UPF exposure of raw data and packet metadata

By defining a new event in the Nupf_EventExposure service, the UPF can expose raw data packet traces with event filters, addressing inefficiencies in existing data retrieval methods and enabling flexible, efficient data analysis without specialized hardware, thus optimizing network resource usage.

WO2025149898A1PCT designated stage expired Publication Date: 2025-07-17TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/050159
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-08
Filing Date
2025-01-07
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Existing mechanisms for exposing user plane data from a User Plane Function (UPF) in a core network are inflexible, inefficient, and require complex standardization processes, limiting the ability to retrieve specific and relevant data for analysis, especially when specialized network taps and packet brokers are needed.

Method used

A new event is defined in the Nupf_EventExposure service allowing the UPF to expose raw data packet traces, enabling a subscription request with event indicators and filters to identify and duplicate user plane data packets, which can be provided in standardized formats like PCAP files, without requiring specialized network taps or packet brokers.

Benefits of technology

This approach allows network operators to efficiently retrieve only desired data, saving bandwidth and resources, and enables agile analysis of raw packet information without needing specific standard Key Performance Indicators (KPIs, thus enhancing data analysis flexibility and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025050159_17072025_PF_FP_ABST
    Figure IB2025050159_17072025_PF_FP_ABST
Patent Text Reader

Abstract

Various embodiments disclosed herein provide for a method for facilitating the exposure of raw data and packet metadata from a User Plane Function (UPF) of a core network to facilitate flexible data analysis of the raw data and packet metadata. Existing services that allow exposure of UPF data can be extended by defining a new event which allows UPF to expose raw data packet traces. A subscription request for data can be passed from a requesting network function (NF) to the UPF, and the subscription request can include an event indicator that indicates user plane data, a target User Equipment (UE) identifier, and an event filter. The UPF can then identify application traffic from a target UE that matches the subscription request, duplicate a subset of the user plane data packets from the application traffic, and then provide the requesting NF with the duplicated user plane data packets.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] UPF EXPOSURE OF RAW DA TA AND PACKET MET AD A TA

[0002] Related Applications

[0003] This application claims the benefit of European patent application serial number 24382009.9, filed January 8, 2024, the disclosure of which is hereby incorporated herein by reference in its entirety.

[0004] Technical Field

[0005] The present disclosure relates to a method for facilitating the exposure of raw data and packet metadata from a User Plane Function (UPF) of a core network to facilitate flexible data analysis of the raw data and packet metadata in a wireless communication system.

[0006] Background

[0007] Network Data Analytics Function (NWDAF) represents the operator-managed network analytics logical function. The NWDAF is designed to streamline the way core network data is produced and consumed, as well as to generate insights and take actions to enhance end-user experience. The NWDAF interacts with different entities for different purposes such as data collection based on event subscription, provided by the Access and Mobility Management Function (AMF), Session Management Function (SMF), Policy Control Function (PCF), Unified Data Management (UDM), Application Function(s) (AF) (directly or via a Network Exposure Function (NEF)), and the Operations, Administration and Maintenance (OAM).

[0008] The NWDAF can also retrieve information about subscriber-related activities or Protocol Data Unit (PDU) sessions from the UDM or Unified Data Repository (UDR) in order to perform defined data analytics processes. The NWDAF can also retrieve information from network functions (NFs) such as the Network Repository Function (NRF) for NF-related information and the Network Slice Selection Function (NSSF) for slice-related information. Based at least in part on the information retrieved, the NWDAF can perform on-demand provision of analytics to customers (e.g., network operators).

[0009] PCFs support a unified policy framework to govern the network behavior. As an example of an operation of the PCF, the PCF can provide Policy and Charging Control (PCC) rules to the SMF. The SMF is then primarily responsible for interacting with the decoupled data plane, creating, updating, and removing PDU sessions as well as managing session context with the User Plane Function (UPF). The UPF supports the handling of user plane traffic, including packet inspection, packet routing and forwarding, traffic usage reporting, and Quality of Service (QoS) handling.

[0010] Summary

[0011] Various embodiments disclosed herein provide a method for facilitating the exposure of raw data and packet metadata from a User Plane Function (UPF) of a core network to facilitate flexible data analysis of the raw data and packet metadata. Existing services that allow exposure of UPF data can be extended by defining a new event that allows UPF to expose raw data packet traces. A subscription request for data can be passed from a requesting network function (NF) to the UPF, and the subscription request can include an event indicator that indicates user plane data, a target User Equipment (UE) identifier, and an event filter. The UPF can then identify application traffic from the target UE that matches the subscription request, duplicate a subset of the user plane data packets from the application traffic, and then provide the requesting NF with the duplicated user plane data packets.

[0012] In an embodiment, a method is provided to expose user plane data by a UPF implemented by a network node. The method includes receiving, from a network function, a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target UE identifier, and an event filter. The method also includes identifying application traffic from a target UE that matches the subscription request. The method also includes duplicating a subset of user plane data packets from the application traffic based on the event filter to produce duplicated user plane data packets and providing, to the network function, the duplicated user plane data packets.

