Network analysis method and device

Through network analysis methods and devices, requests are received, network thresholds and current signaling quantity are obtained, signaling storm risks are determined, and reports are sent for improvement, which solves the problems of signaling storm prediction and prevention, and improves the reliability and availability of the network.

WO2025092592A1PCT designated stage expired Publication Date: 2025-05-08HUAWEI TECH CO LTD

Patent Information

Application Number
PCT/CN2024/127346
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-03
Filing Date
2024-10-25
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

How to predict the occurrence of signaling storms to prevent network unavailability caused by network congestion and avalanche effects.

Method used

A network analysis method and device are provided to obtain a network threshold and a current signaling number by receiving a request from the second device, determining whether there is a signaling storm event, and sending relevant reports to the second device for improvement.

Benefits of technology

It can predict the occurrence of signaling storms, help the second device to make timely improvements, prevent network unavailability, and improve network reliability and availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024127346_08052025_PF_FP_ABST
    Figure CN2024127346_08052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and provides a network analysis method and device. The method comprises: a first device receives a first request from a second device, wherein the first request is used for requesting the first device to determine whether a signaling storm event is present, and the signaling storm event is used for indicating that a network is at risk of experiencing a signaling storm; the first device acquires a network threshold, wherein the network threshold is used for indicating the quantity of signaling that the network can support; and the first device determines a first report on the basis of the network threshold and the current quantity of signaling of the network, wherein the first report is used for indicating that the signaling storm event is present. On the basis of the solution, on the basis of the quantity of signaling that the network can support and the current quantity of signaling of the network, the first device can determine that the network is at risk of experiencing a signaling storm, so that the occurrence of the signaling storm can be predicted.
Need to check novelty before this filing date? Find Prior Art

Description

Network analysis method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on November 3, 2023, with application number 202311464433.8 and invention name “Network Analysis Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and more particularly, to a network analysis method and device. Background Art

[0003] As carriers diversify their services and network architectures, increasing traffic volume places increasing pressure on signaling networks. This high pressure also signals frequent incidents. A signaling storm occurs when a network system receives more signaling requests from terminal devices than it can handle, causing network congestion or even an avalanche effect, leading to network unavailability.

[0004] Therefore, how to predict the occurrence of signaling storms is an urgent problem to be solved.

[0005] Summary of the Invention

[0006] The present application provides a network analysis method and apparatus capable of predicting the occurrence of signaling storms.

[0007] In a first aspect, a network analysis method is provided. The method can be performed by a first device, or by a component in the first device (e.g., a processor, a chip, or a chip system), or by a logic module or software that can implement all or part of the functions of the first device. The method includes: the first device receives a first request from a second device, the first request being used to request the first device to determine whether a signaling storm event exists, the signaling storm event being used to indicate that the network is at risk of a signaling storm; the first device obtains a network threshold, the network threshold being used to indicate the amount of signaling that the network can support; the first device determines a first report based on the network threshold and the current amount of signaling in the network, the first report being used to indicate the presence of the signaling storm event.

[0008] Exemplarily, the first device may be a service producer of a management data analytics service (MDAS), or the first device may be a management data analytics function (MDAF).

[0009] Based on the above solution, the first device can determine that the network has the risk of a signaling storm according to the signaling quantity that the network can support and the current signaling quantity of the network, thereby being able to predict the occurrence of a signaling storm.

[0010] In combination with the first aspect, in certain implementations of the first aspect, the first report includes at least one of abnormal network element information, type information, cause information, ratio information or duration information, wherein the abnormal network element information is used to indicate the network element with abnormal traffic when the signaling storm event occurs, the type information is used to indicate that the event type is a signaling storm, the cause information is used to indicate the cause of the signaling storm event, the ratio information is used to indicate the ratio of the current signaling amount to the historical signaling amount of the network, and the duration information is used to indicate the predicted duration of the signaling storm event.

[0011] Based on the above solution, the second device can improve the network according to the information in the first report, thereby helping the second device to prevent the occurrence of signaling storms.

[0012] In combination with the first aspect, in some implementations of the first aspect, the first device obtains the network threshold, including: the first device receives the network threshold from the second device.

[0013] Based on the above scheme, the network threshold can be sent by the second device to the first device. In this way, the first device can predict whether a signaling storm event exists based on the network threshold required by the second device, thereby achieving the second device's desired goal of preventing signaling storms.

[0014] In combination with the first aspect, in some implementations of the first aspect, the method further includes: the first device sending a maximum signaling quantity that the network can support to the second device.

[0015] Based on the above solution, the first device can send the maximum signaling quantity supported by the network to the second device, so that the second device can obtain the maximum signaling quantity supported by the network. The second device can improve the network based on the maximum signaling quantity supported by the network, thereby helping the second device prevent the occurrence of signaling storms.

[0016] In combination with the first aspect, in some implementations of the first aspect, the network threshold is less than a maximum signaling quantity that the network can support.

[0017] Based on the above solution, the network threshold is less than the maximum signaling volume that the network can support, allowing the first device to determine the presence of a signaling storm event when the risk of a signaling storm in the network is low. Furthermore, the above solution allows the second device to improve the network when the risk of a signaling storm is low, thereby improving the effectiveness of preventing signaling storms.

[0018] In combination with the first aspect, in certain implementations of the first aspect, the method also includes: the first device determines the maximum number of signaling that the network can support based on the availability parameters of multiple network elements in the network, wherein the multiple network elements in the network include a first network element, and the availability parameter of the first network element is the performance management data of the first network element under a first preset signaling number.

[0019] Based on the above solution, the first device can determine the maximum number of signalings that the network can support, so that the second device can obtain the maximum number of signalings that the network can support. The second device can improve the network based on the maximum number of signalings that the network can support, thereby helping the second device prevent the occurrence of signaling storms.

[0020] In combination with the first aspect, in certain implementations of the first aspect, the method also includes: the first device obtains the performance management data of the first network element and the virtual resource usage information of the first network element; the first device determines the availability parameters of the first network element based on the performance management data of the first network element and the virtual resource usage information of the first network element.

[0021] Based on the above solution, the first device can determine the availability parameter of the network element. The availability parameter is the performance management data of the network element under a preset signaling amount. Therefore, the availability parameter of the network element can describe the availability of the network element under signaling impact, which helps prevent the occurrence of signaling storms.

[0022] In combination with the first aspect, in some implementations of the first aspect, the method further includes: the first device sending the availability parameter of the first network element to the second device.

[0023] Based on the above solution, the first device can send the network element's availability parameter to the second device. The availability parameter is performance management data of the network element under a preset signaling volume. Therefore, the network element's availability parameter can describe the network element's availability under signaling shocks, helping the second device prevent signaling storms.

[0024] In combination with the first aspect, in some implementations of the first aspect, the method further includes: the first device receiving a second request from the second device, the second request being used to request the first device to determine availability parameters of multiple network elements in the network.

[0025] Based on the above solution, the first device can request the second device to determine the availability parameter of the network element. The availability parameter is performance management data of the network element under a preset signaling volume. The availability parameter of the network element can describe the availability of the network element under signaling impact. Therefore, the above solution helps the second device achieve the desired goal of preventing signaling storms.

[0026] In combination with the first aspect, in certain implementations of the first aspect, the multiple network elements in the network also include a second network element, wherein the method further includes: the first device obtains an availability parameter of the second network element, the availability parameter of the second network element is the performance management data of the second network element under a second preset signaling quantity, wherein, when the signaling storm occurs, the availability parameter of the second network element does not meet the expected target; the first device determines a second report based on the availability parameter of the second network element, wherein the second report is used to indicate capacity expansion of the second network element.

[0027] Based on the above solution, when the availability parameter of the second network element does not meet the expected target, the first device can suggest to the second device to expand the capacity of the second network element, so as to prevent the occurrence of a signaling storm.

[0028] In combination with the first aspect, in certain implementations of the first aspect, the desired goal includes an expected duration for resolving a signaling storm and / or a maximum number of users that the network can support.

[0029] Based on the above solution, the desired goal may include a desired duration for resolving the signaling storm and / or a maximum number of users that the network can support. The second device provides improvement suggestions to the network element based on the above desired goals, so that the network element can meet the desired duration and maximum number of users in the desired goals, thereby enhancing network availability.

[0030] In combination with the first aspect, in certain implementations of the first aspect, the method further includes: the first device receives a third request from the second device, the third request being used to request the first device to provide suggestions for network elements in the network, wherein the third request includes the desired target.

[0031] Based on the above solution, the first device can request the second device to provide improvement suggestions for the network element, and the request can carry the expected goal, thereby helping to achieve the second device's expected goal of preventing signaling storms.

[0032] In combination with the first aspect, in certain implementations of the first aspect, the method also includes: the first device registers a first management data analysis service MDAS and a second MDAS, wherein the capability information in the registration parameters corresponding to the first MDAS is used to indicate that the first MDAS is capable of determining whether the signaling storm event exists, and the capability information in the registration parameters corresponding to the second MDAS is used to indicate that the second MDAS is capable of providing recommendations for network elements in the network.

[0033] Based on the above solution, the second device can access the access address of the first MDAS or the second MDAS as needed, avoiding the delay caused by the first device identifying the intention of the second device and calling the corresponding MDAS, thereby improving the efficiency of network analysis.

[0034] In a second aspect, a network analysis method is provided. The method can be performed by a second device, or by a component in the second device (e.g., a processor, chip, or chip system), or by a logic module or software that implements all or part of the functions of the second device. The method includes: the second device sending a first request to a first device, the first request being used to request the first device to determine whether a signaling storm event exists, the signaling storm event being used to indicate that the network is at risk of a signaling storm; and the second device receiving a first report from the first device, the first report being used to indicate the presence of the signaling storm event.

[0035] For example, the second device may be a requester, or an operations support system (OSS), or other devices.

[0036] Based on the above solution, the first device can determine that the network has the risk of a signaling storm according to the signaling quantity that the network can support and the current signaling quantity of the network, thereby being able to predict the occurrence of a signaling storm.

[0037] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the second device sending a network threshold to the first device, where the network threshold is used to indicate the amount of signaling that the network can support.

[0038] Based on the above scheme, the network threshold can be sent by the second device to the first device. In this way, the first device can predict whether a signaling storm event exists based on the network threshold required by the second device, thereby achieving the second device's desired goal of preventing signaling storms.

[0039] In combination with the second aspect, in certain implementations of the second aspect, the method further includes: the second device receives the maximum signaling quantity that the network can support from the first device; and the second device determines the network threshold based on the maximum signaling quantity that the network can support.

[0040] Based on the above solution, the second device can determine the network threshold based on the maximum signaling volume that the network can support. In this way, the first device can predict whether a signaling storm event exists based on the network threshold required by the second device, thereby achieving the second device's desired goal of preventing signaling storms.

[0041] In combination with the second aspect, in certain implementations of the second aspect, the network threshold is less than a maximum signaling quantity or a maximum signaling multiple that the network can support.

