Signaling storm processing method, apparatus, and communication device

Through NWDAF, network data is analyzed, signaling storms are detected and predicted, and the problem of signaling storms cannot be identified by the network-side equipment equipment is solved, effective control of signaling storms is achieved, and network robustness and efficiency are improved.

WO2025167885A1PCT designated stage Publication Date: 2025-08-14VIVO MOBILE COMM CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/075741
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-07
Filing Date
2025-02-05
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

The prior art cannot effectively analyze whether there is a signaling storm in the network side equipment, resulting in excessive network resource consumption and affecting network robustness and efficiency.

Method used

Collect and analyze network data through NWDAF, detect or predict signaling storms on network devices, obtain signaling storm analysis results, including the causes of signaling storm and the identification of target equipment, and perform signaling storm control operations.

Benefits of technology

It enhances the robustness of the network, improves the working efficiency of network-side equipment, and can promptly identify and respond to signaling storms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025075741_14082025_PF_FP_ABST
    Figure CN2025075741_14082025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and discloses a signaling storm processing method, an apparatus, and a communication device. The signaling storm processing method in embodiments of the present application comprises: an analysis function acquires target data; and the analysis function analyzes the target data to obtain a signaling storm analysis result of a first network side device, wherein the signaling storm analysis result comprises at least one of: a cause of causing a signaling storm, the cause comprising indication information for indicating that the signaling storm is a signaling storm of a network side device; and an identifier of the first network side device, the first network side device being a target device of a signaling storm.
Need to check novelty before this filing date? Find Prior Art

Description

Signaling storm processing method, device and communication equipment

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on February 7, 2024, with application number 202410175029.7 and entitled “Method, device and communication equipment for processing signaling storms”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application belongs to the field of communication technology, and specifically relates to a method, apparatus and communication equipment for processing a signaling storm. Background Art

[0004] Signaling storms can occur in Third Generation Partnership Projects (3GPP) networks. This can occur when a network function (NF) fails, sending a large amount of abnormal signaling to the target network element (NE). This causes the target NE to consume a large amount of resources to process these messages, resulting in the NE being unable to operate or operating at a low efficiency. Once this occurs, subsequent signaling cannot be processed, causing numerous errors and compromising network robustness.

[0005] In 3GPP networks, the Network Data Analytics Function (NWDAF) has been introduced. It can collect various data generated in the network, perform intelligent data analysis, and ultimately generate corresponding data analysis results to detect or predict various events occurring in the network.

[0006] In related technologies, NWDAF can analyze whether the application function (AF) is congested by analyzing the user plane data related information of the UE, but does not involve the analysis of network-side devices. Therefore, it is impossible to analyze whether other network-side devices (such as gNB, WLAN, AMF and other NFs) have signaling storms. Summary of the Invention

[0007] The embodiments of the present application provide a method, apparatus, and communication device for processing a signaling storm, which can solve the problem that related technologies cannot analyze whether a signaling storm occurs in a network-side device.

[0008] In a first aspect, a method for handling a signaling storm is provided, comprising:

[0009] The analysis function obtains target data;

[0010] The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device;

[0011] The signaling storm analysis result includes at least one of the following:

[0012] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0013] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0014] Secondly, another method for handling signaling storms is provided, including:

[0015] The control function receives the signaling storm analysis result sent by the analysis function;

[0016] The control function performs a signaling storm control operation according to the signaling storm analysis result;

[0017] The signaling storm analysis result includes at least one of the following:

[0018] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0019] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0020] In a third aspect, a signaling storm processing device is provided, which is applied to the analysis function, including:

[0021] Acquisition module, used to obtain target data;

[0022] An analysis module, configured to analyze the target data to obtain a signaling storm analysis result of the first network-side device;

[0023] The signaling storm analysis result includes at least one of the following:

[0024] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0025] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0026] In a fourth aspect, another signaling storm processing device is provided, which is applied to a control function, including:

[0027] An analysis result receiving module is used to receive the signaling storm analysis results sent by the analysis function;

[0028] A signaling storm control module, configured to perform a signaling storm control operation according to the signaling storm analysis result;

[0029] The signaling storm analysis result includes at least one of the following:

[0030] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0031] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0032] In a fifth aspect, a communication device is provided, comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method for processing a signaling storm as described in the first aspect are implemented, or the steps of the method for processing a signaling storm as described in the second aspect are implemented.

[0033] In a sixth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.

[0034] In the seventh aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, or to implement the method described in the second aspect.

[0035] In an eighth aspect, a computer program / program product is provided, wherein the computer program / program product is stored in a storage medium and is executed by at least one processor to implement the steps of the method described in the first aspect or the second aspect.

[0036] In the ninth aspect, a signaling storm processing device / equipment is provided, which includes the device / equipment (configured to) be used to execute the steps of the signaling storm processing method as described in the first aspect, or to execute the steps of the signaling storm processing method as described in the second aspect.

[0037] In an embodiment of the present application, the analysis function analyzes the signaling storm of the network side device according to the target data, and obtains the signaling storm analysis result of the first network side device, so that the network side signaling storm can be controlled according to the signaling storm analysis result, which can enhance the robustness of the network and is conducive to improving the working efficiency of the network side device. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] FIG1 is a block diagram of a wireless communication system to which embodiments of the present application may be applied;

[0039] FIG2 is a flow chart of a method for processing a signaling storm in an embodiment of the present application;

[0040] FIG3 is a flow chart of a method for processing a signaling storm in an embodiment of the present application;

[0041] FIG4 is a flow chart of a method for processing a signaling storm in an embodiment of the present application;

[0042] FIG5 is a flowchart of a method for processing a signaling storm in an embodiment of the present application;

[0043] FIG6 is a structural block diagram of a signaling storm processing device according to an embodiment of the present application;

[0044] FIG7 is a structural block diagram of another apparatus for processing a signaling storm in an embodiment of the present application;

[0045] FIG8 is a structural block diagram of a communication device in an embodiment of the present application;

[0046] FIG9 is a structural block diagram of a network-side device in an embodiment of the present application;

[0047] FIG10 is a structural block diagram of another network-side device in an embodiment of the present application. DETAILED DESCRIPTION

[0048] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0049] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects. For example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.

[0050] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) and other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for illustrative purposes, and the NR terminology is used in most of the following description, but these technologies can also be applied to applications other than NR system applications, such as 6th generation (6G) systems. th Generation, 6G) communication system.

[0051] FIG1 shows a block diagram of a wireless communication system applicable to embodiments of the present application. The wireless communication system includes a terminal device 11 and a network-side device 12 . The terminal device 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device (Wearable Device), a vehicle-mounted device (VUE), a pedestrian terminal (PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, televisions, washing machines, or furniture, etc.), a game console, a personal computer (PC), an ATM or a self-service machine, and other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. It should be noted that the specific type of the terminal device 11 is not limited in the embodiments of the present application. The network side device 12 may include an access network device or a core network device, wherein the access network device 12 may also be referred to as a radio access network device, a radio access network (RAN), a radio access network function, or a radio access network unit. The access network device 12 may include a base station, a WLAN access point, or a WiFi node, etc. The base station may be referred to as a node B, an evolved node B (eNB), an access point, a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home node B, a home evolved node B, a transmitting and receiving point (TRP), or other appropriate terms in the field. As long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.The core network equipment may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application service discovery function (EASDF), unified data management (UDM), unified data storage (UDR), home user server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BSF), application function ( Function, AF), Network Data Analytics Function (NWDAF), Operation, Management, Maintenance (OAM) functions, etc. It should be noted that in the embodiment of the present application, only the core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited.

[0052] The following describes in detail the signaling storm processing method provided by the embodiment of the present application through some embodiments and application scenarios in conjunction with the accompanying drawings.

[0053] 2, a flow chart of a method for processing a signaling storm provided by an embodiment of the present application is shown. The method is applied to the analysis function, as shown in FIG2, and the method may specifically include:

[0054] Step 101: Analyze the function to obtain target data;

[0055] Step 102: The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device.

[0056] The signaling storm analysis result includes at least one of the following:

[0057] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0058] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0059] It should be noted that the analysis function in the embodiment of the present application may be NWDAF, which can collect various data generated in the network and perform intelligent data analysis, and finally generate corresponding data analysis results to detect or predict various events occurring in the network. Of course, the analysis function may also be other devices or network elements that can collect target data and perform data analysis, such as OAM, or external security functions (such as firewalls, intrusion detection systems, intrusion prevention systems, etc.), and this application does not limit this. For example, the analysis function in the present application may be a communication device configured with an AI model, which is trained to implement a network data analysis function.

[0060] The first network side device is a target device of the signaling storm, which can be understood as a target device that is suffering from a signaling storm, or a target device that is predicted to suffer from a signaling storm through an analysis function. The identifier of the first network side device can identify a single network side device. For example, the identifier of the first network side device can be a cell identifier (cell ID), an NF instance ID, and so on; the identifier of the first network side device can also identify a group or multiple network side devices, such as through a tracking area (TA), an area of ​​interest (AoI), a single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI) and other identifiers.

[0061] In an optional embodiment of the present application, the first network side device may be an access network device, such as a base station (gNB), a wireless local area network (WLAN) access point, etc.; the first network side device may also be a core network device, such as an AMF or SMF, etc., which is a network function (NF) that performs signaling interaction with other network side devices or terminals.

[0062] A network-side device signaling storm refers to a signaling storm caused by network-side signaling. This is because other network-side devices send a large amount of signaling to the first network-side device, causing the signaling received by the first network-side device to exceed its processing limit. The first network-side device needs to consume a large amount of resources to process these signalings, which in turn causes the first network-side device to be unable to work or to maintain operation at a lower efficiency.

[0063] The target data is input data for signaling storm analysis. Exemplarily, the target data may be at least one of signaling characteristic information and network capacity information of the first network device. The signaling characteristic information indicates at least one of signaling failure characteristics and signaling anomaly characteristics between the first network device and other network devices; the network capacity information indicates the number of current network contexts for the first network device. Alternatively, the target data may also include at least one of signaling characteristic information and network capacity information of other network devices interacting with the first network device.

[0064] The analysis function analyzes the target data, and may perform signaling storm detection on the first network-side device, for example, detecting the number or ratio of failed messages currently on the first network-side device, detecting the number or ratio of unresponsive messages currently on the first network-side device, detecting the level of the signaling storm, or detecting the trend of the signaling storm, etc. In this case, the signaling storm analysis result is a signaling storm detection result, which may include at least one of an identifier of the first network-side device experiencing the signaling storm and a cause of the signaling storm.

[0065] It is understood that a characteristic of a network element experiencing a signaling storm is that the network element is in an abnormal resource usage state (e.g., a central processing unit (CPU) usage rate of 100% and a memory occupancy rate of 100%). Therefore, in the embodiment of the present application, the abnormal resource usage of the first network-side device can be used as a trigger condition for signaling storm detection.

[0066] The analysis function analyzes the target data and may also predict a signaling storm for the first network-side device. For example, the function may detect the number or ratio of historical and current failure messages for the first network-side device and predict trends, detect the number or ratio of historical and current unresponsive messages for the first network-side device and predict trends, predict the level of the signaling storm, the changing trend of the signaling storm, and predict the time when the signaling storm is likely to occur. In this case, the signaling storm analysis result is a signaling storm prediction result, which may include at least one of an identifier of the first network-side device that is about to experience a signaling storm and a cause of the signaling storm.

[0067] In an optional embodiment of the present application, signaling storm prediction can be achieved in the following manner: NWDAF analyzes historical data to learn that the proportion of rejected signaling for the first network-side device under normal circumstances is maintained at 2% at a certain capacity. NWDAF learns from historical signaling storm results (the administrator can label the signaling storm after it occurs) that when the proportion of rejected signaling exceeds 10%, it indicates that a signaling storm has occurred. NWDAF finds that the current proportion of rejected signaling has gradually increased from 2% to 4% and has an upward trend. NWDAF predicts that a signaling storm may occur in the first network-side device.

[0068] In an embodiment of the present application, the analysis function analyzes the signaling storm of the network side device according to the target data, and obtains the signaling storm analysis result of the first network side device, so that the network side signaling storm can be controlled according to the signaling storm analysis result, which can enhance the robustness of the network and is conducive to improving the working efficiency of the network side device.

[0069] Optionally, the cause of the signaling storm includes at least one of the following:

[0070] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0071] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0072] The signaling storm on the first network side device caused by the signaling sent by the network device may be caused by the following reasons:

[0073] 1. The first network-side device itself is abnormal. For example, the first network-side device itself experiences an abnormality, sending a large number of abnormal requests (such as duplicate messages, malformed messages, etc.) to other network-side devices and receiving replies from other network-side devices, resulting in a network signaling storm. Optionally, the abnormality of the first network-side device itself can also be expressed as a result of the first network-side device itself, such as abnormal behavior of the first network-side device and signaling looping on the first network-side device.