[0013] In an embodiment, the subscription request further comprises a data type indicator that indicates whether the user plane data requested is raw data and / or trace data, and wherein the duplicated user plane data packets include raw data and / or trace data in accordance with the data type indicator.

[0014] In an embodiment, the event filter comprises one or more of a data flow filter that indicates a type of traffic, a direction of traffic, or other packet filter criteria and a metadata filter that indicates any requested metadata. In an embodiment, the packet filter criteria further comprise one or more of a number of packets to report, a list of associated flags, packet sampling criteria.

[0015] In an embodiment, providing the duplicated user plane data packets is in response to a triggering event.

[0016] In an embodiment, the triggering event is indicated in the event filter.

[0017] In an embodiment, the providing the duplicated user plane data packets is performed at a predefined periodicity.

[0018] In an embodiment, the providing the duplicated user plane data packets is via a Nupf_EventExposure_Notify request directed towards the network function.

[0019] In an embodiment, the method further includes storing the duplicated user plane data packets until the user plane data packets are provided to the network function.

[0020] In an embodiment, the network function is at least one of a Session Management Function (SMF) or a Network Data Analytics Function (NWDAF).

[0021] In an embodiment, a network node is provided that is configured to implement a UPF that exposes user plane data. The network node can include a network interface configured to communicate with other network nodes, and processing circuitry configured to receive, from a network function via the network interface, a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target UE identifier, and an event filter. The processing circuitry can also be configured to identify application traffic from a target UE that matches the subscription request, duplicate a subset of the user plane data packets from the application traffic based on the event filter to produce duplicated user plane data packets, and provide, to the network function via the network interface, the duplicated user plane data packets.

[0022] In an embodiment, a computer-readable medium that stores computerexecutable instructions that, when executed by a processor, cause the processor to perform the above embodiments performed by the UPF.

[0023] In an embodiment, a method to expose user plane data by an SMF implemented by a network node. The method includes receiving, from a network function, a subscription request for user plane data that comprises an event indicator that indicates user plane data, a target UE identifier, and an event filter and identifying an event as a UPF event, and a Protocol Data Unit (PDU) session based on the subscription request. The method also includes forwarding the subscription request to a UPF corresponding to the PDU session, receiving duplicated user plane data packets from the UPF, wherein the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter, and forwarding the duplicated user plane data packets to the network function.

[0024] In an embodiment, the subscription request further comprises a data type indicator that indicates whether the user plane data requested is raw data and / or trace data, and wherein the duplicated user plane data packets include raw data and / or trace data in accordance with the data type indicator.

[0025] In an embodiment, the event filter comprises one or more of an access and PDU session filter, a data flow filter that indicates a type of traffic, a direction of traffic, or other packet filter criteria, and a metadata filter that indicates any requested metadata.

[0026] In an embodiment, the packet filter criteria further comprise one or more of a number of packets to report, a list of associated flags, packet sampling criteria.

[0027] In an embodiment, the network function is an NWDAF.

[0028] In an embodiment, a network node is provided that is configured to implement an SMF that exposes user plane data, where the network node includes a network interface configured to communicate with other network nodes, and processing circuitry configured to receive, from a network function via the network interface, a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target UE identifier, and an event filter and identify an event as a UPF event, and a PDU session based on the subscription request. The processing circuitry is also configured to forward the subscription request to a UPF corresponding to the PDU session, receive duplicated user plane data packets from the UPF, where the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter, and forward the duplicated user plane data packets to the network function via the network interface.

[0029] In an embodiment, a computer-readable medium that stores computerexecutable instructions that, when executed by a processor, cause the processor to perform the above embodiments performed by the SMF.

[0030] In an embodiment, a method to expose user plane data by an NWDAF implemented by a network node is provided where the method includes providing, to an SMF a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target UE identifier, and an event filter and receiving, from a network function, duplicated user plane data packets corresponding to the subscription request, wherein the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter.

[0031] In an embodiment, the method also includes receiving, from a consumer network function, a request for analytics data and determining that the request for analytics data corresponds to user plane data.

[0032] In an embodiment, the subscription request further comprises a data type indicator that indicates whether the user plane data requested is raw data and / or trace data, and wherein the duplicated user plane data packets include raw data and / or trace data in accordance with the data type indicator.

[0033] In an embodiment, a network node configured to implement an NWDAF is provided that comprises a network interface configured to communicate with other network nodes and processing circuitry configured to provide, to an SMF, a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target UE identifier, and an event filter and receive, from a network function, duplicated user plane data packets corresponding to the subscription request, wherein the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter.

[0034] In an embodiment, a computer-readable medium that stores computerexecutable instructions that, when executed by a processor, cause the processor to perform the above embodiments performed by the NWDAF.

