Signaling storm analysis method and apparatus, signaling storm control method and apparatus, and communication device
By acquiring and analyzing the target data of the signaling storm and identifying and controlling the signaling storm network elements, the network processing capacity exceeds the limit caused by the signaling storm is solved, and network stability and user experience are improved.
Patent Information
- Application Number
- PCT/CN2025/076152
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2025-02-07
- Publication Date
- 2025-08-14
AI Technical Summary
In 3GPP network, signaling storms cause network element processing capabilities to exceed the limit, resulting in signaling packet loss and user requests that cannot be processed, affecting the user experience.
The target data is obtained through the first network element, and the analysis results of the signaling storm are analyzed, including the network element identification and cause of the signaling storm that is suffered or is about to be subjected to the signaling storm, and signaling storm control is performed.
Reduce the probability of signaling storms and improve communication stability and user experience.
Smart Images

Figure CN2025076152_14082025_PF_FP_ABST
Abstract
Description
Signaling storm analysis method, control method, device and communication equipment
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to Chinese Patent Application No. 202410175214.6 filed in China on February 7, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] The present application belongs to the field of wireless communication technology, and specifically relates to a signaling storm analysis method, control method, device and communication equipment. Background Art
[0004] Signaling storms may occur in Third Generation Partnership Projects (3GPP) networks. This may be caused by user equipment (UE, also known as a terminal) sending a large amount of signaling to network elements (such as base stations (next generation Node B (gNB)) or other network functions (NF) such as Access and Mobility Management Function (AMF)), causing the network element to receive more signaling than it can process. Once this happens, subsequent signaling from other terminals cannot be processed, resulting in signaling packet loss at the terminal, and user requests cannot be processed, affecting the user's service experience. Summary of the Invention
[0005] The embodiments of the present application provide a signaling storm analysis method, control method, apparatus, and communication device, which can obtain signaling storm analysis results through data analysis, thereby reducing the probability of signaling storm occurrence and improving communication stability.
[0006] In a first aspect, a signaling storm analysis method is provided, the method comprising:
[0007] The first network element obtains target data;
[0008] The first network element analyzes the target data to obtain a signaling storm analysis result, wherein the signaling storm analysis result includes an identifier of a second network element that has suffered or is about to suffer a signaling storm and at least one of a signaling storm cause, wherein the signaling storm cause includes indication information for indicating that the signaling storm is a terminal signaling storm.
[0009] In a second aspect, a method for controlling a signaling storm is provided, the method comprising:
[0010] The third network element receives a signaling storm analysis result, where the signaling storm analysis result includes at least one of an identifier of the second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, where the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm.
[0011] The third network element performs a signaling storm control operation according to the signaling storm analysis result.
[0012] In a third aspect, a signaling storm analysis device is provided, comprising:
[0013] Acquisition module, used to obtain target data;
[0014] The first analysis module is used to analyze according to the target data to obtain a signaling storm analysis result, wherein the signaling storm analysis result includes an identifier of a second network element that has suffered or is about to suffer a signaling storm and at least one of a signaling storm cause, and the signaling storm cause includes indication information for indicating that the signaling storm is a terminal signaling storm.
[0015] In a fourth aspect, a signaling storm control device is provided, including:
[0016] a first receiving module, configured to receive a signaling storm analysis result, the signaling storm analysis result including at least one of an identifier of a second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, the signaling storm cause including indication information indicating that the signaling storm is a terminal signaling storm;
[0017] A control module is used to perform signaling storm control operations according to the signaling storm analysis result.
[0018] In a fifth aspect, a communication device is provided, which terminal includes a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the signaling storm analysis method as described in the first aspect are implemented, or when the program or instruction is executed by the processor, the steps of the signaling storm control method as described in the second aspect are implemented.
[0019] In a sixth aspect, a communication device is provided, comprising a processor and a communication interface, wherein the processor is used to obtain target data; perform analysis based on the target data to obtain a signaling storm analysis result, wherein the signaling storm analysis result includes an identifier of a second network element that has suffered or is about to suffer a signaling storm and at least one of the causes of the signaling storm, and the signaling storm cause includes indication information for indicating that the signaling storm is a terminal signaling storm.