[0074] 2. Other network-side devices interacting with the first network-side device are abnormal. For example, other network-side devices accessing the first network-side device are in an abnormal state and continuously send abnormal messages (such as duplicate messages, malformed messages, etc.) to the first network-side device, resulting in a surge in message processing by the first network-side device. Optionally, the abnormality of other network-side devices interacting with the first network-side device can also be expressed as other network-side device reasons, other network-side device abnormalities, other network-side device behavior abnormalities, or other network-side device signaling loops.

[0075] Optionally, the signaling storm analysis result further includes at least one of the following:

[0076] The level of signaling storm;

[0077] The development trend of signaling storms;

[0078] Duration of the signaling storm;

[0079] Characteristic information of abnormal signaling;

[0080] an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device interacting with the first network-side device;

[0081] Feature information of the abnormal network-side device;

[0082] confidence level;

[0083] Prediction time.

[0084] The level of the signaling storm is used to indicate the severity of the signaling storm, and may be, for example, low, medium, or high.

[0085] The development trend of the signaling storm is used to indicate the possible subsequent trend of the signaling storm, for example, it can be rising, falling, unknown, stable, etc.

[0086] The duration of the signaling storm is used to indicate how long the signaling storm may last.

[0087] In the case where the signaling storm analysis result is a signaling storm prediction result, the signaling storm analysis result may further include a confidence level and a prediction time, wherein the confidence level indicates the accuracy of the signaling storm prediction result and the prediction time indicates the predicted time when a signaling storm may occur.

[0088] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0089] Abnormal signaling message;

[0090] The signaling type of the abnormal signaling;

[0091] The proportion of abnormal signaling in all signaling.

[0092] The abnormal signaling message indicates the signaling or message that caused the signaling storm on the network device. For example, if the first network device is a gNB, the abnormal signaling message may be AMF configure failure; or if the first network device is an AMF or SMF, the abnormal signaling message may be a 503 HTTP response message, etc.

[0093] The signaling type of abnormal signaling indicates the type of signaling that caused the signaling storm on the network device. For example, if the first network device is a gNB, the signaling type of abnormal signaling can be N2; or if the first network device is an AMF or SMF, the signaling type of abnormal signaling can be HTTP.

[0094] The identifier of the abnormal network side device is the network side device that interacts with the first network side device and is also the source of the signaling storm. It can be used to identify a single abnormal network side device or multiple abnormal network side devices.

[0095] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0096] abnormal behavior of the abnormal network side device;

[0097] The category of the abnormal network-side device.

[0098] The abnormal behavior of the abnormal network side device may include the abnormal network side device sending repeated signaling, sending malformed signaling, abnormally establishing context, and the like.

[0099] The category of the abnormal network side device is used to indicate the category of the network side device where the abnormality occurs, and can be identified by TA, AoI, S-NSSAAI, etc.

[0100] The level of the signaling storm, its development trend, the type of signaling causing the storm, the characteristics of abnormal signaling, the identification of abnormal network devices, and the characteristics of abnormal network devices can all be determined by analyzing the characteristic signaling and network device data, particularly the characteristics of signaling failures. The duration of the signaling storm can be determined by additional analysis of the time period.

[0101] In an optional embodiment of the present application, the analysis function acquires target data, including:

[0102] The analysis function obtains the first data from the second network side device.

[0103] The second network-side device includes at least one of the following:

[0104] the first network-side device;

[0105] A network-side device for managing the first network-side device.

[0106] In an embodiment of the present application, the analysis function can obtain the first data from the target of the signaling storm (that is, the first network side device in this application), or obtain the first data from the network side device used to manage the first network side device (that is, OAM), and use the obtained first data as the target data for analyzing the signaling storm.

[0107] The network side device used to manage the first network side device may be an Operation Administration Maintenance (OAM) device, or other devices or network elements used to manage the first network side device.

[0108] Optionally, the first data includes at least one of the following:

[0109] Signaling characteristic information of the first network side device; the signaling characteristic information is used to indicate at least one of a signaling failure characteristic and a signaling abnormality characteristic between the first network side device and other network side devices;

[0110] The network capacity information of the first network side device; the network capacity information is used to indicate the number of current network contexts of the first network side device.

[0111] Optionally, before the analysis function obtains the first data from the second network-side device, the method further includes:

[0112] The analysis function sends a first data collection request to the second network side device.

[0113] In an embodiment of the present application, the analysis function may obtain the first data of the first network side device by sending a first data collection request to the first network side device or OAM.

[0114] Exemplarily, the first data collection request may obtain the first data of the first network side device from the first network side device or OAM periodically or irregularly by calling a subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3).

[0115] For example, if the first network-side device is a gNB, the first data collection request can be implemented by calling a subscription notification model (Nnwdaf_AnalyticsSubscription_Subscribe) or a request-response model (Nnwdaf_AnalyticsInfo_Request). The former is based on a subscription-notification model, where the subscriber periodically or sporadically sends messages to the analytics function. The latter is based on a request-response model, where each request is responded to.

[0116] Alternatively, the first network side device is AMF or SMF, and the first data collection request can be achieved by calling the Event_Exposure event reporting service of NF. It can be based on a subscription-notification model, and the subscriber will send messages to NWDAF periodically or irregularly; it can also be based on a request-response model, with one request and one reply.

[0117] Optionally, in addition to collecting the first data of the first network-side device, the NWDAF may also collect data of other network-side devices connected to the first network-side device through this method.

[0118] In another optional embodiment of the present application, the analysis function acquires target data and further includes:

[0119] The analysis function obtains second data from a third network-side device.

[0120] The third network-side device includes at least one of the following:

[0121] a fourth network-side device accessing the first network-side device;

[0122] A network-side device for managing the fourth network-side device.

[0123] In an embodiment of the present application, the analysis function may further obtain the second data from a fourth network-side device, where the fourth network-side device is a network-side device that accesses the first network-side device. Alternatively, the analysis function may obtain the second data from a network-side device used to manage the fourth network-side device, and use the obtained second data as target data for analyzing the signaling storm. Optionally, the network-side device used to manage the fourth network-side device includes an OAM.

[0124] Optionally, when the first network-side device includes an access network device, the fourth network-side device includes another access network device other than the first network-side device, or the fourth network-side device includes a core network device. For example, if the first network-side device is a gNB, the fourth network-side device may be another gNB connected to the first network-side device, or an AMF.

[0125] When the first network-side device includes a core network device, and when the fourth network-side device includes a core network device, the fourth network-side device includes at least one of other core network devices, access network devices, and other network functions other than the first network-side device. For example, if the first network-side device is an AMF or SMF, the fourth network-side device may be a gNB, AUSF, UDM, PCF, SBA NF, UPF, etc. connected to the first network-side device.

[0126] The network-side device used to manage the fourth network-side device may be an OAM, or other devices or network elements used to manage the fourth network-side device.

[0127] Optionally, the second data includes at least one of the following:

[0128] Signaling characteristic information of the fourth network side device; the signaling characteristic information is used to indicate at least one of a signaling failure characteristic and a signaling abnormality characteristic between the fourth network side device and the first network side device;

[0129] The network capacity information of the fourth network side device; the network capacity information is used to indicate the number of current network contexts of the fourth network side device.

[0130] Optionally, before the analysis function obtains the first data from the third network-side device, the method further includes:

[0131] The analysis function sends a second data collection request to the third network-side device.

[0132] In an embodiment of the present application, the analysis function may obtain the second data of the fourth network side device by sending a second data collection request to the fourth network side device or OAM.

[0133] Exemplarily, the second data collection request may obtain the second data of the fourth network side device from the fourth network side device or OAM periodically or irregularly by calling a subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3).

[0134] For example, if the first network-side device is a gNB, the fourth network-side device is an AMF, and the third network-side device is an AMF or OAM, then if the second data is collected from the AMF, the second data collection request can be made by invoking the Event_Exposure event reporting service of a different NF. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, with one request and one reply. If the second data is collected from the OAM, the second data collection request can be made by invoking the subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3) to obtain data from the OAM periodically or irregularly.

[0135] Alternatively, the first network-side device is an AMF or SMF, the fourth network-side device is a source NF, and the third network-side device is a source NF or OAM. If the second data is collected from the source NF, the second data collection request can be made by calling the Event_Exposure event reporting service of different NFs. Based on the subscription-notification mode, the subscriber will periodically or irregularly send a message to the NWDAF. It can also be based on a request-response mode, with one request and one reply. If the second data is collected from OAM, the second data collection request can obtain data from OAM periodically or irregularly by calling the subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0136] Optionally, the NWDAF may select the NF to which the first network-side device (target NF) is connected to send the second data collection request.

[0137] Optionally, the signaling characteristic information includes at least one of the following:

[0138] Number of signaling failure messages;

[0139] The number of all signaling;

[0140] The proportion of signaling failure messages in all signaling;

[0141] The number of unanswered request signals;

[0142] The proportion of unresponsive request signals in all request signals;

[0143] The number of repeated signaling messages;

[0144] The proportion of repeated signaling messages in all signaling;

[0145] The number of malformed signaling messages;

[0146] The proportion of malformed signaling messages in all signaling messages;

[0147] The number of resource allocation messages;

[0148] The proportion of resource allocation messages in all signaling.

[0149] It should be noted that the first data in this application includes at least one of the signaling characteristic information and network capacity information of the first network side device.

[0150] Referring to Table 1, there are shown protocols corresponding to signaling interactions between different types of target network side devices and different types of source network side devices.

[0151] Table 1

[0152] The target network-side device is the target of the signaling storm, that is, the first network-side device in the embodiment of the present application, and the source network-side device is the source of the signaling storm, that is, the abnormal network-side device in the embodiment of the present application. The network-side device signaling storm in the embodiment of the present application can be caused by a large amount of network signaling generated during the interaction between the target network-side device and the source network-side device based on the protocol shown in Table 1, and can specifically be caused by at least one abnormality in the target network-side device and the source network-side device.

[0153] It should be noted that the characteristic of a network-side device suffering from a signaling storm is that the network-side device is in a state of abnormal resource usage. The action of the network-side device may be to continuously reject requests from other network-side devices, thereby causing a large number of rejection messages to reject requests from other network-side devices, or not processing / discarding requests from other network-side devices, resulting in an increase in the proportion of unresponsive request messages.

[0154] As an example, the first network side device is the target gNB, and the fourth network side device accessing the first network side device is at least one of the source gNB and the AMF. The signaling characteristic information in the first data may include at least one of the number of signaling failure messages between the target gNB and a source gNB and the AMF, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of malformed signaling messages, the proportion of malformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0155] It is understood that signaling between gNBs is Xn signaling. Exemplarily, Xn signaling failure messages may include Handover Preparation Failure, Retrieve UE context Failure, S-node Addition / modification Request Reject, Xn Setup Failure, etc., and Xn request signaling may include Handover Preparation Request, Retrieve UE context Request, S-node Addition / modification Request, Xn Setup Request, etc. Xn resource allocation messages may include Handover Request, S-node Addition Request, Xn Setup Request, etc.

[0156] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the gNB is the target network side device and the AMF is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the AMF is rejected by the gNB. The N2 request message specifically refers to the downlink N2 signaling request sent by the AMF. The N2 resource allocation message specifically refers to the message that the AMF requests the gNB to generate a context. Exemplarily, the N2 signaling failure message may include Initial Context Setup Failure, UE Context Modification Failure, AMF configure Failure, Retrieve UE context Failure, Handover Failure, Broadcast Session Setup / modification Failure, etc., and the N2 request message may include Initial Context Setup Request, UE Context Modification Request, AMF configure Request, Retrieve UE context Request, Handover Request, Broadcast Session Setup / modification Request. The N2 resource allocation message may include Initial Context Setup Request, AMF configure Request, Broadcast Session Setup / modification Request, etc.

[0157] As another example, the first network side device is AMF, and the fourth network side device accessing the first network side device is gNB and at least one of other NFs. The signaling characteristic information in the first data may include at least one of the number of signaling failure messages between the AMF and gNB and other NFs, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of malformed signaling messages, the proportion of malformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0158] It can be understood that the signaling between gNB and AMF is N2 signaling. Especially for the scenario where AMF is the target network side device and gNB is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by gNB is rejected by AMF, the N2 request message specifically refers to the uplink N2 signaling request sent by gNB, and the N2 resource allocation message specifically refers to the message that gNB requests AMF to generate a context. Illustratively, the N2 signaling failure message may include Handover Preparation Failure, Path Switch Failure, NG setup Failure, RAN Configuration Failure, UE Context Suspend / Resume Failure, MT Communication Handling Failure, etc., and the N2 request message may include Handover Request, Path Switch Request, NG setup Request, RAN Configuration Update, UE Context Suspend / Resume Request, MT Communication Handling Request, etc. The N2 resource allocation message may include Handover Request, NG setup Request, RAN Configuration Update, etc.

[0159] The signaling between the AMF and other NFs (e.g., SMF, AUSF, UDM, PCF, etc.) is Service-Based Architecture (SBA) signaling, which is carried on HTTP messages. For example, an SBA signaling failure message can be reflected by the response value of an HTTP Response, such as a response value in the 40x or 50x series. Pay special attention to 429 (Client Sends Too Many Requests) and 503 (Service Unavailable). For example, an SBA signaling request message can be judged using the HTTP GET or POST method. SBA resource allocation messages can include messages such as Nnrf_Register requesting the NF to establish a context.