[0035] In an embodiment, an advantage provided by the embodiments described herein include enabling a network operator to expose user plane traffic in a very flexible, simple, and efficient (focused on value information) way leveraging SBA. Thus, retrieving unnecessary data can be mitigated or avoided, thereby potentially saving bandwidth or other communication resources. Instead, data retrieval can focus on only select and specific data which is desired. Additionally, the embodiments disclosed herein enable a UPF to expose packet traces in standardized formats (e.g. Positioning Calculation Application Part (PCAP) file) suitable for analytics / reporting engines. Thus, the solution does not require specialized network taps and packet brokers, or other mechanisms to process inputs from sources. The embodiments also allow an agile mechanism for the NWDAF to analyze raw packet information related to a service without the need of specific standard Key Performance Indicator (KPI) definition. Thus, there is no need for there to be official Third Generation Partnership Program (3GPP) defined specific KPIs.

[0036] Brief Description of the Drawings

[0037] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.

[0038] Figures 1A and IB depict a message sequence chart for a method of exposing raw data and packet metadata from a User Plane Function (UPF) according to some embodiments of the present disclosure.

[0039] Figure 2 illustrates one example of a cellular communications system according to some embodiments of the present disclosure.

[0040] Figures 3 and 4 illustrate example embodiments in which the cellular communication system of Figure 2 is a Fifth Generation (5G) System (5GS).

[0041] Figure 5 is a schematic block diagram of a network node according to some embodiments of the present disclosure.

[0042] Figure 6 is a schematic block diagram that illustrates a virtualized embodiment of the network node of Figure 5 according to some embodiments of the present disclosure.

[0043] Figure 7 is a schematic block diagram of the network node of Figure 5 according to some other embodiments of the present disclosure.

[0044] Detailed Description

[0045] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.

[0046] Network Node: As used herein, a "network node" is any type of node in a core network or any node that implements a core network function. Some examples of a network node include, e.g., a node implementing a Network Data Analytics Function (NWDAF), an Access and Mobility Function (AMF), a User Plane Function (UPF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a Network Function (NF) Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), or the like.

[0047] Note that the description given herein focuses on a Third Generation Partnership Project (3GPP) cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.

[0048] Some of the challenges and or problems facing the current state of the art are that existing user plane events (e.g., UserDataUsageMeasures) defined as part of Nupf_EventExposure service are focused on reporting specific Key Performance Indicators (KPIs) (e.g. volume, throughput, latency, etc.). For defining a new potential KPI (e.g. a future NWDAF analytic that involves data collection from UPF), a new UPF event needs to be standardized ad-hoc by Third Generation Partnership Program (3GPP), which implies a heavy and slow process (e.g. long discussions and times to get something approved by 3GPP, costly from a product implementation perspective, etc.

[0049] Operators typically demand (e.g., for troubleshooting purposes or investigation on new protocols detection) to get access to user payload in raw format for a subscriber or per specific service, therefore some user plane traffic needs to be exposed / ana lyzed by providing raw / sample packet traces. The existing mechanism to do this is based on Sx / N4 FAR duplicate & forward and has the following limitations.

[0050] If the consumer (e.g. NWDAF) desires raw data for a certain application, if the Protocol Data Unit (PDU) session has no installed Packet Detection Rule (PDR) or Packet Detection Information (PDI) in the UPF for that application, the mechanism does not work. PDRs would need to be a mix of Policy and Charging Control (PCC) and reporting domains needs, but 3GPP does not allow a reporting request to trigger a change of PDRs (i.e. dynamic update when needed).

[0051] Unfortunately, this can involve a more complex definition of PCC rules, more PDRs and signaling (statically, at session establishment) across the NFs together with heavier and less efficient UPF packet detection task. The existing Forwarding Action Rule (FAR) duplicate & forward mechanism has no flexibility, e.g. the consumer might be interested only in the initial packets of each flow, as those are the ones containing the most relevant information (e.g. Transmission Control Protocol Setup (TCPsetup) signaling, Transport Layer Security (TLS) connection establishment, specific protocol headers, etc.). Many flows are huge in size (thousands of packets with a total accumulated volume in the order of several MBs) and duration (in the order of hours), so duplicating and forwarding them towards a reporting / analytics engine is very inefficient both in terms of signaling and performance.

[0052] To solve these and other challenges, various embodiments disclosed herein provide for a method for facilitating the exposure of raw data and packet metadata from a User Plane Function (UPF) of a core network to facilitate flexible data analysis of the raw data and packet metadata. Existing services that allow exposure of UPF data can be extended by defining a new event which allows UPF to expose raw data packet traces. A subscription request for data can be passed from a requesting network function (NF) to the UPF, and the subscription request can include an event indicator that indicates user plane data, a target User Equipment (UE) identifier, and an event filter. The UPF can then identify application traffic from the target UE that matches the subscription request, duplicate a subset of the user plane data packets from the application traffic, and then provide the requesting NF with the duplicated user plane data packets.

[0053] In an embodiment, the disclosure includes extending the Nupf_EventExposure service with a new event (e.g. Event-ID=UserData) which allows UPF to expose raw data packet traces. The consumer can subscribe raw data or trace in e.g. Positioning Calculation Application Part (PCAP) file format, corresponding to certain user data traffic, certain traffic direction (uplink, downlink, or both) providing additional filtering criteria to specify the data of interest (e.g. subscriber, application, protocol stack layer / s), sampling criteria and any metadata requested (e.g. timestamp for each packet).

