Event processing framework for analytics
The event processing framework addresses performance and scalability issues in mobile network analytics by segmenting and parallel processing event streams without locks, enhancing throughput and reducing CPU load.
Patent Information
- Application Number
- PCT/IB2024/050309
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-11
- Publication Date
- 2025-07-17
AI Technical Summary
Existing event-based analytics systems in mobile networks face performance issues with single-threaded implementations due to insufficient throughput and scalability, while multi-threaded implementations require locks for ordered processing, causing delays and inefficiencies.
An event processing framework that creates a merged time-ordered stream of events, segments it into ranges, and splits these ranges into sub-streams using a hash function for parallel processing without the need for locks, ensuring sub-stream-level state storage and maintaining event order.
The framework enables efficient, high-throughput processing of large numbers of events by avoiding synchronization delays, allowing parallel execution of tasks across multiple threads while preserving event order and reducing CPU resource consumption.
Smart Images

Figure IB2024050309_17072025_PF_FP_ABST
Abstract
Description
[0001]Attorney Docket No.1009-6566 / P109410WO01 EVENT PROCESSING FRAMEWORK FOR ANALYTICS TECHNICAL FIELD The present disclosure is related to event-based analytics, e.g., in wireless communications networks. BACKGROUND Per-session, event-based, analytics systems are part of the network management domain, e.g., the Management Data Analytics Function (MDAF), or the core network, e.g., the Network Data Analytics Function (NWDAF), in communications networks standardized by the 3rd- Generation Partnership Projection (3GPP). These analytics systems are based on collecting and correlating elementary network events from different network domains, such as the core, radio and transport networks. They calculate radio and network key performance indicators (KPIs), characterizing radio environment or network operation at the user and session level. Some analytics systems may also implement service quality models for estimating end user QoS and QoE characteristics. These types of solutions are suitable for network-wide session-based troubleshooting and analysis of network issues and are used in closed-loop automated network operations for assuring and optimizing service quality. Event-based analytics systems are also used in Service Operation Centers (SOC) for monitoring the quality of the wide variety of services used in the network level, as well as for monitoring the customer experience on individual per subscriber level. These tools are widely used in Customer Care and other business scenarios. Event-based analytics requires real-time collection and correlation of characteristic node and protocol events from different radio and core nodes, probing signaling interfaces (IFs) and sampling of the user-plane traffic. Besides the data collection and correlation functions, the system requires an advanced database, rule engine and big data analytics platform as well. The main functionalities of event-based network analytics systems and the concept of correlation, as applied in those systems, are described in several published patents and patent publications, including: U.S. Patent No.7,929,512, “Performance Management of Cellular Mobile Packet Data Networks;” U.S. Patent Publication No.2011 / 0222414, “Method and Apparatus for Active Probing of Tunneled Internet Protocol (IP) Transmission Paths;” and U.S. Patent Publication No.2012 / 020378, “Network Management System and Method for Identifying and Accessing Quality of Service Issues within a Communications Network.” The entire contents of each of these publications is incorporated herein for reference, for the purposes of providing context and background to the present disclosure. Attorney Docket No.1009-6566 / P109410WO01 The first of these publications, titled “Performance management of cellular mobile packet data networks,” explains the main concept and data sources as well as the idea of correlating selected events from multiple data sources of the different telecom nodes into per session correlated records. The patent publication describes offline parsing of traces. The publication titled “Method and Apparatus for Active Probing of Tunneled Internet (IP) Transmission Paths” describes a method of probing and correlating the user plane data flows to the International Mobile Subscriber Identifier (IMSI) -tagged signaling and radio events from other data sources. The disclosed methods include actively probing a tunneled transmission path from a base station such as an eNB to a core network. A UE-emulator emulates a User Equipment (UE) and provides emulated NAS signaling to a Probe Connection Control (PCC) unit in the base station, which establishes the tunneled transmission path by forwarding the NAS signaling received from the emulator toward the core network. The PCC stores associated communication endpoints and UE-assigned IP addresses. A Probe Traffic Control (PTC) unit within the base station utilizes the stored endpoints and IP addresses to generate probe traffic through the tunneled transmission path toward a probe server or another base station configured as a probe reflector. The probe reflector collects and reports path properties such as packet loss, delay, jitter, and throughput. The publication titled “Network Management System and Method for Identifying and Accessing Quality of Service Issues within a Communications Network” describes the obtaining of service quality metrics for the correlated records and using the correlated records and service and network related KPIs for detecting network related issues that affect service quality. None of these publications, however, provides an adequate framework for addressing performance-related issues that occur with single-thread or multithread software implementations of a real-time event correlation process. Existing multi-thread implementations require the use of locks to maintain ordered processing, which causes processing delays. Single- threaded implementations do not have a time ordering problem, but generally have insufficient performance for high-throughput data processing and do not scale well. Accordingly, improved solutions are needed. SUMMARY The present disclosure addresses these and other problems by providing a real-time event processing framework for a mobile network, which can be applied for processing large number of events efficiently in network and subscriber analytics systems. This framework and related methods are described for mobile telecom networks, but the methods can be applied in other Attorney Docket No.1009-6566 / P109410WO01 areas as well, such as stock market financial applications, particle physics, subscriber profile monitoring, real-time protocol analyzer, Kafka or Spark applications. According to several embodiments described herein, an event-processing framework receives real-time, per-session, time-stamped network and node events from core network functions, such as the Access and Mobility Function (AMF), the 5G Session Management Function (SMF), and / or the User Plane Function (UPF), as well as from radio nodes. The event processing framework first creates one merged time-ordered stream. This stream is segmented into ranges based on either a number of events or a time period. The size of the range can be configured to achieve optimum processing efficiency. In some embodiments, the framework creates tasks for each range. A task includes a set of operations that have to be executed on some or on all the events in a range. The range of events is logically split into fixed number of sub-streams based on a hash function. The hash function, based on which the events are distributed among sub-streams, is selected to ensure sub- stream level state storage so there is no need to synch with other threads. In this way, expensive locks of processing are avoided. The operations corresponding to the task can be executed parallel on these sub-streams. The same set of operations is executed on all threads. The processing phase is done when all tasks of the sub-streams are completed. The processing of a range is done, when all processing phases are completed for the given range. Multiple processing phases can be defined for a range. The processing phases are executed in chain, which means that processing of a new phase can only start after all tasks of the previous processing phase are finished for the given range. The same processing phase can be executed on different ranges within the above defined constraints, which allows further parallel processing (more efficient). The framework processes the events in multiple software threads in a parallel fashion by keeping the time order of the events and avoids locks. Example embodiments of the techniques and systems described herein include a method for event-based analytics, where the method includes the steps of receiving per-session, time- stamped, event records from each of a plurality of data sources and for each of a plurality of distinct communications sessions or event sessions and merging the event records into a time- ordered stream. This example method further includes segmenting the time-ordered into a plurality of ranges, splitting each range into a plurality of sub-streams, based on a first hash function, where the first hash function is selected to ensure sub-stream-level state storage, and processing the sub-streams in parallel, using a thread pool, where this processing comprises performing a predefined set of tasks on each substream, using threads from the thread pool. The Attorney Docket No.1009-6566 / P109410WO01 example method further comprises merging output events from this processing into a first single- ordered output event stream. Variations of this method and systems for carrying out these and other methods are described in detail below. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 illustrates an analytics system implemented in a Network Data Analytics Function (NWDAF) in a mobile network. Figure 2 illustrates an analytics system implemented in a 3GPP Management Data Analytics Function (MDAF) in a mobile network. Figure 3 shows data correlation in an analytics system. Figure 4 illustrates main components of an example event processing framework (EPF), according to some embodiments. Figure 5 shows an EPF processing chain, according to some embodiments. Figure 6 illustrates an example EPF processing phase, according to some embodiments. Figure 7 shows an exemplary method (e.g., procedure) for event-based analytics, according to various embodiments of the present disclosure. Figure 8 shows a communication system according to various embodiments of the present disclosure. Figure 9 shows a UE according to various embodiments of the present disclosure. Figure 10 shows a network node according to various embodiments of the present disclosure. Figure 11 shows host computing system according to various embodiments of the present disclosure. Figure 12 is a block diagram of a virtualization environment in which functions implemented by some embodiments of the present disclosure may be virtualized. Figure 13 illustrates communication between a host computing system, a network node, and a UE via multiple connections, according to various embodiments of the present disclosure. DETAILED DESCRIPTION As noted above, previous disclosures of event-based analytics processing do not provide an adequate framework for addressing performance-related issues that occur with single-thread or multithread software implementations of a real-time event correlation process. For instance, as also noted above, existing multi-thread implementations require the use of locks to maintain ordered processing, which causes processing delays. Single-threaded implementations do not Attorney Docket No.1009-6566 / P109410WO01 have a time ordering problem, but generally have insufficient performance for high-throughput data processing and do not scale well. Processing ordered events one-by-one on a single thread keeps the time order, but has the following limitations: - Performance of a single threaded process is not sufficient for high throughput data processing. - Scaling single-threaded processes require more network resources; available TCP ports are limited on a given host. - Running a lot of processes on a host consumes more CPU resources - the OS has higher load, and context switching is costly in large scale. - Input data might not scale the same way as processes do, repartitioning of input data consumes additional CPU resources and increases code complexity. - Adding / removing sources runtime changes the process topology. Existing multiple-thread frameworks do not support ordered processing without locks. This means that each software thread should wait until all events required for the process arrive. Software threads may wait for each other as well. These issues slow down the processing, which is critical at the high event rate seen in mobile networks. Events may arrive late, missing, or software threads can freeze due to other issues as well, which delays and / or blocks processing of threads. Also, when many small streams should be processed, starting many single threaded processes is not efficient. This may result in scaling bottlenecks on an application level or for the OS, causing extreme CPU usage. These problems can be addressed with a new event processing framework. According to some embodiments, this event processing framework first creates one merged time-ordered stream of event records, or events. This stream is segmented into ranges based on either a number of events or a time period. The size of the range can be configured to achieve optimum processing efficiency. Note that the term “event,” as used in the context of describing event processing, refers to a data record describing and / or triggered by a defined event, where each event is described by one or more network conditions, faults, activity completion, etc., in the system. Hence, the terms “event” and “event record” may be used interchangeably throughout this document. The event processing framework creates tasks for each range. A task includes a set of operations that have to be executed on some or on all the events in a range. The range of events is logically split into fixed number of sub-streams based on a hash function. The hash function, based on which the events are distributed among sub-streams, is selected to ensure sub-stream Attorney Docket No.1009-6566 / P109410WO01 level state storage so there is no need to synch with other threads. Note that the term “hash function” is used in its broadest sense, referring to an function that can be used to map data of arbitrary size to one of a set of fixed-size values – the hash functions used for this splitting of events into a fixed number of sub-streams may operate on a portion of the data in an event record, e.g., on an identifying number or field. In this way, i.e., splitting each range of events into sub-streams so that there is no need to synchronize the processing of one sub-stream with another, expensive locks of processing are avoided. The operations corresponding to the task can be executed parallel on these sub-streams. The same set of operations is executed on all threads. The processing phase is done when all tasks of the sub-streams are completed. The processing of a range is done, when all processing phases are completed for the given range. Multiple processing phases can be defined for a range. The processing phases are executed in chain, which means that processing of a new phase can only start after all tasks of the previous processing phase are finished for the given range. The same processing phase can be executed on different ranges within the above defined constraints, which allows further parallel processing (more efficient). The framework processes the events in multiple software threads in parallel, by keeping the time order of the events, and avoids locks. In the context of a mobile communications network, a new Event-Processing Framework (EPF) according to the concepts and techniques described herein may be implemented in the correlator functionality of an analytics system, which may be, for example, part of either the 3GPP Network Data Analytics Function (NWDAF) or the 3GPP Management Data Analytics Function (MDAF). An NWDAF implementation of an analytics system is shown in Figure 1, while an MDAF implementation is shown in Figure 2. The network architectures shown in Figure 1 and Figure 2 include some or all of the following network functions (NFs): • Application Function (AF, with Naf interface) interacts with the 5GC to provision information to the network operator and to subscribe to certain events happening in operator´s network. An AF offers applications for which service is delivered in a different layer (i.e., transport layer) than the one in which the service has been requested (i.e., signaling layer), the control of flow resources according to what has been negotiated with the network. An AF communicates dynamic session information to PCF (via N5 interface), including description of media to be delivered by transport layer. • Policy Control Function (PCF, with Npcf interface) supports unified policy framework to govern the network behavior, via providing PCC rules (e.g., on the treatment of each service Attorney Docket No.1009-6566 / P109410WO01 data flow that is under PCC control) to the Session Management Function (SMF) via the N7 reference point. PCF provides policy control decisions and flow based charging control, including service data flow detection, gating, QoS, and flow-based charging (except credit management) towards the SMF. The PCF receives session and media related information from the AF and informs the AF of traffic (or user) plane events. • User Plane Function (UPF)– supports handling of user plane (UP) traffic based on the rules received from SMF, including packet inspection and different enforcement actions (e.g., event detection and reporting). UPFs communicate with the RAN (e.g., NG-RNA) via the N3 reference point, with SMFs (discussed below) via the N4 reference point, and with an external packet data network (PDN) via the N6 reference point. The N9 reference point is for communication between two UPFs. • Session Management Function (SMF, with Nsmf interface) interacts with the decoupled traffic (or user) plane, including creating, updating, and removing Protocol Data Unit (PDU) sessions and managing session context with the User Plane Function (UPF), e.g., for event reporting. For example, SMF performs data flow detection (based on filter definitions included in PCC rules), online and offline charging interactions, and policy enforcement. • Charging Function (CHF, with Nchf interface) is responsible for converged online charging and offline charging functionalities. It provides quota management (for online charging), re-authorization triggers, rating conditions, etc. and is notified about usage reports from the SMF. Quota management involves granting a specific number of units (e.g., bytes, seconds) for a service. CHF also interacts with billing systems. • Access and Mobility Management Function (AMF, with Namf interface) terminates the RAN CP interface and handles all mobility and connection management of UEs (similar to MME in EPC). AMFs communicate with UEs via the N1 reference point and with the RAN (e.g., NG-RAN) via the N2 reference point. • Network Exposure Function (NEF) with Nnef interface – acts as the entry point into operator´s network, by securely exposing to AFs the network capabilities and events provided by 3GPP NFs and by providing ways for the AF to securely provide information to 3GPP network. For example, NEF provides a service that allows an AF to