘may, for example’.

[0032] A sign, symbol, or mark of forward slash 7’ is to be interpreted as ‘and / or’ unless particularly mentioned otherwise, where for example, ‘A / B’ may imply ‘A and / or B’.

[0033] The methods, apparatuses and systems provided herein are well-suited for communications involving both wired and wireless networks. An overview of various types of wireless devices and infrastructure is provided with respect to FIGs. 1A-1D, where various elements of the network may utilize, perform, be arranged in accordance with and / or be adapted and / or configured for the methods, apparatuses and systems provided herein.

[0034] FIG. 1A is a system diagram illustrating an example communications system 100 in which one or more disclosed embodiments may be implemented. The communications system 100 may be a multiple access system that provides content, such as voice, data, video, messaging, broadcast, etc., to multiple wireless users. The communications system 100 may enable multiple wireless users to access such content through the sharing of system resources, including wireless bandwidth. For example, the communications systems 100 may employ one or more channelaccess methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), singlecarrier FDMA (SC-FDMA), zero-tail (ZT) unique-word (UW) discreet Fourier transform (DFT) spread OFDM (ZT UW DTS-s OFDM), unique word OFDM (UW-OFDM), resource block- filtered OFDM, filter bank multicarrier (FBMC), and the like.

[0035] As shown in FIG. 1A, the communications system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104 / 113, a core network (CN) 106 / 115, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, though it will be appreciated that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment. By way of example, the WTRUs 102a, 102b, 102c, 102d, any of which may be referred to as a "station" and / or a "STA", may be configured to transmit and / or receive wireless signals and may include (or be) a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a cellular telephone, a personal digital assistant (PDA), a smartphone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi- Fi device, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. Any of the WTRUs 102a, 102b, 102c and 102d may be interchangeably referred to as a UE.

[0036] The communications systems 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b may be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d, e.g., to facilitate access to one or more communication networks, such as the CN 106 / 115, the Internet 110, and / or the networks 112. By way of example, the base stations 114a, 114b may be any of a base transceiver station (BTS), a Node-B (NB), an eNode-B (eNB), a Home Node-B (HNB), a Home eNode-B (HeNB), a gNode-B (gNB), a NR Node-B (NR NB), a site controller, an access point (AP), a wireless router, and the like. While the base stations 114a, 114b are each depicted as a single element, it will be appreciated that the base stations 114a, 114b may include any number of interconnected base stations and / or network elements.

[0037] The base station 114a may be part of the RAN 104 / 113, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), relay nodes, etc. The base station 114a and / or the base station 114bmay be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be in licensed spectrum, unlicensed spectrum, or a combination of licensed and unlicensed spectrum. A cell may provide coverage for a wireless service to a specific geographical area that may be relatively fixed or that may change over time. The cell may further be divided into cell sectors. For example, the cell associated with the base station 114a may be divided into three sectors. Thus, in an embodiment, the base station 114a may include three transceivers, i.e., one for each sector of the cell. In an embodiment, the base station 114a may employ multiple-input multiple output (MIMO) technology and may utilize multiple transceivers for each or any sector of the cell. For example, beamforming may be used to transmit and / or receive signals in desired spatial directions.

[0038] The base stations 114a, 114b may communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which may be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 may be established using any suitable radio access technology (RAT).

[0039] More specifically, as noted above, the communications system 100 may be a multiple access system and may employ one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, and the like. For example, the base station 114a in the RAN 104 / 113 and the WTRUs 102a, 102b, 102c may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may establish the air interface 116 using wideband CDMA (WCDMA). WCDMA may include communication protocols such as High-Speed Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA may include High-Speed Downlink Packet Access (HSDPA) and / or High-Speed Uplink Packet Access (HSUPA).

[0040] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which may establish the air interface 116 using Long Term Evolution (LTE) and / or LTE- Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).

[0041] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as NR Radio Access, which may establish the air interface 116 using New Radio (NR).

[0042] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement multiple radio access technologies. For example, the base station 114a and the WTRUs 102a, 102b, 102c may implement LTE radio access and NR radio access together, for instance using dual connectivity (DC) principles. Thus, the air interface utilized by WTRUs 102a, 102b,102c may be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., an eNB and a gNB).

[0043] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement radio technologies such as IEEE 802.11 (i.e., Wireless Fidelity (Wi-Fi), IEEE 802.16 (i.e., Worldwide Interoperability for Microwave Access (WiMAX)), CDMA2000, CDMA2000 IX, CDMA2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile communications (GSM), Enhanced Data rates for GSM Evolution (EDGE), GSM EDGE (GERAN), and the like.

[0044] The base station 114b in FIG. 1 A may be a wireless router, Home Node-B, Home eNode- B, or access point, for example, and may utilize any suitable RAT for facilitating wireless connectivity in a localized area, such as a place of business, a home, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a roadway, and the like. In an embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.11 to establish a wireless local area network (WLAN). In an embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.15 to establish a wireless personal area network (WPAN). In an embodiment, the base station 114b and the WTRUs 102c, 102d may utilize a cellular-based RAT (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR, etc.) to establish any of a small cell, picocell or femtocell. As shown in FIG. 1 A, the base station 114b may have a direct connection to the Internet 110. Thus, the base station 114b may not be required to access the Internet 110 via the CN 106 / 115.

[0045] The RAN 104 / 113 may be in communication with the CN 106 / 115, which may be any type of network configured to provide voice, data, applications, and / or voice over internet protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. The data may have varying quality of service (QoS) requirements, such as differing throughput requirements, latency requirements, error tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, and the like. The CN 106 / 115 may provide call control, billing services, mobile location-based services, pre-paid calling, Internet connectivity, video distribution, etc., and / or perform high-level security functions, such as user authentication. Although not shown in FIG. 1 A, it will be appreciated that the RAN 104 / 113 and / or the CN 106 / 115 may be in direct or indirect communication with other RANs that employ the same RAT as the RAN 104 / 113 or a different RAT. For example, in addition to being connected to the RAN 104 / 113, which may be utilizing an NR radio technology, the CN 106 / 115 may also be in communication with another RAN (not shown) employing any of a GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or Wi-Fi radio technology.

[0046] The CN 106 / 115 may also serve as a gateway for the WTRUs 102a, 102b, 102c, 102d to access the PSTN 108, the Internet 110, and / or other networks 112. The PSTN 108 may include circuit-switched telephone networks that provide plain old telephone service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices that use common communication protocols, such as the transmission control protocol (TCP), user datagram protocol (UDP) and / or the internet protocol (IP) in the TCP / IP internet protocol suite. The networks 112 may include wired and / or wireless communications networks owned and / or operated by other service providers. For example, the networks 112 may include another CN connected to one or more RANs, which may employ the same RAT as the RAN 104 / 114 or a different RAT.

[0047] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communications system 100 may include multi-mode capabilities (e.g., the WTRUs 102a, 102b, 102c, 102d may include multiple transceivers for communicating with different wireless networks over different wireless links). For example, the WTRU 102c shown in FIG. 1A may be configured to communicate with the base station 114a, which may employ a cellular-based radio technology, and with the base station 114b, which may employ an IEEE 802 radio technology.

[0048] FIG. IB is a system diagram illustrating an example WTRU 102. As shown in FIG. IB, the WTRU 102 may include a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keypad 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power source 134, a global positioning system (GPS) chipset 136, and / or other elements / peripherals 138, among others. It will be appreciated that the WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with an embodiment.

[0049] The processor 118 may be a general purpose processor, a special purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs) circuits, any other type of integrated circuit (IC), a state machine, and the like. The processor 118 may perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 may be coupled to the transceiver 120, which may be coupled to the transmit / receive element 122. While FIG. IB depicts the processor 118 and the transceiver 120 as separate components, it will be appreciated that the processor 118 and the transceiver 120 may be integrated together, e.g., in an electronic package or chip.

[0050] The transmit / receive element 122 may be configured to transmit signals to, or receive signals from, a base station (e.g., the base station 114a) over the air interface 116. For example, in an embodiment, the transmit / receive element 122 may be an antenna configured to transmit and / or receive RF signals. In an embodiment, the transmit / receive element 122 may be an emitter / detector configured to transmit and / or receive IR, UV, or visible light signals, for example. In an embodiment, the transmit / receive element 122 may be configured to transmit and / or receive both RF and light signals. It will be appreciated that the transmit / receive element 122 may be configured to transmit and / or receive any combination of wireless signals.

[0051] Although the transmit / receive element 122 is depicted in FIG. IB as a single element, the WTRU 102 may include any number of transmit / receive elements 122. For example, the WTRU 102 may employ MIMO technology. Thus, in an embodiment, the WTRU 102 may include two or more transmit / receive elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.

[0052] The transceiver 120 may be configured to modulate the signals that are to be transmitted by the transmit / receive element 122 and to demodulate the signals that are received by the transmit / receive element 122. As noted above, the WTRU 102 may have multi-mode capabilities. Thus, the transceiver 120 may include multiple transceivers for enabling the WTRU 102 to communicate via multiple RATs, such as NR and IEEE 802.11, for example.

[0053] The processor 118 of the WTRU 102 may be coupled to, and may receive user input data from, the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or organic light-emitting diode (OLED) display unit). The processor 118 may also output user data to the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128. In addition, the processor 118 may access information from, and store data in, any type of suitable memory, such as the non-removable memory 130 and / or the removable memory 132. The non-removable memory 130 may include random-access memory (RAM), readonly memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, and the like. In other embodiments, the processor 118 may access information from, and store data in, memory that is not physically located on the WTRU 102, such as on a server or a home computer (not shown).