[0160] As another example, the first network side device is SMF, and the fourth network side device accessing the first network side device is UPF and at least one of other NFs. The signaling characteristic information in the first data may include at least one of the number of signaling failure messages between SMF and UPF and other NFs, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of deformed signaling messages, the proportion of deformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0161] It is understandable that the signaling between the SMF and the UPF is N4 signaling, which is also above the PFCP protocol message. Exemplarily, the PFCP signaling failure message may include a PFCP Heartbeat Response with a rejection cause value, a PFCP PFD Management Response, or a PFCP Association Setup / Update / Release Response message. The PFCP signaling request message may include a PFCP Heartbeat Request, a PFCP PFD Management Request, or a PFCP Association Setup / Update / Release Request message.

[0162] The signaling storm occurring in the first network side device may cause a large number of rejection messages to reject the request of the fourth network side device, or not process / discard its request, resulting in an increase in the proportion of unresponsive request messages. Therefore, the characteristic information of the above signaling failure can reflect the characteristics of the signaling storm.

[0163] The signaling sent by the abnormal network side device may have some signaling characteristics, such as repeated signaling, deformed signaling, and a large number of requested resources. Therefore, the characteristic information of the above signaling anomaly can be used to infer whether it is caused by an abnormality of other network side devices other than the first network side device.

[0164] Optionally, the signaling characteristic information further includes at least one of the following:

[0165] an identifier of the first network-side device;

[0166] Category of the first network-side device;

[0167] Time period information.

[0168] In some optional embodiments of the present application, the first data may only count the signaling of the first network side device, and the signaling characteristic information may include at least one of the identification and category of the first network side device and time period information.

[0169] The time period information is used to indicate the time period for collecting signaling feature data.

[0170] Exemplarily, the identifier of the first network side device can be a cell ID, NF instance ID, TA ID, AoI ID, S-NSSAI ID, etc.; the category of the first network side device can be identified by TA, AoI, S-NSSAAI, NF type, TA, AoI, S-NSSAI, etc.

[0171] For example, the signaling characteristic data may be expressed as "cell ID1 (2.20:00-2.312:00, S-NSSAI1): number of Xn signaling failure messages: 200, number of all Xn signalings: 11000; number of N2 signaling failure messages: 1800, number of all N2 signalings: 12000; ..."

[0172] Optionally, the signaling characteristic information includes at least one of the following:

[0173] The identifier of the fourth network-side device;

[0174] Category of the fourth network-side device;

[0175] Time period information.

[0176] In some optional embodiments of the present application, the second data may only count the signaling of the fourth network side device, and the signaling characteristic information may include at least one of the identification and category of the fourth network side device.

[0177] Exemplarily, the identifier of the fourth network side device can be a cell ID, NF instance ID, TA ID, AoI ID, S-NSSAI ID, etc.; the category of the fourth network side device can be identified by TA, AoI, S-NSSAAI, NF type, TA, AoI, S-NSSAI, etc.

[0178] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.20:00-2.312:00, S-NSSAI1): Number of N2 signaling failure messages: 1200, number of all N2 signaling messages: 15000..."

[0179] In another optional embodiment of the present application, more fine-grained statistics may be performed on the signaling feature information, for example, statistics may be collected on the signaling received by the first network side device from different fourth network side devices (eg, NF1, NF2, NF3, ...).

[0180] In another optional embodiment of the present application, the signaling characteristic information of the first data may further include at least one of an identifier and a category of each fourth network-side device accessing the first network-side device.

[0181] For example, assuming that the first network side device is SMF1, the fourth network side device is AMF1, and the other network side device is AMF2, the signaling characteristic data of the first data can be expressed in the form of "SMF ID1 (2.20:00-2.312:00, S-NSSAI1): AMF ID1 (2.20:00-2.3S-NSSAI1): Number of SBA signaling failure messages: 120, number of all SBA signalings: 12340; SMF ID1: AMF ID2 (S-NSSAI2): Number of SBA signaling failure messages: 1500, number of all SBA signalings: 16660;..."

[0182] In another optional embodiment of the present application, the signaling characteristic information of the second data may further include at least one of an identifier and a category of the fourth network side device accessing the first network side device.

[0183] For example, assuming that the first network side device is SMF1 and the fourth network side device is AMF1, the signaling characteristic data of the fourth data can be expressed in the form of "AMF ID1 (2.20:00-2.312:00, S-NSSAI1): SMF ID1 (S-NSSAI1): Number of SBA signaling failure messages: 145, number of all SBA signaling: 12340".

[0184] It should be noted that, when the signaling characteristic information includes the identifier of the fourth network-side device, the specific abnormal network-side device can be located.

[0185] Optionally, the network capacity information includes at least one of the following:

[0186] The number of terminal contexts;

[0187] The number of connected contexts.

[0188] In the first data, the terminal context refers to the context generated by the terminal served by the first network side device, and the connection context refers to the context of the connection between the first network side device and the fourth network side device.

[0189] As an example, the first network side device is a gNB, and the network capacity information of the gNB is used to indicate the number of current network contexts of the gNB. This can be expressed as the number of all N2 or Xn contexts generated by UEs served by one or a group of gNBs (e.g., one TA or one Area of ​​Interest), or the context of connections between network elements.

[0190] As another example, the first network side device is a target NF (e.g., an AMF or SMF), and the network capacity information of the target NF is used to indicate the number of current network contexts of the NF. This can be expressed as the number of all N2 or SBA or PFCP contexts generated by UEs served under one or a group of NFs (e.g., under one TA or one Area of ​​Interest), or as the context of connections between network elements.

[0191] In the second data, the terminal context refers to the context generated by the terminal served by the fourth network side device, and the connection context refers to the context of the connection between the fourth network side device and the first network side device.

[0192] As an example, the fourth network side device is a gNB, and the network capacity information of the gNB is used to indicate the number of current network contexts of the gNB. This can be expressed as the number of all N2 or Xn contexts generated by UEs served by one or a group of gNBs (e.g., one TA or one Area of ​​Interest), or the context of connections between network elements.

[0193] As another example, the fourth network side device is a target NF (e.g., an AMF or SMF), and the network capacity information of the target NF is used to indicate the number of current network contexts of the NF. The expression can be the number of all N2 or SBA or PFCP contexts generated by the UE served under one / a group of NFs (e.g., under one TA or one Area of ​​Interest), or the context of the connection between network elements.

[0194] The network capacity information of the first network side device can be used to infer the cause of the signaling storm. For example, when the number of terminal contexts of the first network side device is small but the communication is large, the signaling storm may be caused by a network element abnormality.

[0195] The second data in this application includes at least one of signaling feature information and network capacity information of the fourth network side device.

[0196] As an example, the first network side device is the target gNB, and the fourth network side device accessing the first network side device is the AMF. The signaling characteristic information in the second data may include at least one of the number of signaling failure messages between the AMF and the target gNB, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of malformed signaling messages, the proportion of malformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0197] The network capacity information of the AMF is used to indicate the number of network contexts currently in use by the AMF. This information can be expressed as the number of all N2 contexts generated for UEs served by one or a group of AMFs (e.g., one TA or one Area of ​​Interest), or the number of contexts for the connection between the target gNB and the AMF.

[0198] As another example, the first network side device is the target NF, and the fourth network side device accessing the first network side device is the source NF. The signaling characteristic information in the second data may include at least one of the number of signaling failure messages between the source NF and the target NF, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of deformed signaling messages, the proportion of deformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0199] The network capacity information of the source NF is used to indicate the number of network contexts currently in the source NF. This information can be expressed as the number of all N2, SBA, or PFCP contexts generated for UEs served by a source NF or a group of source NFs (e.g., a TA or an Area of ​​Interest), or as the number of contexts for connections between network elements.

[0200] The signaling characteristic data and capacity information contained in the second data may also refer to the relevant description of the signaling characteristic data and capacity information of the first data, which will not be repeated here.

[0201] Optionally, the analyzing function obtains the second data from the third network-side device, including:

[0202] The analysis function obtains the second data from the third network side device according to the identifier of the fourth network side device in the first data.

[0203] When the signaling characteristic information includes the identifier of the fourth network-side device, the analysis function may trigger, based on the identifier of the fourth network-side device included in the first data, the acquisition of the second data of the fourth network-side device from the third network-side device, so as to analyze the signaling characteristic information and network capacity information of a specific fourth network-side device and locate the specific abnormal network-side device. The third network-side device is the fourth network-side device, or a network-side device for managing the fourth network-side device, such as an OAM.

[0204] In an optional embodiment of the present application, the analysis function sends a first data collection request to the second network side device, including:

[0205] Upon receiving the first analysis request sent by the control function, the analysis function sends a first data collection request to the second network-side device.

[0206] The first analysis request is used to request a signaling storm analysis to be performed on the first network-side device.

[0207] It should be noted that the control function in this application can trigger the analysis function to perform signaling storm analysis on the first network side device by sending a first analysis request. The control function can be a network function consumer (NF consumer), and the network function consumer can be, for example, a network function such as AMF, PCF, or OAM.

[0208] Optionally, the first analysis request includes at least one of the following:

[0209] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0210] an analysis target, where the analysis target is used to indicate the first network-side device;

[0211] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0212] Among them, the analysis identifier is used to indicate the current analysis, that is, signaling storm analysis. The analysis target is used to indicate the object for which the analysis is directed. The analysis target can be information that identifies one or a group of first network side devices. For example, when the first network side device is a base station, the analysis target can be a cell identifier (Cell ID), a tracking area (TA) ID, an area of ​​interest (Area of ​​Interest), etc.; when the first network side device is an NF, the analysis target can be information that identifies one or a group of NFs, such as NF instance ID, TA ID, Area of ​​Interest, etc. The analysis time may include at least one of the start time and the end time of the analysis. The analysis period may also be a periodic time, that is, the analysis is a periodic analysis. The analysis period will affect the setting of the time period in the signaling feature data.

[0213] Optionally, the method further includes:

[0214] Upon receiving the second analysis request sent by the control function, the analysis function sends the network performance analysis result of the first network-side device to the analysis function.

[0215] The network performance analysis result is used to indicate resource usage of the first network side device.

[0216] In an embodiment of the present application, the control function may request the analysis function to analyze the network performance of the first network-side device in advance (see 3GPP TS 23.288 6.6), thereby obtaining the resource usage of the first network-side device. The control function may trigger a signaling storm analysis for the first network-side device or the group of first network-side devices based on the resource usage. For example, if the resource usage of the first network-side device exceeds a certain threshold (CPU usage is greater than 90%), a first analysis request is sent to the analysis function, requesting the analysis function to perform a signaling storm analysis on the first network-side device.

[0217] It should be noted that the second analysis request can be implemented by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former is based on a subscription-notification model, where the subscriber (analysis function) will periodically or sporadically send messages to the control function. The latter is based on a request-response model, with a response per request.

[0218] Optionally, the method further includes:

[0219] The analysis function sends the signaling storm analysis result to the control function.

[0220] After performing signaling storm analysis on the first network side device, the analysis function may send the signaling storm analysis result to the control function so that the control function performs a signaling storm control operation according to the signaling storm analysis result to enhance the robustness of the network.

[0221] Optionally, the target data includes: current target data and historical target data; the analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device, including:

[0222] The analysis function obtains a signaling storm analysis model based on the historical target data;

[0223] The analysis function performs analysis based on the signaling storm analysis model and the current target data to obtain a signaling storm analysis result of the first network side device.

[0224] In an embodiment of the present application, a signaling storm analysis model can be trained based on historical target data. When signaling storm analysis is required, the current target data is input into the trained signaling storm analysis model for inference to obtain a signaling storm analysis result.

[0225] It is understandable that the signaling storm analysis model can be obtained through machine learning, which can be lightweight machine learning, unsupervised learning, or supervised learning. This application does not limit the specific machine learning method.

[0226] It should be noted that the signaling storm analysis model can be updated as needed, for example, periodically updated according to the most recent historical target data.

[0227] Optionally, if the signaling storm analysis is a signaling storm prediction, the signaling storm analysis result may further include at least one of the following: the confidence of the current prediction (Confidence, also called confidence, used to indicate the certainty of the prediction) and the expected time (used to indicate the time when the signaling storm is predicted to occur).

[0228] Since the signaling storm analysis model is trained based on historical target data, it can be understood as the rules generated by a large amount of historical target data. Therefore, when the current target data shows a trend that conforms to this rule, the signaling storm can be predicted, and the confidence and prediction time of the prediction can also be obtained.

[0229] 3, a flow chart of another method for handling a signaling storm provided by an embodiment of the present application is shown. The method is applied to a control function, as shown in FIG3, and the method may specifically include:

[0230] Step 201: The control function receives the signaling storm analysis result sent by the analysis function;

[0231] Step 202: The control function performs a signaling storm control operation according to the signaling storm analysis result.