provision specific subscription data (e.g., expected UE behavior) for various UEs. In 5G, the NEF may comprise a Packet Flow Description Function (PFDF), which was previously a standalone function. The PFDF is intended to manage the PFDs (Packet Flow Descriptors) provided by Application Service Providers (ASPs) and distribute them to the SMFs. • Network Repository Function (NRF) with Nnrf interface – provides service registration and discovery, enabling NFs to identify appropriate services available from other NFs. Attorney Docket No.1009-6566 / P109410WO01 • Network Slice Selection Function (NSSF) with Nnssf interface – a “network slice” is a logical partition of a 5G network that provides specific network capabilities and characteristics, e.g., in support of a particular service. A network slice instance is a set of NF instances and the required network resources (e.g., compute, storage, communication) that provide the capabilities and characteristics of the network slice. The NSSF enables other NFs (e.g., AMF) to identify a network slice instance that is appropriate for a UE’s desired service. • Authentication Server Function (AUSF) with Nausf interface – based in a user’s home network (HPLMN), it performs user authentication and computes security key materials for various purposes. • Network Data Analytics Function (NWDAF) with Nnwdaf interface – provides network analytics information (e.g., statistical information of past events and / or predictive information) to other NFs on a network slice instance level. • Location Management Function (LMF) with Nlmf interface – supports various functions related to determination of UE locations, including location determination for a UE and obtaining any of the following: DL location measurements or a location estimate from the UE; UL location measurements from the NG RAN; and non-UE associated assistance data from the NG RAN. • The Unified Data Management (UDM) function supports generation of 3GPP authentication credentials, user identification handling, access authorization based on subscription data, and other subscriber-related functions. To provide this functionality, the UDM uses subscription data (including authentication data) stored in the 5GC unified data repository (UDR). • In addition to the UDM, the Unified Data Repository (UDR) supports storage and retrieval of policy data by the PCF, as well as storage and retrieval of application data by NEF. The networks illustrated in Figure 1 and Figure 2 also include user equipments (UEs), which connect to base stations, referred to in 3GPP as “gNodeBs” or “gNBs,” in the context of a 5G network, via a radio interface. The gNBs are in the radio access network (RAN) portion of the wireless communications network, which may be referred to as the RAN domain, while many of the NFs described above are in the core network, or core domain. In Figure 1, the analytics functionality is housed in an NWDAF, in the core domain, while in the architecture shown in Figure 2, the analytics is in an MDAF, in a network management domain. In both cases, the analytics function includes a correlator. The correlator receives and correlates real-time node events from core network functions (NFs), radio base stations (gNBs, eNBs) and probe reports. In a mobile communications network, the primary events may be session management events from an SMF, mobility management events from an AMF, user Attorney Docket No.1009-6566 / P109410WO01 plane reports from a UPF, and radio management and radio resource measurement events from base stations (e.g., gNBs), such as Call Trace Record (CTR) events. Real-time events from other external systems and data sources may be correlated as well. The per-session and per-IMSI correlated records, or streams, are used as input to various analytics functions (AF) implemented in the analytics system. Figure 3 shows how the user data correlation works. The user traffic is handled by different network elements, which then stream event records towards the CSM (Common Stream Mediation) layer. The CSM layer parses incoming events and stores them, e.g., in Avro format. Event records are then further processed and converted to internal format by input adapters according to the originating network function type. Events are then forwarded towards mapper processes, e.g., for adding an International Mobile Subscriber Identifier (IMSI) or other identifier to events that do not originally contain it. User data correlation depends on this field to identify sessions. After assembling events from all types of input sources into separate user records, the correlator outputs user-level metrics and incidents. For parallel processing in different nodes or servers, the system can include multiple correlators, each implementing the event processing framework described in this document. An example of this approach, utilizing three correlators, is shown in Figure 3. The correlator processes events from network elements of various domains (RAN, Core, IMS). Processed events cover most of the subscriber activity in the network including but not limited to: • Attach • Session Establishment • Bearer-related procedures • Mobility • Call Setup • Call Release • Radio condition-related reports (e.g., RSRP and RSRQ) These events are generated for every subscriber. This can result in an event rate on the order of 15 million events per second, for a 100 million-subscriber network. The form and content of an event may differ, depending on the implementation, the source, and / or the type of event, but a typical event might include any of various data elements such as data elements identifying a session, a data bearer, or an address, a failure type and / or failure cause, a trigger type, an error type, etc. An example output of a correlated record output from a correlator is given below. While the details of this example are relevant only to a particular implementation, Attorney Docket No.1009-6566 / P109410WO01 the example includes a number of recognizable data elements that provide a sense of the types of information that might be included in a correlator output. {"start":1441990336561,"dur":21503,"imsi":248022131017960,"n_event":6,"mcc":248," mnc":2,"sources":["S_SGSN_MME_EBM"],"first_event":"T_ABSTRACT_3G_UPDATE_BEA RER","bearers":{"2":{"bid":5,"ipv4":"10.41.68.40","rat":"4G","sgw_addr":"172.17.167.17","qci ":9,"active":"true"},"1":{"bid":5,"ipv4":"10.41.68.40","rat":"3G","active":"false"}},"loc_history ":{"3gpp":{"1":[0,"","",true],"2":[1441990336561,"3G","lacsac_1003_54368",true],"3":[144199 0358064,"4G","eci_260099084",true]},"legacy_format":false},"kpi":{"core":{"service_request_ success":[["3gpp",2,0,{"input_src":"sgsn_mme_ebm","paging_attempts":"0","ggsn_addr":"178. 23.117.194","sreq_type":"DATA","sreq_trigger":"MS"},1,1]],"service_request_total":[["3gpp",2 ,0,{"input_src":"sgsn_mme_ebm","paging_attempts":"0","ggsn_addr":"178.23.117.194","sreq_t ype":"DATA","sreq_trigger":"MS"},1,1]],"tau_duration":[["3gpp",3,0,{"input_src":"sgsn_mme_ ebm","mme_code":"32","mme_gid":"32769","update_type":"ISC_TAU","pgw_addr":"178.23.1 17.194","sgw_addr":"172.17.167.17","old_rat":"3G","old_loc":"lacsac_1003_54368","target_rat ":"4G","target_loc":"eci_260099084"},0.324,1]],"tau_success":[["3gpp",3,0,{"input_src":"sgsn_ mme_ebm","mme_code":"32","mme_gid":"32769","update_type":"ISC_TAU","pgw_addr":"17 8.23.117.194","sgw_addr":"172.17.167.17","old_rat":"3G","old_loc":"lacsac_1003_54368","tar get_rat":"4G","target_loc":"eci_260099084"},1,1]],"tau_total":[["3gpp",3,0,{"input_src":"sgsn_ mme_ebm","mme_code":"32","mme_gid":"32769","update_type":"ISC_TAU","pgw_addr":"17 8.23.117.194","sgw_addr":"172.17.167.17","old_rat":"3G","old_loc":"lacsac_1003_54368","tar get_rat":"4G","target_loc":"eci_260099084"},1,1]]}}} For the purposes of the present disclosure, the following definitions apply: • Stream - Consecutive events with a given order e.g., time. Events can be received in this particular order only. These are global ordering for all sessions. • Sub-stream - Subset of the Stream for which an Event Hash Function returns the same value. • Event Hash function - A defined function that assigns a numeric value to an event. The returned value is in the [0, <sub-stream count>]. The function may be based on a primary event attribute e.g., IMSI or other parameters, such as S1APID, cellID, etc. • Event Processor Logic - defined code for processing an event. • Event Processor Instance - An independent object with its own dedicated state, operating on one sub-stream. • Session - A user-initiated data activity with start and end time. A session generates signaling and user plane traffic in the network, which is monitored by the Analytics System. One Attorney Docket No.1009-6566 / P109410WO01 session may contain multiple services. The sessions in the Analytics System may be processed per IMSI. • Task – A collection of a sub-stream identifier, a range and an Event Processor Instance assigned for the sub-stream identifier. Task execution is lock-free because Event Processor Instances are working on a disjunct set of events (sub-streams) and have independent states. • Worker Thread - A member of a Thread Pool that executes Tasks. • Processing Phase - The Processing Phase is a group of functions performed on substreams (as shown in Figure 6, described below). An example event processing flow and its components are shown in Figure 4. The functionalities of the main components shown in Figure 4 are as follows: • Stream Merger - Creates one merged Stream from multiple input Streams. The input events include time stamps and belong to multiple sessions. The events either arrive in time order, or they are reordered before merging. Stream Merger is lock-free. • Range Creator - Logic to create Ranges from a Stream. A Range can be limited by a timespan e.g., 1 second or a fixed number of events whichever occurs first. This approach is required to make sure that a Worker Thread has enough events to process when there is high traffic, and the processing