[0054] The processor 118 may receive power from the power source 134, and may be configured to distribute and / or control the power to the other components in the WTRU 102. The power source 134 may be any suitable device for powering the WTRU 102. For example, the power source 134 may include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, fuel cells, and the like.

[0055] The processor 118 may also be coupled to the GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to, or in lieu of, the information from the GPS chipset 136, the WTRU 102 may receive location information over the air interface 116 from a base station (e.g., base stations 114a, 114b) and / or determine its location based on the timing of the signals being received from two or more nearby base stations. It will be appreciated that the WTRU 102 may acquire location information by way of any suitable location-determination method while remaining consistent with an embodiment.

[0056] The processor 118 may further be coupled to other elements / peripherals 138, which may include one or more software and / or hardware modules / units that provide additional features, functionality and / or wired or wireless connectivity. For example, the elements / peripherals 138 may include an accelerometer, an e-compass, a satellite transceiver, a digital camera (e.g., for photographs and / or video), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands free headset, a Bluetooth® module, a frequency modulated (FM) radio unit, a digital music player, a media player, a video game player module, an Internet browser, a virtual reality and / or augmented reality (VR / AR) device, an activity tracker, and the like. The elements / peripherals 138 may include one or more sensors, the sensors may be one or more of a gyroscope, an accelerometer, a hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor; a geolocation sensor; an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, and / or a humidity sensor.

[0057] The WTRU 102 may include a full duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for both the uplink (e.g., for transmission) and downlink (e.g., for reception) may be concurrent and / or simultaneous. The full duplex radio may include an interference management unit to reduce and or substantially eliminate self-interference via either hardware (e.g., a choke) or signal processing via a processor (e.g., a separate processor (not shown) or via processor 118). In an embodiment, the WTRU 102 may include a half-duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for either the uplink (e.g., for transmission) or the downlink (e.g., for reception)).

[0058] FIG. 1C is a system diagram illustrating the RAN 104 and the CN 106 according to an embodiment. As noted above, the RAN 104 may employ an E-UTRA radio technology to communicate with the WTRUs 102a, 102b, and 102c over the air interface 116. The RAN 104 may also be in communication with the CN 106.

[0059] The RAN 104 may include eNode-Bs 160a, 160b, 160c, though it will be appreciated that the RAN 104 may include any number of eNode-Bs while remaining consistent with an embodiment. The eNode-Bs 160a, 160b, 160c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In an embodiment, the eNode-Bs 160a, 160b, 160c may implement MIMO technology. Thus, the eNode-B 160a, for example, may use multiple antennas to transmit wireless signals to, and receive wireless signals from, the WTRU 102a.

[0060] Each of the eNode-Bs 160a, 160b, and 160c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the uplink (UL) and / or downlink (DL), and the like. As shown in FIG. 1C, the eNode-Bs 160a, 160b, 160c may communicate with one another over an X2 interface.

[0061] The CN 106 shown in FIG. 1C may include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (PGW) 166. While each of the foregoing elements are depicted as part of the CN 106, it will be appreciated that any one of these elements may be owned and / or operated by an entity other than the CN operator.

[0062] The MME 162 may be connected to each of the eNode-Bs 160a, 160b, and 160c in the RAN 104 via an SI interface and may serve as a control node. For example, the MME 162 may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a particular serving gateway during an initial attach of the WTRUs 102a, 102b, 102c, and the like. The MME 162 may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as GSM and / or WCDMA.

[0063] The SGW 164 may be connected to each of the eNode-Bs 160a, 160b, 160c in the RAN 104 via the SI interface. The SGW 164 may generally route and forward user data packets to / from the WTRUs 102a, 102b, 102c. The SGW 164 may perform other functions, such as anchoring user planes during inter-eNode-B handovers, triggering paging when DL data is available for the WTRUs 102a, 102b, 102c, managing and storing contexts of the WTRUs 102a, 102b, 102c, and the like.

[0064] The SGW 164 may be connected to the PGW 166, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.

[0065] The CN 106 may facilitate communications with other networks. For example, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to circuit-switched networks, such as the PSTN 108, to facilitate communications between the WTRUs 102a, 102b, 102c and traditional land-line communications devices. For example, the CN 106 may include, or may communicatewith, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers.

[0066] Although the WTRU is described in FIGs. 1A-1D as a wireless terminal, it is contemplated that in certain representative embodiments that such a terminal may use (e.g., temporarily or permanently) wired communication interfaces with the communication network.

[0067] In representative embodiments, the other network 112 may be a WLAN.

[0068] A WLAN in infrastructure basic service set (BSS) mode may have an access point (AP) for the BSS and one or more stations (STAs) associated with the AP. The AP may have an access or an interface to a distribution system (DS) or another type of wired / wireless network that carries traffic into and / or out of the BSS. Traffic to STAs that originates from outside the BSS may arrive through the AP and may be delivered to the STAs. Traffic originating from STAs to destinations outside the BSS may be sent to the AP to be delivered to respective destinations. Traffic between STAs within the BSS may be sent through the AP, for example, where the source STA may send traffic to the AP and the AP may deliver the traffic to the destination STA. The traffic between STAs within a BSS may be considered and / or referred to as peer-to-peer traffic. The peer-to-peer traffic may be sent between (e.g., directly between) the source and destination STAs with a direct link setup (DLS). In certain representative embodiments, the DLS may use an 802. l ie DLS or an 802.1 Iz tunneled DLS (TDLS). A WLAN using an Independent BSS (IBSS) mode may not have an AP, and the STAs (e.g., all of the STAs) within or using the IBSS may communicate directly with each other. The IBSS mode of communication may sometimes be referred to herein as an "ad-hoc" mode of communication.

[0069] When using the 802.1 lac infrastructure mode of operation or a similar mode of operations, the AP may transmit a beacon on a fixed channel, such as a primary channel. The primary channel may be a fixed width (e.g., 20 MHz wide bandwidth) or a dynamically set width via signalling. The primary channel may be the operating channel of the BSS and may be used by the STAs to establish a connection with the AP. In certain representative embodiments, Carrier sense multiple access with collision avoidance (CSMA / CA) may be implemented, for example in in 802.11 systems. For CSMA / CA, the STAs (e.g., every STA), including the AP, may sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by a particular STA, the particular STA may back off. One STA (e.g., only one station) may transmit at any given time in a given BSS.

[0070] High throughput (HT) STAs may use a 40 MHz wide channel for communication, for example, via a combination of the primary 20 MHz channel with an adjacent or nonadj acent 20 MHz channel to form a 40 MHz wide channel.

[0071] Very high throughput (VHT) STAs may support 20 MHz, 40 MHz, 80 MHz, and / or 160 MHz wide channels. The 40 MHz, and / or 80 MHz, channels may be formed by combining contiguous 20 MHz channels. A 160 MHz channel may be formed by combining 8 contiguous 20 MHz channels, or by combining two non-contiguous 80 MHz channels, which may be referred to as an 80+80 configuration. For the 80+80 configuration, the data, after channel encoding, may be passed through a segment parser that may divide the data into two streams. Inverse fast fourier transform (IFFT) processing, and time domain processing, may be done on each stream separately. The streams may be mapped on to the two 80 MHz channels, and the data may be transmitted by a transmitting STA. At the receiver of the receiving STA, the above-described operation for the 80+80 configuration may be reversed, and the combined data may be sent to a medium access control (MAC) layer, entity, etc.

[0072] Sub 1 GHz modes of operation are supported by 802.1 laf and 802.11 ah. The channel operating bandwidths, and carriers, are reduced in 802.1 laf and 802.1 lah relative to those used in802.1 In, and 802.1 lac. 802.1 laf supports 5 MHz, 10 MHz and 20 MHz bandwidths in the TV white space (TVWS) spectrum, and 802.1 lah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non-TVWS spectrum. According to a representative embodiment,802.1 lah may support meter type control / machine-type communications (MTC), such as MTC devices in a macro coverage area. MTC devices may have certain capabilities, for example, limited capabilities including support for (e.g., only support for) certain and / or limited bandwidths. The MTC devices may include a battery with a battery life above a threshold (e.g., to maintain a very long battery life).

[0073] WLAN systems, which may support multiple channels, and channel bandwidths, such as802.1 In, 802.1 lac, 802.1 laf, and 802.1 lah, include a channel which may be designated as the primary channel. The primary channel may have a bandwidth equal to the largest common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel may be set and / or limited by a STA, from among all STAs in operating in a BSS, which supports the smallest bandwidth operating mode. In the example of 802.1 lah, the primary channel may be 1 MHz wide for STAs (e.g., MTC type devices) that support (e.g., only support) a 1 MHz mode, even if the AP, and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier sensing and / or network allocation vector (NAV) settings may depend on the status of the primary channel. If the primary channel is busy, for example, due to a STA (which supports only a 1 MHz operating mode), transmitting to the AP,the entire available frequency bands may be considered busy even though a majority of the frequency bands remains idle and may be available.

[0074] In the United States, the available frequency bands, which may be used by 802.1 lah, are from 902 MHz to 928 MHz. In Korea, the available frequency bands are from 917.5 MHz to 923.5 MHz. In Japan, the available frequency bands are from 916.5 MHz to 927.5 MHz. The total bandwidth available for 802.1 lah is 6 MHz to 26 MHz depending on the country code.

[0075] FIG. ID is a system diagram illustrating the RAN 113 and the CN 115 according to an embodiment. As noted above, the RAN 113 may employ an NR radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 113 may also be in communication with the CN 115.