[0232] The signaling storm analysis result includes at least one of the following:

[0233] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0234] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0235] It should be noted that in the embodiment of the present application, the control function may be a network function consumer, and the network function consumer may be, for example, a network function such as AMF, PCF, NRF or OAM.

[0236] The analysis function may be NWDAF, which can collect various data generated in the network and perform intelligent data analysis, and finally generate corresponding data analysis results to detect or predict various events occurring in the network. Of course, the analysis function may also be other devices or network elements that can collect target data and perform data analysis, such as OAM, or external security functions (such as firewalls, intrusion detection systems, intrusion prevention systems, etc.), and this application does not limit this. For example, the analysis function in this application may be a communication device configured with an AI model, which is trained to implement a network data analysis function.

[0237] The first network side device is a target device of the signaling storm, which can be understood as a target device that is suffering from a signaling storm, or a target device that is predicted to suffer from a signaling storm through an analysis function. The identifier of the first network side device can identify a single network side device. For example, the identifier of the first network side device can be a cell identifier (cell ID), an NF instance ID, and so on; the identifier of the first network side device can also identify a group or multiple network side devices, such as through a tracking area (TA), an area of ​​interest (AoI), a single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI) and other identifiers.

[0238] In an optional embodiment of the present application, the first network side device may be an access network device, such as a base station (gNB), a wireless local area network (WLAN) access point, etc.; the first network side device may also be a core network device, such as an AMF or SMF, etc., which is a network function (NF) that performs signaling interaction with other network side devices or terminals.

[0239] A network-side device signaling storm refers to a signaling storm caused by network-side signaling. This is because other network-side devices send a large amount of signaling to the first network-side device, causing the signaling received by the first network-side device to exceed its processing limit. The first network-side device needs to consume a large amount of resources to process these signalings, which in turn causes the first network-side device to be unable to work or to maintain operation at a lower efficiency.

[0240] In an embodiment of the present application, the control function may receive a signaling storm analysis result from the analysis function. Optionally, the analysis function may perform a signaling storm analysis based on the target data, obtain a signaling storm analysis result, and send the signaling storm analysis result to the control function. After receiving the signaling storm analysis result, the control function performs a signaling storm analysis control operation based on the signaling storm analysis result to enhance network robustness.

[0241] It should be noted that signaling storm analysis may be signaling storm detection, for example, detecting the number or ratio of failed messages currently sent by the first network-side device, detecting the number or ratio of unresponsive messages currently sent by the first network-side device, detecting the level of the signaling storm, or detecting the trend of the signaling storm, etc. In this case, the signaling storm analysis result is a signaling storm detection result, which may include at least one of an identifier of the first network-side device experiencing the signaling storm and a cause of the signaling storm.

[0242] Alternatively, signaling storm analysis can also be signaling storm prediction, for example, detecting the number or ratio of historical and current failure messages of the first network-side device and predicting the trend, detecting the number or ratio of historical and current unresponsive messages of the first network-side device and predicting the trend, predicting the level of the signaling storm, the changing trend of the signaling storm, predicting the time when the signaling storm is likely to occur, etc. In this case, the signaling storm analysis result is a signaling storm prediction result, which can include at least one of the identification of the first network-side device that is about to experience a signaling storm and the cause of the signaling storm.

[0243] Optionally, the cause of the signaling storm includes at least one of the following:

[0244] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0245] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0246] The signaling storm on the first network side device caused by the signaling sent by the network device may be caused by the following reasons:

[0247] 1. The first network-side device itself is abnormal. For example, the first network-side device itself experiences an abnormality, sending a large number of abnormal requests (such as duplicate messages, malformed messages, etc.) to other network-side devices and receiving replies from other network-side devices, resulting in a network signaling storm. Optionally, the abnormality of the first network-side device itself can also be expressed as a result of the first network-side device itself, such as abnormal behavior of the first network-side device and signaling looping on the first network-side device.

[0248] 2. Other network-side devices interacting with the first network-side device are abnormal. For example, other network-side devices accessing the first network-side device are in an abnormal state and continuously send abnormal messages (such as duplicate messages, malformed messages, etc.) to the first network-side device, resulting in a surge in message processing by the first network-side device. Optionally, the abnormality of other network-side devices interacting with the first network-side device can also be expressed as other network-side device reasons, other network-side device abnormalities, other network-side device behavior abnormalities, or other network-side device signaling loops.

[0249] Optionally, the signaling storm analysis result further includes at least one of the following:

[0250] The level of signaling storm;

[0251] The development trend of signaling storms;

[0252] Duration of the signaling storm;

[0253] Characteristic information of abnormal signaling;

[0254] Identification of abnormal network-side devices;

[0255] Feature information of the abnormal network-side device;

[0256] confidence level;

[0257] Prediction time.

[0258] The level of the signaling storm is used to indicate the severity of the signaling storm, and may be, for example, low, medium, or high.

[0259] The development trend of the signaling storm is used to indicate the possible subsequent trend of the signaling storm, for example, it can be rising, falling, unknown, stable, etc.

[0260] The duration of the signaling storm is used to indicate how long the signaling storm may last.

[0261] The control function can determine what control measures to take based on one or more of the signaling storm's level, development trend, and duration, such as a milder control measure like capacity expansion or a more aggressive control measure like isolation.

[0262] For example, if the level is low and the development trend is stable, the control function may take a mild control measure. If the level is high and the development trend is rising, and the duration indicates that it may last for a long time, the control function may take a more aggressive control measure.

[0263] The level, development trend, and duration of the signaling storm can help the control function determine the overall impact of the current signaling storm on the network, thereby serving as a judgment factor to influence the final control measures.

[0264] The level and trend of the signaling storm, the type of signaling involved, the characteristics of abnormal signaling, and the characteristics of abnormal network devices can all be determined by analyzing the characteristic data of signaling and network devices, especially the characteristics of signaling failures. The duration of the signaling storm can be determined by additional analysis of the time period.

[0265] In the case where the signaling storm analysis result is a signaling storm prediction result, the signaling storm analysis result may further include a confidence level and a prediction time, wherein the confidence level indicates the accuracy of the signaling storm prediction result and the prediction time indicates the predicted time when a signaling storm may occur.

[0266] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0267] Abnormal signaling message;

[0268] The signaling type of the abnormal signaling;

[0269] The proportion of abnormal signaling in all signaling.

[0270] The abnormal signaling message indicates the signaling or message that caused the signaling storm on the network device. For example, if the first network device is a gNB, the abnormal signaling message may be AMF configure failure; or if the first network device is an AMF or SMF, the abnormal signaling message may be a 503 HTTP response message, etc.

[0271] The signaling type of abnormal signaling indicates the type of signaling that caused the signaling storm on the network device. For example, if the first network device is a gNB, the signaling type of abnormal signaling can be N2; or if the first network device is an AMF or SMF, the signaling type of abnormal signaling can be HTTP.

[0272] The control function can record the characteristic information of abnormal signaling to help administrators conduct subsequent tracking and investigation when encountering unknown signaling storms.

[0273] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0274] abnormal behavior of the abnormal network side device;

[0275] The category of the abnormal network-side device.

[0276] The abnormal behavior of the abnormal network side device may include the abnormal network side device sending repeated signaling, sending malformed signaling, abnormally establishing context, and the like.

[0277] The category of the abnormal network side device is used to indicate the category of the network side device where the abnormality occurs, and can be identified by TA, AoI, S-NSSAAI, etc.

[0278] The level of the signaling storm, its development trend, the type of signaling causing the storm, the characteristics of abnormal signaling, the identification of abnormal network devices, and the characteristics of abnormal network devices can all be determined by analyzing the characteristic signaling and network device data, particularly the characteristics of signaling failures. The duration of the signaling storm can be determined by additional analysis of the time period.

[0279] The control function can determine which control method to take based on the characteristic information of abnormal network-side devices, for example, whether to control in a group manner or in a single point manner.

[0280] For example, if the abnormal behavior of the abnormal network side device is abnormal context establishment, the control function can adopt an isolation control method. If the abnormal network side devices are of the same category, the control function can adopt a group control method.

[0281] The characteristic information of the abnormal network-side device can help the control function determine the behavior or common characteristics of the abnormal network-side device, thereby serving as a judgment factor to influence the final control measures.

[0282] In some optional embodiments of the present application, before the control function receives the signaling storm analysis result sent by the analysis function, the method further includes:

[0283] The control function sends a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

[0284] The control function may trigger the analysis function to perform signaling storm analysis on the first network side device by sending a first analysis request.

[0285] Optionally, the first analysis request includes at least one of the following:

[0286] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0287] an analysis target, where the analysis target is used to indicate the first network-side device;

[0288] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0289] Among them, the analysis identifier is used to indicate the current analysis, that is, signaling storm analysis. The analysis target is used to indicate the object for which the analysis is directed. The analysis target can be information that identifies one or a group of first network side devices. For example, when the first network side device is a base station, the analysis target can be a cell identifier (Cell ID), a tracking area (TA) ID, an area of ​​interest (Area of ​​Interest), etc.; when the first network side device is an NF, the analysis target can be information that identifies one or a group of NFs, such as NF instance ID, TA ID, Area of ​​Interest, etc. The analysis period can include at least one of the start time and end time of the analysis. The analysis period can also be a periodic time, that is, the analysis is a periodic analysis.

[0290] Optionally, the control function sends a first analysis request to the analysis function, including:

[0291] The control function obtains a network performance analysis result of the first network side device;

[0292] When the network performance analysis result indicates that resource usage of the first network-side device is in an abnormal state, the control function sends the first analysis request to the analysis function.

[0293] In an embodiment of the present application, the control function may obtain the network performance analysis result of the first network side device in advance, and the network performance analysis result is used to indicate the resource usage of the first network side device. The control function may send a first analysis request to the analysis function when the network performance analysis result indicates that the resource usage of the first network side device is in an abnormal state, triggering the analysis function to perform a signaling storm analysis on this or this group of first network side devices. For example, if the resource usage of the first network side device exceeds a certain threshold (CPU usage is greater than 90%), it can be considered that the resource usage of the first network side device is in an abnormal state, and the control function will be triggered to send a first analysis request to the analysis function, requesting the analysis function to perform a signaling storm analysis on the first network side device.

[0294] Optionally, the control function obtains a network performance analysis result of the first network-side device, including:

[0295] The control function sends a second analysis request to the analysis function, where the second analysis request is used to request analysis of network performance of the first network-side device;

[0296] The control function receives the network performance analysis result of the first network side device sent by the analysis function.

[0297] In an embodiment of the present application, the control function may request the analysis function to analyze the network performance of the first network side device (see 3GPP TS 23.288 6.6) through a second analysis request, thereby obtaining the network performance analysis result of the first network side device.

[0298] It should be noted that the second analysis request can be implemented by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former is based on a subscription-notification model, where the subscriber (analysis function) will periodically or sporadically send messages to the control function. The latter is based on a request-response model, with a response per request.

[0299] In the embodiment of the present application, mitigation measures can be taken for signaling storm detection, and defensive measures can be taken for signaling storm prediction.

[0300] The mitigation and protection of signaling storms are collectively referred to as signaling storm control operations. The following examples illustrate signaling storm control operations.

[0301] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0302] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the local policy of the control function for the first network side device according to the identification of the first network side device, so that the first network side device cannot be discovered.

[0303] The control function in the embodiment of the present application may be a network storage function (NF Repository Function, NRF), which is used to register, manage, and detect the status of NFs to achieve automated management of all NFs. When each NF is started, it must register with the NRF to provide services. The registration information may include the type, address, service list, etc. of the NF. In the embodiment of the present application, when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the NRF may modify the local policy for the first network side device in the NRF according to the identifier of the first network side device, so that the first network side device cannot be discovered by other network side devices. Optionally, the first network side device may temporarily be unable to discover other network side devices, thereby isolating the abnormal first network side device and reducing the interaction between the first network side device and other network side devices. The local policy may be an access control list, and the NRF sets the first network side device to be non-actively discoverable and / or non-discoverable in the access control list.

[0304] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0305] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the local policy of the control function for the abnormal network side device according to the identification of the abnormal network side device, so that the abnormal network side device cannot be discovered.

[0306] The control function in the embodiment of the present application may be an NRF. When the cause of the signaling storm indicates that the signaling storm is caused by network-side devices other than the first network-side device, the NRF may modify the local policy for the abnormal network-side device in the NRF according to the identifier of the abnormal network-side device, so that the abnormal network-side device cannot be discovered by other network-side devices. Optionally, the abnormal network-side device may temporarily not choose to discover other network-side devices, thereby isolating the abnormal network-side device and reducing the interaction between the abnormal network-side device and other network-side devices. The local policy may be an access control list, and the NRF may set the abnormal network-side device to be non-actively discoverable and / or non-discoverable in the access control list.

[0307] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0308] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the first slice information of the first network side device to second slice information according to the identifier of the first network side device, and the first slice information is different from the second slice information.