does not become burst-like when there is low traffic. • Range Collector - A container that stores multiple ranges that are being processed. This component is responsible for removing a range when all processing tasks are done on that range. • Task Creator - It creates multiple independent tasks for each range. A task performs the processing defined by an Event Processor on a sub-stream in the range. • Event Processors - A set of user defined business logic that implements an operation on events one-by-one. Multiple event processors can be added. One instance of an event processor operates on one sub-stream. Operations can be simple, e.g. converting input events to another format or calculating statistics. It can also be complex, executing state machines and large number of calculations. An Event Processor can modify existing events, even create or remove events from the stream in place, keeping the order within the stream. An Event Processor can implement output functionality for an application, e.g., writing files, calling external APIs or streaming data to external system. • Event distributor - This module splits the thick stream into sub-streams using a hash function that corresponds to Event Processors of the current Processing Phase. • TaskCollector - A container to store the tasks. Responsible for ordering the tasks. It handles task dependencies, e.g. if event processor ‘A’ must be done before event processor ‘B’ on a range. Order of Processing phases is enforced within a range. Order of Processing Phases is enforced across successive ranges. Attorney Docket No.1009-6566 / P109410WO01 • ThreadPool - A collection of threads dedicated for executing tasks obtained from Task Collector. It should be appreciated that these or similar functionalities may have different names in various implementations. The exact division between and / or grouping of functionalities may differ as well, in various implementations. The grouping shown in Figure 4 is an example, and should not be understood as limiting. In the event processing flow, input streams are merged into a single ordered stream. Figure 5 shows an example EPF processing chain, which includes several processing phases. Within each processing phase, an event distributor splits the thick stream into sub-streams, using a hash function (based on an event attribute, e.g., imsi / icid) that corresponds to an event processor or to the business logic of the processing phase. Figure 6 shows an example of an EPF processing phase. Sub-streams may be processed in parallel by the Thread Pool. A processing phase can keep events in its output stream for the next stage, it can remove or add new events. When operations are executed in each worker thread, output events are merged again into a single ordered stream (see Figure 6). Multiple processing phases can be executed on the stream. The hash function is usually different for each processing phase. Example use-case implementations with EPF modules, in the context of a communications network, include, but are not limited to: • IMSI mapping of Radio events based on S1APID – Hash function is based on the S1APID. This guarantees that the same S1APID will always be placed into the same sub-stream. The Event Processor implements mapping of IMSI based on S1APIDs. • Calculating KPIs for a radio cell - Hash function is based on cell ID. This guarantees that the same cell ID will always be placed into the same sub-stream. The Event Processor implements the KPI calculation logic for cell IDs. • Calculating KPIs for a subscriber session - Hash function is based on IMSI. This guarantees that the same IMSI will always be placed into the same sub-stream. The Event Processor implements KPI calculation based on events corresponding to the same IMSI. • Generating a per-session correlated record - Hash function is based on IMSI. This guarantees that the same IMSI will always be placed into the same sub-stream. The Event Processor implements generation of per-session correlated record based on events corresponding to the same IMSI. Use cases are not limited to the context of a communications network. The event- processing framework described herein is applicable to non-telecom use cases as well, where large amount of events should be processed in multiple operation steps and keeping time order of events is important. These include: Attorney Docket No.1009-6566 / P109410WO01 • Stock market, financial applications - In financial and stock market applications, multiple orders arrive from multiple sources in a relatively short time – these should be processed in time order. • Particle physics - In high-energy physics experiments, a large number of different detectors are used for detecting the trajectory, energy, etc. of millions of elementary particles generated in high energy collisions. At least some of these events should be correlated, filtered and processed in real time. The business logic here is to identify particular events, determine cross sections, measure energies, mass of particles, identify events related to directly not detectable particles, etc. • Subscriber profile monitoring (Google, Facebook, etc.) - In web analytics, in user profiling in particular, there are a large number of events generated by users that need to be processed, mapped to users based on IP addresses, possibly in real-time. This correlation of data is then used for providing context aware services, personalized ads, or other analytics. Even if a user generates relative low event rate, there can be millions of users, which result in a high event rate overall. • Real-time protocol analyzer - The EPF described herein can be used to implement real- time protocol analyzers, where the “events” are the packets going through the monitored endpoint, and the processors could be the ordered set of protocol analyzers that process their own part of the protocol stack (e.g.: phase1 – IP, phase2 – TCP, phase3 - HTTP). Hashing by target IP address and TCP port could guarantee the ability to collect process-based summary or to follow long TCP streams and reassemble their packets in timely order. In this case the packets targeted to different applications (or at least different ports of those) can be processed in parallel. On the other hand hashing by source IP address enables parallel statistical analysis of the data sources. The solution could be scalable to any amount of network traffic. • Kafka stream, Spark applications, use cases - Large-scale data processing and analytics engine (like Kafka Streams or Spark) can use EPF as the underlying multi-threaded processing framework: the worker nodes of a processing cluster run the custom user-defined processing. The engine can guarantee time-ordered processing as well as support advanced correlation features. The user-defined hashing, filtering functions and business logic can be embedded into the engine, and they must follow some basic rules. Examples include analyzing financial events and alerting customers with real-time financial events – alerting rules may include simple user transaction alerts or complex client-defined alerts. Low latency can be achieved by the multi- threaded stream processing. Other examples include: connecting and analyzing mobile-first services; messaging apps and related services; communication, content, entertainment, and Attorney Docket No.1009-6566 / P109410WO01 advertising; as well as new businesses in Fintech, AI, and other domains (e.g. LINE-messaging). Subscriber-based inter-service analytics are another example. The EPF described herein is a framework for processing large traffic in a single multithreaded process. A cloud native application can be created based on processing units that utilize EPF. In a cloud native setting, having lots of single threaded pods is not efficient, as the CPU in the backing node will have to do many context switches to run all the single threaded pods. Having more pods could imply having more network overhead, too. Advantages that may be provided by various implementations of this framework may include one or more of the following: • The framework can handle large number of input streams: CPU heavy processing is done on a dedicated worker thread pool. The size of this pool is not related to the number of inputs. Input streams have separate lock-free event cache containers on input threads so the merging thread can handle many inputs since it does not have to wait for input threads, and it does not do any CPU heavy processing. • The framework handles thick input streams: CPU heavy processing is decoupled from input handling. The framework creates a thick ordered stream either from many smaller streams or a few thick streams. In any case CPU heavy processing is done on a single thick stream and can be done by a configurable number of worker threads. • The framework can process the events efficiently on large number of CPUs (50+), without significant concurrency penalty: input caching on separate thread prevents waiting for input. Processing is done by tasks. These tasks work on sub-streams that are hashed so they do not share data and do not need to do synchronization. Events are collected into ranges so tasks are large enough for efficient processing. • The framework can combine ordered streams, creating one ordered stream from many without adding latency: the merging algorithm (aka receive queue logic) allows preserving the order of events without adding latency. • The framework keeps the time order of events: merging keeps order, see above. Processing also keeps the order of events. This has multiple reasons: A task cannot change the order of events. The order of task execution does not change the event order. Not only is the output ordered but the business logic also receives the events in time order. • The framework is lock free and allows lock-free processing: input stream collection uses lock-free containers. Processing is done by tasks that do not require locks because tasks work on sub-streams that are