[0076] The RAN 113 may include gNBs 180a, 180b, 180c, though it will be appreciated that the RAN 113 may include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, 180c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In an embodiment, the gNBs 180a, 180b, 180c may implement MIMO technology. For example, gNBs 180a, 180b may utilize beamforming to transmit signals to and / or receive signals from the WTRUs 102a, 102b, 102c. Thus, the gNB 180a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a. In an embodiment, the gNBs 180a, 180b, 180c may implement carrier aggregation technology. For example, the gNB 180a may transmit multiple component carriers to the WTRU 102a (not shown). A subset of these component carriers may be on unlicensed spectrum while the remaining component carriers may be on licensed spectrum. In an embodiment, the gNBs 180a, 180b, 180c may implement Coordinated Multi-Point (CoMP) technology. For example, WTRU 102a may receive coordinated transmissions from gNB 180a and gNB 180b (and / or gNB 180c).

[0077] The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using transmissions associated with a scalable numerology. For example, OFDM symbol spacing and / or OFDM subcarrier spacing may vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using subframe or transmission time intervals (TTIs) of various or scalable lengths (e.g., including a varying number of OFDM symbols and / or lasting varying lengths of absolute time).

[0078] The gNBs 180a, 180b, 180c may be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non-standalone configuration. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c without also accessing other RANs (e.g., such as eNode-Bs 160a, 160b, 160c). In the standaloneconfiguration, WTRUs 102a, 102b, 102c may utilize one or more of gNBs 180a, 180b, 180c as a mobility anchor point. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using signals in an unlicensed band. In a non- standalone configuration WTRUs 102a, 102b, 102c may communicate with / connect to gNBs 180a, 180b, 180c while also communicating with / connecting to another RAN such as eNode-Bs 160a, 160b, 160c. For example, WTRUs 102a, 102b, 102c may implement DC principles to communicate with one or more gNBs 180a, 180b, 180c and one or more eNode-Bs 160a, 160b, 160c substantially simultaneously. In the non- standalone configuration, eNode-Bs 160a, 160b, 160c may serve as a mobility anchor for WTRUs 102a, 102b, 102c and gNBs 180a, 180b, 180c may provide additional coverage and / or throughput for servicing WTRUs 102a, 102b, 102c.

[0079] Each of the gNBs 180a, 180b, 180c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, support of network slicing, dual connectivity, interworking between NR and E-UTRA, routing of user plane data towards user plane functions (UPFs) 184a, 184b, routing of control plane information towards access and mobility management functions (AMFs) 182a, 182b, and the like. As shown in FIG. ID, the gNBs 180a, 180b, 180c may communicate with one another over an Xn interface.

[0080] The CN 115 shown in FIG. ID may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one session management function (SMF) 183a, 183b, and at least one Data Network (DN) 185a, 185b. While each of the foregoing elements are depicted as part of the CN 115, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.

[0081] The AMF 182a, 182b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N2 interface and may serve as a control node. For example, the AMF 182a, 182b may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, support for network slicing (e.g., handling of different protocol data unit (PDU) sessions with different requirements), selecting a particular SMF 183a, 183b, management of the registration area, termination of NAS signalling, mobility management, and the like. Network slicing may be used by the AMF 182a, 182b, e.g., to customize CN support for WTRUs 102a, 102b, 102c based on the types of services being utilized WTRUs 102a, 102b, 102c. For example, different network slices may be established for different use cases such as services relying on ultra-reliable low latency (URLLC) access, services relying on enhanced massive mobile broadband (eMBB) access, services for MTC access, and / or the like. The AMF 162 may provide a control plane function for switching between the RAN 113 and other RANs (not shown) that employ other radiotechnologies, such as LTE, LTE-A, LTE-A Pro, and / or non-3GPP access technologies such as WiFi.

[0082] The SMF 183a, 183b may be connected to an AMF 182a, 182b in the CN 115 via an N11 interface. The SMF 183a, 183b may also be connected to a UPF 184a, 184b in the CN 115 via an N4 interface. The SMF 183a, 183b may select and control the UPF 184a, 184b and configure the routing of traffic through the UPF 184a, 184b. The SMF 183a, 183b may perform other functions, such as managing and allocating UE IP address, managing PDU sessions, controlling policy enforcement and QoS, providing downlink data notifications, and the like. A PDU session type may be IP -based, non-IP based, Ethernet-based, and the like.

[0083] The UPF 184a, 184b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N3 interface, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, e.g., to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPF 184, 184b may perform other functions, such as routing and forwarding packets, enforcing user plane policies, supporting multihomed PDU sessions, handling user plane QoS, buffering downlink packets, providing mobility anchoring, and the like.

[0084] The CN 115 may facilitate communications with other networks. For example, the CN 115 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 115 and the PSTN 108. In addition, the CN 115 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers. In an embodiment, the WTRUs 102a, 102b, 102c may be connected to a local Data Network (DN) 185a, 185b through the UPF 184a, 184b via the N3 interface to the UPF 184a, 184b and an N6 interface between the UPF 184a, 184b and the DN 185a, 185b.

[0085] In view of FIGs. 1 A-1D, and the corresponding description of FIGs. 1 A-1D, one or more, or all, of the functions described herein with regard to any of: WTRUs 102a-d, base stations 114a- b, eNode-Bs 160a-c, MME 162, SGW 164, PGW 166, gNBs 180a-c, AMFs 182a-b, UPFs 184a- b, SMFs 183a-b, DNs 185a-b, and / or any other element(s) / device(s) described herein, may be performed by one or more emulation elements / devices (not shown). The emulation devices may be one or more devices configured to emulate one or more, or all, of the functions described herein. For example, the emulation devices may be used to test other devices and / or to simulate network and / or WTRU functions.

[0086] The emulation devices may be designed to implement one or more tests of other devices in a lab environment and / or in an operator network environment. For example, the one or more emulation devices may perform the one or more, or all, functions while being fully or partiallyimplemented and / or deployed as part of a wired and / or wireless communication network in order to test other devices within the communication network. The one or more emulation devices may perform the one or more, or all, functions while being temporarily implemented / deployed as part of a wired and / or wireless communication network. The emulation device (e.g., a network node) may be directly coupled to another device for purposes of testing and / or may performing testing using over-the-air wireless communications.

[0087] The one or more emulation devices may perform the one or more, including all, functions while not being implemented / deployed as part of a network node (e.g., wired and / or wireless communication network). For example, the emulation devices may be utilized in a testing scenario in a testing laboratory and / or a non-deployed (e.g., testing) wired and / or wireless communication network in order to implement testing of one or more components. The one or more emulation devices may be test equipment. Direct RF coupling and / or wireless communications via RF circuitry (e.g., which may include one or more antennas) may be used by the emulation devices to transmit and / or receive data.

[0088] The 5G system may support access control functionality. One example of access control functionality in the 5G system is unified access control (UAC) functionality. In case of the UAC feature is used, the network may broadcast barring control information associated with access categories and access identifiers. The broadcasted information will be received by WTRUs. In case of the WTRU needs to transmit a message to the network, the WTRU may determine an access category and access identifier that is associated with the message. The WTRU may then compare the access category and access identifier of the request against the broadcast information to determine if the message should be barred. In case of the WTRU determines that that the message should be barred, then the WTRU may check again if the message should be barred. The WTRU will wait a time period before checking again and the time period that the WTRU waits may be based on broadcasted information.

[0089] This UAC may be used by the network to protect itself against overload. The ability to bar certain WTRUs or certain types of messages from being transmitted in the network will cause some traffic to be blocked, but overload conditions may be prevented. Thus, higher priority WTRUs and traffic will be able to successfully use the 5G System to send and receive data.

[0090] A RAN node may determine to bar certain traffic when it receives an OVERLOAD START message from the AMF, when receiving a request from the 0AM system, or based on logic that is internal to the RAN Node.

[0091] The OVERLOAD START message may be sent from an AMF to a RAN node. For example, the AMF may indicate in the OVERLOAD START message that the AMF requests the RAN node to limit new connection requests from WTRUs, new connection requests from WTRUsthat are for uplink NAS signaling, and new connection requests that are associated with certain S- NSSAI(s). The AMF may also provide a value that indicates the percentage of connection requests to be restricted.

[0092] When the AMF determines that the overload situation has changed, the AMF may send an OVERLOAD STOP message to the RAN node to indicate that the overload situation is over or may send an OVERLOAD START message to the RAN node with updated information. For example, the updated information may indicate a new percentage value that permits more or less connection requests.

[0093] A network data analytics function (NWDAF) may provide services to consumer NFs such as the AMF. Two examples of NWDAF services are Nnwdaf_EventsSubscription and Nwdaf AnalyticsInfo. These services can be used by a consumer NF to obtain information about the load level of another NF, a network slice, or a network slice instance.

[0094] Existing network data analytics function based framework may have (e.g., great) potential in detection, prevention and mitigation of potential abnormal network conditions such as signaling storm. To enhance the NWDAF-based framework for such purposes, the following issues may need to be addressed.

[0095] What and how additional information can be collected from network functions or WTRUs for the purpose of detection, prevention and mitigation of potential abnormal network conditions. And whether existing analytics can be enhanced or new analytics be generated for such purposes.

[0096] What actions the network may take to prevent or mitigate abnormal network conditions. This may include: how to determine the potentially problematic nodes which can be any on of: WTRUs, network nodes, or third-party application functions (e.g., via network API) and alert the management system about those problematic nodes; how to automatically adjust the network configuration or policies to prevent or mitigate the potential risk; and how to determine the potential root cause(s) of the potential risk and make further long-term configuration / policy adjustment to mitigate the future risk.