[0309] In the embodiment of the present application, the control function may be OAM or NRF. For example, when the first network-side device is the target gNB, if the cause of the signaling storm indicates that the signaling storm is caused by an abnormality of the target gNB itself, the control function may be OAM. OAM may modify the slice information to which the target gNB belongs based on the identifier of the target gNB, placing the target gNB in ​​an isolated slice, thereby preventing other network-side devices (such as other gNBs or AMF) from selecting the target gNB for access, thereby reducing signaling interaction between the target gNB and other network-side devices.

[0310] In the case where the first network side device is the target NF, if the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the target NF itself, the control function can be OAM or NRF. The control function can modify the slice information to which the target NF belongs according to the identifier of the target NF, and place the target NF in an isolated slice, so that other network side devices (such as other NFs or gNBs) do not select the target NF for access, thereby reducing the signaling interaction between the target NF and other network side devices.

[0311] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0312] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the third slice information of the abnormal network side device to the fourth slice information according to the identification of the abnormal network side device, and the third slice information is different from the fourth slice information.

[0313] In an embodiment of the present application, the control function may be OAM or NRF. For example, when the first network-side device is the target gNB, if the cause of the signaling storm indicates that the network-side device signaling storm is caused by other network-side devices other than the first network-side device (e.g., other gNBs or AMFs), the control function may be OAM, and OAM may modify the slice information to which the abnormal network-side device belongs based on the identifier of the abnormal network-side device, and place the abnormal network-side device in an isolated slice, so that other network-side devices (e.g., other gNBs or AMFs) do not select the abnormal network-side device for access, thereby reducing signaling interaction between the abnormal network-side device and other network-side devices.

[0314] In the case where the first network side device is the target NF, if the cause of the signaling storm indicates that the network side device signaling storm is caused by other NFs other than the target NF, the control function may be OAM or NRF. The control function may modify the slice information to which the abnormal NF belongs according to the identifier of the abnormal NF, and place the abnormal NF in an isolated slice, so that other network side devices (such as other NFs or gNBs) do not select the abnormal NF for access, thereby reducing the signaling interaction between the abnormal NF and other network side devices.

[0315] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0316] When the cause of the signaling storm indicates that the network-side device signaling storm is caused by an abnormality of the first network-side device itself, the control function notifies the first network-side device to release connections with all other network-side devices.

[0317] In this embodiment of the present application, the control function may be an OAM or an AMF. For example, when the first network-side device is a target gNB, if the cause of the signaling storm indicates that the signaling storm is caused by an abnormality in the target gNB itself, the OAM may notify the target gNB to release connections with other NFs, thereby reducing signaling interactions between the abnormal target gNB and other NFs; alternatively, the AMF may release the N2 interface with the target gNB, thereby reducing signaling interactions between the AMF and the abnormal target gNB.

[0318] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0319] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the first network side device to release the connection with the abnormal network side device.

[0320] In this embodiment of the present application, the control function may be an OAM or an AMF. For example, when the first network-side device is a target gNB, the cause of the signaling storm indicates that the signaling storm is caused by a network-side device other than the target gNB. The control function may be OAM. If the abnormal network-side device includes a gNB, OAM may notify the target gNB to release the Xn connection with the abnormal gNB based on the identifier of the abnormal gNB. If the abnormal network-side device includes an AMF, OAM may notify the target gNB to release the N2 connection with the abnormal AMF.

[0321] In the case where the first network side device is the target NF, the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormal gNB other than the target NF. The control function may be an AMF, and the AMF may notify the target NF to release the N2 interface between the target NF and the abnormal gNB.

[0322] The embodiment of the present application reduces the signaling interaction between the first network side device and the abnormal network side device by releasing the connection between the first network side device and the abnormal network side device.

[0323] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0324] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the abnormal network side device to release the connection with the first network side device.

[0325] In this embodiment of the present application, the control function may be an OAM or an AMF. For example, when the first network-side device is a target gNB, the cause of the signaling storm indicates that the signaling storm is caused by a network-side device other than the target gNB. The control function may be OAM. If the abnormal network-side device includes a gNB, OAM may notify the abnormal gNB to release the Xn connection with the target gNB based on the abnormal gNB identifier. If the abnormal network-side device includes an AMF, OAM may notify the abnormal AMF to release the N2 connection with the target gNB.

[0326] In the case where the first network side device is the target NF, the cause of the signaling storm indicates that the signaling storm is caused by an abnormal gNB other than the target NF. The control function may be an AMF, and the AMF may notify the abnormal gNB to release the N2 interface between the abnormal gNB and the target NF.

[0327] The embodiment of the present application reduces the signaling interaction between the first network side device and the abnormal network side device by releasing the connection between the abnormal network side device and the first network side device.

[0328] Optionally, after releasing the connection between the abnormal network side device and the first network side device, the control function may also prevent subsequent connections between the abnormal network side device and other network side devices.

[0329] The following is an example of the method for processing a signaling storm provided in the embodiment of the present application, with reference to a specific application scenario.

[0330] As an example, a gNB (i.e., the first network-side device in this application is a gNB) is detected to determine whether it is under a signaling attack. Referring to FIG4 , a flow chart of a method for handling a signaling storm provided by an embodiment of the present application is shown. As shown in FIG4 , the method for handling a signaling storm provided by an embodiment of the present application may include the following steps:

[0331] Step 1: The NF consumer sends a signaling storm analysis request to the NWDAF, requesting a signaling storm analysis. The signaling storm analysis request includes an analysis identifier and, optionally, an analysis target and an analysis period.

[0332] The analysis flag indicates the current analysis, i.e., signaling storm. The analysis target indicates the target of the analysis, which can be information identifying one or a group of target gNBs, such as Cell ID, TA ID, Area of ​​Interest, etc. The analysis period indicates the start and end time of the analysis.

[0333] Optionally, the NF consumer may request the NWDAF to analyze the target gNB's network performance (see 3GPP TS 23.288 6.6) in advance to obtain the target gNB's resource usage. The NF consumer can trigger a signaling storm analysis for the target gNB or group of target gNBs based on the resource usage. For example, if the target gNB's resource usage exceeds a certain threshold (CPU utilization greater than 90%), the signaling storm analysis request is sent to the NWDAF.

[0334] Signaling storm analysis requests can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe service (subscription notification model) or the Nnwdaf_AnalyticsInfo_Request service (request-response model). The former is based on a subscription-notification model, where the subscriber will periodically or sporadically send messages to the NF consumer. The latter is based on a request-response model, with each request receiving a reply.

[0335] Step 2: NWDAF sends a first data collection request to OAM to collect the signaling feature information of the target gNB and the network capacity information of the target gNB.

[0336] The first data collection request may obtain data from the OAM periodically or irregularly by invoking a subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0337] Optionally, the NWDAF may also directly request the first data from the target gNB instead of indirectly through OAM.

[0338] Optionally, in addition to collecting data from the target gNB, the NWDAF can also use this method to collect data from the gNB to which it is connected.

[0339] Step 3: The NWDAF obtains first data from the OAM or the target gNB. The first data includes the gNB's signaling feature information and the gNB's network capacity information.

[0340] The signaling characteristic information of the target gNB is used to indicate the characteristics of signaling failure and / or signaling anomaly between the target gNB and the source gNB and between the target gNB and the AMF.

[0341] Signaling characteristic information may include the number of signaling failure messages between the target gNB and a specific gNB / AMF, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of duplicate signaling messages, the ratio of duplicate signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it may also include the identifier of the target NF (e.g., cell ID) and the NF type (e.g., TA, AoI, S-NSSAI).

[0342] Signaling between gNBs is Xn signaling. Exemplarily, Xn signaling failure messages may include Handover Preparation Failure, Retrieve UE context Failure, S-node Addition / modification Request Reject, or Xn Setup Failure. Xn request signaling may include Handover Preparation Request, Retrieve UE context Request, S-node Addition / modification Request, or Xn Setup Request. Xn resource allocation messages may include Handover Request, S-node Addition Request, or Xn Setup Request.

[0343] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the gNB is the target network side device and the AMF is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the AMF is rejected by the gNB. The N2 request message specifically refers to the downlink N2 signaling request sent by the AMF. The N2 resource allocation message specifically refers to the message that the AMF requests the gNB to generate a context. Exemplarily, the N2 signaling failure message may include Initial Context Setup Failure, UE Context Modification Failure, AMF configure Failure, Retrieve UE context Failure, Handover Failure, Broadcast Session Setup / modification Failure, etc., and the N2 request message may include Initial Context Setup Request, UE Context Modification Request, AMF configure Request, Retrieve UE context Request, Handover Request, Broadcast Session Setup / modification Request. The N2 resource allocation message may include Initial Context Setup Request, AMF configure Request, Broadcast Session Setup / modification Request, etc.

[0344] Optionally, the signaling feature information of the target gNB further includes at least one of the following:

[0345] The identifier of the target gNB;

[0346] Category of target gNB;

[0347] Time period information.

[0348] At this time, the first data can only count the signaling of the target gNB, and the signaling characteristic information can include at least one of the identifier and category of the target gNB and time period information.

[0349] The time period information is used to indicate the time period for collecting signaling feature data.

[0350] For example, the signaling characteristic data may be expressed in the form of "cell ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): number of Xn signaling failure messages: 200, number of all Xn signalings: 11000; number of N2 signaling failure messages: 1800, number of all N2 signalings: 12000; ...".

[0351] Optionally, the signaling feature information of the target gNB further includes at least one of the following:

[0352] Identification of other gNBs or AMFs;

[0353] Category of other gNB or AMF;

[0354] Time period information.

[0355] At this point, more fine-grained statistics can be performed on the signaling feature information, such as counting the signaling received by the target gNB from different other gNBs or AMFs.

[0356] For example, the signaling characteristic data may be expressed in the form of "gNB ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): AMF ID1 (2.2 0:00-2.3 S-NSSAI1): Number of N2 signaling failure messages: 120, number of all N2 signaling: 12340; gNB ID1: gNB ID2 (2.2 0:00-2.3 S-NSSAI2): Number of Xn signaling failure messages: 1500, number of all Xn signaling: 16660; ... ".

[0357] It should be noted that when the signaling characteristic information contains the identifiers of other gNBs or AMFs, the specific abnormal network side device can be located.

[0358] A signaling storm may cause a large number of rejection messages to reject requests from other gNBs or AMFs, or not process or discard their requests, resulting in an increase in the proportion of unresponsive request messages. Therefore, the characteristic information of the above signaling failure can reflect the characteristics of the signaling storm.

[0359] The signaling sent by the abnormal NF may have some signaling characteristics, such as repeated signaling, malformed signaling, and a large number of requested resources. Therefore, the characteristic information of the above signaling anomalies can be used to infer whether it is caused by the NF anomaly.

[0360] The target gNB's network capacity information indicates the number of network contexts currently in the target gNB. This information can be expressed as the number of all N2 or Xn contexts generated for UEs served by a target gNB or a group of target gNBs (e.g., a TA or an Area of ​​Interest), or as the number of contexts for connections between network elements.

[0361] The target gNB's network capacity information can be used to infer the cause of the signaling storm. For example, if the target gNB has a small number of network contexts but a high volume of traffic, it may be caused by a network element anomaly.

[0362] Step 4: Optionally, the NWDAF sends a second data collection request to the AMF or OAM to collect the signaling characteristic information of the AMF and the network capacity information of the AMF and / or the signaling characteristic information of the gNB and the network capacity information of the gNB.

[0363] It should be noted that the AMF and gNB here refer to network devices that interact with the target gNB.

[0364] If collecting data from the AMF, the second data collection request can be made by calling the Event_Exposure event reporting service of different NFs. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, where each request is responded to once.

[0365] If the data is collected from the OAM, the first data collection request may obtain data from the OAM periodically or irregularly by calling a subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0366] Optionally, the NWDAF may select the AMF or gNB to which the target gNB is connected to send a second data collection request.

[0367] Step 5: Optionally, the AMF / OAM sends second data to the NWDAF. The second data includes the signaling feature information of the AMF and the network capacity information of the AMF and / or the signaling feature information of the gNB and the network capacity information of the gNB.

[0368] Among them, the signaling characteristic information of the AMF is used to indicate the characteristics of the signaling failure and / or signaling abnormality between the target gNB and the AMF.

[0369] Signaling characteristic information may include the number of signaling failure messages between the AMF and the target gNB, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of duplicate signaling messages, the ratio of duplicate signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it may also include the source NF identifier (e.g., NF instance ID) and NF type (e.g., NF type, TA, AoI, S-NSSAI).

[0370] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the gNB is the target network side device and the AMF is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the AMF is rejected by the gNB. The N2 request message specifically refers to the downlink N2 signaling request sent by the AMF. The N2 resource allocation message specifically refers to the message that the AMF requests the gNB to generate a context. Exemplarily, the N2 signaling failure message may include Initial Context Setup Failure, UE Context Modification Failure, AMF configure Failure, Retrieve UE context Failure, Handover Failure, Broadcast Session Setup / modification Failure, etc., and the N2 request message may include Initial Context Setup Request, UE Context Modification Request, AMF configure Request, Retrieve UE context Request, Handover Request, Broadcast Session Setup / modification Request. The N2 resource allocation message may include Initial Context Setup Request, AMF configure Request, Broadcast Session Setup / modification Request, etc.