[0042] Based on the above solution, the network threshold is less than the maximum signaling volume that the network can support, allowing the first device to determine the presence of a signaling storm event when the risk of a signaling storm in the network is low. Furthermore, the above solution allows the second device to improve the network when the risk of a signaling storm is low, thereby improving the effectiveness of preventing signaling storms.

[0043] In combination with the second aspect, in certain implementations of the second aspect, the multiple network elements in the network include a first network element, wherein the method further includes: the second device receives an availability parameter of the first network element from the first device, and the availability parameter of the first network element is the performance management data of the first network element under a first preset signaling quantity; the second device configures the first network element according to the availability parameter of the first network element.

[0044] Based on the above solution, the second device can configure the availability parameter on the network element. The availability parameter is the performance management data of the network element under a preset signaling amount. Therefore, the availability parameter of the network element can describe the availability of the network element under signaling impact, which helps the network element prevent the occurrence of signaling storms.

[0045] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the second device sending a second request to the first device, where the second request is used to request the first device to determine availability parameters of multiple network elements in the network.

[0046] Based on the above solution, the first device can request the second device to determine the availability parameter of the network element. The availability parameter is performance management data of the network element under a preset signaling volume. The availability parameter of the network element can describe the availability of the network element under signaling impact. Therefore, the above solution helps the second device achieve the desired goal of preventing signaling storms.

[0047] In combination with the second aspect, in certain implementations of the second aspect, the multiple network elements in the network also include a second network element, wherein the method further includes: the second device receives a second report from the first device, and the second report is used to indicate the expansion of the second network element, wherein, when the signaling storm occurs, the availability parameter of the second network element does not meet the expected target.

[0048] Based on the above solution, when the availability parameter of the second network element does not meet the expected target, the first device can suggest to the second device to expand the capacity of the second network element, so as to prevent the occurrence of a signaling storm.

[0049] In combination with the second aspect, in certain implementations of the second aspect, the desired goal includes an expected duration for resolving a signaling storm and / or a maximum number of users that the network can support.

[0050] Based on the above solution, the desired goal may include a desired duration for resolving the signaling storm and / or a maximum number of users that the network can support. The second device provides improvement suggestions to the network element based on the above desired goals, so that the network element can meet the desired duration and maximum number of users in the desired goals, thereby enhancing network availability.

[0051] In combination with the second aspect, in certain implementations of the second aspect, the third request includes the desired target, and the third request is used to request the first device to provide suggestions for network elements in the network, wherein the method also includes: the second device sends the third request to the first device.

[0052] Based on the above solution, the first device can request the second device to provide improvement suggestions for the network element, and the request can carry the expected goal, thereby helping to achieve the second device's expected goal of preventing signaling storms.

[0053] In combination with the second aspect, in certain implementations of the second aspect, the method also includes: the second device queries the registration parameters of the first device; the second device receives the registration parameters of the first management data analysis service MDAS and the registration parameters of the second MDAS, the capability information in the registration parameters corresponding to the first MDAS is used to indicate that the first MDAS can determine whether the signaling storm event exists, and the capability information in the registration parameters corresponding to the second MDAS is used to indicate that the second MDAS can provide suggestions for network elements in the network.

[0054] Based on the above solution, the second device can access the access address of the first MDAS or the second MDAS as needed, avoiding the delay caused by the first device identifying the intention of the second device and calling the corresponding MDAS, thereby improving the efficiency of network analysis.

[0055] In a third aspect, a communication device is provided, comprising a processor, wherein the processor is configured to enable the communication device to execute the first aspect and any possible method of the first aspect, or enable the communication device to execute the first aspect and any possible method of the second aspect, by executing a computer program or instruction, or by processing a circuit.

[0056] In one possible implementation, the communication device further includes a memory for storing the computer program or instruction. Further, the processor is specifically configured to call and execute the computer program or computer instruction stored in the memory, so that the processor implements any one of the implementations of the first aspect or the second aspect.

[0057] In one possible implementation, the communication device further includes a transceiver (also referred to as a communication interface), the transceiver being configured to input and / or output signals via the communication interface, and the processor being configured to control the transceiver to transmit and receive signals.

[0058] In a fourth aspect, a communication device is provided, comprising a processing circuit (also referred to as a processor) and an input / output interface (also referred to as an interface circuit), the input / output interface being used to input and / or output signals, the processing circuit being used to execute the first aspect and any possible method of the first aspect; or the processing circuit being used to execute the second aspect and any possible method of the second aspect.

[0059] In one possible implementation, the processor is configured to communicate with other devices via an interface circuit and execute any one of the implementations in the first aspect or any one of the implementations in the second aspect.

[0060] In a fifth aspect, a communication device is provided. The communication device may be a first device, or a device or module for performing the function of the first device; the communication device may be a second device, or a device or module for performing the function of the second device.

[0061] In one possible implementation, the communication device may include a module or unit corresponding to each of the methods / operations / steps / actions described in the first aspect. The module or unit may be a hardware circuit, software, or a combination of hardware circuit and software.

[0062] In another possible implementation, the communication device may include a module or unit corresponding to each of the methods / operations / steps / actions described in the second aspect. The module or unit may be a hardware circuit, software, or a combination of hardware circuit and software.

[0063] In the sixth aspect, a computer-readable storage medium is provided, on which a computer program or instruction is stored. When the computer program or the instruction is run on a computer, the first aspect and any possible method of the first aspect are executed; or, the second aspect and any possible method of the second aspect are executed.

[0064] In the seventh aspect, a computer program product is provided, comprising a computer program or instructions, which, when run on a computer, causes the first aspect and any possible method of the first aspect to be executed; or causes the second aspect and any possible method of the second aspect to be executed.

[0065] In an eighth aspect, a communication device is provided, comprising a processor connected to a memory and configured to call a program stored in the memory to execute any possible method of the first aspect or any possible method of the second aspect. The memory may be located within or outside the communication device. The processor may include one or more processors.

[0066] In one implementation, the communication device of the third, fourth, and fifth aspects may be a chip or a chip system.

[0067] In a ninth aspect, a chip device is provided, comprising a processor for calling a computer program or computer instruction in a memory so that the processor executes any one of the implementations in the first aspect or any one of the implementations in the second aspect.

[0068] Optionally, the processor is coupled to the memory via an interface.

[0069] In a tenth aspect, a communication system is provided, which includes a first device and a second device; the first device is used to execute the method shown in the first aspect, and the second device is used to execute the method shown in the second aspect.

[0070] In the eleventh aspect, a communication method is provided, which is applied to a first device and a second device, wherein the method includes: the first device executes the method shown in the first aspect; the second device executes the method shown in the second aspect.

[0071] The description of the advantageous effects of any of the third to eleventh aspects etc. may refer to the description of the advantageous effects of the first or second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] FIG1 is a schematic diagram of a network architecture of a communication system applicable to an embodiment of the present application.

[0073] FIG2 is a schematic flow chart of signaling processing.

[0074] FIG3 is a schematic block diagram of a communication system provided in an embodiment of the present application.

[0075] FIG4 is a schematic flow chart of a network analysis method provided in an embodiment of the present application.

[0076] FIG5 is a schematic flowchart of a registration method provided in an embodiment of the present application.

[0077] FIG6 is a schematic flowchart of a registration parameter query method provided in an embodiment of the present application.

[0078] FIG7 is a schematic flowchart of a network element capability evaluation method provided in an embodiment of the present application.

[0079] FIG8 is a schematic flowchart of a network capability evaluation method provided in an embodiment of the present application.

[0080] FIG9 is a schematic flowchart of a signaling storm event detection method provided in an embodiment of the present application.

[0081] FIG10 is a schematic flowchart of a signaling storm event analysis method provided in an embodiment of the present application.

[0082] FIG11 is a schematic flowchart of another network analysis method provided in an embodiment of the present application.

[0083] FIG12 is a schematic block diagram of a communication device according to an embodiment of the present application.

[0084] FIG13 is a schematic block diagram of another communication device according to an embodiment of the present application.

[0085] FIG14 is a schematic block diagram of a communication system according to an embodiment of the present application. DETAILED DESCRIPTION

[0086] The technical solution in this application will be described below with reference to the accompanying drawings.

[0087] The technical solution provided by this application can be applied to various communication systems, such as the fifth generation (5 th generation, 5G) or new radio (NR) system, long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, etc. The technical solution provided by this application can also be applied to future communication systems, such as the sixth generation (6 th The technical solution provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.

[0088] Figure 1 shows a schematic diagram of the network architecture of a communication system applicable to an embodiment of the present application. The network architecture includes terminal equipment, access network equipment, access and mobility management network element, session management network element, user plane function network element, policy control network element, network slice selection network element, network warehouse function network element, network data analysis network element, unified data management network element, unified data storage network element, authentication service function network element, network capability exposure network element, application function network element, and a data network (DN) connected to the operator's network. The terminal equipment can send service data to the data network through the access network equipment and user plane function network element, and receive service data from the data network.

[0089] A terminal device is a device with wireless transceiver capabilities that can be deployed on land, including indoors or outdoors, handheld, wearable, or vehicle-mounted; it can also be deployed on water (such as ships); it can also be deployed in the air (such as airplanes, balloons, and satellites). The terminal device can communicate with the core network via the radio access network (RAN) and exchange voice and / or data with the RAN. The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a mobile internet device (MID), a wearable device, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in smart grids, a wireless terminal in transportation safety, a wireless terminal in smart cities, a wireless terminal in smart homes, etc. The embodiments of this application do not limit the application scenarios. Terminal devices may also be referred to as user equipment (UE), mobile stations, and remote stations. The embodiments of this application do not limit the specific technology, device form, or name of the terminal devices.

[0090] Access network equipment is a device in the network used to connect terminal devices to the wireless network. Access network equipment can be a node in the radio access network, which can also be called a base station, or a radio access network (RAN) node (or device). In addition, RAN can also be equivalent to the next generation radio access network (NG-RAN) in the layer 3 relay architecture. In other words, RAN can be NG-RAN. For ease of description, RAN is sometimes used below to refer to access network equipment. It is understandable that RAN can also be AN.

[0091] The access network equipment may include an evolved base station (NodeB or eNB or e-NodeB, evolutionary Node B) in a long term evolution (LTE) system or an evolved LTE system (LTE-Advanced, LTE-A), such as a traditional macro base station eNB and a micro base station eNB in ​​a heterogeneous network scenario, or may also include a next generation node B (gNB) in a 5G or NR system, or may also include a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a transmission reception point (TRP), a home base station (e.g., home evolved NodeB, or home Node B, HNB), a base band unit (BBU), a base band pool BBU pool, or a WiFi access point (AP), etc., or may also include a centralized unit (CU) and a distributed unit (CU) in a cloud radio access network (CloudRAN) system. Unit (DU), not limited in the embodiments of the present application. In a separate deployment scenario where the access network equipment includes a CU and a DU, the CU supports protocols such as radio resource control (RRC), packet data convergence protocol (PDCP), and service data adaptation protocol (SDAP); the DU mainly supports the radio link control layer (RLC), media access control layer (MAC), and physical layer protocols.