[0097] In case of an access and mobility management function (AMF) determines that it is necessary to resolve an overload situation by sending an overload start message to a RAN Node, the AMF may need to determine what signaling the RAN Node should limit and what percentage the signaling should be limited. The AMF may make this determination based only on data that is collected by the AMF. Mobile network (e.g., 5G) system enhancements may be desired to improve how the AMF determines what signaling the RAN node should limit and what percentage the signaling should be limited. For example, an improved procedure might select signaling types and percentages based on activity and observations of activity in more of the 5GC (e.g., UPFs and SMFs).

[0098] In case of the RAN node determines that it is necessary to resolve an overload situation by barring certain traffic, the RAN node may determine what signaling the RAN node should limit and what percentage the signaling should be limited. The RAN node may make this determination based only on data that is collected by the RAN. Mobile network (e.g., 5G) system enhancements may be desired to improve how the RAN Node determines what signaling the RAN Node should limit and what percentage the signaling should be limited. For example, an improved procedure might select signaling types and percentages based on activity and observations of activity in more of the 5GC (e.g., UPFs and SMFs).

[0099] In an embodiment, a NWDAF module may be responsible for monitoring network anomaly and is denoted herein as “Network Anomaly Monitoring Function” (NAMF). The NWDAF or the NAMF module in the NWDAF may request (e.g., a few) network functions to collect data for network anomaly (e.g., signaling storm) detection and prevention. Specifically, the NWDAF may request the statistics of control plane interfaces and signaling. It may specify the list of target control plane interfaces and the desired statistics (e.g., number of control plane signaling / messages, etc.) in the request. The network functions may produce the requested statistics and may send it back to the NWDAF for network anomaly detection. In addition, the network functions may send the requested statistics back to the NWDAF for network anomaly prevention.

[0100] There may be multiple NAMF instances in a NWDAF. For example, each NAMF module may be responsible for monitoring network anomaly in a certain area, or for certain network slices or data networks (i.e., S-NSSAIs / DNN). The main functionalities of NAMF may include any of: collect data or statistics from the chosen / selected NFs (e.g., AMF, SMF, UPF, SMSF, NEF, MDAF) for detecting network anomaly, e.g., against set targets; train AI / ML models using the collected data or request model training services from model training logical function (MTLF); use the AI / ML model to detect a network anomaly (e.g., source NFs contributing to overload) and generate alarm when it is detected; trigger the NWDAF to take further actions to prevent or mitigate the abnormal situation (e.g., through the network management system or through management data analytics function (MDAF), and trigger deregistration of impacted NF towards NRF).

[0101] The further actions to prevent or mitigate the abnormal situation may include any of: network repository function (NRF) may register for network function (NF) misbehavior related events with MDAF and / or any other security function (e.g., security information and event management (SIEM)) the operator may deploy; when receiving an event of a misbehaving NF instance, NRF may mark this NF instance as unavailable or compromised; when receiving an event of a NF instance resuming a normal functioning state, NRF may mark this NF instance asavailable or clear the compromised / unhealthy state; NRF may notify a consumer function that request or is actively using the NF indicating compromised / unavailable status of the NF instance; NRF may notify a consumer function that requests or is actively using the NF indicating NF instance being back to a available state; and NRF may select from a list of candidates NF instance based on its availability / health state (e.g., if NF is compromised, does not return NF instance info to a requesting consumer NF).

[0102] The above embodiment focuses on the enhancement of NWDAF data collection for the purpose of network anomaly monitoring. A NAMF may choose the target NFs from which the data is to be collected based on any of the following factors: the interested areas for the network anomaly monitoring, for example, only the NFs that are responsible for the interested areas may be chosen / selected; the type of network anomaly, for example, if it is signaling storm that needs to be monitored, the critical control plane nodes such as AMFs may be chosen / selected; the target network slices, for example, the NFs belonging to the target network slice may be chosen / selected; the target data network name (DNN), NFs (e.g., SMF) providing service towards the target DNN may be selected for NAMF monitoring; and the target AFs or AF types, NFs (e.g., PCF, NEF) providing interface / API with the target AF may be selected for NAMF monitoring.

[0103] The above factors (the interested areas, the type of network anomaly to monitor, the target network slices, etc.) may be configured (e.g., by network management system) or determined according to other available statistics or analytics (e.g., number of WTRUs in the area, NF load or performance analytics, etc.).

[0104] The NAMF may use the NWDAF data collection framework and procedures to collect data from the target NFs. Specifically, any of the following new inputs may be added when the NWDAF / NAMF sends the request to the target NFs.

[0105] List of control plane interfaces for which the statistics may be generated. The control plane interfaces may include the logical interfaces between NFs and the logical interfaces between WTRUs and NFs. The control plane interfaces may include the external interfaces between 5GC and external entities.

[0106] For example, if the target NF is an AMF, the list of control plane interfaces may include the (e.g., next generation (NG)) connections between gNBs and AMF, NAS connections between WTRUs and AMF, AMF-SMF interfaces, AMF-UDM interfaces, etc. Each control plane interface may be associated with a interface identifier. For example, the (e.g., NG) connection between a gNB and a AMF may be identified by a combination of gNB-ID and AMF ID.

[0107] Related to one or more control plane interfaces, any of the following parameters / filters may be further specified: Type of control plane signals of interest, for example, WTRU-associated signals / messages and / or non-WTRU-associated signals / messages, UL signals and / or DL signals,3GPP-access signals and / or non-3GPP access signals; interested type of service operation or name of service operation, for example, service operation type of subscribe / notify which is subscribed by target NF (e.g., AMF) may be interested or service operation provided by target NF (e.g. Namf EventExposure service operation by AMF); type of statistics to be generated for one or multiple control plane interfaces; thresholds for the load level monitoring (e.g., high or low threshold or signal / service call rates).

[0108] For example, for (e.g., NG) connections between gNBs and AMF or NAS connections, the following statistics may be generated: number of NG or NAS connections; rate of increment / decrem ent of number of NG or NAS connections; number of control plane signals / messages in a unit time (e.g., number of messages per second), this could be an aggregate number of all control plane signals / messages, or it may be number associated with a specific category of control plane signals (e.g. signals related to MO signaling, SMS, etc.); size of control plane signals / messages in a unit time (e.g., n-Mbits / s), this could be an aggregate size of all control plane signals / messages, or it may be size associated with a specific category of control plane signals (e.g. signals related to MO signaling, SMS, etc.); rate of increment / decrement of number / size of control plane signals / messages; bandwidth occupancy ratio; etc.

[0109] List of user plane interfaces for which the statistics may be generated. For example, if the target NF is a UPF, the list of user plane interfaces may include general packet radio service tunnelling protocol (GTP) connections between gNBs and LTPF (N3 interface), GTP connections between UPFs (N9 interface), data link between LTPF and DN (N6 interface), SMF and LTPF (N4 interface) etc.

[0110] Related to one or more user plane interfaces, any of the following param eters / filters may be further specified: type of user plane data of interest, for example, UL data and / or DL data, 3GPP-access data and / or non-3GPP data, IP or Ethernet or unstructured (non-IP) data, etc.... ; destination of user plane data, for example, specific destination Data Network Name (DNN) or destination IP address; network slice (S-NSSAIs); and type of statistics to be generated for one or multiple user plane interfaces.[OHl] For example, for GTP connections between gNBs and UPF, any of the following statistics may be generated: number of data packets in a unit time (e.g., number of messages per second); size of aggregate data packets in a unit time (e.g., n-Mbits / s); rate of increment / decrement of number / size of data packets; bandwidth occupancy ratio; ratio of data packets retransmission; etc.

[0112] Fig. 2 is an example of a control plane signaling load data collection. Referring to Fig. 2, according to the above inputs / filters, the chosen / selected NF may generate the statistics and report it to the NWDAF / NAMF

[0113] At step 2.0, the NWDAF / NAMF may be configured with network anomaly monitoring strategies and according to the strategy, it may determine to monitor the control plane signaling load in a specific area for a period of time. It may locate one or multiple AMFs that are responsible for the target area.

[0114] At step 2.1, the NWDAF / NAMF may send a Namf_EventExposure_Subscribe request to the target AMF(s). It may specify an event identifier (e.g., event to be reported) as “Control Plane Signal Load” and, in the associated event filter, it may further specify any of the following: the control plane interfaces of interest, e.g., all or a subset of (e.g., NG) interfaces between the AMF and its connected gNBs, the subset of (e.g., NG) interfaces may be chosen / selected based on the area codes (e.g., TAI) that the gNBs belong to, the (e.g., NG) interface may be identified by a combination of gNB ID and AMF ID; type of control plane signals of interest, e.g., only WTRU- associated and UL control plane signals are of interest; and type of statistics to be generated, e.g., number of NG connections, rate of increment / decrem ent of number of NG connections, number and size of control plane messages in a unit time, etc.

[0115] At step 2.2, the AMF may monitor the control plane signals on the specified control plane interfaces and generate the desired statistics.

[0116] At step 2.3, the AMF may report the generated statistics to the NWDAF / NAMF according to reporting criteria (e.g., periodically).

[0117] In an embodiment, NWDAF-initiated configuration / policy control mechanisms for network anomaly prevention and mitigation may be implemented. After the NWDAF / NAMF has detected the network abnormal situations, it may initiate network reactions to mitigate the situation and prevent the risk from being developed into more serious problems (e.g., service outage)

[0118] In an embodiment, in case of RAN signaling overload, the NWDAF may request (via AMF) to adjust unified access control (UAC) parameters to restrict the number of network accesses. The NWDAF may determine the problematic RANs based on network anomaly detection. The NWDAF may provide recommended UAC parameters to the target RANs and the RANs implement the recommended UAC to mitigate the overload situation.