[0371] Signaling between gNBs is Xn signaling. Exemplarily, Xn signaling failure messages may include Handover Preparation Failure, Retrieve UE context Failure, S-node Addition / modification Request Reject, or Xn Setup Failure. Xn request signaling may include Handover Preparation Request, Retrieve UE context Request, S-node Addition / modification Request, or Xn Setup Request. Xn resource allocation messages may include Handover Request, S-node Addition Request, or Xn Setup Request.

[0372] Optionally, the signaling feature information of the AMF or gNB further includes at least one of the following:

[0373] AMF or gNB identity;

[0374] Type of AMF or gNB;

[0375] Time period information.

[0376] At this time, the first data may only count the signaling of the AMF or gNB, and the signaling characteristic information may include at least one of the identification and category of the AMF or gNB and the time period information.

[0377] The time period information is used to indicate the time period for collecting signaling feature data.

[0378] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): Number of N2 signaling failure messages: 1200, number of all N2 signaling: 15000...; gNB ID2 (2.2 0:00-2.3 12:00, S-NSSAI1): Number of Xn signaling failure messages: 200, number of all Xn signaling: 11000".

[0379] Optionally, the signaling feature information of the target gNB further includes at least one of the following:

[0380] The identifier of the target gNB;

[0381] Category of target gNB;

[0382] Time period information.

[0383] At this point, more fine-grained statistics can be performed on the signaling feature information, such as statistics on the signaling interacting between other gNBs or AMF and the target gNB.

[0384] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): gNB ID1 (2.2 0:00-2.3 S-NSSAI1): Number of N2 signaling failure messages: 120, number of all N2 signaling: 12340;" or "gNB ID2: gNB ID1 (2.2 0:00-2.3 S-NSSAI2): Number of Xn signaling failure messages: 1500, number of all Xn signaling: 16660;..."

[0385] The network capacity information of the AMF is used to indicate the number of network contexts currently served by the AMF. This information can be expressed as the number of all N2 contexts generated for UEs served by one or a group of AMFs (e.g., one TA or one Area of ​​Interest), or the number of contexts for the connection between the gNB and the AMF.

[0386] The gNB's network capacity information indicates the number of network contexts currently available on the gNB. This information can be expressed as the number of N2 or Xn contexts generated for UEs served by a gNB or a group of gNBs (e.g., a TA or an Area of ​​Interest), or as the number of contexts for connections between network elements.

[0387] Step 6: NWDAF performs analysis based on the first data and the second data (optional) to obtain a signaling storm analysis result. The signaling analysis result may include a detection result and a prediction result.

[0388] The detection result output may include the cause of the signaling storm (e.g., a self-abnormality, an abnormality of another NF), the target (identifying the signaling storm target, which can identify a single gNB, such as the cell ID, or multiple gNBs, such as TA, AoI, S-NSSAAI). Optionally, it also includes the signaling storm level (indicating the severity of the signaling storm, such as low, medium, and high), the trend (subsequent trend of the signaling storm, such as increasing / decreasing / unknown / stable), the signaling type (e.g., N2), abnormal signaling messages (e.g., AMF configure failure), the proportion of abnormal signaling to normal signaling, the duration, the abnormal NF identifier, the abnormal NF behavior (which may include NF sending repeated signaling, NF sending malformed signaling, NF abnormal context establishment, etc.), and the NF abnormality category (which may be identified by TA, AoI, S-NSSAAI, etc.).

[0389] The output of the prediction result can be additionally increased with confidence (used to indicate the confidence of the current prediction result) and expected time (the predicted time when the signaling storm may occur) based on the above information element.

[0390] It is particularly important to note that the prediction can be achieved in the following way: NWDAF analyzes historical data and learns that the proportion of rejected signaling under normal circumstances for gNBs at a certain capacity is maintained at 2%. Based on historical signaling storm results (administrators mark signaling storms after they occur), NWDAF knows that when the proportion of rejected signaling exceeds 10%, it indicates a signaling storm has occurred. NWDAF finds that the current proportion of rejected signaling is gradually increasing from 2% to 4%, and has an upward trend. NWDAF predicts that a signaling storm may occur in this gNB.

[0391] Step 7: NWDAF sends the above signaling storm analysis results to the NF consumer.

[0392] Step 8: Optionally, NWDAF obtains updated data from AMF / OAM.

[0393] Step 9: Optionally, the NWDAF performs analysis based on the updated data to generate an updated signaling storm analysis result.

[0394] Step 10: Optionally, the NWDAF sends the updated signaling storm analysis result to NF consume.

[0395] Step 11: The NF consumer performs control based on the signaling storm analysis results. For specific control operations, refer to the example shown in Table 2:

[0396] Table 2

[0397] As another example, it is detected whether the AMF or SMF (that is, the case where the first network side device in this application is AMF or SMF) is subjected to a signaling attack. Referring to Figure 5, a flowchart of another method for handling a signaling storm provided by an embodiment of the present application is shown. As shown in Figure 5, the method for handling a signaling storm provided by an embodiment of the present application may include the following steps:

[0398] Step 1: The NF consumer sends a signaling storm analysis request to the NWDAF, requesting a signaling storm analysis. The signaling storm analysis request includes an analysis identifier and, optionally, an analysis target and an analysis period.

[0399] The analysis identifier indicates the current analysis, i.e., the signaling storm. The analysis target indicates the object of the analysis, which can be information identifying one or a group of NFs, such as NF instance ID, TA ID, Area of ​​Interest, etc. The analysis period indicates the start and end time of the analysis.

[0400] Optionally, the NF consumer may request the NWDAF to analyze the network performance of the AMF / SMF in advance (see 3GPP TS 23.288 6.5), thereby obtaining the resource usage of the AMF / SMF. The NF consumer can trigger a signaling storm analysis for this or this group of AMF / SMFs based on the resource usage. For example, if the resource usage of the AMF / SMF exceeds a certain threshold (CPU usage greater than 90%), the above signaling storm analysis request is sent to the NWDAF.

[0401] Signaling storm analysis requests can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former uses a subscription-notification model, where the subscriber periodically or sporadically sends messages to the NF consumer. The latter uses a request-response model, with a single reply per request.

[0402] Step 2: NWDAF sends a first data collection request to OAM / target NF to collect signaling feature information of the target NF and network capacity information of the target NF (optional).

[0403] The first data collection request for OAM may obtain data from OAM periodically or irregularly by calling a subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3).

[0404] The first data collection request for the target NF can be generated by calling the NF's Event_Exposure event reporting service. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, where each request is responded to once.

[0405] Step 3: NWDAF obtains first data from OAM / target NF. The first data includes signaling feature information of the target NF and network capacity information of the target NF (optional).

[0406] The signaling characteristic information of the target NF is used to indicate characteristics of signaling failure and / or signaling abnormality when the target NF communicates with other NFs.

[0407] If the target NF is an AMF, the signaling characteristic information may include the number of signaling failure messages between the AMF and gNB, and between the AMF and other NFs, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of duplicate signaling messages, the ratio of duplicate signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it may also include the identifier of the target NF (e.g., NF instance ID) and the NF type (e.g., NF type, TA, AoI, S-NSSAI).

[0408] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the AMF is the target network side device and the gNB is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the gNB is rejected by the AMF. The N2 request message specifically refers to the uplink N2 signaling request sent by the gNB. The N2 resource allocation message specifically refers to the message that the gNB requests the AMF to generate a context. Illustratively, the N2 signaling failure message may include Handover Preparation Failure, Path Switch Failure, NG setup Failure, RAN Configuration Failure, UE Context Suspend / Resume Failure, MT Communication Handling Failure, etc., and the N2 request message may include Handover Request, Path Switch Request, NG setup Request, RAN Configuration Update, UE Context Suspend / Resume Request, MT Communication Handling Request, etc. The N2 resource allocation message may include Handover Request, NG setup Request, RAN Configuration Update, etc.

[0409] Signaling between the AMF and other NFs (e.g., SMF, AUSF, UDM, PCF, etc.) is SBA signaling, carried over HTTP messages. For example, an SBA signaling failure message can be reflected by an HTTP response value, such as a 40x or 50x response value. Pay particular attention to 429 (Client Sends Too Many Requests) and 503 (Service Unavailable), which are common responses during signaling storms. For example, SBA signaling request messages can be determined using the HTTP GET or POST method. SBA resource allocation messages can include messages such as Nnrf_Register requesting NF context establishment.

[0410] If the target NF is an SMF, the signaling characteristic information may include the number of signaling failure messages between the SMF and the UPF, and between the SMF and other NFs (also SBA), the number of all signaling, the number of all request signaling, the ratio of all signaling failure messages to all signaling, the number of unresponsive request signaling, and the ratio of unresponsive request signaling to all request signaling. Optionally, it may also include the number of repeated signaling messages, the ratio of repeated signaling messages to all signaling, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling. Optionally, it also includes the identifier of the source NF (e.g., NF instance ID) and the type of NF (e.g., NF type, TA, AoI, S-NSSAI), etc.

[0411] Signaling between the SMF and UPF is N4 signaling, which is also based on PFCP protocol messages. For example, a PFCP signaling failure message may include a PFCP Heartbeat Response message with a rejection cause value, a PFCP PFD Management Response message, or a PFCP Association Setup / Update / Release Response message. A PFCP signaling request message may include a PFCP Heartbeat Request message, a PFCP PFD Management Request message, or a PFCP Association Setup / Update / Release Request message.

[0412] If the target NF is another NF, the signaling feature information is the signaling feature message between NFs (SBA).

[0413] Optionally, the signaling feature information of the target NF further includes at least one of the following:

[0414] The identification of the target NF;

[0415] Category of target NF;

[0416] Time period information.

[0417] At this time, the first data may only count the signaling of the target NF, and the signaling characteristic information may include at least one of the identifier and category of the target NF and time period information.

[0418] The time period information is used to indicate the time period for collecting signaling feature data.

[0419] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): Number of N2 signaling failure messages: 200, number of all N2 signalings: 11000; number of SBA signaling failure messages: 1800, number of all SBA signalings: 12000; ... ".

[0420] Optionally, the signaling feature information of the target NF further includes at least one of the following:

[0421] Other NF identification;

[0422] Other categories of NF;

[0423] Time period information.

[0424] At this time, more fine-grained statistics can be performed on the signaling feature information, such as counting the signaling received by the target NF from different other NFs.

[0425] For example, the signaling characteristic data may be expressed in the form of "SMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): AMF ID1 (2.2 0:00-2.3S-NSSAI1): Number of SBA signaling failure messages: 120, number of all SBA signalings: 12340; SMF ID1: UPF ID1 (2.2 0:00-2.3 S-NSSAI2): Number of PFCP signaling failure messages: 1500, number of all PFCP signalings: 16660;..."

[0426] It should be noted that, when the signaling characteristic information includes the identifier of other NFs, the specific abnormal network-side device can be located.

[0427] A signaling storm may cause a large number of rejection messages to reject requests from other NFs, or not process or discard their requests, resulting in an increase in the proportion of unresponsive request messages. Therefore, the characteristic information of the above signaling failure can reflect the characteristics of the signaling storm.

[0428] The signaling sent by the abnormal NF may have some signaling characteristics, such as repeated signaling, malformed signaling, and a large number of requested resources. Therefore, the characteristic information of the above signaling anomalies can be used to infer whether it is caused by the NF anomaly.

[0429] The target NF's network capacity information indicates the number of network contexts currently in the NF. This information can be expressed as the number of all N2, SBA, or PFCP contexts generated for UEs served by a NF or a group of NFs (e.g., a TA or an Area of ​​Interest), or as the number of contexts for connections between network elements.

[0430] The network capacity information of the NF can be used to infer the cause of the signaling storm. For example, when the number of network contexts of the NF is small but the communication is high, it may be caused by a network element abnormality.

[0431] Step 4: Optionally, the NWDAF sends a second data collection request to the OAM / source NF to collect signaling feature information of the source NF and network capacity information of the source NF (optional).

[0432] If data is collected from the source NF, the second data collection request can be made by calling the Event_Exposure event reporting service of a different NF. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, where each request is responded to once.

[0433] If the data is collected from the OAM, the first data collection request may obtain data from the OAM periodically or irregularly by calling a subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0434] Optionally, the NWDAF may select the NF to which the target NF is connected to send the data collection request.

[0435] Step 5: Optionally, the OAM / source NF sends second data to the NWDAF. The second data is the signaling feature information of the source NF and the network capacity information of the source NF (optional).

[0436] The signaling characteristic information of the source NF is used to indicate the characteristics of the signaling failure and / or signaling anomaly between the source NF and the target NF.

[0437] The signaling characteristic information may include the number of signaling failure messages between the source NF and the target NF, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of repeated signaling messages, the ratio of repeated signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it also includes the identifier of the target NF (e.g., NF instance ID) and the type of NF (e.g., NF type, TA, AoI, S-NSSAI), etc.

[0438] The NF message is the same as step 3.