[0020] In the seventh aspect, a communication device is provided, including a processor and a communication interface, wherein the communication interface is used to receive a signaling storm analysis result, the signaling storm analysis result includes an identifier of a second network element that has suffered or is about to suffer a signaling storm and at least one of the causes of the signaling storm, and the signaling storm cause includes indication information for indicating that the signaling storm is a terminal signaling storm; the processor is used to perform a signaling storm control operation according to the signaling storm analysis result.
[0021] In an eighth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the signaling storm analysis method as described in the first aspect are implemented, or the steps of the signaling storm control method as described in the second aspect are implemented.
[0022] In the ninth aspect, a wireless communication system is provided, including: a first network element and a third network element, wherein the first network element can be used to execute the steps of the signaling storm analysis method as described in the first aspect, and the third network element can be used to execute the steps of the signaling storm control method as described in the second aspect.
[0023] In the tenth aspect, a chip is provided, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run a program or instruction to implement the signaling storm analysis method as described in the first aspect, or to implement the signaling storm control method as described in the second aspect.
[0024] In the eleventh aspect, a computer program product is provided, comprising computer instructions, which, when executed by a processor, implement the steps of the signaling storm analysis method described in the first aspect above, or, when executed by a processor, implement the steps of the signaling storm control method described in the second aspect above.
[0025] In an embodiment of the present application, a signaling storm caused by terminal signaling is analyzed in the network element based on the target data to obtain a signaling storm analysis result, so that the signaling storm can be controlled according to the signaling storm analysis result, thereby enhancing the stability of the network and improving the user's service experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] FIG1 is a block diagram of a wireless communication system applicable to embodiments of the present application;
[0027] FIG2 is a flow chart of a method for analyzing a signaling storm according to an embodiment of the present application;
[0028] FIG3 is a flow chart of a method for controlling a signaling storm according to an embodiment of the present application;
[0029] FIG4 is a flow chart of a method for analyzing and controlling a signaling storm according to an embodiment of the present application;
[0030] FIG5 is a second flow chart of a method for analyzing and controlling a signaling storm according to an embodiment of the present application;
[0031] FIG6 is a schematic diagram of the structure of a signaling storm analysis device according to an embodiment of the present application;
[0032] FIG7 is a schematic structural diagram of a signaling storm control device according to an embodiment of the present application;
[0033] FIG8 is a schematic structural diagram of a communication device according to an embodiment of the present application;
[0034] FIG9 is a schematic structural diagram of a network-side device according to an embodiment of the present application. DETAILED DESCRIPTION
[0035] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0036] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0037] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.
[0038] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for example purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th Generation (6G) communication systems.
[0039] FIG1 is a block diagram of a wireless communication system applicable to an embodiment of the present application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device (Wearable Device), an aircraft (Flight Vehicle), a vehicle-mounted device (VUE), a ship-mounted device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), a game console, a personal computer (PC), an ATM, or a self-service machine, or other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may include an access network device or a core network device, wherein the access network device may also be called a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit. The access network device may include a base station, a wireless local area network (WLAN) access point (AP) or a wireless fidelity (WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
[0040] The core network device may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application server discovery function (EASDF), unified data management (UDM), unified data storage (UDR), home user server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BNSF), network access function (UE ... Function, BSF), application function (AF), network data analysis function (NWDAF), operation, management, maintenance (OAM) functions, etc. It should be noted that in the embodiment of the present application, only the core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited.
[0041] The following, in conjunction with the accompanying drawings, describes in detail the signaling storm analysis method, control method, apparatus, and communication device provided by the embodiments of the present application through some embodiments and their application scenarios.
[0042] Referring to FIG. 2 , an embodiment of the present application provides a signaling storm analysis method, including:
[0043] Step 21: The first network element obtains target data;
[0044] The target data is the input data for signaling storm analysis.