[0119] In case of the NWDAF / NAMF detects a control plane interface anomaly, e.g., surge of number of control signals over the interface, it may identify the problematic node. For example, if the control signal surge occurs over a (e.g., NG) connection, it may identify that the gNB associated with the problematic (e.g., NG) connection is the source of the control signal surge. To more quickly respond to the abnormal situation, the NWDAF may directly instruct the affected gNB (via the AMF) to adjust UAC barring parameters to control the signal surge. Alternatively, the network functions (e.g., AMFs) may subscribe to anomaly notifications from the NWDAF and receives the notification and action instructions from the NWDAF when the anomaly occurs.

[0120] The NWDAF may send a “Signal Load Control Request ” message or “Signal Load Control Notification” message to the AMF, indicating any of: the cause of signal load control request, e.g., surge of signal load in a short time; the target of the signal load control action, e.g., the gNB ID which is the source of the signal load surge; the adjusted UAC barring parameters, e.g., the access identities and / or access categories that need to be barred, the adjusted (increment or decrement) barring factor and barring time, etc.; and the duration of the signal load control. After this duration, the node (e.g., gNB) that takes the action may return to its previous UAC barring configurations.

[0121] The AMF may forward the signal load control information to the target gNB in a next generation application protocol (NGAP) message (e.g., overload start) and the target gNB may implement UAC barring adjustment as instructed by the signal load control information.

[0122] Fig. 3 is an example of a direct NWDAF-controlled UAC parameters adjustment signaling.

[0123] At step 3.1, the NWDAF / NAMF may detect a surge of number of control signals over the interface, and may identify the problematic node. For example, if the control signal surge occurs over a (e.g., NG) connection, it may identify the source of the control signal surge (gNB ID).

[0124] At step 3.2, the NWDAF / NAMF may send a “Signal Load Control Request ” message to the AMF, indicating any of the cause of signal load control request, e.g., surge of signal load in a short time; the target of the signal load control action, e.g., the gNB ID which is the source of the signal load surge; the adjusted UAC barring parameters, e.g., the access identities and / or access categories that need to be barred; and the duration of the signal load control.

[0125] At step 3.3, the AMF may forward the signal load control information to the target gNB in a next generation application protocol (NGAP) message (e.g., overload start) and the target gNB may implement UAC barring adjustment as instructed by the signal load control information.

[0126] At step 3.4, the NWDAF / NAMF may continue to monitor the control plane signal situation after the signal load control action is implemented and may send further signal load control instructions (e.g. cancel the signal load control action, change the signal load control parameters, increase / decrease the duration of the signal load control action, etc.)

[0127] In an embodiment, the NWDAF may determine how to mitigate overload.

[0128] Fig. 4 is an example of procedure for how the NWDAF may be used to improve network performance and minimize network disruptions during overload situations. Referring to Fig. 4, the procedure shows how the AMF may use the NWDAF to determine what types of traffic and what percentage of traffic the AMF should request to be barred.

[0129] At step 4.1, the AMF may determine that current network conditions are indicative of overload in the AMF or indicate that overload in the AMF may soon occur. The AMF may determine that an overload condition needs to be mitigated. The AMF may make this determination by observing the number of WTRUs that are registered via the AMF, the number of WTRUs that are registered to certain slices (S-NSSAIs), the number of established PDU Sessions, or an indication from an operation administration and maintenance (0AM) system.

[0130] At step 4.2, based on the determination of step 4.1 , the AMF may request a service of the NWDAF. The AMF may send a request restriction recommendations message to the NWDAF. The message indicates that the AMF requests restriction recommendations. The message provides the NWDAF with information about the current network conditions and an AMF Load Target. The request restriction recommendations message may also indicate to the NWDAF that the AMF request result predictions from the NWDAF. The request restriction recommendations message may also indicate a service area to the NWDAF.

[0131] At step 4.2, the NWDAF may receive the request restriction recommendations message from the AMF. The message may indicate that the AMF requests restriction recommendations. The message may provide the NWDAF with information about the current network conditions and an AMF load target. The message may also indicate to the NWDAF that the AMF request Result Predictions from the NWDAF. The message may also indicate a Service Area to the NWDAF.

[0132] More particularly, in the service invocation (e.g., request) the AMF may provide information about the current network conditions and an AMF load target to the NWDAF. The AMF may also indicate to the NWDAF that the AMF requests restriction recommendations from the NWDAF. The AMF may also indicate to the NWDAF that the AMF request result predictions from the NWDAF. The AMF may also indicate a Service Area to the NWDAF.

[0133] The service area may represent an area that is served by the AMF and the area where the AMF has determined to apply load control. The service area may be expressed as a set of cell identities, RAN node identities, tracking area identities, or a geographical area.

[0134] The information about the current network conditions that is provided by the AMF to the NWDAF may be information that relates to how much processing is currently required by the AMF. For example, the AMF may indicate the number of WTRUs that are registered to the AMF or the number of UEs that are in the CM CONNECTED state. The AMF may also indicate perslice information to the NWDAF. For example, the AMF may indicate how many UEs are registered to each slice that the AMF is a part of. Alternatively, the information about the current network conditions may be a scalar value (e.g., an integer) that represents the load level of the AMF.

[0135] The AMF load target that is provided by the AMF to the NWDAF may be a scalar value that represents the desired AMF load level. The NWDAF may use this information to derive restriction recommendations for the AMF. For example, if the AMF load target is very low, then the NWDAF may determine that a lot of activity needs to be restricted, whereas if the AMF load target is relatively higher the NWDAF may determine that a relatively lower amount of activity needs to be restricted.

[0136] The request that is sent in this step 4.2 may include an event identifier parameter that is set to a value that indicates that the AMF requests restriction recommendations from the NWDAF.

[0137] The service that is invoked in this step 4.2 may be the Nnwdaf EventsSubscription or Nwdaf_AnalyticsInfo service.

[0138] At step 4.3, the NWDAF may determine restriction recommendations. The NWDAF may use the AMF load target to derive / to determine the restriction recommendations. The NWDAF may use the information about the current network conditions that is provided by the AMF to (e.g., help) derive / to determine the restriction recommendations. Based on the information in the request from the AMF, the NWDAF may request and receive NF load information from an NRF or the 0AM System. The NF load information may relate to the AMF or to other network functions that are part of the same slice(s) as the AMF. Based on the information in the request from the AMF, the NWDAF may collect information from the UPF(s) that are part of the same slices as the AMF and may use the information to (e.g., help) determine restriction recommendations. The NWDAF may also derive / determine a result prediction. A result prediction may be a prediction of what the AMF load will change to if the AMF follows the restriction recommendations from the NWDAF. The NWDAF may also derive / determine a restricted service area. The restricted service area may be the set of cell identities, tracking area identities, geographical area, or RAN node identity over which restriction recommendations apply.

[0139] More particularly, at step 4.3, the NWDAF may determine restriction recommendations. As described above, the NWDAF may use the AMF load target to derive / to determine the restriction recommendations.

[0140] In order to derive / to determine the restriction recommendations, the NWDAF will also need to determine the current load on the AMF and other network functions that are serving the slices that the AMF is a part of. The information about the current network conditions that is provided by the AMF to the NWDAF may also be used to derive / to determine the restriction recommendations.

[0141] The NWDAF may also collect information from other network function and may use the information to (e.g., help) derive / to determine the restriction recommendations. For example, the NWDAF may request and receive NF load information from an NRF or 0AM System. The NFload information may relate to the AMF or to other network functions that are part of the same slice(s) as the AMF. For example, the NWDAF may collect information from the UPF(s) that are part of the same slices as the AMF and may use the information to (e.g., help) determine restriction recommendations.

[0142] The restriction recommendations may indicate to the AMF that the NWDAF recommends RRC connection requests be restricted or that NAS connection requests be restricted. The restriction recommendations may include a percentage of restriction recommendation that represents the percentage of RRC connection requests and non access stratum (NAS) connection request that should be restricted. The recommendation may be provided on a per S-NSSAI basis.

[0143] The NWDAF may also derive / determine a result prediction. A result prediction may be a prediction of what the AMF Load will change to if the AMF follows the restriction recommendations from the NWDAF.

[0144] The NWDAF may also derive / determine a restricted service area. The restricted service area may be the set of cell identities, tracking area identities, geographical area, or RAN node identity over which restriction recommendations apply.

[0145] At step 4.4, the AMF may receive a response from the NWDAF. The response may include restriction recommendations. The response may also include a result prediction. The response may also include a restricted service area. The response may include multiple sets of restriction recommendations and a result prediction and / or restricted service area for each member of the set of restriction recommendations.

[0146] At step 4.4, the NWDAF may transmit a response to the AMF. The response may include restriction recommendations. The restriction recommendations may indicate to the AMF that the NWDAF recommends RRC connection requested be restricted or that NAS connection requests be restricted. The restriction recommendations may include a percentage recommendation that represents the percentage of RRC connection requests and NAS connection request that should be restricted. The recommendation may be provided on a per S-NSSAI basis.

[0147] More particularly, at step 4.4, the NWDAF may provide the restriction recommendations, result prediction, and restricted service area to the AMF.

[0148] Alternatively, the NWDAF may provide multiple sets of restriction recommendations and a result prediction and / or restricted service area for each member of the set of restriction recommendations. The AMF may then use the result predictions to choose which set of restriction recommendations to select. For example, the AMF may select the set of restriction recommendations that will likely result in an AMF load that is close to a desired value. The desired value may be configured in the AMF via 0AM procedures.

[0149] This message may be in response to the AMF invoking the Nnwdaf EventsSubscription or Nwdaf_AnalyticsInfo service. For example, this message may be an Nnwdaf_Analytics_Notify service.At step 4.5, the AMF may transmit an OVERLOAD START message to a RAN node. The values that are provided to the RAN node in the OVERLOAD START message may be the values that were provided by the NWDAF or may be determined based on the values that were provided by the NWDAF.