[0054] In an embodiment, an advantage provided by the embodiments described herein includes enabling a network operator to expose user plane traffic in a very flexible, simple, and efficient way (focused on value information). Thus, retrieving unnecessary data can be mitigated or avoided, thereby potentially saving bandwidth or other communication resources. Instead, data retrieval can focus on only select and specific data which is desired. Additionally, the embodiments disclosed herein enable a UPF to expose packet traces in standardized formats (e.g., PCAP file) suitable for analytics / reporting engines. Thus, the solution does not require specialized network taps and packet brokers, or other mechanisms to process inputs from sources.

[0055] The embodiments also allow an agile mechanism for the NWDAF to analyze raw packet information related to a service without the need of specific standard Key Performance Indicator (KPI) definition. Thus, there is no need for there to be official 3GPP defined specific KPIs.

[0056] Figures 1A and IB depict a message sequence chart for a method of exposing raw data and packet metadata from a UPF according to some embodiments of the present disclosure.

[0057] The messages in the message sequence chart in Figures 1A and IB are between UE 212, UPF 314, SMF 308, NWDAF 316, a consumer (e.g., a network operator) 102, as well as an application server 104. It is to be appreciated that optional steps are depicted with broken lines, while exemplary or required steps, for the one or more embodiments, are depicted with solid lines.

[0058] At step 106, the consumer 102 can subscribe to one or more analytics that are performed by the NWDAF. The analytic can be any type of data analysis product that may desire data from the UPF. The subscription can trigger, at step 108, a subscription request from the consumer 102 to the NWDAF 316. In an embodiment, the subscription request can be in the form of a Nnwdaf_AnalyticsSubscription_Subscribe request message and can include an identifier identifying the analytic (e.g., Analytic-ID).

[0059] At step 110, the NWDAF 316 can answer the subscription request from step 108 with a response that indicates to the consumer 102 that the NWDAF 316 has accepted the request.

[0060] At step 112, the NWDAF 316 triggers data collection from the UPF 314 via the SMF 308 when the NWDAF 316 determines that, to satisfy the request, data from UPF is needed and it triggers data collection from UPF (via SMF) sending a Nsmf_EventExposure_Subscribe request message at step 114 to the SMF 308. The Nsmf_EventExposure_Subscribe request message can include one or more of the following parameters, including an Event-ID, an Event-Target (target UE identifier), optionally a DataReport-Type indicating a type of data, and an event filter.

[0061] • Event-ID (UserData): Indicates to collect user plane data. • Event-Target (UE-ID): Indicates the target UE / s for this event.

[0062] • DataReport-Type (optional) (Raw / Trace): Indicates the type of data preferred for the event requested: a. Raw: indicates to report raw packets. In this case, the requested protocol stack layers might also be indicated, e.g. to report L3 and L4 headers only, the whole packet starting from L3 (e.g. Internet Protocol (IP) header and above) or just L7 payload information. b. Trace: indicates to report packet traces. In this case, the trace format might also be indicated, e.g. Trace-Format set to PCAP Next Generation Dump File Format.

[0063] • Event-Filter, including: a. Access and PDU session related filters: including e.g. i. RAT (Radio Access Technology) type ii. AOI (Area of Interest) iii. Data Network Name (DNN), Single Network Slice Selection Assistance Information (S-NSSAI) iv. Basic Service Set Identifier (BSSID) / Service Set Identifier (SSID) v. Session and Service Continuity (SSC) Mode vi. Multipath interface vii. Etc.

[0064] The event filters are very relevant if the request is for Any_UE, such as when the consumer is not interested in a specific user but rather in one or more PDU sessions that meet certain conditions) b. Data Flow related filters: i. List of App-ID (example.com) or traffic filters, this indicates the user traffic (applications, destination servers...) targeted by the request. ii. Direction (uplink / downlink / both): Indicates which traffic direction of data flow is of interest. iii. Packet filter criteria, including e.g.

[0065] 1. Number of packets: Indicates the number of packets to report (e.g. the first N packets for each flow), OR

[0066] 2. List of flags, e.g.: a. Transmission Control Protocol Setup (TCPSetup) flag (indicates to report only TCP setup signaling packets, e.g. TCP SYN, TCP SYNACK and TCP ACK) b. Transport Layer Security Setup (TLSSetup) (indicates to report only TLS setup signaling packets, e.g. TLS Client Hello) c. Quick UDP Internet Connections (QUICSetup) (indicates to report only QUIC setup signaling packets, e.g. QUIC CHLO)

[0067] 3. Other packet filter criteria, e.g. sampling percentage indicating to report only a percentage (e.g. 10%) of the target flows, or to report service information only (e.g. skip transport acknowledges or packet retransmissions), or packets up to a first silent period. c. Requested Metadata: Indicates the requested metadata, e.g. data flow metadata (timestamp (corresponding to the time when each packet was detected by UPF), detailed packet classification result, packet handling actions (e.g. buffer, forward, drop, modify, etc.), sequence number in the ip-flow), subscriber session information, UPF interface used, etc.