[0045] Step 22: The first network element analyzes the target data to obtain a signaling storm analysis result;
[0046] The signaling storm analysis result includes at least one of an identifier of a second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, wherein the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm. The signaling storm analysis result is output data of the signaling storm analysis.
[0047] The terminal signaling storm is a signaling storm caused by terminal signaling, which is caused by the terminal sending a large amount of signaling to the second network element, resulting in the signaling received by the second network element exceeding the upper limit that the second network element can process.
[0048] The second network element identifies the signaling storm target. The identifier of the second network element can identify a single second network element, for example, through a cell identifier (cell Identity, cell ID), an identifier of a network function instance (NF instance ID), or can identify multiple second network elements, for example, through a tracking area (Tracking Area, TA), an area of interest (Area of Interest, AoI), a single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI) and other identifiers.
[0049] In some embodiments, the analysis may optionally be signaling storm detection, such as detecting the number or ratio of failure messages currently sent to the network element, detecting the number or ratio of unresponsive messages currently sent to the network element, detecting the current terminal capacity of the network element, or detecting the current behavior of terminals served by the network element. In this case, the signaling storm analysis result is a signaling storm detection result, and the signaling storm analysis result may include at least one of an identifier of the second network element experiencing the signaling storm and a cause of the signaling storm. That is, the second network element is experiencing a signaling storm.
[0050] In some embodiments, the signaling storm analysis may optionally be a signaling storm prediction, for example, detecting the number or ratio of historical and current failure messages of a network element and predicting a trend, detecting the number or ratio of historical and current unresponsive messages of a network element and predicting a trend, detecting the current capacity of a network element and predicting a capacity change trend, or detecting the current behavior of a terminal and predicting a behavior trend. In this case, the signaling storm analysis result is a signaling storm prediction result. The signaling storm analysis result may include at least one of an identifier of a second network element that is about to experience a signaling storm and a cause of the signaling storm. That is, the second network element is predicted to be likely to experience a signaling storm.
[0051] In an embodiment of the present application, the conditions for determining whether the second network element has suffered or is about to suffer a signaling storm may be, for example: when the current proportion of failure messages of the second network element exceeds 50%, it is determined that the second network element has suffered a signaling storm; when the current proportion of failure messages of the second network element exceeds 40% and has an upward trend, it is determined that the second network element is about to suffer a signaling storm.
[0052] In an embodiment of the present application, a signaling storm caused by terminal signaling is analyzed in the network element based on the target data to obtain a signaling storm analysis result, so that the signaling storm can be controlled according to the signaling storm analysis result, thereby enhancing the robustness of the network and improving the user's service experience.
[0053] In some embodiments, optionally, the first network element may be a network data analytics function (NWDAF), which may collect various data generated in the network, perform intelligent data analysis, and ultimately generate corresponding data analysis results to detect or predict various events occurring in the network. Of course, the first network element may also be other network elements that can collect target data and perform data analysis, and this application does not limit this.
[0054] In some embodiments, optionally, the second network element can be a network function (NF) that performs signaling interaction with the terminal, such as a base station (gNB), a wireless local area network (WLAN), an AMF or an SMF.
[0055] A signaling storm is characterized by abnormal resource usage (e.g., 100% CPU usage and 100% memory usage) of a network element. Therefore, the triggering condition for signaling storm analysis can be determined by the resource usage of the network element.
[0056] In some embodiments, optionally, before the first network element obtains the target data, the method further includes:
[0057] The first network element obtains a network performance analysis result of the second network element;
[0058] When the network performance analysis result indicates that the second network element is in an abnormal resource usage state, the first network element triggers the acquisition of target data, and the first network element analyzes the target data to obtain a signaling storm analysis result.
[0059] For example, if the resource usage of the second network element exceeds a certain threshold (such as CPU usage greater than 90%), the first network element triggers the start of signaling storm analysis and starts acquiring target data.
[0060] Signaling storms on the network side caused by signaling sent by terminals may be caused by the following two reasons:
[0061] Cause on the target side: The network element's own signaling processing capability is insufficient and cannot handle requests sent by a large number of terminals, resulting in a signaling storm.