[0092] The access and mobility management network element is mainly used for the attachment and tracking area update processes of terminals in mobile networks. The access and mobility management network element can provide non-access stratum (NAS) messages, complete registration management, connection management, reachability management, allocation of tracking area list (TA list), legal monitoring, access authorization, authentication and mobility management, etc., and transparently route session management (SM) messages to the session management network element. In the fifth generation (5G) communication system, the access and mobility management network element can be the access and mobility management function (AMF). In future communication systems (such as 6G communication systems), the mobility management network element can still be the AMF network element, or it can have other names, which is not limited in this application.

[0093] The session management network element is mainly used for session and bearer management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to terminals and selecting user plane function network elements that provide message forwarding functions. In 5G communication systems, the session management network element can be a session management function (SMF). In future communication systems (such as 6G communication systems), the session management network element can still be an SMF network element, or it can have other names, which are not limited by this application.

[0094] The user plane function network element is mainly used to process user messages, such as forwarding, billing, legal interception, etc. In addition, the user plane function network element can be used for routing and forwarding, threshold control, traffic monitoring, verification and other functions of user plane data. The user plane function network element can also be used for the management of UE IP addresses, the management of core network (CN) tunnel information, etc. The user plane function network element can also be called a protocol data unit (PDU) session anchor (PSA). In a 5G communication system, the user plane function network element can be a user plane function (UPF). In future communication systems (such as 6G communication systems), the user plane function network element can still be a UPF network element, or it can have other names, which is not limited in this application.

[0095] The policy control network element includes user subscription data management functions, policy control functions, billing policy control functions, QoS control, etc. In the 5G communication system, the policy control network element can be a policy control function (PCF). In future communication systems (such as 6G communication systems), the policy control network element can still be a PCF network element, or it can have other names, which is not limited in this application.

[0096] The network slice selection function network element is mainly used to select a suitable network slice for the service of the terminal device. In the 5G communication system, the network slice selection network element can be a network slice selection function (NSSF) network element. In future communication systems (such as 6G communication systems), the network slice selection network element can still be an NSSF network element, or it can have other names, which is not limited by this application.

[0097] The network repository function network element is mainly used to provide registration and discovery functions for network elements or services provided by network elements. In 5G communication systems, the network repository function network element can be a network repository function (NRF). In future communication systems (such as 6G communication systems), the network repository function network element can still be an NRF network element, or it can have other names, which is not limited by this application.

[0098] The network data analysis network element can collect data from various network functions (NFs), such as policy control network elements, session management network elements, user plane function network elements, access and mobility management network elements, and application function network elements (through network capability exposure function network elements), and perform analysis and prediction. In a 5G communication system, the network data analysis network element can be a network data analysis function (NWDAF). In future communication systems (such as 6G communication systems), the network data analysis network element can still be an NWDAF network element, or it can have other names, which is not limited by this application.

[0099] The unified data management network element is mainly used to manage the contract information of terminal devices. In the 5G communication system, the unified data management network element can be unified data management (UDM). In future communication systems (such as 6G communication systems), the unified data management network element can still be the UDM network element, or it can have other names, which is not limited by this application.

[0100] The unified data storage network element is mainly used to store structured data information, including contract information, policy information, and network data or business data defined in a standard format. In the 5G communication system, the unified data storage network element can be a unified data repository (UDR). In future communication systems (such as 6G communication systems), the unified data storage network element can still be a UDR network element, or it can have other names, which is not limited by this application.

[0101] The authentication service function network element is mainly used to perform security authentication on the terminal device. In the 5G communication system, the authentication service function network element can be the authentication server function (AUSF). In future communication systems (such as 6G communication systems), the authentication service function network element can still be the AUSF network element, or it can have other names, which is not limited by this application.

[0102] A network capability exposure network element can controllably expose some network functions to applications. In a 5G communication system, a network capability exposure network element can be a network exposure function (NEF). In future communication systems (such as a 6G communication system), the network capability exposure network element can still be an NEF network element, or it can have other names, which are not limited by this application.

[0103] The application function network element can provide service data of various applications to the control plane network elements of the operator's communication network, or obtain network data information and control information from the control plane network elements of the communication network. In the 5G communication system, the application function network element can be an application function (AF). In future communication systems (such as 6G communication systems), the application function network element can still be an AF network element, or it can have other names, which is not limited by this application. For example, the application function network element can also be called an application server or a service server. In addition, the application function network element can be deployed in the operator network or by a third party.

[0104] Data networks are primarily used to provide data transmission services to terminal devices. Data networks can be private networks, such as local area networks (LANs), public data networks (PDNs), such as the Internet, or proprietary networks deployed jointly by operators, such as those configured with IP multimedia core network subsystem (IMS) services. Data networks can also be provided by third parties.

[0105] It should be understood that the above-mentioned network element or function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the above-mentioned network element or function can be implemented by a single device, or by multiple devices, or as a functional module within a single device, which is not specifically limited in the embodiments of the present application.

[0106] It should also be understood that the above naming is only defined to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other networks in the future. For example, in a 6G network, some or all of the above networks may continue to use the terminology in 5G, or other names may be used. The interface name between the various network elements in Figure 1 is only an example. The name of the interface in the specific implementation may be other names, and this application does not make specific limitations on this. In addition, the name of the message (or signaling) transmitted between the above-mentioned network elements is only an example and does not constitute any limitation on the function of the message itself.

[0107] It should be noted that the aforementioned "network element" may also be referred to as an entity, device, apparatus, or module, and this application does not specifically limit this. Furthermore, in this application, for ease of understanding and explanation, the term "network element" is omitted in some descriptions. For example, the PCF network element is referred to as PCF. In this case, the "PCF" should be understood as a PCF network element or PCF entity. The following descriptions of identical or similar situations are omitted.

[0108] For ease of description, the network elements in Figure 1 other than the terminal devices are referred to as the network system. The terminal devices send signaling to the network system, which then receives the signaling and processes it through multiple network elements within the system. It's understood that each network element has limited signaling processing capabilities, and the overall network system's signaling processing capabilities are limited by the processing capabilities of each network element.

[0109] Figure 2 is a schematic flow chart of signaling processing. As shown in Figure 2, a UE sends multiple signaling messages to the network system. Processing these messages requires sequentially invoking network elements such as the access network device, AMF, SMF, IMS, and UDM. Assuming the UDM front-end (access network device, AMF, SMF, and IMS) processes signaling messages from the UE according to normal procedures, it will receive and process a large number of signaling messages and then send a signaling processing request to the UDM, requesting further processing of the signaling messages from the UE. If the UDM receives an excessive number of signaling processing requests, it may not be able to process all of them in a timely manner. Therefore, the UDM needs to implement flow control measures. For example, the UDM may reject signaling processing requests or refrain from processing them for an extended period of time. If a signaling message from the UE is rejected by the network system, the UDM front-end processing of the signaling message will be ineffective, and the UE will need to resend the signaling message to the network system. Alternatively, if a signaling message sent by the UE remains unprocessed by the network system for an extended period of time, the UE may resend the signaling message to the network system. In this case, a large number of UEs will resend signaling to the network system. At the same time, the network system has not yet processed the signaling sent by the UE before, and the newly sent signaling by the UE is processed by the front end of the UDM, causing the UDM to receive new signaling processing requests. This will cause the UDM to accumulate a large number of pending signaling processing requests, and the number of pending signaling processing requests continues to increase. When the above process develops to a certain scale (for example, a large number of users cannot obtain the services of the network system within 1 hour), a signaling storm will occur. The signaling storm will cause long-term congestion in the network system, resulting in unavailable services of the network system.

[0110] It should be noted that Figure 2 is only an example and does not constitute a limitation of the present application. For example, the signaling from the UE may be processed by more or fewer network elements. For another example, the signaling from the UE may be processed by other network elements other than the access network equipment, AMF, SMF, IMS and UDM. In addition, the above-mentioned AMF may also be replaced by a mobility management entity (MME), the above-mentioned SMF may also be replaced by a packet data network gateway (PGW), and the above-mentioned UDM may also be replaced by a home subscriber server (HSS).

[0111] A signaling storm occurs when the network system receives more signaling from terminal devices than it can handle. This can occur for a variety of reasons, including a large amount of signaling sent in a short period of time by a terminal device, a network element failure, a network system failure, a radio access network failure, a bearer network failure, or other unexpected disasters.

[0112] Therefore, how to predict the occurrence of signaling storms is an urgent problem to be solved.

[0113] FIG3 is a schematic block diagram of a communication system 300 provided in an embodiment of the present application.

[0114] 3 , OSS 310 can interact with MDAF 320. For example, MDAF 320 can provide MDAS services, and OSS 310 can use these services to request MDAF 320 to predict signaling storms or analyze the network system or network elements therein. Based on the request received from OSS 310, MDAF 320 can predict signaling storms or analyze the network system or network elements therein, and send a report on the prediction or analysis to OSS 310.

[0115] If network element 330 is a physical network function (PNF), MDAF 320 can send a request message to network element 330 to obtain information such as performance management (PM). If network element 330 is a virtual network function (VNF), MDAF 320 can send a request message to network function virtualization (NFV) management and orchestration (MANO) 340 to obtain information such as PM and virtual resource usage. Based on the information obtained, MDAF 320 can predict signaling storms or analyze the network system or network elements within it.

[0116] FIG4 is a schematic flow chart of a network analysis method 400 provided in an embodiment of the present application. Method 400 can predict the occurrence of a signaling storm. Method 400 is described below with reference to FIG4 .

[0117] S410: A first device receives a first request from a second device, the first request being used to request the first device to determine whether a signaling storm event exists, the signaling storm event being used to indicate that a network is at risk of a signaling storm. Accordingly, the second device sends the first request to the first device.

[0118] For example, the first device may be a service provider of an MDAS, or the first device may be an MDAF 320. However, this application is not limited thereto, and the first device may also be another device. The second device may be a requester, or the OSS 310. Alternatively, the second device may be another device.

[0119] The first request may be any request, and the first request may be carried in any message. The first request may also have other names, such as a signaling storm event discovery request, etc., which is not limited in this application.

[0120] A signaling storm event is used to indicate that the network is at risk of a signaling storm. The network in method 400 may be the aforementioned network system, and the network may include multiple network elements, which may be core network elements, access network devices, bearer network elements, and the like. The existence of a signaling storm event indicates that the network is at risk of a signaling storm. It is understandable that the existence of a signaling storm event does not mean that a signaling storm has occurred, nor does it mean that a fault (fault or failure) has occurred. The existence of a signaling storm event may also be expressed in other ways, such as a signaling storm event occurring, a signaling storm event appearing, and the present application does not limit this.

[0121] It should be noted that signaling storm and failure are two different concepts. When a signaling storm occurs, there may be no failure. Some time after the signaling storm occurs, due to the continuous accumulation of signaling in a certain network element in the network, a failure may occur. However, handling the failure at this time requires a lot of resources, and the failure has already caused business losses. It can be seen that signaling storm and failure are concepts at different levels. In some embodiments, MDAF can predict that the network has not experienced or failed. Alternatively, MDAF can determine that the network has not experienced or failed. Alternatively, the network has not experienced or failed. It can be understood that an alarm does not mean that a failure has occurred. The alarm may just be an anomaly in the network, which can be recovered through the network's self-healing mechanism and will not affect the network.