[0439] The network capacity information of the source NF is used to indicate the number of network contexts currently in the NF. This information can be expressed as the number of all N2, SBA, or PFCP contexts generated for UEs served by a NF or a group of NFs (e.g., a TA or an Area of ​​Interest), or as the number of contexts for connections between network elements.

[0440] Step 6: NWDAF performs analysis based on the first data and the second data (optional) to obtain a signaling storm analysis result. The signaling analysis result may include a detection result and a prediction result.

[0441] The output of the detection results may include the cause of the signaling storm (e.g., abnormality of the NF itself, abnormality of other NFs), target (identification of the signaling storm target, which may identify a single NF, such as NF instance ID, or multiple NFs, such as NF type, TA, AoI, S-NSSAAI). Optionally, it also includes the level of the signaling storm (indicating the severity of the signaling storm, such as low, medium, and high), trend (subsequent trend of the signaling storm, such as rising / falling / unknown / stable), signaling type (e.g., HTTP), abnormal signaling message (e.g., HTTP response of 503), the proportion of abnormal signaling to normal signaling, duration, abnormal NF identification, NF abnormal behavior (including NF sending repeated signaling, NF sending deformed signaling, NF abnormal context establishment, etc.), and NF abnormal category (which can be identified by TA, AoI, S-NSSAAI, etc.).

[0442] The output of the prediction result can be additionally increased with confidence (used to indicate the confidence of the current prediction result) and expected time (the predicted time when the signaling storm may occur) based on the above information element.

[0443] It is particularly important to note that the prediction can be achieved in the following way: NWDAF analyzes historical data and learns that under normal circumstances, the proportion of rejected signals for NFs at a certain capacity remains at 2%. Based on historical signaling storm results (administrators mark signaling storms after they occur), NWDAF learns that when the proportion of rejected signals exceeds 10%, it indicates a signaling storm has occurred. NWDAF finds that the current proportion of rejected signals is gradually increasing from 2% to 4% and has an upward trend. Therefore, NWDAF predicts that a signaling storm may occur in this NF.

[0444] Step 7: NWDAF sends the above signaling storm analysis results to the NF consumer.

[0445] Step 8: Optionally, NWDAF obtains updated data from NF / OAM.

[0446] Step 9: Optionally, the NWDAF performs analysis based on the updated data to generate an updated signaling storm analysis result.

[0447] Step 10: Optionally, the NWDAF sends the updated signaling storm analysis result to NF consume.

[0448] Step 11: The NF consumer performs control based on the signaling storm analysis results. For specific control operations, refer to the example shown in Table 3:

[0449] Table 3

[0450] The signaling storm processing method provided in the embodiment of the present application can be executed by a signaling storm processing device. In the embodiment of the present application, the signaling storm processing device executing the signaling storm processing method is used as an example to illustrate the signaling storm processing device provided in the embodiment of the present application.

[0451] The embodiment of the present application provides a signaling storm processing device. Referring to FIG6 , a structural block diagram of a signaling storm processing device provided by the embodiment of the present application is shown. The device can be applied to the analysis function. As shown in FIG6 , the device can specifically include:

[0452] Acquisition module 301, used to acquire target data;

[0453] An analysis module 302 is configured to analyze the target data to obtain a signaling storm analysis result of the first network-side device;

[0454] The signaling storm analysis result includes at least one of the following:

[0455] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0456] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0457] Optionally, the reason includes at least one of the following:

[0458] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0459] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0460] Optionally, the signaling storm analysis result further includes at least one of the following:

[0461] The level of signaling storm;

[0462] The development trend of signaling storms;

[0463] Duration of the signaling storm;

[0464] Characteristic information of abnormal signaling;

[0465] an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device interacting with the first network-side device;

[0466] Feature information of the abnormal network-side device;

[0467] confidence level;

[0468] Prediction time.

[0469] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0470] Abnormal signaling message;

[0471] The signaling type of the abnormal signaling;

[0472] The proportion of abnormal signaling in all signaling.

[0473] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0474] abnormal behavior of the abnormal network side device;

[0475] The category of the abnormal network-side device.

[0476] Optionally, the acquisition module includes:

[0477] The first acquisition submodule is configured to acquire the first data from a second network-side device, wherein the second network-side device includes at least one of the following:

[0478] the first network-side device;

[0479] A network-side device for managing the first network-side device.

[0480] Optionally, the first data includes at least one of the following:

[0481] signaling characteristic information of the first network-side device;

[0482] Network capacity information of the first network-side device.

[0483] Optionally, the acquisition module further includes:

[0484] The second acquisition submodule is configured to acquire second data from a third network-side device; the third network-side device includes at least one of the following:

[0485] a fourth network-side device accessing the first network-side device;

[0486] A network-side device for managing the fourth network-side device.

[0487] Optionally, the second data includes at least one of the following:

[0488] signaling characteristic information of the fourth network-side device;

[0489] Network capacity information of the fourth network-side device.

[0490] Optionally, the signaling characteristic information includes at least one of the following:

[0491] Number of signaling failure messages;

[0492] The number of all signaling;

[0493] The proportion of signaling failure messages in all signaling;

[0494] The number of unresponsive request signals;

[0495] The proportion of unresponsive request signals in all request signals;

[0496] The number of repeated signaling messages;

[0497] The proportion of repeated signaling messages in all signaling;

[0498] The number of malformed signaling messages;

[0499] The proportion of malformed signaling messages in all signaling messages;

[0500] The number of resource allocation messages;

[0501] The proportion of resource allocation messages in all signaling.

[0502] Optionally, the signaling characteristic information further includes at least one of the following:

[0503] an identifier of the first network-side device;

[0504] Category of the first network-side device;

[0505] Time period information, where the time period information is used to indicate a time period for collecting the signaling characteristic information.

[0506] Optionally, the signaling characteristic information includes at least one of the following:

[0507] The identifier of the fourth network-side device;

[0508] The category of the fourth network-side device.

[0509] Optionally, the second acquisition submodule includes:

[0510] The second data acquiring unit is configured to acquire the second data from the third network side device according to the identifier of the fourth network side device in the first data.

[0511] Optionally, the network capacity information includes at least one of the following:

[0512] The number of terminal contexts;

[0513] The number of connected contexts.

[0514] Optionally, the acquisition module further includes:

[0515] The first request sending submodule is used to send a first data collection request to the second network side device.

[0516] Optionally, the first request sending submodule includes:

[0517] a first request sending unit, configured to send a first data collection request to the second network-side device upon receiving the first analysis request sent by the control function;

[0518] The first analysis request is used to request a signaling storm analysis to be performed on the first network-side device.

[0519] Optionally, the first analysis request includes at least one of the following:

[0520] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0521] an analysis target, where the analysis target is used to indicate the first network device;

[0522] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0523] Optionally, the device further comprises:

[0524] The network performance analysis result sending module is used to send the network performance analysis result of the first network side device to the analysis function when receiving the second analysis request sent by the control function.

[0525] Optionally, the device further comprises:

[0526] The signaling storm analysis result sending module is used to send the signaling storm analysis result to the control function.

[0527] Optionally, the target data includes: current target data and historical target data;

[0528] The analysis module includes:

[0529] A model training submodule, configured to obtain a signaling storm analysis model based on the historical target data;

[0530] The analysis submodule is configured to perform analysis based on the signaling storm analysis model and the current target data to obtain a signaling storm analysis result of the first network-side device.

[0531] Optionally, the network-side device for managing the first network-side device, or the network-side device for managing the fourth network-side device, includes an operation, administration, and maintenance function OAM.

[0532] Optionally, when the first network side device includes an access network device, the fourth network side device includes other access network devices other than the first network side device, or the fourth network side device includes a core network device; when the first network side device includes a core network device, and the fourth network side device includes a core network device, the fourth network side device includes other core network devices other than the first network side device, access network devices, and at least one of other network functions.

[0533] Optionally, the control function comprises a network function consumer.

[0534] Optionally, the analysis function includes a network data analysis function NWDAF.

[0535] The signaling storm processing device provided in the embodiment of the present application can implement the various processes implemented in the method embodiment of Figure 2 and achieve the same technical effect. To avoid repetition, it will not be described here.

[0536] The present application also provides another signaling storm processing device. Referring to FIG7 , a structural block diagram of another signaling storm processing device provided by the present application is shown. The device can be applied to the control function. As shown in FIG7 , the device can specifically include:

[0537] Analysis result receiving module 401, used to receive the signaling storm analysis result sent by the analysis function;

[0538] A signaling storm control module 402 is configured to perform a signaling storm control operation according to the signaling storm analysis result;

[0539] The signaling storm analysis result includes at least one of the following:

[0540] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0541] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0542] Optionally, the reason includes at least one of the following:

[0543] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0544] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0545] Optionally, the signaling storm analysis result further includes at least one of the following:

[0546] The level of signaling storm;

[0547] The development trend of signaling storms;

[0548] Duration of the signaling storm;

[0549] Characteristic information of abnormal signaling;

[0550] an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device interacting with the first network-side device;

[0551] Feature information of the abnormal network-side device;

[0552] confidence level;

[0553] Prediction time.

[0554] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0555] Abnormal signaling message;

[0556] The signaling type of the abnormal signaling;

[0557] The proportion of abnormal signaling in all signaling.

[0558] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0559] abnormal behavior of the abnormal network side device;

[0560] The category of the abnormal network-side device.

[0561] Optionally, the device further comprises:

[0562] The first analysis request sending module is used to send a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

[0563] Optionally, the first analysis request includes at least one of the following:

[0564] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0565] an analysis target, where the analysis target is used to indicate the first network-side device;

[0566] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0567] Optionally, the first analysis request sending module includes:

[0568] A network performance analysis result acquisition submodule, configured to acquire a network performance analysis result of the first network-side device;

[0569] The first analysis request sending submodule is used to send the first analysis request to the analysis function when the network performance analysis result indicates that the resource usage of the first network side device is in an abnormal state.

[0570] Optionally, the network performance analysis result acquisition submodule includes:

[0571] A second analysis request sending unit, configured to send a second analysis request to the analysis function, wherein the second analysis request is used to request analysis of network performance of the first network-side device;

[0572] A network performance analysis result receiving unit is used to receive the network performance analysis result of the first network side device sent by the analysis function.

[0573] Optionally, the signaling storm control module includes:

[0574] The first control submodule is used to modify the local policy for the first network side device in the control function according to the identification of the first network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, so that the first network side device cannot be discovered.

[0575] Optionally, the signaling storm control module includes:

[0576] The second control submodule is used to modify the local policy for the abnormal network side device in the control function according to the identification of the abnormal network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identification of the abnormal network side device, so that the abnormal network side device cannot be discovered.

[0577] Optionally, the signaling storm control module includes:

[0578] The third control submodule is used to modify the first slice information of the first network side device to the second slice information according to the identification of the first network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by the abnormality of the first network side device itself, and the first slice information is different from the second slice information.

[0579] Optionally, the signaling storm control module includes:

[0580] The fourth control submodule is used to modify the third slice information of the abnormal network side device to the fourth slice information according to the identifier of the abnormal network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identifier of the abnormal network side device, and the third slice information is different from the fourth slice information.

[0581] Optionally, the signaling storm control module includes:

[0582] The fifth control submodule is configured to notify the first network side device to release connections with all other network side devices when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself.

[0583] Optionally, the signaling storm control module includes:

[0584] The sixth control submodule is used to notify the first network side device to release the connection with the abnormal network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identification of the abnormal network side device.

[0585] Optionally, the signaling storm control module includes:

[0586] The seventh control submodule is used to notify the abnormal network side device to release the connection with the first network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identification of the abnormal network side device.

[0587] The signaling storm processing device provided in the embodiment of the present application can implement each process implemented in the method embodiment of Figure 3 and achieve the same technical effect. To avoid repetition, it will not be described here.

[0588] Optionally, as shown in Figure 8, an embodiment of the present application further provides a communication device 900, including a processor 901 and a memory 902, wherein the memory 902 stores a program or instruction that can be run on the processor 901. For example, when the communication device 900 is a network side device, the program or instruction is executed by the processor 901 to implement the various steps of the embodiment of the method for handling the signaling storm described in the first aspect above, and can achieve the same technical effect. When the communication device 900 is a terminal device, the program or instruction is executed by the processor 901 to implement the various steps of the embodiment of the method for handling the signaling storm described in the second aspect above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0589] The present application also provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the method embodiment shown in Figure 2 or Figure 3. This network-side device embodiment corresponds to the aforementioned network-side device method embodiment, and each implementation process and implementation method of the aforementioned method embodiment can be applied to this network-side device embodiment and can achieve the same technical effects.

[0590] Specifically, an embodiment of the present application further provides a network-side device. As shown in FIG9 , the network-side device 1100 includes an antenna 111, a radio frequency device 112, a baseband device 113, a processor 114, and a memory 115. Antenna 111 is connected to radio frequency device 112. In the uplink direction, radio frequency device 112 receives information via antenna 111 and sends the received information to baseband device 113 for processing. In the downlink direction, baseband device 113 processes the information to be transmitted and sends it to radio frequency device 112. Radio frequency device 112 processes the received information and then sends it through antenna 111.