[0150] More particularly, at step 4.5, the AMF may send an OVERLOAD START message to the RAN node. As described above, the OVERLOAD START message may request that the RAN node limits new connection requests from WTRUs, new connection requests from WTRUs that are for uplink NAS signaling, or new connection requests that are associated with certain S- NSSAI(s). The AMF may also provide a value that indicates the percentage of connection requests to be restricted. The values that are provided to the RAN node in the OVERLOAD START message may be the values that were provided by the NWDAF in step 4.4 or may be determined based on the values that were provided by the NWDAF in step 4.4.

[0151] The restriction recommendations that are provided by the NWDAF to the AMF may include, or be associated with, an expiration time value. The expiration time value may be used by the AMF to determine when to stop using the overload mitigation recommendations from the NWDAF. When the AMF determines that the restriction recommendations no longer apply, the AMF may send a new OVERLOAD START message to the RAN node to request a different restriction configuration or the AMF may send an OVERLOAD STOP message to the RAN node.

[0152] In an embodiment, the NWDAF may determine barring configuration.

[0153] Fig. 5 is an example of procedure for how the NWDAF may be used to improve network performance and minimize network disruptions when access barring is applies. The procedure shows how the RAN node may use the NWDAF to determine what access categories and access identities should be barred.

[0154] At step 5.1, the RAN node may determine that UAC settings should be changed. In other words, the RAN Node determines that UAC broadcast information should be changed or the RAN Node should begin to broadcast UAC information. The RAN node may make this determination based on internal logic, a request from the 0AM system, or reception of an OVERLOAD START message from the AMF. For example, the determination may be triggered by the OVERLOAD START signal (step 5.0) and the process that was illustrated by Fig. 4.

[0155] At step 5.2, the RAN node may transmit a message to the NWDAF. The message may indicate that the message is a request for UAC recommendations from the NWDAF. The messageincludes information about the current RAN node conditions and a RAN node load target. The message may also indicate that UAC result predictions are requested from the NWDAF. The message may also indicate a service area to the NWDAF. The service area may be expressed as a set of cell identities, tracking areas identities, or a geographical area.

[0156] At step 5.2, the NWDAF may receive a message from the RAN node. The message may indicate that the message is a request for UAC recommendations. The message includes information about the current RAN node conditions and the RAN node load target. The message may also indicate that UAC result predictions are requested from the NWDAF. The message may also indicate the service area to the NWDAF. The service area may be expressed as a set of cell identities, tracking areas identities, or a geographical area.

[0157] More particularly, at step 5.2, based on the determination of step 5.1, the RAN node invokes a service of the NWDAF. In the service invocation (e.g., request) the RAN node may provide information about the current RAN node conditions and a RAN node load target to the NWDAF. The RAN node may also indicate to the NWDAF that the RAN node requests UAC recommendations from the NWDAF. The RAN node may also indicate to the NWDAF that the RAN node request UAC result predictions from the NWDAF. The RAN node may also indicate a service area to the NWDAF. The service area may represent an area that is served by the RAN node and the area where the RAN node has determined to apply barring. The service area may be expressed as a set of cell identities, tracking areas identities, or a geographical area.

[0158] The information about the current RAN Node conditions, that may be provided by the RAN node to the NWDAF, may be information that relates to how much processing is currently required by the RAN node or the degree to which RAN resources are being consumed. For example, the RAN node may indicate the number of WTRUs that are connected to the RAN node. The RAN node may also indicate per-slice information to the NWDAF. For example, the RAN node may indicate how many connected WTRUs associated with a certain S-NSSAI value in a RRC connection establishment request message or used RACH resources that are associated with a certain S-NSSAI value in the RRC connection establishment request message. Alternatively, the information about the current RAN node conditions may be a scalar value (e.g., an integer) that represents the load level of the RAN Node.

[0159] The RAN node load target that is provided by the RAN node to the NWDAF may be a scalar value that represents the desired RAN node load level. The NWDAF may use this information to (e.g., help) derive / determine UAC recommendations for the RAN node. For example, in case of the RAN node load target is very low, then the NWDAF may determine that a lot of activity needs to be restricted e.g., barred), whereas if the RAN load target is relatively higher, the NWDAF may determine that a relatively lower amount of activity needs to be restricted(e.g., barred), restricting more activity may mean that more access categories or access identities should restricted whereas restricting less activity may mean that fewer access categories or access identities should be restricted. The UAC recommendation may also include a barring factor and a barring time. A barring factor is a value that represents the likelihood that an access will be barred. A barring time represents the average time that a WTRU should wait before reattempting a barred access. A relatively low RAN node load target may result in selecting a high barring time and a high barring factor. A relatively high RAN node load target may result in selecting a low barring time and a low barring factor.

[0160] The service that is invoked by the RAN Node in this step 5.2 may be the Nnwdaf_EventsSubscription or Nwdaf_AnalyticsInfo service.

[0161] At step 5.3, the NWDAF may use the information from the request message (step 5.2) to derive / determine UAC recommendations for the RAN node. The UAC recommendations may indicate to the RAN Node that the NWDAF recommends barring certain access identities or access categories. The UAC recommendations may indicate to the RAN node that activity related to a certain S-NSSAI should be barred. The UAC recommendation may also include a barring factor and a barring time. The NWDAF may also derive / determine a RAN load result prediction. The NWDAF may also derive / determine a UAC service area.

[0162] More particularly, at step 5.3, the NWDAF may determine UAC recommendations based on the information that was received in step 5.2 as described above.

[0163] As described above, the NWDAF may use the RAN load target to derive / determine the UAC recommendations. The information about the current RAN node conditions that is provided by the RAN node to the NWDAF may be used to derive / to determine the UAC recommendations. For example, if the RAN node load is already high, then the NWDAF may determine that more information needs to be barred.

[0164] The NWDAF may also collect information from other network function and may use the information to (e.g., help) derive / determine the UAC recommendations. For example, the NWDAF may request and receive NF load information from an NRF or 0AM System. The NF load information may relate to network functions that are part of the same slice(s) that were indicated in the information about the current RAN node conditions. For example, the NWDAF may collect information from AMF(s) and UPF(s) that are part of the same slices as that were indicated in the information that was provided by the RAN node and may use the information to determine UAC recommendations. The information from the AMF(s) and UPF(s) may be used by the NWDAF to determine the level of activity that is expected within the slice(s).

[0165] The UAC recommendations may indicate to the RAN node that the NWDAF recommends barring certain access identities or access categories. Note that an access categoriesmay be associated with an S-NSSAI(s). Alternatively, the UAC recommendations may indicate to the RAN node that activity related to a certain S-NSSAI should be barred. The NWDAF may be configured by the OAM system with information that indicates that an access category is associated with an S-NSSAI. The UAC recommendation may also include a barring factor and a barring time. A barring factor is a value that represents the likelihood that an access will be barred. A barring time represents the average time that a WTRU should wait before reattempting a barred access.

[0166] The NWDAF may also derive / determine a RAN load result prediction. A RAN load result prediction may be a prediction of what the RAN load will change to in case of the RAN follows the UAC recommendations from the NWDAF.

[0167] The NWDAF may also derive / determine a UAC service area. The UAC service area may be the set of cell identities, over which the UAC recommendations apply.

[0168] At step 5.4, the RAN node may receive a response from the NWDAF. The response may include UAC recommendations. The response may also include RAN load result prediction. The response may also include a UAC service area. The response may include multiple sets of UAC recommendations and a RAN load result prediction and / or UAC service area for each member of the set of UAC recommendations.

[0169] At step 5.4, the NWDAF may transmit the response to the RAN node. The response may include the UAC recommendations. The response may also include RAN load result prediction. The response may also include a UAC service area. The response may include multiple sets of UAC recommendations and a RAN load result prediction and / or UAC service area for each member of the set of UAC recommendations.

[0170] More particularly, at step 5.4, the NWDAF may provide the UAC recommendations, RAN load result prediction, and UAC service area to the RAN node.

[0171] Alternatively, the NWDAF may provide multiple sets of UAC recommendations and a RAN load result prediction and / or UAC service area for each member of the set of UAC recommendations. The RAN node may then use the RAN load result predictions to choose which set of UAC recommendations to select. For example, the RAN node may select the set of UAC recommendations that will likely result in an RAN load that is close to a desired value. The desired value may be configured in the RAN node via OAM procedures. This message may be in response to the RAN node invoking the Nnwdaf_EventsSubscription or Nwdaf_AnalyticsInfo service. For example, this message may be an Nnwdaf_Analytics_Notify service.

[0172] At step 5.5, the RAN node may determine UAC broadcast information and begin to broadcast the information. The UAC broadcast information may be determined based on the UAC recommendations that were received from the NWDAF.

[0173] The RAN node may then use the RAN load result predictions to choose which set of UAC recommendations to use to determine the UAC broadcast information. For example, the RAN node may use the set of UAC recommendations that will likely result in an RAN load that is close to a desired value. The desired value may be configured in the RAN node via 0AM procedures.

[0174] More particularly, at step 5.5, the RAN node may begin to broadcast indication(s) that selected access categories and access identities are barred. The barring time and barring factor may also be broadcasted. The selected access categories, access identities, barring time and barring factor may be selected from the UAC recommendations that were received in step 5.4.

[0175] The UAC recommendations may include, or be associated with, a time value, e.g., a time duration value. The time value may be used by the RAN node to determine when to stop broadcasting the barring information. In case of the RAN node determines that the UAC recommendations no longer apply, the RAN node may stop broadcasting the barring information.