hashed so they do not share data and synchronization is not needed. Figure 7 is a process flow diagram illustrating an example method for event-based analytics, according to the techniques described herein. It will be appreciated that the method Attorney Docket No.1009-6566 / P109410WO01 shown in Figure 7, as described in detail below, is intended to be a generalization of the techniques described above. Thus, while much of the discussion above focused on analytics in a mobile communications system, the described techniques are not limited to that context, and are more generally applicable. The method shown in Figure 7 includes, as shown at block 710, the step of receiving per- session, time-stamped, event records. These are received from each of a plurality of data sources and for each of a plurality of distinct communications sessions or event sessions. The communication sessions may be sessions in a mobile communications network, for example. The method further comprises, as shown at blocks 720 and 730, the steps of merging the event records into a time-ordered stream and segmenting the time-ordered stream into a plurality of ranges. The method further comprises splitting each range into a plurality of sub-streams, based on a first hash function, as shown at block 740. As was discussed above, the first hash function is selected to ensure sub-stream-level state storage. The method further comprises, as shown at block 750, processing the sub-streams for each range in parallel, using a thread pool. This processing comprises performing a predefined set of tasks on each substream, using threads from the thread pool. As shown at block 760, output events from this processing are merged into a first single-ordered output event stream. As was discussed above, the processing of each range may be split into two or more phases, where the splitting of the range into sub-streams may differ for some or all of the phases. Thus, in some embodiments of the method shown in Figure 7, the splitting, processing, and merging described above for each range may correspond to a first processing phase for the respective range. The method may then comprise executing a second processing phase for each range, where the executing of the second processing phase comprises splitting each range into a second plurality of sub-streams, based on a second hash function, where the second hash function is selected to ensure sub-stream-level state storage and differs from the first hash function, processing the second plurality of sub-streams in parallel, using the thread pool, and merging output events from said processing of the second plurality of the substreams into a second single-ordered output event stream. These steps may be repeated again for each of one or more additional phases, in some embodiments. In some embodiments of the method shown in Figure 7, the first hash function assigns a numeric value to an event, based on an attribute of the event. In some embodiments, the attribute is a subscriber identifier, a session identifier, or a cell identifier. In some embodiments, the event records are for events in a communications network, where the event records are received from any one or more of any of: an access and mobility Attorney Docket No.1009-6566 / P109410WO01 function (AMF); a 5G session management function (SMF); a user plane function (UPF); and a radio node. Examples of the events in such an embodiment were discussed above. Although various embodiments are described herein above in terms of methods, apparatus, devices, computer-readable medium and receivers, the person of ordinary skill will readily comprehend that such methods can be embodied by various combinations of hardware and software in various systems, communication devices, computing devices, control devices, apparatuses, non-transitory computer-readable media, etc. Figure 8 shows an example of a communication system 800 in accordance with some embodiments. This or a similar communication system may provide the context for a data analytics function utilizing one or more of the techniques described above. In this example, the communication system 800 includes a telecommunication network 802 that includes an access network 804, such as a radio access network (RAN), and a core network 806, which includes one or more core network nodes 808. The access network 804 includes one or more access network nodes, such as network nodes 810a and 810b (one or more of which may be generally referred to as network nodes 810), or any other similar 3GPP access node or non-3GPP access point. The network nodes 810 facilitate direct or indirect connection of UEs, such as by connecting UEs 812a, 812b, 812c, and 812d (one or more of which may be generally referred to as UEs 812) to the core network 806 over one or more wireless connections. Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 800 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 800 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system. The UEs 812 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 810 and other communication devices. Similarly, the network nodes 810 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 812 and / or with other network nodes or equipment in the telecommunication network 802 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 802. Attorney Docket No.1009-6566 / P109410WO01 In the depicted example, the core network 806 connects the network nodes 810 to one or more hosts, such as host 816. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 806 includes one more core network nodes (e.g., core network node 808) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 808. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), Analytics Data Repository Function (ADRF), network repository function (NRF), network data analytics function (NWDAF), and / or a User Plane Function (UPF). The host 816 may be under the ownership or control of a service provider other than an operator or provider of the access network 804 and / or the telecommunication network 802, and may be operated by the service provider or on behalf of the service provider. The host 816 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server. As a whole, the communication system 800 of Figure 8 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox. Attorney Docket No.1009-6566 / P109410WO01 In some examples, the telecommunication network 802 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network 802 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 802. For example, the telecommunications network 802 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive IoT services to yet further UEs. In some examples, the UEs 812 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 804 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 804. Additionally, a UE may be configured for operating in single- or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e., being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio – Dual Connectivity (EN-DC). In the example, the hub 814 communicates with the access network 804 to facilitate indirect communication between one or more UEs (e.g., UE 812c and / or 812d) and network nodes (e.g., network node 810b). In some examples, the hub 814 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 814 may be a broadband router enabling access to the core network 806 for the UEs. As another example, the hub 814 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 810, or by executable code, script, process, or other instructions in the hub 814. As another example, the hub 814 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 814 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub 814 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 814 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 814 acts as a proxy server or orchestrator for the UEs, in particular in if one or more of the UEs are low energy IoT devices. The hub 814 may have a constant / persistent or intermittent connection to the network node 810b. The hub 814 may also allow for a different communication scheme and / or schedule between the hub 814 and UEs (e.g., UE 812c and / or 812d), and between the hub 814 and the Attorney Docket No.1009-6566 / P109410WO01 core network 806. In other examples, the hub 814 is connected to the core network 806 and / or one or more UEs via a wired connection. Moreover, the hub 814 may be configured to connect to an M2M service provider over the access network 804 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 810 while still connected via the hub 814 via a wired or wireless connection. In some embodiments, the hub 814 may be a dedicated hub – that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 810b. In other embodiments, the hub 814 may be a non-dedicated hub – that is, a device which is capable of operating to route communications between the UEs and network node 810b, but which is additionally capable of operating as a communication start and / or end point for certain data channels. Figure 9 shows a UE 900 in accordance with some embodiments. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE. A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle- to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter). The UE 900 includes processing circuitry 902 that is operatively coupled via a bus 904 to an input / output interface 906, a power source 908, a memory 910, a communication interface 912, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 9. The level of integration between the components Attorney Docket No.1009-6566 / P109410WO01 may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc. The processing circuitry 902 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 910. The processing circuitry 902 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field- programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 902 may include multiple central processing units (CPUs). In the example, the input / output interface 906 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 900. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device. In some embodiments, the power source 908 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source 908 may further include power circuitry for delivering power from the power source 908 itself, and / or an external power source, to the various parts of the UE 900 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source 908. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 908 to make the power suitable for the respective components of the UE 900 to which power is supplied. Attorney Docket No.1009-6566 / P109410WO01 The memory 910 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read- only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 910 includes one or more application programs 914, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 916. The memory 910 may store, for use by the UE 900, any of a variety of various operating systems or combinations of operating systems. The memory 910 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 910 may allow the UE 900 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 910, which may be or comprise a device-readable storage medium. The processing circuitry 902 may be configured to communicate with an access network or other network using the communication interface 912. The communication interface 912 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 922. The communication interface 912 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 918 and / or a receiver 920 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 918 and receiver 920 may be coupled to one or more antennas (e.g., antenna 922) and may share circuit components, software or firmware, or alternatively be implemented separately. In the illustrated embodiment, communication functions of the communication interface 912 may include cellular communication, Wi-Fi communication, LPWAN communication, data Attorney Docket No.1009-6566 / P109410WO01 communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth. Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 912, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., an alert is sent when moisture is detected), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient). As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input. A UE, when in the form of an Internet of Things (IoT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an IoT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or Virtual Reality (VR), a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an Attorney Docket No.1009-6566 / P109410WO01 industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an IoT device comprises circuitry and / or software in dependence of the intended application of the IoT device in addition to other components as described in relation to the UE 900 shown in Figure 9. As yet another specific example, in an IoT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation. In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators. Figure 10 shows a network node 1000 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)). Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS). Attorney Docket No.1009-6566 / P109410WO01 Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs). The network node 1000 includes a processing circuitry 1002, a memory 1004, a communication interface 1006, and a power source 1008. The network node 1000 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 1000 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 1000 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 1004 for different RATs) and some components may be reused (e.g., a same antenna 1010 may be shared by different RATs). The network node 1000 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 1000, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 1000. The processing circuitry 1002 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 1000 components, such as the memory 1004, to provide network node 1000 functionality. In some embodiments, the processing circuitry 1002 includes a system on a chip (SOC). In some embodiments, the processing circuitry 1002 includes one or more of radio frequency (RF) transceiver circuitry 1012 and baseband processing circuitry 1014. In some embodiments, the radio frequency (RF) transceiver circuitry 1012 and the baseband processing circuitry 1014 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. Attorney Docket No.1009-6566 / P109410WO01 In alternative embodiments, part or all of RF transceiver circuitry 1012 and baseband processing circuitry 1014 may be on the same chip or set of chips, boards, or units. The memory 1004 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 1002. The memory 1004 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions (collectively denoted computer program product 1004a) capable of being executed by the processing circuitry 1002 and utilized by the network node 1000. The memory 1004 may be used to store any calculations made by the processing circuitry 1002 and / or any data received via the communication interface 1006. In some embodiments, the processing circuitry 1002 and memory 1004 is integrated. The communication interface 1006 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 1006 comprises port(s) / terminal(s) 1016 to send and receive data, for example to and from a network over a wired connection. The communication interface 1006 also includes radio front-end circuitry 1018 that may be coupled to, or in certain embodiments a part of, the antenna 1010. Radio front-end circuitry 1018 comprises filters 1020 and amplifiers 1022. The radio front-end circuitry 1018 may be connected to an antenna 1010 and processing circuitry 1002. The radio front-end circuitry may be configured to condition signals communicated between antenna 1010 and processing circuitry 1002. The radio front-end circuitry 1018 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 1018 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 1020 and / or amplifiers 1022. The radio signal may then be transmitted via the antenna 1010. Similarly, when receiving data, the antenna 1010 may collect radio signals which are then converted into digital data by the radio front-end circuitry 1018. The digital data may be passed to the processing circuitry 1002. In other embodiments, the communication interface may comprise different components and / or different combinations of components. In certain alternative embodiments, the network node 1000 does not include separate radio front-end circuitry 1018, instead, the processing circuitry 1002 includes radio front-end Attorney Docket No.1009-6566 / P109410WO01 circuitry and is connected to the antenna 1010. Similarly, in some embodiments, all or some of the RF transceiver circuitry 1012 is part of the communication interface 1006. In still other embodiments, the communication interface 1006 includes one or more ports or terminals 1016, the radio front-end circuitry 1018, and the RF transceiver circuitry 1012, as part of a radio unit (not shown), and the communication interface 1006 communicates with the baseband processing circuitry 1014, which is part of a digital unit (not shown). The antenna 1010 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 1010 may be coupled to the radio front-end circuitry 1018 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 1010 is separate from the network node 1000 and connectable to the network node 1000 through an interface or port. The antenna 1010, communication interface 1006, and / or the processing circuitry 1002 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 1010, the communication interface 1006, and / or the processing circuitry 1002 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment. The power source 1008 provides power to the various components of network node 1000 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 1008 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 1000 with power for performing the functionality described herein. For example, the network node 1000 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 1008. As a further example, the power source 1008 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail. Embodiments of the network node 1000 may include additional components beyond those shown in Figure 10 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 1000 may include user interface equipment to allow input of information into the network node 1000 and to allow Attorney Docket No.1009-6566 / P109410WO01 output of information from the network node 1000. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 1000. In various embodiments, network node 1000 (and its constituent components) can be configured to perform operations comprising various methods described herein, such as methods performed by a gateway exposure function (GEF), network repository function (NRF), network data analytics function (NWDAF), or 3GPP Management Data Analytics Function (MDAF). Figure 11 is a block diagram of a host 1100, which may be an embodiment of the host 816 of Figure 8, in accordance with various aspects described herein. As used herein, the host 1100 may be or comprise various combinations hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, container, or processing resources in a server farm. The host 1100 may provide one or more services to one or more UEs. The host 1100 includes processing circuitry 1102 that is operatively coupled via a bus 1104 to an input / output interface 1106, a network interface 1108, a power source 1110, and a memory 1112. Other components may be included in other embodiments. Features of these components may be substantially similar to those described with respect to the devices of previous figures, such as Figures 9 and 10, such that the descriptions thereof are generally applicable to the corresponding components of host 1100. The memory 1112 may include one or more computer programs including one or more host application programs 1114 and data 1116, which may include user data, e.g., data generated by a UE for the host 1100 or data generated by the host 1100 for a UE. Embodiments of the host 1100 may utilize only a subset or all of the components shown. The host application programs 1114 may be implemented in a container-based architecture and may provide support for video codecs (e.g., Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for multiple different classes, types, or implementations of UEs (e.g., handsets, desktop computers, wearable display systems, heads-up display systems). The host application programs 1114 may also provide for user authentication and licensing checks and may periodically report health, routes, and content availability to a central node, such as a device in or on the edge of a core network. Accordingly, the host 1100 may select and / or indicate a different host for over-the-top services for a UE. The host application programs 1114 may support various protocols, such as the HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP), Real-Time Streaming Protocol (RTSP), Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc. Attorney Docket No.1009-6566 / P109410WO01 Figure 12 is a block diagram illustrating a virtualization environment 1200 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1200 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. Applications 1202 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment 1200 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. For example, in various embodiments, various gateway exposure functions (GEF), network repository functions (NRF), and network data analytics functions (NWDAF) described herein can be instantiated as virtual NFs in environment 1200, such that each instantiation performs operations corresponding to methods (or procedures) described elsewhere herein. Hardware 1204 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry (collectively denoted computer program product 1204a), and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 1206 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 1208a and 1208b (one or more of which may be generally referred to as VMs 1208), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 1206 may present a virtual operating platform that appears like networking hardware to the VMs 1208. The VMs 1208 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 1206. Different embodiments of the instance of a virtual appliance 1202 may be implemented on one or more of VMs 1208, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server Attorney Docket No.1009-6566 / P109410WO01 hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment. In the context of NFV, a VM 1208 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs 1208, and that part of hardware 1204 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 1208 on top of the hardware 1204 and corresponds to the application 1202. Hardware 1204 may be implemented in a standalone network node with generic or specific components. Hardware 1204 may implement some functions via virtualization. Alternatively, hardware 1204 may be part of a larger cluster of hardware (e.g., such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 1210, which, among others, oversees lifecycle management of applications 1202. In some embodiments, hardware 1204 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 1212 which may alternatively be used for communication between hardware nodes and radio units. Figure 13 shows a communication diagram of a host 1302 communicating via a network node 1304 with a UE 1306 over a partially wireless connection in accordance with some embodiments. Example implementations, in accordance with various embodiments, of the UE (such as a UE 812a of Figure 8 and / or UE 900 of Figure 9), network node (such as network node 810a of Figure 8 and / or network node 1000 of Figure 10), and host (such as host 816 of Figure 8 and / or host 1100 of Figure 11) discussed in the preceding paragraphs will now be described with reference to Figure 13. Like host 1100, embodiments of host 1302 include hardware, such as a communication interface, processing circuitry, and memory. The host 1302 also includes software, which is stored in or accessible by the host 1302 and executable by the processing circuitry. The software includes a host application that may be operable to provide a service to a remote user, such as the UE 1306 connecting via an over-the-top (OTT) connection 1350 extending between the UE 1306 and host 1302. In providing the service to the remote user, a host application may provide user data which is transmitted using the OTT connection 1350. Attorney Docket No.1009-6566 / P109410WO01 The network node 1304 includes hardware enabling it to communicate with the host 1302 and UE 1306. The connection 1360 may be direct or pass through a core network (like core network 806 of Figure 8) and / or one or more other intermediate networks, such as one or more public, private, or hosted networks. For example, an intermediate network may be a backbone network or the Internet. The UE 1306 includes hardware and software, which is stored in or accessible by UE 1306 and executable by the UE’s processing circuitry. The software includes a client application, such as a web browser or operator-specific “app” that may be operable to provide a service to a human or non-human user via UE 1306 with the support of the host 1302. In the host 1302, an executing host application may communicate with the executing client application via the OTT connection 1350 terminating at the UE 1306 and host 1302. In providing the service to the user, the UE's client application may receive request data from the host's host application and provide user data in response to the request data. The OTT connection 1350 may transfer both the request data and the user data. The UE's client application may interact with the user to generate the user data that it provides to the host application through the OTT connection 1350. The OTT connection 1350 may extend via a connection 1360 between the host 1302 and the network node 1304 and via a wireless connection 1370 between the network node 1304 and the UE 1306 to provide the connection between the host 1302 and the UE 1306. The connection 1360 and wireless connection 1370, over which the OTT connection 1350 may be provided, have been drawn abstractly to illustrate the communication between the host 1302 and the UE 1306 via the network node 1304, without explicit reference to any intermediary devices and the precise routing of messages via these devices. As an example of transmitting data via the OTT connection 1350, in step 1308, the host 1302 provides user data, which may be performed by executing a host application. In some embodiments, the user data is associated with a particular human user interacting with the UE 1306. In other embodiments, the user data is associated with a UE 1306 that shares data with the host 1302 without explicit human interaction. In step 1310, the host 1302 initiates a transmission carrying the user data towards the UE 1306. The host 1302 may initiate the transmission responsive to a request transmitted by the UE 1306. The request may be caused by human interaction with the UE 1306 or by operation of the client application executing on the UE 1306. The transmission may pass via the network node 1304, in accordance with the teachings of the embodiments described throughout this disclosure. Accordingly, in step 1312, the network node 1304 transmits to the UE 1306 the user data that was carried in the transmission that the host 1302 initiated, in accordance with the teachings of the embodiments described throughout this disclosure. In step 1314, the UE 1306 receives the user data carried in the transmission, which Attorney Docket No.1009-6566 / P109410WO01 may be performed by a client application executed on the UE 1306 associated with the host application executed by the host 1302. In some examples, the UE 1306 executes a client application which provides user data to the host 1302. The user data may be provided in reaction or response to the data received from the host 1302. Accordingly, in step 1316, the UE 1306 may provide user data, which may be performed by executing the client application. In providing the user data, the client application may further consider user input received from the user via an input / output interface of the UE 1306. Regardless of the specific manner in which the user data was provided, the UE 1306 initiates, in step 1318, transmission of the user data towards the host 1302 via the network node 1304. In step 1320, in accordance with the teachings of the embodiments described throughout this disclosure, the network node 1304 receives user data from the UE 1306 and initiates transmission of the received user data towards the host 1302. In step 1322, the host 1302 receives the user data carried in the transmission initiated by the UE 1306. One or more of the various embodiments improve the performance of OTT services provided to the UE 1306 using the OTT connection 1350, in which the wireless connection 1370 forms the last segment. More precisely, embodiments can enable an ADRF (or other data repository) to easily verify whether a data consumer network function (NFc) is authorized to access and receive analytics data and / or models that have been collected from a data producer network function (e.g., NWDAF) and stored in ADRF. This prevents ADRF from distributing proprietary and / or sensitive data to an unauthorized and / or “rogue” prospective NFc. Thus, embodiments can improve security of analytics and / or models used in 5G networks. Improved network security can increase the value of OTT services delivered via the network to both service providers and end users. In an example scenario, factory status information may be collected and