[0122] S420: The first device obtains a network threshold, where the network threshold is used to indicate the amount of signaling that the network can support.

[0123] The number of signalings can be a specific number or a relative number. As an example in which the number of signalings is a specific number, the number of signalings can be 1000. As an example in which the number of signalings is a relative value, the number of signalings can be 10 times a certain benchmark. The above-mentioned benchmark can be set manually, for example, set to 100. The above-mentioned benchmark can also be the specific number of signalings received by the network during the last signaling storm, signaling storm event or failure. The above-mentioned benchmark can also be the specific number of signalings received by the network at a certain point in time. The above-mentioned time point can be a specific time point, such as a certain moment in the past, or a relative time point, such as a time point a period of time (for example, 30 days) before the time point of executing S420. The above-mentioned time length can be pre-configured. It should be noted that this application does not limit the benchmark, and the benchmark can also be set in other ways.

[0124] It is understood that under certain performance requirements, the network has a maximum amount of signaling that it can support. For example, if the registration success rate is 80% and the single-user registration duration is 10 seconds, the network has a maximum number of user registration requests that it can support. Alternatively, the network threshold indicates the amount of signaling that the network can process while meeting the performance requirements. Alternatively, the network threshold indicates the amount of signaling that the network can process under performance conditions. The desired target may be determined by the second device or another device.

[0125] The network threshold can be used to indicate the maximum number of signaling operations that the network can support, or can be used to indicate a number of signaling operations that is less than the maximum number of signaling operations that the network can support. For example, if the maximum number of signaling operations that the network can support is 1000, the network threshold can be 1000, or any value less than 1000. For example, if the maximum number of signaling operations that the network can support is 10 times, the network threshold can be 10 times, or any value less than 10 times.

[0126] The maximum amount of signaling that the network can support can also be called the maximum increase in the signaling amount, or the maximum signaling impact that the entire network can support, or the maximum increase in the key performance indicator (KPI) (for example, the maximum number of sessions that the network can support, or the maximum number of user registration requests that the network can support).

[0127] Optionally, in another implementation scenario of the above embodiment, S420 includes: the first device receiving the network threshold from the second device.

[0128] The network threshold may be included in the first request. In other words, the first request may include the network threshold. Thus, the first device may determine the network threshold based on the first request. Alternatively, the first device may obtain the network threshold from the first request.

[0129] However, this application does not limit the specific manner in which the first device receives the network threshold. For example, the network threshold may also be carried in other messages. In other words, other messages may include the network threshold. In this way, the first device may determine the network threshold based on other messages. Alternatively, the first device may obtain the network threshold from other messages.

[0130] The first device receiving the network threshold from the second device can be understood as the first device receiving information indicating the network threshold.

[0131] Based on the above scheme, the network threshold can be sent by the second device to the first device. In this way, the first device can predict whether a signaling storm event exists based on the network threshold required by the second device, thereby achieving the second device's desired goal of preventing signaling storms.

[0132] Optionally, in another implementation scenario of the above embodiment, S420 includes: the first device determines the network threshold according to availability parameters of multiple network elements in the network.

[0133] An availability parameter may also be referred to as an availability indicator. For example, the multiple network elements include a first network element, a second network element, and a third network element. The availability parameter of the first network element may be performance management data of the first network element under a first preset signaling quantity. The availability parameter of the second network element may be performance management data of the second network element under a second preset signaling quantity. The availability parameter of the third network element may be performance management data of the third network element under a third preset signaling quantity.

[0134] The first preset signaling quantity, the second preset signaling quantity, and the third preset signaling quantity can be specific quantities or relative quantities. For the meanings of specific quantities and relative quantities, refer to the embodiment of S420 above. The first preset signaling quantity, the second preset signaling quantity, and the third preset signaling quantity can be all the same, partially the same, or all different. Below, taking the first preset signaling quantity as an example, the embodiments of the second preset signaling quantity and the third preset signaling quantity can refer to the embodiment of the first preset signaling quantity.

[0135] The first preset signaling quantity can be set to one or more. Thus, the availability parameter of the first network element can be one or more. In the case that the availability parameter of the first network element is multiple, the availability parameter of the first network element can be used to indicate the performance management data or KPI of the first network element under different signaling impacts. The maximum number of signalings that each network element in the multiple network elements can theoretically support. The first preset signaling quantity can be the maximum number of signalings that the first network element can support, or it can be a signaling quantity smaller than the maximum number of signalings that can be supported. For example, the maximum number of signalings that the first network element can support is 500, the first preset signaling quantity can be 500, or it can be any value less than 500. For example, the maximum number of signalings that the first network element can support is 5 times, the first preset signaling quantity can be 5 times, or it can be any value less than 5 times.

[0136] The above example only takes the case where the multiple network elements include the first network element, the second network element, and the third network element, and the present application does not limit this. For example, the multiple network elements may include more or fewer network elements.

[0137] Performance management data can be PM. For example, when the first network element is an AMF, the performance management data of the first network element can include the number of registered users, registration success rate, single user registration duration, maximum registration duration, etc. It is understood that the performance management data can also include other parameters, such as the average registration duration of multiple users, the maximum registration duration of multiple users, and the number of registration failures.

[0138] A lower availability parameter for a network element indicates a lower signaling volume that the network element can support. A higher availability parameter for a network element indicates a higher signaling volume that the network element can support. In other words, if a network element has a lower availability parameter when signaling volume is high, it may not meet expectations. If a network element has a higher availability parameter when signaling volume is high, it may meet expectations.

[0139] The first device comprehensively analyzes the availability parameters of multiple network elements in the network to determine the amount of signaling that the network can support, i.e., the network threshold. This application does not limit the specific method for determining the network threshold based on the availability parameters. For example, it can be based on an artificial intelligence (AI) algorithm or other algorithms.

[0140] S430: The first device determines a first report according to the network threshold and the current signaling amount of the network, where the first report is used to indicate the existence of the signaling storm event.

[0141] The current signaling quantity is a concept relative to the historical signaling quantity. The current signaling quantity can be the signaling quantity when executing S430, or it can be the signaling quantity when executing S410 or S420. The historical signaling quantity is the signaling quantity over a period of time in the past. For example, the historical signaling quantity can be the "benchmark" of the relative quantity of signaling. That is to say, the above-mentioned benchmark can also be the specific number of signaling received by the network during the last signaling storm, signaling storm event or failure. The historical signaling quantity can be the specific number of signaling received by the network at a certain point in time. The above-mentioned time point can be a specific time point, such as a certain moment in the past, or a relative time point, such as a time point some time ago (for example, 30 days) from the time point of executing S430. The above-mentioned duration can be pre-configured. It should be noted that this application does not limit the benchmark, and the benchmark can also be set in other ways.

[0142] As an example, the network threshold is a specific number of signalings that the network can support, wherein S430 includes: when the current signaling number is greater than or equal to the network threshold, the first device determines that the signaling storm event exists.

[0143] As another example, the network threshold is a relative amount of signaling that the network can support, wherein S430 includes: the first device obtaining a historical amount of signaling of the network. If a multiple of the current amount of signaling relative to the historical amount of signaling is greater than or equal to the network threshold, the first device determines that the signaling storm event exists.

[0144] The current signaling quantity may include the quantity of user registration request signaling, the quantity of sessions, etc. This application does not limit this.

[0145] It should be noted that this application does not limit the specific method of determining the first report. In addition to the two examples above, other methods can also be used to determine the first report. For example, an AI algorithm or other algorithms can be used to determine the first report.

[0146] In addition, the present application does not limit the specific name of the first report, and the first report may also have other names, such as indication information, report information, feedback information, feedback list, etc. The first report is a name of a type of information.

[0147] The first report may indicate the presence of the signaling storm event. Alternatively, the first report may indicate the occurrence or emergence of the signaling storm event. Alternatively, the first report may indicate that the network is at risk of a signaling storm.

[0148] As an alternative to S430, method 400 may include: the first device determining another report based on the network threshold and the current signaling amount of the network, the another report being used to indicate that the signaling storm event does not exist. The specific details of this embodiment are opposite to the description of the embodiment related to S430.

[0149] Based on the above solution, the first device can determine that the network has the risk of a signaling storm according to the signaling quantity that the network can support and the current signaling quantity of the network, thereby being able to predict the occurrence of a signaling storm.

[0150] Optionally, in another implementation scenario of the above embodiment, the method 430 further includes: the first device sending a first report to the second device, and correspondingly, the second device receiving the first report from the first device.

[0151] The first device sending the first report to the second device can be understood as the first device sending information indicating the first report to the second device. The first report can be carried in any message. This application does not limit the specific name of the first report. The first report can also have other names, such as indication information, report information, feedback information, feedback list, etc. The first report is the name of a type of information.

[0152] Optionally, in another implementation scenario of the above embodiment, the first report includes at least one of abnormal network element information, type information, cause information, ratio information or duration information, wherein the abnormal network element information is used to indicate the network element with abnormal traffic when the signaling storm event occurs, the type information is used to indicate that the event type is a signaling storm, the cause information is used to indicate the cause of the signaling storm event, the ratio information is used to indicate the ratio of the current signaling amount to the historical signaling amount of the network, and the duration information is used to indicate the predicted duration of the signaling storm event.

[0153] The first device may determine at least one of abnormal network element information, type information, cause information, ratio information, or duration information based on PM data such as KPIs, for example, using an AI algorithm or other algorithms.

[0154] Table 1 shows an embodiment of the first report. It should be noted that Table 1 is merely an example and does not limit the present application. For example, the first report may include more or less information than that in Table 1. For another example, the first report may replace any information in Table 1 with other information.

[0155] Table 1 Information element (IE) of the first report

[0156] Abnormal network element information can be included in the field corresponding to the fault prediction target. For example, the fault prediction target can indicate the network element with abnormal traffic flow during a signaling storm event. The network element with abnormal traffic flow has an availability parameter below a preset threshold during the signaling storm event. Alternatively, multiple network elements in the network are ranked from highest to lowest based on their availability parameters during the signaling storm event, with the network element with abnormal traffic flow being the lowest in the ranking.

[0157] The type information can be carried in the field corresponding to the potential fault type. In this way, the potential fault type can be used to indicate that the event type is a signaling storm. Based on the type information, the second device can determine (or know) that a signaling storm event has occurred. In other words, the type information can be used to indicate that a signaling storm event has occurred or appeared. In other words, the type information can be used to indicate that a signaling storm event exists. The potential fault type can also be used to indicate other types, such as equipment alarm, software or processing error alarm, quality of service alarm, or security service or mechanism violation.

[0158] The time of event occurrence can be used to indicate the time or point in time when the signaling storm event occurs. For example, the first device determines that a signaling storm event occurs at time A, and the time of event occurrence can be used to indicate time A. The event identifier can be used to indicate the identifier of the signaling storm event. The perceived severity can be used to indicate the severity of the signaling storm event. For example, the perceived severity can be divided into three levels: high, medium, and low, where a perceived severity of high indicates that the severity of the signaling storm event is high.