[0062] Source-side cause: A group of terminals accessing the network element are in an abnormal state (such as being maliciously controlled or being turned on and off simultaneously in the same area). They repeatedly send messages, causing a surge in message processing by the network element, resulting in a signaling storm.
[0063] Therefore, in some embodiments, optionally, the signaling storm cause is further used to indicate that the terminal signaling storm is caused by insufficient processing capability of the second network element, or that the terminal signaling storm is caused by an abnormal terminal.
[0064] Optionally, the signaling storm cause may also indicate a more specific cause, for example, the terminal signaling storm is caused by terminal aggregation, the terminal signaling storm is caused by the terminal sending a large amount of signaling at the same time, the terminal signaling storm is caused by the terminal being maliciously controlled, the terminal signaling storm is caused by terminal application, the terminal signaling storm is caused by insufficient CPU of the second network element, or the terminal signaling storm is caused by insufficient memory of the second network element, etc.
[0065] The target data of the embodiment of the present application may include at least one of the following:
[0066] First data, where the first data is signaling characteristic data of the second network element.
[0067] Second data, where the second data is terminal capacity information of the second network element.
[0068] The third data is the first behavior data of the terminal served by the second network element.
[0069] Fourth data, the fourth data is a behavior data analysis result of second behavior data of the terminal served by the second network element.
[0070] The following describes the above four types of target data and the corresponding types of signaling storm analysis results.
[0071] In some embodiments, the target data may optionally include first data, where the first data is signaling characteristic data of the second network element. The signaling characteristic data may indicate characteristics of signaling failure of the terminal, reflecting characteristics of a signaling storm.
[0072] When a network element encounters a signaling storm, it may continuously reject the terminal's requests, resulting in a large number of rejection messages to reject the terminal's requests, or not process / discard the terminal's requests, resulting in an increase in the proportion of unresponsive request messages.
[0073] Therefore, in some embodiments, optionally, the signaling characteristic data includes at least one of the following information of the terminal served by the second network element: the number of target signaling failure messages, the number of all target signalings, the proportion of target signaling failure messages to all target signalings, the number of unresponsive target request messages, the number of all target request messages, and the proportion of unresponsive target request messages to all target request messages.
[0074] A signaling storm may cause a large number of rejection messages to reject the terminal's request, or not process / discard the terminal's request, resulting in an increase in the number / proportion of unresponsive request messages. Therefore, the above signaling feature data can reflect the characteristics of the signaling storm.
[0075] In some embodiments, optionally, the target signaling includes at least one of Radio Resource Control (RRC) signaling and Non-Access Stratum (NAS) signaling. Optionally, if the second network element is a base station, the target signaling is RRC signaling; if the second network element is an AMF or SMF, the target signaling is NAS signaling.
[0076] In some embodiments, optionally, the target request message includes at least one of an RRC request message and a NAS request message. Optionally, if the second network element is a base station, the target request message is an RRC request message; if the second network element is an AMF or SMF, the target request message is a NAS request message. The target signaling includes the target request message.
[0077] In some embodiments, optionally, the target signaling failure message includes at least one of the following: RRC Reject message, RRC Release message, Registration Reject message, Service Reject message, Authentication Reject message, Protocol Data Unit (PDU) session establishment Reject message, PDU session modification Reject message, PDU session release Reject message;
[0078] Optionally, if the second network element is a base station, the target signaling failure message includes at least one of the following: an RRC reject (Reject) message, an RRC release (Release) message.
[0079] Optionally, if the second network element is AMF, the target signaling failure message includes at least one of the following: a registration reject (Registration Reject) message, a service reject (Service Reject) message, and an authentication reject (Authentication Reject) message.
[0080] Optionally, if the second network element is SMF, the target signaling failure message includes at least one of the following: a protocol data unit (PDU) session establishment reject (PDU session establishment Reject) message, a PDU session modification reject (PDU session modification Reject) message, and a PDU session release reject (PDU session release Reject) message.