analyzed by the host 1302. As another example, the host 1302 may process audio and video data which may have been retrieved from a UE for use in creating maps. As another example, the host 1302 may collect and analyze real-time data to assist in controlling vehicle congestion (e.g., controlling traffic lights). As another example, the host 1302 may store surveillance video uploaded by a UE. As another example, the host 1302 may store or control access to media content such as video, audio, VR or AR which it can broadcast, multicast or unicast to UEs. As other examples, the host 1302 may be used for energy pricing, remote control of non-time critical electrical load to balance power generation needs, location services, presentation services (such as compiling diagrams etc. from data collected from remote devices), or any other function of collecting, retrieving, storing, analyzing and / or transmitting data. Attorney Docket No.1009-6566 / P109410WO01 In some examples, a measurement procedure may be provided for the purpose of monitoring data rate, latency and other factors on which the one or more embodiments improve. There may further be an optional network functionality for reconfiguring the OTT connection 1350 between the host 1302 and UE 1306, in response to variations in the measurement results. The measurement procedure and / or the network functionality for reconfiguring the OTT connection may be implemented in software and hardware of the host 1302 and / or UE 1306. In some embodiments, sensors (not shown) may be deployed in or in association with other devices through which the OTT connection 1350 passes; the sensors may participate in the measurement procedure by supplying values of the monitored quantities exemplified above, or supplying values of other physical quantities from which software may compute or estimate the monitored quantities. The reconfiguring of the OTT connection 1350 may include message format, retransmission settings, preferred routing etc.; the reconfiguring need not directly alter the operation of the network node 1304. Such procedures and functionalities may be known and practiced in the art. In certain embodiments, measurements may involve proprietary UE signaling that facilitates measurements of throughput, propagation times, latency and the like, by the host 1302. The measurements may be implemented in that software causes messages to be transmitted, in particular empty or ‘dummy’ messages, using the OTT connection 1350 while monitoring propagation times, errors, etc. The foregoing merely illustrates the principles of the disclosure. Various modifications and alterations to the described embodiments will be apparent to those skilled in the art in view of the teachings herein. It will thus be appreciated that those skilled in the art will be able to devise numerous systems, arrangements, and procedures that, although not explicitly shown or described herein, embody the principles of the disclosure and can be thus within the spirit and scope of the disclosure. Various embodiments can be used together with one another, as well as interchangeably therewith, as should be understood by those having ordinary skill in the art. The term unit, as used herein, can have conventional meaning in the field of electronics, electrical devices and / or electronic devices and can include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein. Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or Attorney Docket No.1009-6566 / P109410WO01 microcontrollers, as well as other digital hardware, which may include Digital Signal Processor (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according one or more embodiments of the present disclosure. As described herein, device and / or apparatus can be represented by a semiconductor chip, a chipset, or a (hardware) module comprising such chip or chipset; this, however, does not exclude the possibility that a functionality of a device or apparatus, instead of being hardware implemented, be implemented as a software module such as a computer program or a computer program product comprising executable software code portions for execution or being run on a processor. Furthermore, functionality of a device or apparatus can be implemented by any combination of hardware and software. A device or apparatus can also be regarded as an assembly of multiple devices and / or apparatuses, whether functionally in cooperation with or independently of each other. Moreover, devices and apparatuses can be implemented in a distributed fashion throughout a system, so long as the functionality of the device or apparatus is preserved. Such and similar principles are considered as known to a skilled person. Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. It will be further understood that terms used herein should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein. In addition, certain terms used in the present disclosure, including the specification and drawings, can be used synonymously in certain instances (e.g., “data” and “information”). It should be understood, that although these terms (and / or other terms that can be synonymous to one another) can be used synonymously herein, there can be instances when such words can be intended to not be used synonymously. Further, to the extent that the prior art knowledge has not been explicitly incorporated by reference herein above, it is explicitly incorporated herein in its entirety. All publications referenced are incorporated herein by reference in their entireties. If the Attorney Docket No.1009-6566 / P109410WO01 publications have different versions, the most recent version as of the filing date of this application is intended.
Claims
Attorney Docket No.1009-6566 / P109410WO01 CLAIMS What is claimed is:
1. A method for event-based analytics, the method comprising: receiving (710) per-session, time-stamped, event records, from each of a plurality of data sources and for each of a plurality of distinct communications sessions or event sessions; merging (720) the event records into a time-ordered stream; segmenting (730) the time-ordered stream into a plurality of ranges; splitting (740) each range into a plurality of sub-streams, based on a first hash function, wherein the first hash function is selected to ensure sub-stream-level state storage; processing (750) the sub-streams for each range in parallel, using a thread pool, wherein said processing comprises performing a predefined set of tasks on each sub- stream, using threads from the thread pool; and merging (760) output events from said processing into a first single-ordered output event stream.
2. The method of claim 1, wherein said splitting (740), processing (750), and merging (760) for each range correspond to a first processing phase for the respective range, and wherein the method comprises executing a second processing phase for each range, the executing of the second processing phase comprising: splitting each range into a second plurality of sub-streams, based on a second hash function, wherein the second hash function is selected to ensure sub-stream-level state storage and differs from the first hash function; processing the second plurality of sub-streams in parallel, using the thread pool; and merging output events from said processing of the second plurality of the substreams into a second single-ordered output event stream.
3. The method of claim 1 or 2, wherein the first hash function assigns a numeric value to an event, based on an attribute of the event.
4. The method of claim 3, wherein the attribute includes a subscriber identifier, a session identifier, or a cell identifier.Attorney Docket No.1009-6566 / P109410WO01 5. The method of claim 3, wherein the attribute includes any one of a network function identifier, base station identifier, subscriber or subscription group name or identifier, terminal device type, vendor identifier, and software version.
6. The method of any one of claims 1-5, wherein processing (750) the sub-streams for each range in parallel comprises correlating event records according to event source and / or according to event type.
7. The method of any one of claims 1-6, wherein the event records are for events in a communications network, and wherein the event records are received from any one or more of any of: an access and mobility function, AMF; a 5G session management function, SMF; a user plane function, UPF; and a radio node.
8. The method of claim 7, wherein the method is carried out in a Network Data Analytics Function, NWDAF.
9. The method of claim 7, wherein the method is carried out in a 3GPP Management Data Analytics Function, MDAF.
10. A data analytics function, comprising communication interface circuitry (1106) and processing circuitry (1102) that are operably coupled and configured to communicate with other nodes and functions of a communications network, wherein the processing circuitry and the communication interface circuitry are further configured to perform any one of the methods of claims 1-9.
11. A data analytics function of a communications network, the data analytics function being adapted to carry out a method according to any one of claims 1-9.
12. A computer program product comprising computer-executable instructions that, when executed by processing circuitry associated with a data analytics function of a communication network, configure the data analytics function to carry out a method according to any one of claims 1-9.Attorney Docket No.1009-6566 / P109410WO01 13. A computer-readable medium comprising the computer program product of claim 12.
Citation Information
Patent Citations
Method and apparatus for active probing of tunneled internet protocol (IP) transmission paths
US20110222414A1
Widely tunable optical parametric generator having narrow bandwidth field
US20120020378A1
Performance management of cellular mobile packet data networks
US7929512B2
Convergent mediation system with dynamic resource allocation
US20110010581A1