[0068] At step 116, the SMF 308 may optionally answer the request message in step 114 with a successful response indicating that the SMF 308 has accepted the subscription request.

[0069] At step 118, the SMF 308 determines that the requested event is a UPF 314 event. The SMF 308 can select the PDU Sessions which are targeted by the request, where the PDU sessions match the filtering criteria in the event-target and event-filters. SMF 308 may apply sampling if many PDU Sessions are candidates to data collection. The sampling can include selecting a random number of the PDU sessions that meet the criteria or can select a subset of the PDU sessions based on some other criteria. Then SMF 308, at step 120 forwards the subscription request to the UPF 314 to trigger data collection by sending a Nupf_EventExposure_Subscribe request message including the same parameters in the subscription request as described above except those only intended for PDU Session selection by the SMF 308 (e.g., the access and PDU session related filters). At 120, the SMF 308 can send the subscribe request message to the UPF 314, where the subscription request comprises an event indicator that indicates user plane data, a target User Equipment, UE, identifier, and an event filter, and if successful, the UPF 314 can optionally send a response at step 122 acknowledging the request and indicating it was successfully received.

[0070] At 124, the application traffic between the application server 104 and the UE 212 may initiate, and the traffic may be forwarded to the application server via one or more of the core network nodes (e.g., UPF 314, SMF 308, etc.). At 126 for example, the application traffic can be directed from the UE 212 to the UPF 314 which at step 128 can determine that one or more packets of the traffic may correspond to or matches the parameters in the subscription request received from the SMF 308 or the NWDAF 316. In an embodiment, the UPF 314 detects traffic for UE-ID and at step 130 duplicates or makes a copy of the relevant packets (on a per flow basis) based on the Data Flow related filters in the request. At step 132, the UPF 314 can forward the application traffic to the application server 104, while maintaining a store of the duplicated packets.

[0071] At step 134, the UPF 314 can report that User data matching the Event- ID=UserData has been detected when all the TCP setup signaling packets have been detected based on one or more of the event filters. In an embodiment, the UPF 314 can store the duplicated data until a triggering event or occurrence happens (e.g., based on event filters) and then report to the NWDAF 316 and or SMF 308. Alternatively, in other embodiments, the UPF 314 can report at regular or predefined periodic intervals the information matching the subscription request that has been received up until the reporting time.

[0072] The UPF can then trigger at step 136 or optionally step 141, a Nupf_EventExposure_Notify request towards NWDAF 316 including the following parameters:

[0073] • Event-ID=UserData

[0074] • UE-ID. This indicates the target UEs for this event.

[0075] • EventData. This includes the filtered copied traffic as requested, with the data type requested plus the requested metadata (as per Data Report-Type and Event- Filter), e.g. all the raw packets matching the criteria in the Event-Filter (e.g. TCP SYN, TCP SYNACK and TCP ACK packets for a certain application on a per flow basis). The UPF 314 can report the notify request at step 136 to the SMF 308 which can optionally respond with a notify response at step 138, and then the SMF 308 can forward the notify request to the NWDAF 316 at step 140. Alternatively, the UPF 314 may optionally send the notify request directly to the NWDAF 316 at step 141.

[0076] At step 142, the NWDAF 316 can perform the analytics requested by the consumer 102 based on the data collected from UPF 314 and can trigger a notify request (Nnwdaf_AnalyticsSubscription_Notify request) message to the consumer 102 at step 144 including the Analytic-ID and the corresponding AnalyticResult. At step 146, the consumer 102 can optionally answer the NWDAF 316 with a message indicating that the notify request was successfully received.

[0077] Figure 2 illustrates one example of a cellular communications system 200 in which embodiments of the present disclosure may be implemented. In the embodiments described herein, the cellular communications system 200 is a 5G system (5GS) including a Next Generation RAN (NG-RAN) and a 5G Core (5GC). In this example, the RAN includes base stations 202-1 and 202-2, which in the 5GS include NR base stations (gNBs) and optionally next generation eNBs (ng-eNBs) (e.g., LTE RAN nodes connected to the 5GC), controlling corresponding (macro) cells 204-1 and 204-2. The base stations 202-1 and 202-2 are generally referred to herein collectively as base stations 202 and individually as base station 202. Likewise, the (macro) cells 204-1 and 204-2 are generally referred to herein collectively as (macro) cells 204 and individually as (macro) cell 204. The RAN may also include a number of low power nodes 206-1 through 206-4 controlling corresponding small cells 208-1 through 208-4. The low power nodes 206-1 through 206-4 can be small base stations (such as pico or femto base stations) or RRHs, or the like. Notably, while not illustrated, one or more of the small cells 208-1 through 208-4 may alternatively be provided by the base stations 202. The low power nodes 206-1 through 206-4 are generally referred to herein collectively as low power nodes 206 and individually as low power node 206. Likewise, the small cells 208-1 through 208-4 are generally referred to herein collectively as small cells 208 and individually as small cell 208. The cellular communications system 200 also includes a core network 210, which in the 5G System (5GS) is referred to as the 5GC. The base stations 202 (and optionally the low power nodes 206) are connected to the core network 210. The base stations 202 and the low power nodes 206 provide service to wireless communication devices 212-1 through 212-5 in the corresponding cells 204 and 208. The wireless communication devices 212-1 through 212-5 are generally referred to herein collectively as wireless communication devices 212 and individually as wireless communication device 212. In the following description, the wireless communication devices 212 are oftentimes UEs, but the present disclosure is not limited thereto.