[0081] In some embodiments, optionally, the target request message includes at least one of the following: RRC Setup Request message, RRC Resume Request message, RRC Reestablishment Request message, RRC Reconfiguration Complete message, Registration Request message, Service Request message, control plane service request message, PDU session establishment Request message, PDU session modification Request message, and PDU session release Request message.
[0082] Optionally, if the second network element is a base station, the target request message includes at least one of the following: an RRC setup request (RRC Setup Request) message, an RRC resume request (RRC Resume Request) message, an RRC reestablishment request (RRC Reestablishment Request) message, and an RRC reconfiguration complete (RRC Reconfiguration Complete) message.
[0083] Optionally, if the second network element is AMF, the target request message includes at least one of the following: a registration request (Registration Request) message, a service request (Service Request) message, and a control plane service request message.
[0084] Optionally, if the second network element is SMF, the target request message includes at least one of the following: a PDU session establishment request (PDU session establishment Request) message, a PDU session modification request (PDU session modification Request) message, and a PDU session release request (PDU session release Request) message.
[0085] Optionally, the terminals served by the second network element may be all terminals served by the second network element, or may be some terminals served by the second network element.
[0086] Optionally, the signaling feature data may be the signaling feature data of each terminal or the signaling feature data of all terminals. It should be noted that if the signaling feature data of each terminal is not counted but only the signaling feature data of all terminals is counted, the specific abnormal terminal cannot be located.
[0087] Thus, optionally, the signaling feature data also includes at least one of an identifier and a category of the terminal served by the second network element. The categories include, for example, access category, access identifier, type allocation code (TAC), and single network slice selection assistance information (S-NSSAI). When the signaling feature data includes the identifier of the terminal, the specific abnormal terminal can be located.
[0088] Optionally, the signaling characteristic data further includes time period information, which is used to indicate a time period for collecting the signaling characteristic data.
[0089] In some embodiments, optionally, the signaling storm analysis result further includes at least one of the following:
[0090] The level of the signaling storm is used to indicate the severity of the signaling storm, for example, it can be low, medium, or high;
[0091] The trend of the signaling storm is used to indicate the possible subsequent trend of the signaling storm, such as rising, falling, unknown, stable, etc.
[0092] The signaling type of the signaling storm is used to indicate the type of signaling that caused the signaling storm, such as RRC, NAS, etc.
[0093] Abnormal signaling message, used to indicate the signaling message that caused the signaling storm, such as RRC Reject;
[0094] The ratio of abnormal signaling to normal signaling;
[0095] Signaling storm duration, used to indicate the possible duration of the signaling storm.
[0096] The level of the signaling storm, its trend, the type of signaling involved, abnormal signaling messages, and the ratio of abnormal signaling to normal signaling can all be determined by analyzing signaling feature data, particularly signaling failure characteristics. The duration of the signaling storm can be determined by additional analysis of the time period.
[0097] In some embodiments, the first network element obtaining target data includes:
[0098] The first network element sends a first data collection request to Operation Administration Maintenance (OAM) or the second network element;
[0099] The first network element receives the first data from the OAM or the second network element.
[0100] Optionally, the first data collection request may obtain the first data of the second network element from the OAM periodically or irregularly by calling a subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS28.532).
[0101] Optionally, if the first network obtains the first data directly from the second network element, for example, when the second network element is AMF / SMF, the Event_Exposure event reporting service of AMF / SMF can be called. Based on the subscription-notification mode, the subscriber will periodically or irregularly send the first data of AMF / SMF to NWDAF. It can also be based on a request-response mode, with one request and one reply.
[0102] In some embodiments, the target data includes second data, and the second data is terminal capacity information of the second network element.
[0103] The terminal capacity information of the second network element is used to indicate the number of terminals currently served by the second network element. This information may be expressed as the number of terminals served by a single second network element, or as the number of terminals served by a group of second network elements (for example, when the second network element is a base station, this information may be expressed as the number of terminals served by a TA or an Area of Interest).
[0104] Optionally, the second data further includes at least one of an identifier and a category of a terminal served by the second network element.