[0159] The cause information may be carried in a field corresponding to the root cause of the signaling storm. For example, the cause information may indicate the cause of the signaling storm, such as network interruption, disaster, or failure.

[0160] The ratio information can be carried in the field corresponding to the KPI change. For example, if the ratio of the current signaling amount to the historical signaling amount is 10, or the current signaling amount is 10 times the historical signaling amount, the ratio information or KPI change can be used to indicate 10.

[0161] Duration information can be carried in the field corresponding to the signaling storm duration. For example, the duration information can indicate 1000 minutes, indicating that the duration of the signaling storm event is 1000 minutes. The self-healing mechanism of the signaling storm often takes a long time, so the occurrence of signaling storms needs to be prevented.

[0162] This application does not limit the specific name of the first report, and the first report may also have other names, such as indication information, report information, feedback information, feedback list, etc. The first report is a name of a type of information.

[0163] Based on the above solution, the second device can improve the network according to the information in the first report, thereby helping the second device to prevent the occurrence of signaling storms.

[0164] Optionally, in another implementation scenario of the above embodiment, the method 400 further includes: the first device sending the maximum signaling quantity supported by the network to the second device. Correspondingly, the second device receives the maximum signaling quantity supported by the network from the first device.

[0165] For example, the first device may determine the maximum number of signalings that the network can support based on availability parameters of multiple network elements in the network. This application does not limit the specific method of determining the maximum number of signalings that the network can support, for example, it may be determined by an AI algorithm or other algorithms.

[0166] The first device sends the maximum signaling quantity that the network can support to the second device, which can be understood as the first device sending information to the second device for indicating the maximum signaling quantity that the network can support.

[0167] Based on the above solution, the first device can send the maximum signaling quantity supported by the network to the second device, so that the second device can obtain the maximum signaling quantity supported by the network. The second device can improve the network based on the maximum signaling quantity supported by the network, thereby helping the second device prevent the occurrence of signaling storms.

[0168] Optionally, in another implementation scenario of the above embodiment, the method 400 further includes: the second device determines the network threshold according to the maximum signaling quantity that the network can support.

[0169] As an example, the second device may determine the network threshold as a maximum signaling quantity that the network can support. As another example, the second device may determine a signaling quantity that is smaller than the maximum signaling quantity that the network can support as the network threshold.

[0170] Based on the above solution, the second device can determine the network threshold based on the maximum signaling volume that the network can support. In this way, the first device can predict whether a signaling storm event exists based on the network threshold required by the second device, thereby achieving the second device's desired goal of preventing signaling storms.

[0171] Optionally, in another implementation scenario of the above embodiment, the network threshold is smaller than the maximum signaling quantity that the network can support.

[0172] For example, the maximum number of signalings that the network can support is 1000, and the network threshold may be 800. For another example, the maximum number of signalings that the network can support is 10 times, and the network threshold may be 8 times.

[0173] It is understood that if the network threshold is equal to the maximum number of signalings that the network can support, then when the current number of signalings is close to the maximum number of signalings that the network can support, the first device can determine that a signaling storm event exists. In this case, the network is at a greater risk of experiencing a signaling storm, and may even fail. If the network threshold is less than the maximum number of signalings that the network can support, then when the current number of signalings is less than the maximum number of signalings that the network can support, the first device can determine that a signaling storm event exists. In this case, the risk of the network experiencing a signaling storm is lower, and the risk of failure is even lower, thereby improving the effectiveness of preventing signaling storms.

[0174] Based on the above solution, the network threshold is less than the maximum signaling volume that the network can support, allowing the first device to determine the presence of a signaling storm event when the risk of a signaling storm in the network is low. Furthermore, the above solution allows the second device to improve the network when the risk of a signaling storm is low, thereby improving the effectiveness of preventing signaling storms.

[0175] Optionally, in another implementation scenario of the above embodiment, the method 400 also includes: the first device determines the maximum number of signalings that the network can support based on the availability parameters of multiple network elements in the network, wherein the multiple network elements in the network include a first network element, and the availability parameter of the first network element is the performance management data of the first network element under a first preset signaling number.

[0176] The availability parameter may also be referred to as an availability index. The first preset signaling quantity may be a specific quantity or a relative quantity. The meaning of the specific quantity and the relative quantity can be found in the embodiment of S420 above.

[0177] The first preset signaling quantity may be the maximum signaling quantity supported by the first network element, or may be a signaling quantity smaller than the maximum signaling quantity supported. For example, if the maximum signaling quantity supported by the first network element is 500, the first preset signaling quantity may be 500, or may be any value smaller than 500. For example, if the maximum signaling quantity supported by the first network element is 5 times, the first preset signaling quantity may be 5 times, or may be any value smaller than 5 times.

[0178] Performance management data can be PM. For example, when the first network element is an AMF, the performance management data of the first network element can include the number of registered users, registration success rate, single user registration duration, maximum registration duration, etc. It is understood that the performance management data can also include other parameters, such as the average registration duration of multiple users, the maximum registration duration of multiple users, and the number of registration failures.

[0179] A lower availability parameter for a network element indicates a lower signaling volume that the network element can support. A higher availability parameter for a network element indicates a higher signaling volume that the network element can support. In other words, if a network element has a lower availability parameter when signaling volume is high, it may not meet expectations. If a network element has a higher availability parameter when signaling volume is high, it may meet expectations.

[0180] The first device comprehensively analyzes the availability parameters of multiple network elements in the network to determine the maximum number of signalings that the network can support. This application does not limit the specific method of determining the maximum number of signalings that the network can support based on the availability parameters. For example, it can be based on an AI algorithm or other algorithms.

[0181] Based on the above solution, the first device can determine the maximum number of signalings that the network can support, so that the second device can obtain the maximum number of signalings that the network can support. The second device can improve the network based on the maximum number of signalings that the network can support, thereby helping the second device prevent the occurrence of signaling storms.

[0182] Optionally, in another implementation scenario of the above embodiment, the method 400 also includes: the first device obtains the performance management data of the first network element and the virtual resource usage information of the first network element; the first device determines the availability parameters of the first network element based on the performance management data of the first network element and the virtual resource usage information of the first network element.

[0183] For example, the first device may obtain performance management data and virtual resource usage information of the first network element from NFV MANO 340. For example, the first device may send a request message to NFV MANO 340 to request the performance management data and virtual resource usage information of the first network element. NFV MANO 340 may send the performance management data and virtual resource usage information of the first network element to the first network element based on the request message.

[0184] Performance management data can be PM. For example, when the first network element is an AMF, the performance management data of the first network element can include the number of registered users, registration success rate, single user registration duration, maximum registration duration, etc. It is understood that the performance management data can also include other parameters, such as the average registration duration of multiple users, the maximum registration duration of multiple users, and the number of registration failures.

[0185] Virtual resource usage information can be used to indicate virtual resource usage. Virtual resources can include at least one of a virtual processor, virtual memory, or virtual disk. Virtual resources can also include other resources. Virtual resource usage information can include virtual processor utilization, virtual memory utilization, virtual disk utilization, etc. Virtual resource usage information can also include other information.

[0186] This application does not limit the specific method for determining the availability parameter based on performance management data and virtual resource usage information. For example, it can be based on an AI algorithm or other algorithms. It should be noted that the above only uses the first network element as an example. The embodiments of this application can also determine the availability parameters of other network elements. For example, the first device can determine the availability parameter of the second network element based on the performance management data of the second network element and the virtual resource usage information of the second network element.

[0187] Based on the above solution, the first device can determine the availability parameter of the network element. The availability parameter is the performance management data of the network element under a preset signaling amount. Therefore, the availability parameter of the network element can describe the availability of the network element under signaling impact, which helps prevent the occurrence of signaling storms.

[0188] Optionally, in another implementation scenario of the above embodiment, the method 400 further includes: the first device sending an availability parameter of the first network element to the second device. Accordingly, the second device receives the availability parameter of the first network element from the first device, where the availability parameter of the first network element is performance management data of the first network element under a first preset signaling quantity.

[0189] Based on the above solution, the first device can send the network element's availability parameter to the second device. The availability parameter is performance management data of the network element under a preset signaling volume. Therefore, the network element's availability parameter can describe the network element's availability under signaling shocks, helping the second device prevent signaling storms.

[0190] Optionally, in another implementation scenario of the above embodiment, the method 400 further includes: the second device configuring the first network element according to the availability parameter of the first network element.

[0191] For example, the second device may send configuration information to the first network element, where the configuration information includes an availability parameter of the first network element.

[0192] Based on the above solution, the second device can configure the availability parameter on the network element. The availability parameter is the performance management data of the network element under a preset signaling amount. Therefore, the availability parameter of the network element can describe the availability of the network element under signaling impact, which helps the network element prevent the occurrence of signaling storms.

[0193] Optionally, in another implementation scenario of the above embodiment, the method 400 further includes: the first device receiving a second request from the second device, the second request being used to request the first device to determine availability parameters of multiple network elements in the network. Accordingly, the second device sends the second request to the first device.

[0194] Exemplarily, the second request may include a network element identifier (or network element type) and a target signaling type. For example, the second request includes an AMF identifier and a registration request, so that the first device can determine the availability parameter of the AMF under a certain number of registration requests based on the second request.

[0195] The second request may be any request, and may be carried in any message. The second request may also have other names, such as a network element capability evaluation request or a network element availability evaluation request, etc., which are not limited in this application.

[0196] The second request can be triggered by an event, such as a holiday or network upgrade. In other words, when an event occurs, the second device can send the second request to the first device. The second request can also be proactively sent by the second device; in other words, the second device's sending of the second request is independent of any other event.

[0197] Based on the above solution, the first device can request the second device to determine the availability parameter of the network element. The availability parameter is performance management data of the network element under a preset signaling volume. The availability parameter of the network element can describe the availability of the network element under signaling impact. Therefore, the above solution helps the second device achieve the desired goal of preventing signaling storms.

[0198] Optionally, in another implementation scenario of the above embodiment, the multiple network elements in the network further include a second network element, wherein the method 400 further includes: the first device obtaining an availability parameter of the second network element, the availability parameter of the second network element being performance management data of the second network element under a second preset signaling quantity, the second network element being a bottleneck network element, wherein when the signaling storm occurs, the availability parameter of the second network element does not meet a desired target; the first device determining a second report based on the availability parameter of the second network element, wherein the second report is used to indicate capacity expansion for the second network element. Accordingly, the second device receives the second report from the first device.

[0199] As an example, the first device can determine the availability parameter of the second network element based on the performance management data of the second network element and the virtual resource usage information of the second network element, thereby enabling the first device to obtain the availability parameter of the second network element. As another example, the first device can obtain the availability parameter of the second network element from NFV MANO 340 or the second device. The second network element may have already been configured with the availability parameter. In this case, the first device can send a request message to NFV MANO 340 or the second device, requesting NFV MANO 340 or the second device to feedback the availability parameter of the second network element. NFV MANO 340 or the second device queries the configuration information of the second network element to obtain the availability parameter of the second network element and sends the availability parameter of the second network element to the first device. The first device receives the availability parameter of the second network element from NFV MANO 340 or the second device, thereby enabling the first device to obtain the availability parameter of the second network element.