[0176] Referring to FIG. 6, a method, 600, implemented in a network anomaly monitoring function, NAMF, module, may comprise a step of receiving, 610, by the NAMF module, configuration information indicating a network anomaly monitoring strategy. The method, 600, may further comprise a step of determining, 620, to monitor, based on the network anomaly monitoring strategy, a network anomaly in a network area. The method, 600, may further comprise a step of selecting, 630, at least one network function element of the network related to the network area. The method, 600, may further comprise a step of transmitting, 640, to the selected network function element, a message indicating a request for statistics related to the network area, based on the network anomaly monitoring strategy; and a step of receiving, 650, from the selected network function element, the requested statistics.

[0177] Referring to FIG. 7, a method 700, implemented in a network anomaly monitoring function, NAMF, module, may comprise a step of receiving 710, from a network node element, a first message comprising a request for restriction recommendations, the first message further comprising information indicating current network conditions and the network node element load target. The method 700 may further comprise a step of determining 720 restriction recommendations based on the information of the first message; and a step of transmitting 730, to the network node element, a second message comprising information including the determined restriction recommendations.

[0178] Referring to FIG. 8, a method 800, implemented in a network function module, may comprise a step wherein the network function module may receive 810, a first message comprising configuration information indicating a network anomaly monitoring strategy. The network function module may be, as anon-limited example, a network data analytics function module. The method 800 may comprise a step wherein the network function module may monitor 820, basedon the network anomaly monitoring strategy, a network anomaly in a network area. The network area may comprise at least one network interface. The network area may comprise one or more control plane interfaces. The method 800 may comprise a step wherein the network function module may select 830 at least one network function element of a network related to the network area. The selected network function element may be an access and mobility management function element of the network. Selecting at least one network function element may comprise any of selecting at least one network function element responsible for monitoring the network area; and selecting at least one network function element based on the network anomaly.

[0179] The method 800 may comprise a step wherein the network function module may transmit 840, to the selected network function element, a second message indicating a request for statistics related to the network area, based on the network anomaly monitoring strategy; and may receive 850, from the selected network function element, said statistics.

[0180] The statistics may comprise any of a number of non-access stratum, NAS, connections; rate of increment / decrement of number of NAS connections, number of control plane signals in a unit time, size of control plane signals, and bandwidth occupancy ratio.

[0181] The second message may further comprise an event identifier associated with an event filter for the statistics, wherein the event identifier may indicate one or more event of control plane interface signal loads, and wherein the event filter may comprise any of a type of control plane, a type of statistics to be generated by the selected network function element, and a type or name of service operation subscribed by the network function element.

[0182] The method 800 may comprise a step wherein the network function module may receive periodically the statistics. The method 800 may comprise a step wherein the network function module may determine network anomaly based on the received statistics. The method 800 may comprise a step wherein the network function module may determine network anomaly prevention based on the received statistics.

[0183] The method may comprise a step wherein the network function module may transmit, to a network function node, a signaling storm notification comprising information indicating a cause of a signaling load and a source network node of the signaling load.

[0184] Although features and elements are provided above in particular combinations, one of ordinary skill in the art will appreciate that each feature or element can be used alone or in any combination with the other features and elements. The present disclosure is not to be limited in terms of the particular embodiments described in this application, which are intended as illustrations of various aspects. Many modifications and variations may be made without departing from its spirit and scope, as will be apparent to those skilled in the art. No element, act, or instruction used in the description of the present application should be construed as critical oressential to the invention unless explicitly provided as such. Functionally equivalent methods and apparatuses within the scope of the disclosure, in addition to those enumerated herein, will be apparent to those skilled in the art from the foregoing descriptions. Such modifications and variations are intended to fall within the scope of the appended claims. The present disclosure is to be limited only by the terms of the appended claims, along with the full scope of equivalents to which such claims are entitled. It is to be understood that this disclosure is not limited to particular methods or systems.

[0185] The foregoing embodiments are discussed, for simplicity, with regard to the terminology and structure of infrared capable devices, i.e., infrared emitters and receivers. However, the embodiments discussed are not limited to these systems but may be applied to other systems that use other forms of electromagnetic waves or non-electromagnetic waves such as acoustic waves.

[0186] It is also to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, the term "video" or the term "imagery" may mean any of a snapshot, single image and / or multiple images displayed over a time basis. As another example, when referred to herein, the terms "user equipment" and its abbreviation "UE", the term "remote" and / or the terms "head mounted display" or its abbreviation "HMD" may mean or include (i) a wireless transmit and / or receive unit (WTRU); (ii) any of a number of embodiments of a WTRU; (iii) a wireless-capable and / or wired-capable (e.g., tetherable) device configured with, inter alia, some or all structures and functionality of a WTRU; (iii) a wireless-capable and / or wired-capable device configured with less than all structures and functionality of a WTRU; or (iv) the like. Details of an example WTRU, which may be representative of any WTRU recited herein, are provided herein with respect to FIGs. 1 A-1D. As another example, various disclosed embodiments herein supra and infra are described as utilizing a head mounted display. Those skilled in the art will recognize that a device other than the head mounted display may be utilized and some or all of the disclosure and various disclosed embodiments can be modified accordingly without undue experimentation. Examples of such other device may include a drone or other device configured to stream information for providing the adapted reality experience.

[0187] In addition, the methods provided herein may be implemented in a computer program, software, or firmware incorporated in a computer-readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (transmitted over wired or wireless connections) and computer-readable storage media. Examples of computer- readable storage media include, but are not limited to, a read only memory (ROM), a random access memory (RAM), a register, cache memory, semiconductor memory devices, magnetic media such as internal hard disks and removable disks, magneto-optical media, and optical mediasuch as CD-ROM disks, and digital versatile disks (DVDs). A processor in association with software may be used to implement a radio frequency transceiver for use in a WTRU, UE, terminal, base station, RNC, or any host computer.

[0188] Variations of the method, apparatus and system provided above are possible without departing from the scope of the invention. In view of the wide variety of embodiments that can be applied, it should be understood that the illustrated embodiments are examples only, and should not be taken as limiting the scope of the following claims. For instance, the embodiments provided herein include handheld devices, which may include or be utilized with any appropriate voltage source, such as a battery and the like, providing any appropriate voltage.

[0189] Moreover, in the embodiments provided above, processing platforms, computing systems, controllers, and other devices that include processors are noted. These devices may include at least one Central Processing Unit ("CPU") and memory. In accordance with the practices of persons skilled in the art of computer programming, reference to acts and symbolic representations of operations or instructions may be performed by the various CPUs and memories. Such acts and operations or instructions may be referred to as being "executed," "computer executed" or "CPU executed."

[0190] One of ordinary skill in the art will appreciate that the acts and symbolically represented operations or instructions include the manipulation of electrical signals by the CPU. An electrical system represents data bits that can cause a resulting transformation or reduction of the electrical signals and the maintenance of data bits at memory locations in a memory system to thereby reconfigure or otherwise alter the CPU's operation, as well as other processing of signals. The memory locations where data bits are maintained are physical locations that have particular electrical, magnetic, optical, or organic properties corresponding to or representative of the data bits. It should be understood that the embodiments are not limited to the above-mentioned platforms or CPUs and that other platforms and CPUs may support the provided methods.

[0191] The data bits may also be maintained on a computer readable medium including magnetic disks, optical disks, and any other volatile (e.g., Random Access Memory (RAM)) or non-volatile (e.g., Read-Only Memory (ROM)) mass storage system readable by the CPU. The computer readable medium may include cooperating or interconnected computer readable medium, which exist exclusively on the processing system or are distributed among multiple interconnected processing systems that may be local or remote to the processing system. It should be understood that the embodiments are not limited to the above-mentioned memories and that other platforms and memories may support the provided methods.

[0192] In an illustrative embodiment, any of the operations, processes, etc. described herein may be implemented as computer-readable instructions stored on a computer-readable medium. Thecomputer-readable instructions may be executed by a processor of a mobile unit, a network element, and / or any other computing device.

[0193] There is little distinction left between hardware and software implementations of aspects of systems. The use of hardware or software is generally (but not always, in that in certain contexts the choice between hardware and software may become significant) a design choice representing cost versus efficiency tradeoffs. There may be various vehicles by which processes and / or systems and / or other technologies described herein may be effected (e.g., hardware, software, and / or firmware), and the preferred vehicle may vary with the context in which the processes and / or systems and / or other technologies are deployed. For example, if an implementer determines that speed and accuracy are paramount, the implementer may opt for a mainly hardware and / or firmware vehicle. If flexibility is paramount, the implementer may opt for a mainly software implementation. Alternatively, the implementer may opt for some combination of hardware, software, and / or firmware.

[0194] The foregoing detailed description has set forth various embodiments of the devices and / or processes via the use of block diagrams, flowcharts, and / or examples. Insofar as such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, it will be understood by those within the art that each function and / or operation within such block diagrams, flowcharts, or examples may be implemented, individually and / or collectively, by a wide range of hardware, software, firmware, or virtually any combination thereof. In an embodiment, several portions of the subject matter described herein may be implemented via Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), digital signal processors (DSPs), and / or other integrated formats. However, those skilled in the art will recognize that some aspects of the embodiments disclosed herein, in whole or in part, may be equivalently implemented in integrated circuits, as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or as virtually any combination thereof, and that designing the circuitry and / or writing the code for the software and or firmware would be well within the skill of one of skill in the art in light of this disclosure. In addition, those skilled in the art will appreciate that the mechanisms of the subject matter described herein may be distributed as a program product in a variety of forms, and that an illustrative embodiment of the subject matter described herein applies regardless of the particular type of signal bearing medium used to actually carry out the distribution. Examples of a signal bearing medium include, but are not limited to, the following: a recordable type medium such as a floppy disk, a hard disk drive, a CD, a DVD, a digital tape, a computer memory, etc., and a transmission type medium such as a digital and / or an analogcommunication medium (e.g., a fiber optic cable, a waveguide, a wired communications link, a wireless communication link, etc.).