[0105] In some embodiments, optionally, if the target data includes the second data, the signaling storm analysis result further includes: the signaling storm cause indicates that the processing capability of the second network element is insufficient, or the terminal signaling storm is caused by an abnormal terminal.
[0106] The terminal capacity information of the second network element can be used to infer the cause of the signaling storm. For example, when the number of terminals is small but the signaling is large, it may be caused by terminal abnormality. When the number of terminals is large and the signaling is also large, it may be caused by insufficient capacity of the second network element itself.
[0107] In some embodiments, optionally, the first network element acquiring target data includes:
[0108] The first network element sends a second data collection request to the OAM or the second network element;
[0109] The first network element receives the second data from the OAM or the second network element.
[0110] In some embodiments, the first network element may also send a second data collection request to the NF (eg, AMF, Location Services (LCS), SMF, or AF); and receive the second data from the NF.
[0111] In some embodiments, the target data may optionally include third data, where the third data is first behavior data of a terminal served by the second network element. The first behavior data may be used to analyze whether the terminal is abnormal.
[0112] In some embodiments, optionally, the first behavior data of the terminal includes at least one of mobility behavior data and session behavior data of the terminal.
[0113] In some embodiments, optionally, before the first network element performs analysis based on the target data, the method further includes:
[0114] The first network element sends a third data collection request to the AMF, SMF or UDM;
[0115] The first network element receives the third data from the AMF, SMF or UDM.
[0116] Optionally, the third data collection request can be generated by calling the Event_Exposure event reporting service of the AMF, SMF, or UDM. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send the third data to the NWDAF. Alternatively, it can be based on a request-response model, where each request is responded to once.
[0117] For example, when the third data is obtained from the AMF, the third data may include at least one of the following: the terminal identifier, the terminal's single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI), the terminal's location (such as Tracking Area Identity (TAI)), the terminal's category (such as Type Allocation Code (TAC)), the number of terminal registration updates (used to indicate the number of times the terminal sends a registration request), the terminal access performance trend (used to measure changes in the terminal's mobility status, such as access, switching, etc.), and the terminal's location change trend (used to measure changes in the UE's location).
[0118] When the third data is obtained from the SMF, the third data may include at least one of the following: terminal identification, terminal S-NSSAI, data network name (DNN), application identification, expected behavior (including expected terminal movement trajectory, whether the terminal is fixed in position, terminal communication duration, terminal communication interval, terminal communication time, etc.), communication start / end time, uplink and downlink data rate, total traffic, PDU session identification, PDU inactivity time and status, terminal session performance trend (used to measure changes in terminal session status, such as session establishment and session release), terminal communication trend (used to measure UE communication changes), etc.
[0119] In some embodiments, the target data may optionally include fourth data, which is a behavior data analysis result of second behavior data of the terminal served by the second network element. The second behavior data may be used to analyze whether the terminal is abnormal, and the second behavior data is not limited herein.
[0120] In some embodiments, optionally, the behavior data analysis result includes at least one of the following: terminal abnormal behavior analysis data and terminal aggregation analysis data.
[0121] Optionally, the terminal abnormal behavior analysis data may include at least one of the following: abnormal terminal location, abnormal terminal wake-up, ping-pong effect of the terminal, and unknown wireless link failure of the terminal; the terminal concentration analysis data may include at least one of the following: the number of terminals in a certain area, and the proportion of concentrated terminals in the terminals requested for analysis.
[0122] In some embodiments, optionally, the signaling storm analysis result also includes at least one of the following: abnormal terminal identification, abnormal terminal behavior (if the cause is an abnormal terminal, it may include abnormal terminal location, abnormal terminal wake-up, ping-pong effect of the terminal, unknown wireless link failure of the terminal, etc.), abnormal terminal location, abnormal terminal category (available access category, access identifier, TAC, S-NSSAI, etc.).
[0123] The abnormal terminal identification, abnormal terminal behavior, abnormal terminal location, and abnormal terminal category can all be obtained by analyzing the terminal's behavior data. The terminal's behavior data may include the terminal's signaling feature data in the first data, the terminal's first behavior data in the third data, and the terminal's abnormal behavior analysis data in the fourth data.