[0078] Figure 3 illustrates a wireless communication system represented as a 5G network architecture composed of core Network Functions (NFs), where interaction between any two NFs is represented by a point-to-point reference point / interface. Figure 3 can be viewed as one particular implementation of the system 200 of Figure 2.

[0079] Seen from the access side the 5G network architecture shown in Figure 3 comprises a plurality of UEs 212 connected to either a RAN 202 or an Access Network (AN) as well as an AMF 300. Typically, the R(AN) 202 comprises base stations, e.g. such as eNBs or gNBs or similar. Seen from the core network side, the 5GC NFs shown in Figure 3 include a NSSF 302, an AUSF 304, a UDM 306, the AMF 300, a SMF 308, a PCF 310, and an Application Function (AF) 312.

[0080] Reference point representations of the 5G network architecture are used to develop detailed call flows in the normative standardization. The N1 reference point is defined to carry signaling between the UE 212 and AMF 300. The reference points for connecting between the AN 202 and AMF 300 and between the AN 202 and UPF 314 are defined as N2 and N3, respectively. There is a reference point, Nil, between the AMF 300 and SMF 308, which implies that the SMF 308 is at least partly controlled by the AMF 300. N4 is used by the SMF 308 and UPF 314 so that the UPF 314 can be set using the control signal generated by the SMF 308, and the UPF 314 can report its state to the SMF 308. N9 is the reference point for the connection between different UPFs 314, and N14 is the reference point connecting between different AMFs 300, respectively. N15 and N7 are defined since the PCF 310 applies policy to the AMF 300 and SMF 308, respectively. N12 is utilized for the AMF 300 to perform authentication of the UE 212. N8 and N10 are defined because the subscription data of the UE 212 is used for the AMF 300 and SMF 308.

[0081] The 5GC network aims at separating UP and CP. The UP carries user traffic while the CP carries signaling in the network. In Figure 3, the UPF 314 is in the UP and all other NFs, i.e., the AMF 300, SMF 308, PCF 310, AF 312, NSSF 302, AUSF 304, and UDM 306, are in the CP. Separating the UP and CP guarantees each plane resource to be scaled independently. It also allows UPFs to be deployed separately from CP functions in a distributed fashion. In this architecture, UPFs may be deployed very close to UEs to shorten the Round Trip Time (RTT) between UEs and data network for some applications involving low latency.

[0082] The core 5G network architecture is composed of modularized functions. For example, the AMF 300 and SMF 308 are independent functions in the CP. Separated AMF 300 and SMF 308 allow independent evolution and scaling. Other CP functions like the PCF 310 and AUSF 304 can be separated as shown in Figure 3. Modularized function design enables the 5GC network to support various services flexibly.

[0083] Each NF interacts with another NF directly. It is possible to use intermediate functions to route messages from one NF to another NF. In the CP, a set of interactions between two NFs is defined as service so that its reuse is possible. This service enables support for modularity. The UP supports interactions such as forwarding operations between different UPFs.

[0084] Figure 4 illustrates a 5G network architecture using service-based interfaces between the NFs in the CP, instead of the point-to-point reference points / interfaces used in the 5G network architecture of Figure 3. However, the NFs described above with reference to Figure 3 correspond to the NFs shown in Figure 4. The service(s) etc. that a NF provides to other authorized NFs can be exposed to the authorized NFs through the service-based interface. In Figure 4 the service based interfaces are indicated by the letter "N" followed by the name of the NF, e.g. Namf for the service based interface of the AMF 300 and Nsmf for the service based interface of the SMF 308, etc. The NEF 400 and the NRF 402 in Figure 4 are not shown in Figure 3 discussed above. However, it should be clarified that all NFs depicted in Figure 3 can interact with the NEF 400 and the NRF 402 of Figure 4 as necessary, though not explicitly indicated in Figure 3.

[0085] Some properties of the NFs shown in Figures 3 and 4 may be described in the following manner. The AMF 300 provides UE-based authentication, authorization, mobility management, etc. A UE 212 even using multiple access technologies is basically connected to a single AMF 300 because the AMF 300 is independent of the access technologies. The SMF 308 is responsible for session management and allocates Internet Protocol (IP) addresses to UEs. It also selects and controls the UPF 314 for data transfer. If a UE 212 has multiple sessions, different SMFs 308 may be allocated to each session to manage them individually and possibly provide different functionalities per session. The AF 312 provides information on the packet flow to the PCF 310 responsible for policy control in order to support QoS. Based on the information, the PCF 310 determines policies about mobility and session management to make the AMF 300 and SMF 308 operate properly. The AUSF 304 supports authentication function for UEs or similar and thus stores data for authentication of UEs or similar while the UDM 306 stores subscription data of the UE 212. The Data Network (DN), not part of the 5GC network, provides Internet access or operator services and similar.