[0200] The first device may determine that the second network element is a bottleneck network element based on availability parameters of multiple network elements in the network. For example, if the availability parameter of the second network element is less than the availability parameters of other network elements, the second network element may be determined to be a bottleneck network element. The bottleneck network element may be one or more network elements.

[0201] In some embodiments, the desired goal includes a desired duration for resolving a signaling storm and / or a maximum number of users that the network can support.

[0202] Based on the above solution, the desired goal may include a desired duration for resolving the signaling storm and / or a maximum number of users that the network can support. The second device provides improvement suggestions to the network element based on the above desired goals, so that the network element can meet the desired duration and maximum number of users in the desired goals, thereby enhancing network availability.

[0203] A network element (NE) whose availability parameters do not meet expectations is called a bottleneck NE. A bottleneck NE is one of the network's multiple NEs that is least resistant to signaling shocks. When a signaling storm occurs, the availability parameters of the bottleneck NE do not meet expectations. Consequently, the bottleneck NE cannot meet the expected duration to resolve the signaling storm or the maximum number of users the network is required to support. Consequently, implementing other measures, such as flow control, on the bottleneck NE will not meet the expected targets. In this case, expanding the capacity of the bottleneck NE can prevent the signaling storm.

[0204] Expanding the capacity of the second network element may be understood as increasing the virtual resources of the second network element, such as increasing the input and output upper limit of the virtual processor of the second network element, the capacity of the virtual memory, or the capacity of the virtual disk.

[0205] In some embodiments, the first device determines the second report based on the availability parameter and the desired target of the second network element.

[0206] As an example, the first device may determine the second report based on the availability parameter and convergence information of the second network element, wherein the convergence information is used to indicate the expected time length for the network to process the signaling received by the network within a preset time window after a signaling storm occurs.

[0207] For example, the preset event window may be 180 seconds. Within 180 seconds after the signaling storm occurs, the network receives multiple connection requests from terminal devices. The convergence information may indicate that the network takes 200 seconds to process these connection requests. The expected duration indicated by the convergence information may be calculated from the start of the preset time window, in other words, from the moment the signaling storm occurs. For example, when the expected duration indicated by the convergence information is less than or equal to the duration threshold, the first device may suggest that the second device expand the capacity of the second network element in order to enable the network to more quickly achieve the expected duration that the second device expects to resolve the signaling storm. The duration threshold may be set in advance.

[0208] As another example, the first device may determine the second report based on the availability parameter, user number information, and convergence information of the second network element. The user number information indicates the number of user online requests received by the network within a preset time window that the network can process after a signaling storm occurs. That is, the user number information may indicate the maximum number of users that the network can support.

[0209] As an example of combining user count information with convergence information, consider a scenario where, within 180 seconds of a signaling storm, the network receives multiple user login requests from terminal devices. The second network element expects the network to process the upper limit of 100 user requests within 200 seconds. It is understood that the user count information may originate from the second device. That is, in some embodiments, the second device sends the user count information to the first device, and the first device receives the user count information from the second device. Therefore, the user count information is a desired goal for the second device.

[0210] The suggestion for expanding the capacity of the second network element indicated in the first report may be called a scaling recommendation. It should be noted that the second report, convergence information, and user number information may also have other names, which are not limited in this application.

[0211] Based on the above solution, when the second network element is a bottleneck network element, the first device can suggest the second device to expand the capacity of the second network element, so as to prevent the occurrence of a signaling storm.

[0212] In some other embodiments, the second report may further include a flow control recommendation. For example, the flow control recommendation may indicate configuring new flow control parameters for the third network element. Table 2 is an example of a recommendation report.

[0213] Table 2 Recommended IEs to be reported

[0214] Among them, the suggestion information indicating that the third network element should be configured with flow control can be carried in the flow control configuration suggestion of the flow control network element, and the suggestion information indicating that the second network element should be expanded can be carried in the expansion suggestion for the bottleneck network element.

[0215] Optionally, in another implementation scenario of the above embodiment, method 400 further includes: the first device receiving a third request from the second device, wherein the third request includes the desired target, and the third request is used to request the first device to provide a recommendation for a network element in the network. Accordingly, the second device sends the third request to the first device.

[0216] The third request can be any request and can be carried in any message. The third request can also have other names, such as a signaling storm event analysis request, etc., which are not limited in this application. As an example, the third request can also carry network element availability parameters.

[0217] Based on the above solution, the first device can request the second device to provide improvement suggestions for the network element, and the request can carry the expected goal, thereby helping to achieve the second device's expected goal of preventing signaling storms.

[0218] Optionally, in another implementation scenario of the above embodiment, the method 400 also includes: the first device registers a first MDAS and a second MDAS, wherein the capability information in the registration parameters corresponding to the first MDAS is used to indicate that the first MDAS can determine whether the signaling storm event exists, and the capability information in the registration parameters corresponding to the second MDAS is used to indicate that the second MDAS can provide recommendations for network elements in the network.

[0219] The first device can send a request message to a management service (MnS) registry network element, requesting the creation of registration parameters for a first MDAS and a second MDAS. After receiving the request message, the management service registry network element creates the registration parameters for the first MDAS and the second MDAS based on the request message. Table 3 shows the registration parameters for the first MDAS or the second MDAS.

[0220] Table 3 Registration parameters of the first MDAS or the second MDAS

[0221] Among them, the label can indicate the identifier of the first MDAS or the second MDAS. The type can include MDAS, and the type is used to indicate that the service type of the first MDAS or the second MDAS is MDAS. The access address can indicate the access address of the first MDAS or the second MDAS. The management scope indicates the management scope of the first MDAS or the second MDAS, for example, the management scope corresponds to the identifier of the subnetwork that the first MDAS can manage. Support capabilities may include fault management, signaling analysis, preventive assessment, etc. Support capabilities can be used to indicate capability information supported by the MDAS. Among them, fault management can be used to indicate that the capability of the MDAS supports determining whether the signaling storm event exists, and signaling analysis can be used to indicate that the capability of the MDAS supports providing recommendations for network elements in the network. Fault management capabilities can be further subdivided, for example, they can be divided into faults that support signaling congestion types and faults that do not support signaling congestion types.

[0222] The capability information in the registration parameters is carried in the supported capability field. For example, the first MDAS may support fault management and support signaling congestion type faults. The second MDAS may support signaling analysis.

[0223] Based on the above solution, the second device can access the access address of the first MDAS or the second MDAS as needed, avoiding the delay caused by the first device identifying the intention of the second device and calling the corresponding MDAS, thereby improving the efficiency of network analysis.

[0224] Optionally, in another implementation scenario of the above embodiment, the method 400 also includes: the second device queries the registration parameters of the first device; the second device receives the registration parameters of the first management data analysis service MDAS and the registration parameters of the second MDAS, the capability information in the registration parameters corresponding to the first MDAS is used to indicate that the first MDAS can determine whether the signaling storm event exists, and the capability information in the registration parameters corresponding to the second MDAS is used to indicate that the second MDAS can provide suggestions for network elements in the network.

[0225] Based on the above solution, the second device can access the access address of the first MDAS or the second MDAS as needed, avoiding the delay caused by the first device identifying the intention of the second device and calling the corresponding MDAS, thereby improving the efficiency of network analysis.

[0226] FIG5 is a schematic flow chart of a registration method 500 provided in an embodiment of the present application. The method 500 will be described below with reference to FIG5 .

[0227] S510 : MDAF 320 sends a request message to the MnS registration network element, where the request message is used to request the creation of registration parameters. Correspondingly, the MnS registration network element receives the request message from MDAF 320 .

[0228] The MDAF 320 may be the first device. The registration parameter may be a registration parameter of the first MDAS or the second MDAS. The registration parameter may also be referred to as MnS information (Info).

[0229] S520: The MnS registration network element creates registration parameters to complete the registration.

[0230] For example, the registration parameter may be a registration parameter of the first MDAS or the second MDAS. The registration parameter may include at least one of a tag, a type, a version, an access address, a management scope, and a support capability. For details, see the relevant embodiment of Table 3.

[0231] FIG6 is a schematic flow chart of a registration parameter query method 600 provided in an embodiment of the present application. The method 600 will be described below with reference to FIG6 .

[0232] S610 , the OSS 310 sends a query message to the MnS registration network element, where the query message is used to request to query registration parameters. Correspondingly, the MnS registration network element receives the query message from the OSS 310 .

[0233] The OSS 310 may be the second device.

[0234] S620: The MnS registration network element sends registration parameters to the OSS 310. Correspondingly, the OSS 310 receives the registration parameters from the MnS registration network element.

[0235] Illustratively, the registration parameters may include registration parameters for the first MDAS and / or the second MDAS. The registration parameters may include at least one of a tag, type, version, access address, management scope, and supported capabilities. For details, see the relevant embodiments in Table 3. The registration parameters may also include registration parameters for other services, which are not limited in this application.

[0236] FIG7 is a schematic flow chart of a network element capability evaluation method 700 provided in an embodiment of the present application. The method 700 will be described below with reference to FIG7 .

[0237] S710 , the OSS 310 sends a second request to the MDAF 320 , where the second request is used to request the MDAF 320 to determine availability parameters of multiple network elements in the network.

[0238] Exemplarily, the second request may include a network element identifier (or network element type) and a target signaling type. For example, the second request includes the identifier and registration signaling of the AMF, so that the first device can determine the availability parameters of the AMF under a certain number of registration signalings based on the second request. The second request can be any request, and the second request can be carried in any message. The second request can also have other names, such as a network element capability assessment request or a network element availability assessment request, etc., which are not limited in this application. The second request can be triggered by an event, such as a holiday event, a network upgrade event, etc. In other words, when an event occurs, OSS 310 can execute S710. The second request can also be sent actively by OSS 310. In other words, OSS 310 can actively execute S710 without relying on the triggering of other events.

[0239] S720 : MDAF 320 receives performance management data and virtual resource usage information from NFV MANO 340 . Accordingly, NFV MANO 340 sends the performance management data and virtual resource usage information to MDAF 320 .

[0240] Performance management data can be PM. For example, when the first network element is an AMF, the performance management data of the first network element can include the number of registrations, the registration success rate, the registration duration of a single user, etc. It is understood that the performance management data can also include other parameters, such as the average registration duration of multiple users, the maximum registration duration of multiple users, the number of registration failures, etc.

[0241] Virtual resource usage information can be used to indicate virtual resource usage. Virtual resources may include at least one of a virtual processor, virtual memory, or virtual disk. Virtual resources may also include other resources. Virtual resource usage information may include virtual processor utilization, virtual memory utilization, virtual disk utilization, etc. Virtual resource usage information may also include other information.