[0591] The method executed by the network-side device in the above embodiment may be implemented in the baseband device 113 , which includes a baseband processor.

[0592] The baseband device 113 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 9, one of the chips is, for example, a baseband processor, which is connected to the memory 115 through a bus interface to call the program in the memory 115 and execute the network device operations shown in the above method embodiment.

[0593] The network side device may further include a network interface 116, which is, for example, a common public radio interface (CPRI).

[0594] Specifically, the network side device 1100 of the embodiment of the present application also includes: instructions or programs stored in the memory 115 and executable on the processor 114. The processor 114 calls the instructions or programs in the memory 115 to execute the methods executed by the modules shown in FIG6 or FIG7 and achieve the same technical effect. To avoid repetition, they will not be elaborated here.

[0595] The embodiment of the present application further provides a network side device. As shown in FIG10 , the network side device 1200 includes: a processor 1201, a network interface 1202, and a memory 1203. The network interface 1202 is, for example, a common public radio interface (CPRI).

[0596] Specifically, the network side device 1200 of the embodiment of the present application also includes: instructions or programs stored in the memory 1203 and executable on the processor 1201. The processor 1201 calls the instructions or programs in the memory 1203 to execute the methods executed by the modules shown in FIG6 or FIG7 and achieve the same technical effect. To avoid repetition, it will not be described here.

[0597] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned signaling storm processing method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0598] The processor is the processor in the terminal device described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0599] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned signaling storm processing method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0600] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0601] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned signaling storm processing method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0602] An embodiment of the present application also provides a signaling storm processing system, including: a terminal device and a network side device, wherein the terminal can be used to execute the steps of the signaling storm processing method described in the second aspect above, and the network side device can be used to execute the steps of the signaling storm processing method described in the first aspect above.

[0603] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0604] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0605] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0606] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0607] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0608] In addition, each functional unit in each embodiment of the present disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0609] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0610] It is understood that the embodiments described in the embodiments of the present disclosure may be implemented using hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the modules, units, and sub-units may be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, or other electronic units or combinations thereof for performing the functions described in the present disclosure.

[0611] For software implementation, the techniques described in the embodiments of the present disclosure can be implemented by modules (e.g., procedures, functions, etc.) that perform the functions described in the embodiments of the present disclosure. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or external to the processor.

[0612] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A method for processing a signaling storm, wherein: The method comprises: The analysis function obtains target data; The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

2. The method according to claim 1, wherein The reasons include at least one of the following: The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself; The network-side device signaling storm is caused by other network-side devices except the first network-side device.

3. The method according to claim 1 or 2, wherein: The signaling storm analysis result also includes at least one of the following: The level of signaling storm; The development trend of signaling storms; Duration of the signaling storm; Characteristic information of abnormal signaling; an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device interacting with the first network-side device; Feature information of the abnormal network-side device; confidence level; Prediction time.

4. The method according to claim 3, wherein: The characteristic information of the abnormal signaling includes at least one of the following: Abnormal signaling message; The signaling type of the abnormal signaling; The proportion of abnormal signaling in all signaling.

5. The method according to claim 3 or 4, wherein: The characteristic information of the abnormal network side device includes at least one of the following: abnormal behavior of the abnormal network side device; The category of the abnormal network-side device.

6. The method according to any one of claims 1 to 5, wherein: The analysis function obtains target data, including: The analysis function obtains the first data from a second network-side device; the second network-side device includes at least one of the following: the first network-side device; A network-side device for managing the first network-side device.

7. The method according to claim 6, wherein: The first data includes at least one of the following: signaling characteristic information of the first network-side device; Network capacity information of the first network-side device.

8. The method according to claim 6 or 7, wherein: The analysis function acquires target data and further includes: The analysis function obtains the second data from a third network-side device; the third network-side device includes at least one of the following: a fourth network-side device accessing the first network-side device; A network-side device for managing the fourth network-side device.

9. The method according to claim 8, wherein The second data includes at least one of the following: signaling characteristic information of the fourth network-side device; Network capacity information of the fourth network-side device.

10. The method according to claim 7 or 9, wherein: The signaling characteristic information includes at least one of the following: Number of signaling failure messages; The number of all signaling; The proportion of signaling failure messages in all signaling; The number of unanswered request signals; The proportion of unresponsive request signals in all request signals; The number of repeated signaling messages; The proportion of repeated signaling messages in all signaling; The number of malformed signaling messages; The proportion of malformed signaling messages in all signaling messages; The number of resource allocation messages; The proportion of resource allocation messages in all signaling.

11. The method according to claim 10, wherein: The signaling characteristic information also includes at least one of the following: an identifier of the first network-side device; Category of the first network-side device; Time period information, where the time period information is used to indicate a time period for collecting the signaling characteristic information.

12. The method according to claim 10 or 11, wherein: The signaling characteristic information includes at least one of the following: The identifier of the fourth network-side device; The category of the fourth network-side device.

13. The method according to claim 12, wherein: The analysis function obtains the second data from the third network side device, including: The analysis function obtains the second data from the third network side device according to the identifier of the fourth network side device in the first data.

14. The method according to claim 7 or 9, wherein: The network capacity information includes at least one of the following: The number of terminal contexts; The number of connected contexts.

15. The method according to any one of claims 6 to 14, wherein: Before the analysis function obtains the first data from the second network-side device, the method further includes: The analysis function sends a first data collection request to the second network side device.

16. The method according to claim 15, wherein The analysis function sends a first data collection request to the second network side device, including: The analysis function sends a first data collection request to the second network side device when receiving the first analysis request sent by the control function; The first analysis request is used to request a signaling storm analysis to be performed on the first network-side device.

17. The method according to claim 16, wherein The first analysis request includes at least one of the following: An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis; an analysis target, where the analysis target is used to indicate the first network device; Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

18. The method according to claim 16 or 17, wherein The method further comprises: Upon receiving the second analysis request sent by the control function, the analysis function sends the network performance analysis result of the first network-side device to the analysis function.

19. The method according to any one of claims 16 to 18, wherein: The method further comprises: The analysis function sends the signaling storm analysis result to the control function.

20. The method according to any one of claims 1 to 19, wherein The target data includes: current target data and historical target data; The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device, including: The analysis function obtains a signaling storm analysis model based on the historical target data; The analysis function performs analysis based on the signaling storm analysis model and the current target data to obtain a signaling storm analysis result of the first network side device.

21. The method according to claim 8, wherein The network-side device for managing the first network-side device, or the network-side device for managing the fourth network-side device, includes an operation, administration, and maintenance function OAM.

22. The method according to claim 8, wherein In the case where the first network side device includes an access network device, the fourth network side device includes other access network devices other than the first network side device, or the fourth network side device includes a core network device; in the case where the first network side device includes a core network device, and the fourth network side device includes a core network device, the fourth network side device includes other core network devices other than the first network side device, access network devices and at least one of other network functions.

23. The method according to any one of claims 16 to 19, wherein: The control function comprises a network function consumer.

24. The method according to any one of claims 1 to 23, wherein The analysis function includes a network data analysis function NWDAF.

25. A method for processing a signaling storm, wherein: The method comprises: The control function receives the signaling storm analysis result sent by the analysis function; The control function performs a signaling storm control operation according to the signaling storm analysis result; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

26. The method according to claim 25, wherein The reasons include at least one of the following: The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself; The network-side device signaling storm is caused by other network-side devices except the first network-side device.

27. The method according to claim 25 or 26, wherein The signaling storm analysis result also includes at least one of the following: The level of signaling storm; The development trend of signaling storms; Duration of the signaling storm; Characteristic information of abnormal signaling; an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device interacting with the first network-side device; Feature information of the abnormal network-side device; confidence level; Prediction time.

28. The method according to claim 27, wherein The characteristic information of the abnormal signaling includes at least one of the following: Abnormal signaling message; The signaling type of the abnormal signaling; The proportion of abnormal signaling in all signaling.

29. The method according to claim 27 or 28, wherein The characteristic information of the abnormal network side device includes at least one of the following: abnormal behavior of the abnormal network side device; The category of the abnormal network-side device.

30. The method according to any one of claims 25 to 29, wherein Before the control function receives the signaling storm analysis result sent by the analysis function, the method further includes: The control function sends a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

31. The method according to claim 30, wherein The first analysis request includes at least one of the following: An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis; an analysis target, where the analysis target is used to indicate the first network-side device; Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

32. The method according to claim 30 or 31, wherein The control function sends a first analysis request to the analysis function, comprising: The control function obtains a network performance analysis result of the first network side device; When the network performance analysis result indicates that resource usage of the first network-side device is in an abnormal state, the control function sends the first analysis request to the analysis function.

33. The method according to claim 32, wherein The control function obtains the network performance analysis result of the first network side device, including: The control function sends a second analysis request to the analysis function, where the second analysis request is used to request analysis of network performance of the first network-side device; The control function receives the network performance analysis result of the first network side device sent by the analysis function.

34. The method according to any one of claims 26 to 33, wherein The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the local policy of the control function for the first network side device according to the identification of the first network side device, so that the first network side device cannot be discovered.

35. The method according to any one of claims 27 to 33, wherein The control function performs a signaling storm control operation according to the signaling storm analysis result, including When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the local policy of the control function for the abnormal network side device according to the identification of the abnormal network side device, so that the abnormal network side device cannot be discovered.

36. The method according to any one of claims 26 to 33, wherein The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the first slice information of the first network side device to second slice information according to the identifier of the first network side device, and the first slice information is different from the second slice information.

37. The method according to any one of claims 27 to 33, wherein The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the third slice information of the abnormal network side device to the fourth slice information according to the identification of the abnormal network side device, and the third slice information is different from the fourth slice information.

38. The method according to any one of claims 26 to 33, wherein The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the network-side device signaling storm is caused by an abnormality of the first network-side device itself, the control function notifies the first network-side device to release connections with all other network-side devices.

39. The method according to any one of claims 27 to 33, wherein The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the first network side device to release the connection with the abnormal network side device.

40. The method according to any one of claims 27 to 33, wherein The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the abnormal network side device to release the connection with the first network side device.

41. A signaling storm processing device, wherein: Applied to the analysis function, the device comprises: Acquisition module, used to obtain target data; An analysis module, configured to analyze the target data to obtain a signaling storm analysis result of the first network-side device; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

42. The processing device according to claim 41, wherein The acquisition module includes: A first acquisition submodule, configured to acquire first data from a second network-side device; The second network-side device includes at least one of the following: the first network-side device; A network-side device for managing the first network-side device.

43. The processing device according to claim 42, wherein The first data includes at least one of the following: signaling characteristic information of the first network-side device; Network capacity information of the first network-side device.

44. The processing device according to claim 42 or 43, wherein The acquisition module further includes: A second acquisition submodule, configured to acquire second data from a third network-side device; The third network-side device includes at least one of the following: a fourth network-side device accessing the first network-side device; A network-side device for managing the fourth network-side device.

45. A signaling storm processing device, wherein: Applied to the control function, the device comprises: An analysis result receiving module is used to receive the signaling storm analysis results sent by the analysis function; A signaling storm control module, configured to perform a signaling storm control operation according to the signaling storm analysis result; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

46. The processing device according to claim 45, wherein The processing device further includes: The first analysis request sending module is used to send a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

47. The processing device according to claim 46, wherein The first analysis request includes at least one of the following: An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis; an analysis target, where the analysis target is used to indicate the first network-side device; Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

48. The processing device according to claim 46 or 47, wherein The first analysis request sending module includes: A network performance analysis result acquisition submodule, configured to acquire a network performance analysis result of the first network-side device; The first analysis request sending submodule is used to send the first analysis request to the analysis function when the network performance analysis result indicates that the resource usage of the first network side device is in an abnormal state.

49. The processing device according to claim 48, wherein The network performance analysis result acquisition submodule includes: A second analysis request sending unit, configured to send a second analysis request to the analysis function, wherein the second analysis request is used to request analysis of network performance of the first network-side device; A network performance analysis result receiving unit is used to receive the network performance analysis result of the first network side device sent by the analysis function.

50. A communication device, wherein: It includes a processor and a memory, the memory storing a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the method for processing a signaling storm as described in any one of claims 1 to 24, or implements the steps of the method for processing a signaling storm as described in any one of claims 25 to 40.

51. A readable storage medium, wherein: The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, it implements the method for processing a signaling storm as described in any one of claims 1 to 24, or implements the steps of the method for processing a signaling storm as described in any one of claims 25 to 40.

52. A computer program product, wherein The method comprises computer instructions, which, when executed by a processor, implement the steps of the method for processing a signaling storm as described in any one of claims 1 to 24, or the method, when executed by a processor, implement the steps of the method for processing a signaling storm as described in any one of claims 25 to 40.

Citation Information

Patent Citations

  • Signaling storm blocking method, device and equipment and storage medium

    CN112448894A

  • Behavior processing method and device, terminal, network side equipment and medium

    CN117014922A

  • Detection and relaxation of signaling abnormality in wireless network

    JP2018078546A