[0086] An NF may be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g., a cloud infrastructure.

[0087] Figure 5 is a schematic block diagram of a network node 500 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The network node 500 may, for example, implement a core network function from core network 210, such as an SMF 308, a UPF 314, or an NWDAF 316. As illustrated, the network node 500 includes a control system 502 that includes one or more processors 504 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), computer readable memory 506, and a network interface 508. The one or more processors 504 are also referred to herein as processing circuitry. The one or more processors 504 operate to provide one or more functions of a network node 500 as described herein. In some embodiments, the function(s) are implemented in software that is stored, e.g., in a computer readable medium (e.g., non-transitory computer readable medium such as memory 506) and executed by the one or more processors 504.

[0088] Figure 6 is a schematic block diagram that illustrates a virtualized embodiment of the network node 500 according to some embodiments of the present disclosure. This discussion is equally applicable to other types of network nodes. Further, other types of network nodes may have similar virtualized architectures. Again, optional features are represented by dashed boxes.

[0089] As used herein, a "virtualized" network node is an implementation of the network node 500 in which at least a portion of the functionality of the network node 500 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). As illustrated in this example, the network node 500 may include the control system 502 as described above. The network node 500 includes one or more processing nodes 600 coupled to or included as part of a network(s) 602. If present, the control system 502 is connected to the processing node(s) 600 via the network 602. Each processing node 600 includes one or more processors 604 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 606, and a network interface 608.

[0090] In this example, functions 610 of the network node 500 described herein are implemented at the one or more processing nodes 600 or distributed across the one or more processing nodes 600 and the control system 502 in any desired manner. In some particular embodiments, some or all of the functions 610 of the network node 500 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environment(s) hosted by the processing node(s) 600. As will be appreciated by one of ordinary skill in the art, additional signaling or communication between the processing node(s) 600 and the control system 502 is used in order to carry out at least some of the desired functions 610.

[0091] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of network node 500 or a node (e.g., a processing node 600) implementing one or more of the functions 610 of the network node 500 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).

[0092] Figure 7 is a schematic block diagram of the network node 500 according to some other embodiments of the present disclosure. The network node 500 includes one or more modules 700, each of which is implemented in software. The module(s) 700 provide the functionality of the network node 500 described herein. This discussion is equally applicable to the processing node 600 of Figure 6 where the modules 700 may be implemented at one of the processing nodes 600 or distributed across multiple processing nodes 600 and / or distributed across the processing node(s) 600 and the control system 502.

[0093] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special -purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0094] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).

Claims

Claims1. A method to expose user plane data by a User Plane Function, UPF, (314) implemented by a network node (500), the method comprising: receiving (120), from a network function (308, 316), a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target User Equipment, UE, identifier, and an event filter; identifying (128) application traffic from a target UE that matches the subscription request; duplicating (130) a subset of user plane data packets from the application traffic based on the event filter to produce duplicated user plane data packets; and providing (136), to the network function (308, 316), the duplicated user plane data packets.

2. The method of claim 1, wherein the subscription request further comprises a data type indicator that indicates whether the user plane data requested is raw data and / or trace data, and wherein the duplicated user plane data packets include raw data and / or trace data in accordance with the data type indicator.

3. The method of any of claims 1 to 2, wherein the event filter comprises one or more of: a data flow filter that indicates a type of traffic, a direction of traffic, or other packet filter criteria; and a metadata filter that indicates any requested metadata.

4. The method of claim 3, wherein the packet filter criteria further comprise one or more of: a number of packets to report, a list of associated flags, packet sampling criteria.

5. The method of any of claims 1 to 4, wherein the providing the duplicated user plane data packets is in response to a triggering event.

6. The method of claim 5, wherein the triggering event is indicated in the event filter.

7. The method of any of claims 1 to 4, wherein the providing the duplicated user plane data packets is performed at a predefined periodicity.

8. The method of any of claims 1 to 7, wherein the providing the duplicated user plane data packets is via a Nupf_EventExposure_Notify request directed towards the network function (308, 316).

9. The method of any of claims 1 to 8, further comprising: storing (130) the duplicated user plane data packets until the user plane data packets are provided to the network function (308, 316).

10. The method of any of claims 1 to 9, wherein the network function (308, 316) is at least one of a Session Management Function, SMF, (308) or a Network Data Analytics Function, NWDAF, (316).

11. A network node (500) configured to implement a User Plane Function, UPF, (314) that exposes user plane data, the network node (500) comprising a network interface (508) configured to communicate with other network nodes, and processing circuitry (504) configured to: receive (120), from a network function (308, 316) via the network interface, a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target User Equipment, UE, identifier, and an event filter; identify (128) application traffic from a target UE that matches the subscription request; duplicate (130) a subset of user plane data packets from the application traffic based on the event filter to produce duplicated user plane data packets; and provide (136), to the network function (308, 316) via the network interface, the duplicated user plane data packets.