[0242] In some embodiments, before S720 , the method 700 further includes: the NFV MANO 340 receiving a request message from the MDAF 320 , the request message being used to request performance management data and virtual resource usage information. Accordingly, the MDAF 320 sends the request message to the NFV MANO 340 .

[0243] S730: MDAF 320 determines availability parameters of network elements based on the performance management data and virtual resource usage information.

[0244] The availability parameter of a network element is the performance management data of the network element under a preset signaling quantity. The availability parameter can also be called an availability index. The preset signaling quantity can be a specific number or a relative number.

[0245] S740 : MDAF 320 sends the availability parameter of the network element to OSS 310 . Correspondingly, OSS 310 receives the availability parameter of the network element from MDAF 320 .

[0246] Furthermore, the OSS 310 may configure the network element according to the availability parameters of the network element.

[0247] FIG8 is a schematic flow chart of a network capability evaluation method 800 provided in an embodiment of the present application. The method 800 will be described below with reference to FIG8 .

[0248] S810 , the OSS 310 sends a fourth request to the MDAF 320 , where the fourth request is used to request determination of the maximum signaling quantity and bottleneck network element that the network can support.

[0249] Exemplarily, the fourth request may include a network scope identifier and a target signaling type, wherein the network scope identifier may be a subnetwork ID or identifiers of multiple network elements, or specific subnet location information.

[0250] The fourth request may be any request, and may be carried in any message. The fourth request may also have other names, such as a network capability assessment request or a network availability assessment request, etc., which are not limited in this application.

[0251] The fourth request can be triggered by an event, such as a holiday or network upgrade. In other words, OSS 310 can execute S810 when an event occurs. The fourth request can also be proactively sent by OSS 310. In other words, OSS 310 can proactively execute S810 without relying on other events.

[0252] S820: The MDAF 320 obtains availability parameters of multiple network elements in the network.

[0253] In some embodiments, MDAF 320 can obtain the availability parameters of a network element from the network element's configuration information. For example, MDAF 320 can send a request message to NFV MANO 340 or OSS 330, requesting that NFV MANO 340 or OSS 330 provide feedback on the availability parameters of a second network element. NFV MANO 340 or OSS 330 queries the configuration information of the second network element, thereby obtaining the availability parameters of the second network element and sending the availability parameters of the second network element to MDAF 320. MDAF 320 receives the availability parameters of the second network element from NFV MANO 340 or OSS 330, thereby obtaining the availability parameters of the second network element. If the network element does not have availability parameters configured, S720 and S730 can be executed to determine the availability parameters. For another example, MDAF 320 can determine the availability parameters of the network element based on the network element's performance management data and virtual resource usage information, thereby obtaining the availability parameters of each network element.

[0254] S830: The MDAF 320 determines the bottleneck network element and the maximum signaling quantity that the network can support based on the availability parameters of multiple network elements in the network.

[0255] S840: MDAF 320 sends the maximum signaling quantity that the network can support to OSS 310. Correspondingly, OSS 310 receives the maximum signaling quantity that the network can support from MDAF 320.

[0256] In some embodiments, the method 800 further includes: the MDAF 320 sending the information of the bottleneck network element to the OSS 310. Accordingly, the OSS 310 receives the information of the bottleneck network element from the MDAF 320.

[0257] FIG9 is a schematic flow chart of a signaling storm event detection method 900 provided in an embodiment of the present application. The method 900 is described below with reference to FIG9 .

[0258] S910, OSS 310 sends a first request to the first MDAS, the first request being used to request the first MDAS to determine whether a signaling storm event exists, where the signaling storm event indicates that the network has a risk of a signaling storm. For details, please refer to the embodiment of S410, which will not be described here in detail.

[0259] The first request may carry a network threshold. For example, in S830, if the maximum number of signaling messages received by OSS 310 from MDAF 320 is 10 times the maximum number of messages supported by the network, the network threshold in the first request sent by OSS 310 may be 8 times. It should be noted that the above is merely an example and does not constitute a limitation of this application.

[0260] S920: The first MDAS receives the current signaling quantity of the network from the NFV MANO 340. Accordingly, the NFV MANO 340 sends the current signaling quantity of the network to the first MDAS.

[0261] In some embodiments, before S920 , the method 900 further includes: the NFV MANO 340 receiving a request message from the first MDAS, the request message being used to request the current signaling quantity of the network. Accordingly, the first MDAS sends the request message to the NFV MANO 340 .

[0262] S930: The first MDAS determines a first report according to the current signaling amount of the network and the network threshold, where the first report is used to indicate the presence of a signaling storm event.

[0263] S940: The first MDAS sends a first report to the OSS 310. Accordingly, the OSS 310 receives the first report from the first MDAS.

[0264] FIG10 is a schematic flow chart of a signaling storm event analysis method 1000 provided in an embodiment of the present application. The method 1000 will be described below with reference to FIG10 .

[0265] S1010 , the OSS 310 sends a third request to the second MDAS, where the third request is used to request the second MDAS to provide suggestions for network elements in the network.

[0266] S1020: The second MDAS receives the performance management data and virtual resource usage information from the NFV MANO 340. Accordingly, the NFV MANO 340 sends the performance management data and virtual resource usage information to the second MDAS.

[0267] Performance management data can be PM. For example, when the first network element is an AMF, the performance management data of the first network element can include the number of registrations, the registration success rate, the registration duration of a single user, etc. It is understood that the performance management data can also include other parameters, such as the average registration duration of multiple users, the maximum registration duration of multiple users, the number of registration failures, etc.

[0268] Virtual resource usage information can be used to indicate virtual resource usage. Virtual resources may include at least one of a virtual processor, virtual memory, or virtual disk. Virtual resources may also include other resources. Virtual resource usage information may include virtual processor utilization, virtual memory utilization, virtual disk utilization, etc. Virtual resource usage information may also include other information.

[0269] In some embodiments, before S1020 , the method 1000 further includes: the NFV MANO 340 receiving a request message from the second MDAS, the request message being used to request performance management data and virtual resource usage information. Accordingly, the second MDAS sends the request message to the NFV MANO 340 .

[0270] S1030: The second MDAS determines a second report based on the performance management data and the virtual resource usage information. The second report is used to instruct capacity expansion of the network element.

[0271] S1040: The second MDAS sends a second report to the OSS 310. Accordingly, the OSS 310 receives the second report from the second MDAS.

[0272] Figure 11 is a schematic flowchart of another network analysis method 1100 provided in an embodiment of the present application. Method 1100 may be a combination of method 900 and method 1000, except that method 1100 does not distinguish between the first MDAS and the second MDAS, but rather combines the first MDAS and the second MDAS into MDAF 320. Method 1100 is described below with reference to Figure 11.

[0273] S1110, OSS 310 sends a first request to MDAF 320, the first request being used to request MDAF 320 to determine whether a signaling storm event exists, where the signaling storm event indicates that the network has a risk of a signaling storm.

[0274] The first request may carry a network threshold. For example, in S830, if the maximum number of signaling messages received by OSS 310 from MDAF 320 is 10 times the maximum number of messages supported by the network, the network threshold in the first request sent by OSS 310 may be 8 times. It should be noted that the above is merely an example and does not constitute a limitation of this application.

[0275] S1120 , MDAF 320 receives the current signaling quantity of the network from NFV MANO 340 . Accordingly, NFV MANO 340 sends the current signaling quantity of the network to MDAF 320 .

[0276] In some embodiments, before S1120 , the method 1100 further includes: the NFV MANO 340 receiving a request message from the MDAF 320 , the request message being used to request the current signaling quantity of the network. Accordingly, the MDAF 320 sends the request message to the NFV MANO 340 .

[0277] S1130: The MDAF 320 determines a first report according to the current signaling amount of the network and a network threshold, where the first report is used to indicate the presence of a signaling storm event.

[0278] S1140 : MDAF 320 sends a first report to OSS 310 . Correspondingly, OSS 310 receives the first report from MDAF 320 .

[0279] S1150 , OSS 310 sends a third request to MDAF 320 , where the third request is used to request MDAF 320 to provide suggestions for network elements in the network.

[0280] S1160 : MDAF 320 receives performance management data and virtual resource usage information from NFV MANO 340 . Accordingly, NFV MANO 340 sends the performance management data and virtual resource usage information to MDAF 320 .

[0281] Performance management data can be PM. For example, when the first network element is an AMF, the performance management data of the first network element can include the number of registrations, the registration success rate, the registration duration of a single user, etc. It is understood that the performance management data can also include other parameters, such as the average registration duration of multiple users, the maximum registration duration of multiple users, the number of registration failures, etc.

[0282] Virtual resource usage information can be used to indicate virtual resource usage. Virtual resources may include at least one of a virtual processor, virtual memory, or virtual disk. Virtual resources may also include other resources. Virtual resource usage information may include virtual processor utilization, virtual memory utilization, virtual disk utilization, etc. Virtual resource usage information may also include other information.

[0283] In some embodiments, before S1160 , the method 1100 further includes: the NFV MANO 340 receiving a request message from the MDAF 320 , the request message being used to request performance management data and virtual resource usage information. Accordingly, the MDAF 320 sends the request message to the NFV MANO 340 .

[0284] S1170: MDAF 320 determines a second report based on the performance management data and the virtual resource usage information. The second report is used to indicate capacity expansion of the network element.

[0285] S1180 : MDAF 320 sends a second report to OSS 310 . Correspondingly, OSS 310 receives the second report from MDAF 320 .

[0286] The following is an introduction to the device embodiment corresponding to the method embodiment of the present application. The following is only a brief introduction to the device, and the specific implementation steps and details of the solution can be referred to the method embodiment above.

[0287] To implement the various functions of the methods provided herein, both terminal devices and network devices may include hardware structures and / or software modules, with the aforementioned functions implemented in the form of hardware structures, software modules, or a combination of hardware structures and software modules. Whether a particular function is implemented in the form of hardware structures, software modules, or a combination of hardware structures and software modules depends on the specific application and design constraints of the technical solution.

[0288] Figure 12 is a schematic block diagram of a communication device 1200 according to an embodiment of the present application. The communication device 1200 includes a processor 1210 and a transceiver 1220, which may be interconnected via a bus 1230. The communication device 1200 may be a first device or a second device.

[0289] Optionally, the communication device 1200 may further include a memory 1240. The memory 1240 includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM), and is used for related instructions and data.

[0290] The processor 1210 may be one or more central processing units (CPUs). In the case where the processor 1210 is a CPU, the CPU may be a single-core CPU or a multi-core CPU. The processor 1210 may be a signal processor, a chip, or other integrated circuit that can implement the method of the present application, or a portion of the circuitry used for processing functions in the aforementioned processor, chip, or integrated circuit. In addition, the transceiver 1220 may also be referred to as an input / output interface or a communication interface. The transceiver 1220 is used for input or output of signals or data, and may also be an input / output circuit.