[0195] Those skilled in the art will recognize that it is common within the art to describe devices and / or processes in the fashion set forth herein, and thereafter use engineering practices to integrate such described devices and / or processes into data processing systems. That is, at least a portion of the devices and / or processes described herein may be integrated into a data processing system via a reasonable amount of experimentation. Those having skill in the art will recognize that a typical data processing system may generally include one or more of a system unit housing, a video display device, a memory such as volatile and non-volatile memory, processors such as microprocessors and digital signal processors, computational entities such as operating systems, drivers, graphical user interfaces, and applications programs, one or more interaction devices, such as a touch pad or screen, and / or control systems including feedback loops and control motors (e.g., feedback for sensing position and / or velocity, control motors for moving and / or adjusting components and / or quantities). A typical data processing system may be implemented utilizing any suitable commercially available components, such as those typically found in data computing / communication and / or network computing / communication systems.

[0196] The herein described subject matter sometimes illustrates different components included within, or connected with, different other components. It is to be understood that such depicted architectures are merely examples, and that in fact many other architectures may be implemented which achieve the same functionality. In a conceptual sense, any arrangement of components to achieve the same functionality is effectively "associated" such that the desired functionality may be achieved. Hence, any two components herein combined to achieve a particular functionality may be seen as "associated with" each other such that the desired functionality is achieved, irrespective of architectures or intermedial components. Likewise, any two components so associated may also be viewed as being "operably connected", or "operably coupled", to each other to achieve the desired functionality, and any two components capable of being so associated may also be viewed as being "operably couplable" to each other to achieve the desired functionality. Specific examples of operably couplable include but are not limited to physically mateable and / or physically interacting components and / or wirelessly interactable and / or wirelessly interacting components and / or logically interacting and / or logically interactable components.

[0197] With respect to the use of substantially any plural and / or singular terms herein, those having skill in the art can translate from the plural to the singular and / or from the singular to the plural as is appropriate to the context and / or application. The various singular / plural permutations may be expressly set forth herein for sake of clarity.

[0198] It will be understood by those within the art that, in general, terms used herein, and especially in the appended claims (e.g., bodies of the appended claims) are generally intended as "open" terms (e.g., the term "including" should be interpreted as "including but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "includes but is not limited to," etc.). It will be further understood by those within the art that if a specific number of an introduced claim recitation is intended, such an intent will be explicitly recited in the claim, and in the absence of such recitation no such intent is present. For example, where only one item is intended, the term "single" or similar language may be used. As an aid to understanding, the following appended claims and / or the descriptions herein may include usage of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed to imply that the introduction of a claim recitation by the indefinite articles "a" or "an" limits any particular claim including such introduced claim recitation to embodiments including only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" and indefinite articles such as "a" or "an" (e.g., "a" and / or "an" should be interpreted to mean "at least one" or "one or more"). The same holds true for the use of definite articles used to introduce claim recitations. In addition, even if a specific number of an introduced claim recitation is explicitly recited, those skilled in the art will recognize that such recitation should be interpreted to mean at least the recited number (e.g., the bare recitation of "two recitations," without other modifiers, means at least two recitations, or two or more recitations). Furthermore, in those instances where a convention analogous to "at least one of A, B, and C, etc." is used, in general such a construction is intended in the sense one having skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). In those instances where a convention analogous to "at least one of A, B, or C, etc." is used, in general such a construction is intended in the sense one having skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). It will be further understood by those within the art that virtually any disjunctive word and / or phrase presenting two or more alternative terms, whether in the description, claims, or drawings, should be understood to contemplate the possibilities of including one of the terms, either of the terms, or both terms. For example, the phrase "A or B" will be understood to include the possibilities of "A" or "B" or "A and B." Further, the terms "any of' followed by a listing of a plurality of items and / or a plurality of categories of items, as used herein, are intended to include "any of," "any combination of," "any multiple of," and / or "any combinationof multiples of the items and / or the categories of items, individually or in conjunction with other items and / or other categories of items. Moreover, as used herein, the term "set" is intended to include any number of items, including zero. Additionally, as used herein, the term "number" is intended to include any number, including zero. And the term "multiple", as used herein, is intended to be synonymous with "a plurality".

[0199] In addition, where features or aspects of the disclosure are described in terms of Markush groups, those skilled in the art will recognize that the disclosure is also thereby described in terms of any individual member or subgroup of members of the Markush group.

[0200] As will be understood by one skilled in the art, for any and all purposes, such as in terms of providing a written description, all ranges disclosed herein also encompass any and all possible subranges and combinations of subranges thereof. Any listed range can be easily recognized as sufficiently describing and enabling the same range being broken down into at least equal halves, thirds, quarters, fifths, tenths, etc. As a non-limiting example, each range discussed herein may be readily broken down into a lower third, middle third and upper third, etc. As will also be understood by one skilled in the art all language such as "up to," "at least," "greater than," "less than," and the like includes the number recited and refers to ranges which can be subsequently broken down into subranges as discussed above. Finally, as will be understood by one skilled in the art, a range includes each individual member. Thus, for example, a group having 1-3 cells refers to groups having 1, 2, or 3 cells. Similarly, a group having 1-5 cells refers to groups having 1, 2, 3, 4, or 5 cells, and so forth.

[0201] Moreover, the claims should not be read as limited to the provided order or elements unless stated to that effect. In addition, use of the terms "means for" in any claim is intended to invoke 35 U.S.C. §112, 6 or means-plus-function claim format, and any claim without the terms "means for" is not so intended.

Claims

CLAIMS1. A method, implemented in a network function module, comprising: receiving, by the network function module, a first message comprising configuration information indicating a network anomaly monitoring strategy; monitoring, based on the network anomaly monitoring strategy, a network anomaly in a network area; selecting at least one network function element of a network related to the network area; transmitting, to the selected network function element, a second message indicating a request for statistics related to the network area, based on the network anomaly monitoring strategy; and receiving, from the selected network function element, said statistics.

2. The method of claim 1, wherein the network area comprises at least one network interface.

3. The method of any of claim 1 and claim 2, wherein the network area comprises one or more control plane interfaces.

4. The method of any of the preceding claims, wherein the selected network function element is an access and mobility management function element of the network.

5. The method of any of the preceding claims, wherein the statistics comprises any of a number of non-access stratum, NAS, connections, rate of increment / decrem ent of number of NAS connections, number of control plane signals in a unit time, size of control plane signals, and bandwidth occupancy ratio.

6. The method of any of the preceding claims, wherein the second message further comprises an event identifier associated with an event filter for the statistics7. The method of claim 6, wherein the event identifier indicates one or more event of control plane interface signal loads, and wherein the event filter comprises any of a type of control plane, a type of statistics to be generated by the selected network function element, and a type or name of service operation subscribed by the network function element.

8. The method of any of the preceding claims, wherein selecting at least one network function element comprises any of selecting at least one network function element responsible for monitoring the network area; and selecting at least one network function element based on the network anomaly.

9. The method of any of the preceding claims, comprising receiving periodically the statistics.

10. The method of any of the preceding claims, comprising determining network anomaly based on the received statistics.

11. The method of any of the preceding claims, comprising determining network anomaly prevention based on the received statistics.

12. The method of any of the preceding claims, wherein the network function module is a network data analytics function module.

13. The method of any of the preceding claims, comprising transmitting, to a network function node, a signaling storm notification comprising information indicating a cause of a signaling load and a source network node of the signaling load.

14. A network function module comprising a processor, a transceiver unit and a storage unit, and configured to: receive, by the network function module, a first message comprising configuration information indicating a network anomaly monitoring strategy;monitor, based on the network anomaly monitoring strategy, a network anomaly in a network area; select at least one network function element of a network related to the network area; transmit, to the selected network function element, a second message indicating a request for statistics related to the network area, based on the network anomaly monitoring strategy; and receive, from the selected network function element, said statistics.

15. The network function module of claim 14, wherein the network area comprises at least one network interface.

16. The network function module of any of claims 14 and 15, wherein the network area comprises one or more control plane interfaces.

17. The network function module of any of the claims 14 to 16, wherein the selected network function element is an access and mobility management function element of the network.

18. The network function module of any of the claims 14 to 17, wherein the statistics comprises any of a number of non-access stratum, NAS, connections, rate of increment / decrem ent of number of NAS connections, number of control plane signals in a unit time, size of control plane signals, and bandwidth occupancy ratio.

19. The network function module of any of the claims 14 to 18, wherein the second message further comprises an event identifier associated with an event filter for the statistics.

20. The network function module of claim 19, wherein the event identifier indicates one or more event of control plane interface signal loads, and wherein the event filter comprises any of a type of control plane, a type of statistics to be generated by the selected network function element, and a type or name of service operation subscribed by the network function element.

21. The network function module of any of the claims 14 to 20, wherein selecting at least one network function element comprises any of selecting at least one network function element responsible for monitoring the network area; and selecting the at least one network function element based on the network anomaly.

22. The network function module of any of the claims 14 to 21, configured to receive periodically the statistics.

23. The network function module of any of the claims 14 to 22 configured to determine network anomaly based on the received statistics.

24. The network function module of any of the claims 14 to 23 configured to determine network anomaly prevention based on the received statistics.

25. The network function module of any of the claims 14 to 24, wherein the network function module is a network data analytics function module.

26. The network function module of any of the claims 14 to 25 configured to transmit, to a network function node, a signaling storm notification comprising information indicating a cause of a signaling load and a source network node of the signaling load.