12. The network node (500) of claim 11, wherein the processing circuitry is further configured to perform the methods of claims 2 to 10.

13. A computer-readable medium (506) that stores computer-executable instructions, that when executed by a processor (504), cause the processor (504) to implement a method according to any one of claims 1 to 10.

14. A method to expose user plane data by a Session Management Function, SMF, (308) implemented by a network node (500), the method comprising: receiving (114), from a network function (316), a subscription request for user plane data that comprises an event indicator that indicates user plane data, a target User Equipment, UE, identifier, and an event filter; identifying (118) an event as a User Plane Function, UPF, event, and a Protocol Data Unit, PDU, session based on the subscription request; forwarding (120) the subscription request to a UPF (314) corresponding to the PDU session; receiving (136) duplicated user plane data packets from the UPF (314), wherein the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter; and forwarding (140) the duplicated user plane data packets to the network function (316).

15. The method of claim 14, wherein the subscription request further comprises a data type indicator that indicates whether the user plane data requested is raw data and / or trace data, and wherein the duplicated user plane data packets include raw data and / or trace data in accordance with the data type indicator.

16. The method of any of claims 14 to 15, wherein the event filter comprises one or more of: an access and PDU session filter; a data flow filter that indicates a type of traffic, a direction of traffic, or other packet filter criteria; and a metadata filter that indicates any requested metadata.

17. The method of claim 16, wherein the packet filter criteria further comprise one or more of: a number of packets to report, a list of associated flags, packet sampling criteria.

18. The method of any of claims 14 to 17, wherein the network function is a Network Data Analytics Function, NWDAF (316).

19. A network node (500) configured to implement a Session Management Function, SMF, that exposes user plane data, the network node (500) comprising a network interface (508) configured to communicate with other network nodes, and processing circuitry (504) configured to: receive (114), from a network function (316) via the network interface, a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target User Equipment, UE, identifier, and an event filter; identify (118) an event as a User Plane Function, UPF, event, and a Protocol Data Unit, PDU, session based on the subscription request; forward (120) the subscription request to a UPF (314) corresponding to the PDU session; receive (136) duplicated user plane data packets from the UPF (314), wherein the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter; and forward (140) the duplicated user plane data packets to the network function (316) via the network interface.

20. The network node (500) of claim 19, wherein the processing circuitry is further configured to perform the methods of claims 15 to 18.

21. A computer-readable medium (506) that stores computer-executable instructions that, when executed by a processor (504), cause the processor (504) to implement a method according to any one of claims 14 to 18.

22. A method to expose user plane data by a Network Data Analytics Function, NWDAF, (316) implemented by a network node (500), the method comprising: providing (114), to a Session Management Function, SMF, (308) a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target User Equipment, UE, identifier, and an event filter; and receiving (140), from a network function (308, 314), duplicated user plane data packets corresponding to the subscription request, wherein the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter.

23. The method of claim 22, further comprising: receiving (108), from a consumer network function (102), a request for analytics data; and determining (112) that the request for analytics data corresponds to user plane data.

24. The method of any of claims 22 to 23, wherein the subscription request further comprises a data type indicator that indicates whether the user plane data requested is raw data and / or trace data, and wherein the duplicated user plane data packets include raw data and / or trace data in accordance with the data type indicator.

25. The method of any of claims 22 to 24, wherein the event filter comprises one or more of: an access and Protocol Data Unit, PDU, session filter; a data flow filter that indicates a type of traffic, a direction of traffic, or other packet filter criteria; and metadata filter that indicates any requested metadata.

26. The method of claim 25, wherein the packet filter criteria further comprise one or more of: a number of packets to report, a list of associated flags, packet sampling criteria.

27. The method of any of claims 22 to 26, wherein the network function (308, 314) is at least one of the SMF (308) or a User Plane Function, UPF, (314).

28. A network node (500) configured to implement a Network Data Analytics Function, NWDAF, that exposes user plane data, the network node (500) comprising a network interface (508) configured to communicate with other network nodes, and processing circuitry (504) configured to: provide (114), to a Session Management Function, SMF, (308) via the network interface, a subscription request for user plane data, wherein the subscription request comprises an event indicator that indicates user plane data, a target User Equipment, UE, identifier, and an event filter; and receive (140), from a network node (308, 314) via the network interface, duplicated user plane data packets corresponding to the subscription request, wherein the duplicated user plane data packets comprise a subset of user plane data packets in accordance with the event filter.

29. The network node (500) of claim 28, wherein the processing circuitry is further configured to perform the methods of claims 23 to 27.

30. A computer-readable medium (506) that stores computer-executable instructions, that when executed by a processor (504), cause the processor (504) to implement a method according to any one of claims 22 to 27.

Citation Information

Patent Citations

  • Method and apparatus for detecting service and analyzing service characteristic using nwdaf in mobile communication system

    US20210099367A1

  • Data reporting method, apparatus, and system

    US20250056297A1

  • Data reporting method, apparatus, and system

    WO2023213134A1