[0291] When the communication device 1200 is a first device, illustratively, the communication device 1200 includes a processor 1210 and a transceiver 1220. The transceiver 1220 is configured to receive a first request from a second device, the first request being configured to request the first device to determine whether a signaling storm event exists, the signaling storm event being configured to indicate that a network is at risk of a signaling storm; the processor 1210 is configured to obtain a network threshold, the network threshold being configured to indicate the amount of signaling that the network can support, and to determine a first report based on the network threshold and the current amount of signaling on the network, the first report being configured to indicate the presence of the signaling storm event.

[0292] When the communication device 1200 is the second device, illustratively, the communication device 1200 includes a transceiver 1220. The transceiver 1220 is configured to send a first request to the first device, the first request being configured to request the first device to determine whether a signaling storm event exists, the signaling storm event being configured to indicate that a risk of a signaling storm occurs in the network, and to receive a first report from the first device, the first report being configured to indicate the existence of the signaling storm event.

[0293] The above description is merely exemplary. For details, please refer to the contents of the above method embodiments. The implementation of each operation in FIG6 may also correspond to the corresponding description of the method embodiments shown in FIG3 to FIG11.

[0294] Figure 13 is a schematic block diagram of another communication device 1300 according to an embodiment of the present application. Communication device 1300 can be the first device or the second device, or a chip or module within the first device or the second device, configured to implement the methods described in the above embodiments. Communication device 1300 includes a transceiver unit 1310. The following provides an exemplary description of transceiver unit 1310.

[0295] The transceiver unit 1310 may include a transmitting unit and a receiving unit. The transmitting unit is used to perform a transmitting operation of the communication device, and the receiving unit is used to perform a receiving operation of the communication device. For ease of description, this embodiment of the application combines the transmitting unit and the receiving unit into a single transceiver unit. This is described here as a unified description and will not be repeated later.

[0296] When the communication device 1300 is a first device, illustratively, the transceiver unit 1310 is configured to receive a first request from a second device.

[0297] Optionally, the communication device 1300 may further include a processing unit 1320, which is configured to execute the content of the first device involving processing, coordination and other steps.

[0298] When the communication device 1300 is a second device, illustratively, the transceiver unit 1310 is configured to send a first request to the first device.

[0299] Optionally, the communication device 1300 may further include a processing unit 1320, which is used to execute the content of the second device involving processing, coordination and other steps.

[0300] The above contents are merely exemplary descriptions. When the communication device 1300 is the first device or the second device, it will be responsible for executing the methods or steps related to the first device or the second device in the above method embodiments.

[0301] Optionally, the communication device 1300 further includes a storage unit 1330, which is used to store a program or code for executing the aforementioned method.

[0302] The device embodiments shown in Figures 12 and 13 are used to implement the embodiments shown in Figures 3 to 11. The specific execution steps and methods of the devices shown in Figures 12 and 13 can refer to the contents of the aforementioned method embodiments.

[0303] Figure 14 is a schematic block diagram of a communication system 1400 according to an embodiment of the present application. The communication system 1400 includes a first device and a second device, and the first device and the second device are used to implement the embodiments of Figures 3 to 11 above.

[0304] The present application also provides a chip, including a processor, for calling and executing instructions stored in a memory, so that a communication device equipped with the chip executes the methods in the above examples.

[0305] The present application also provides another chip, comprising: an input interface, an output interface, and a processor, wherein the input interface, the output interface, and the processor are connected via an internal connection path, and the processor is configured to execute code in a memory. When the code is executed, the processor is configured to execute the methods in the above examples. Optionally, the chip also includes a memory, which is configured to store computer programs or code.

[0306] The present application also provides a processor, which is coupled to a memory and is used to execute the methods and functions involving the first device or the second device in any of the above embodiments.

[0307] In another embodiment of the present application, a computer program product including instructions is provided. When the computer program product is run on a computer, the method of the above embodiment is implemented.

[0308] The present application also provides a computer program. When the computer program is executed in a computer, the method of the aforementioned embodiment is implemented.

[0309] In another embodiment of the present application, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a computer, the method described in the above embodiment is implemented.

[0310] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0311] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0312] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0313] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0314] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0315] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0316] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A network analysis method, characterized in that: include: The first device receives a first request from the second device, the first request is used to request the first device to determine whether there is a signaling storm event, the signaling storm event is used to indicate that there is a risk of a signaling storm occurring in the network; The first device acquires a network threshold, where the network threshold is used to indicate the amount of signaling that the network can support; The first device determines a first report according to the network threshold and the current signaling amount of the network, where the first report is used to indicate the existence of the signaling storm event.

2. The method according to claim 1, characterized in that The first report includes at least one of abnormal network element information, type information, cause information, ratio information or duration information, wherein the abnormal network element information is used to indicate the network element with abnormal traffic when the signaling storm event occurs, the type information is used to indicate that the event type is a signaling storm, the cause information is used to indicate the cause of the signaling storm event, the ratio information is used to indicate the ratio of the current signaling amount to the historical signaling amount of the network, and the duration information is used to indicate the predicted duration of the signaling storm event.

3. The method according to claim 1 or 2, characterized in that: The first device acquires a network threshold, including: The first device receives the network threshold from the second device.

4. The method according to claim 3, characterized in that Also includes: The first device sends a maximum signaling quantity that the network can support to the second device.

5. The method according to claim 4, characterized in that The network threshold is less than a maximum signaling quantity that the network can support.

6. The method according to claim 4 or 5, characterized in that: Also includes: The first device determines the maximum number of signalings that the network can support based on availability parameters of multiple network elements in the network, wherein the multiple network elements in the network include a first network element, and the availability parameter of the first network element is performance management data of the first network element under a first preset signaling number.

7. The method according to claim 6, characterized in that Also includes: The first device obtains performance management data of the first network element and virtual resource usage information of the first network element; The first device determines the availability parameter of the first network element according to the performance management data of the first network element and the virtual resource usage information of the first network element.

8. The method according to claim 7, characterized in that Also includes: The first device sends an availability parameter of the first network element to the second device.

9. The method according to claim 7 or 8, characterized in that: Also includes: The first device receives a second request from the second device, where the second request is used to request the first device to determine availability parameters of multiple network elements in the network.

10. The method according to any one of claims 1 to 9, characterized in that The multiple network elements in the network further include a second network element, wherein the method further includes: The first device obtains an availability parameter of the second network element, where the availability parameter of the second network element is performance management data of the second network element under a second preset signaling quantity, wherein when the signaling storm occurs, the availability parameter of the second network element does not meet an expected target; The first device determines a second report according to an availability parameter of the second network element, wherein the second report is used to indicate capacity expansion of the second network element.

11. The method according to claim 10, characterized in that The expected target includes an expected duration for resolving the signaling storm and / or a maximum number of users that the network can support.

12. The method according to claim 10 or 11, characterized in that: Also includes: The first device receives a third request from the second device, where the third request is used to request the first device to provide suggestions for network elements in the network, wherein the third request includes the desired target.

13. The method according to any one of claims 10 to 12, characterized in that Also includes: The first device registers a first management data analysis service MDAS and a second MDAS, wherein the capability information in the registration parameters corresponding to the first MDAS is used to indicate that the first MDAS can determine whether the signaling storm event exists, and the capability information in the registration parameters corresponding to the second MDAS is used to indicate that the second MDAS can provide suggestions for network elements in the network.

14. A network analysis method, characterized in that: include: The second device sends a first request to the first device, wherein the first request is used to request the first device to determine whether a signaling storm event exists, and the signaling storm event is used to indicate that the network is at risk of a signaling storm; the second device receives a first report from the first device, wherein the first report is used to indicate the existence of the signaling storm event.

15. The method according to claim 14, characterized in that Also includes: The second device sends a network threshold to the first device, where the network threshold is used to indicate the amount of signaling that the network can support.

16. The method according to claim 15, characterized in that Also includes: The second device receives a maximum signaling quantity that the network can support from the first device; The second device determines the network threshold according to a maximum signaling quantity that the network can support.

17. The method according to claim 16, characterized in that The network threshold is smaller than a maximum signaling quantity or a maximum signaling multiple that the network can support.

18. The method according to any one of claims 14 to 17, characterized in that The plurality of network elements in the network include a first network element, wherein the method further comprises: The second device receives an availability parameter of the first network element from the first device, where the availability parameter of the first network element is performance management data of the first network element under a first preset signaling quantity; The second device configures the first network element according to the availability parameter of the first network element.

19. The method according to claim 18, characterized in that Also includes: The second device sends a second request to the first device, where the second request is used to request the first device to determine availability parameters of multiple network elements in the network.

20. The method according to any one of claims 14 to 19, characterized in that The multiple network elements in the network further include a second network element, wherein the method further includes: The second device receives a second report from the first device, where the second report is used to indicate capacity expansion of the second network element, wherein when the signaling storm occurs, an availability parameter of the second network element does not meet a desired target.

21. The method according to claim 20, characterized in that The expected target includes an expected duration for resolving the signaling storm and / or a maximum number of users that the network can support.

22. The method according to claim 20 or 21, characterized in that The third request includes the desired target, and the third request is used to request the first device to provide suggestions for network elements in the network, wherein the method further includes: The second device sends the third request to the first device.

23. The method according to any one of claims 20 to 22, characterized in that Also includes: The second device queries the registration parameters of the first device; The second device receives registration parameters of a first management data analysis service MDAS and registration parameters of a second MDAS, the capability information in the registration parameters corresponding to the first MDAS being used to indicate that the first MDAS is capable of determining whether the signaling storm event exists, and the capability information in the registration parameters corresponding to the second MDAS being used to indicate that the second MDAS is capable of providing recommendations for network elements in the network.

24. A communication device, characterized in that: The method comprises at least one module, wherein the at least one module is used to execute the method according to any one of claims 1 to 13, or the at least one module is used to execute the method according to any one of claims 14 to 23.

25. A communication system, characterized in that: The method comprises a first device and a second device, wherein the first device is used to execute the method according to any one of claims 1 to 13, and the second device is used to execute the method according to any one of claims 14 to 23.

26. A communication device, characterized in that: It comprises a processing circuit and an input / output interface, wherein the input / output interface is used to input and / or output signals, and the processing circuit is used to execute the method described in any one of claims 1 to 13, or the processing circuit is used to execute the method described in any one of claims 14 to 23.

27. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program or instructions, and when the computer program or the instructions are executed on a computer, the method according to any one of claims 1 to 13 is executed, or the method according to any one of claims 14 to 23 is executed.

28. A communication method, characterized in that: The method is applied to a first device and a second device, wherein the method includes: The first device executes the method according to any one of claims 1 to 13; the second device executes the method according to any one of claims 14 to 23.

29. A computer program product, characterized in that The computer program product stores computer-readable instructions, and when the computer-readable instructions are executed on a computer, the computer is caused to perform the method according to any one of claims 1 to 23.

Citation Information

Patent Citations

  • Network analysis method and device

    CN119945920A

  • Early warning method and device for signaling storm and electronic equipment

    CN115150034A

  • Determining network system issues

    CN116158113A

  • Method, apparatus and computer program

    US20230065199A1

  • Security enhancements for cellular communication systems

    US20230136287A1

Cited By

  • Handling network abnormal behaviour

    GB2638339A