[0124] In some embodiments, optionally, before the first network element performs analysis based on the target data, the method further includes:
[0125] The first network element analyzes second behavior data of the terminal served by the second network element to obtain the behavior data analysis result.
[0126] In some embodiments, optionally, the first network element acquiring the target data includes:
[0127] Responding to the signaling storm analysis request, acquiring the target data;
[0128] The signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
[0129] In some embodiments, optionally, before the first network element obtains the target data, the method includes:
[0130] The first network element receives a signaling storm analysis request sent by a third network element.
[0131] In some embodiments, optionally, the signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
[0132] The analysis identifier indicates the current analysis, i.e., signaling storm analysis. The analysis target indicates the target of the analysis, which may be information identifying one or a group of second network elements. For example, when the second network element is a base station, the analysis target may be a cell ID, a tracking area (TA) ID, an area of interest, etc. The analysis time may include at least one of the start time and the end time of the analysis. The analysis time may also be a periodic time, i.e., the analysis is a periodic analysis.
[0133] Alternatively, a signaling storm analysis request can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former (Nnwdaf_AnalyticsSubscription_Subscribe) uses a subscription-notification model, where the subscriber periodically or sporadically sends signaling storm analysis results to the NF consumer. The latter (Nnwdaf_AnalyticsInfo_Request) uses a request-response model, with a single request and a single reply.
[0134] In some embodiments, optionally, after the first network element performs analysis based on the target data to obtain a signaling storm analysis result, the method further includes: the first network element sends the signaling storm analysis result to a third network element.
[0135] In some embodiments, optionally, the third network element includes a network function consumer (NF consumer), and the network function consumer may be, for example, a network function such as AMF, PCF or OAM.
[0136] In some embodiments, optionally, the target data includes: current target data and historical target data;
[0137] The first network element performs analysis based on the target data, including:
[0138] The first network element obtains a signaling storm analysis model according to the historical target data;
[0139] The first network element performs analysis according to the signaling storm analysis model and the current target data.
[0140] That is, a signaling storm analysis model is trained based on historical target data. When signaling storm analysis is required, the current target data is input into the trained signaling storm analysis model for inference to obtain the signaling storm analysis results.
[0141] Optionally, the signaling storm analysis model can be obtained through machine learning, which can be lightweight machine learning, unsupervised learning, or supervised learning. This application does not limit the specific machine learning method.
[0142] It should be noted that the signaling storm analysis model can be updated as needed, for example, periodically updated according to the most recent historical target data.
[0143] In some embodiments, optionally, if the signaling analysis is a signaling storm prediction, the signaling storm analysis result may also include at least one of the following: the confidence of the current prediction (Confidence, also known as confidence, used to indicate the certainty of the prediction) and the expected time (used to indicate the time when the signaling storm is predicted to occur).
[0144] Since the signaling storm analysis model is obtained by the first network element based on historical target data, it can be understood as the rules generated by a large amount of historical target data. Therefore, when the current target data shows a trend that conforms to this rule, the signaling storm can be predicted, and the confidence and prediction time of the prediction can also be obtained.
[0145] Referring to FIG3 , an embodiment of the present application further provides a method for controlling a signaling storm, including:
[0146] Step 31: The third network element receives a signaling storm analysis result, where the signaling storm analysis result includes at least one of an identifier of the second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, where the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm.
[0147] Optionally, the signaling storm cause may also indicate a more specific cause, for example, the terminal signaling storm is caused by terminal aggregation, the terminal signaling storm is caused by the terminal sending a large amount of signaling at the same time, the terminal signaling storm is caused by the terminal being maliciously controlled, the terminal signaling storm is caused by terminal application, the terminal signaling storm is caused by insufficient CPU of the second network element, or the terminal signaling storm is caused by insufficient memory of the second network element, etc.
[0148] Step 32: The third network element performs a signaling storm control operation according to the signaling storm analysis result.
[0149] In the embodiment of the present application, controlling the signaling storm according to the signaling storm analysis result can enhance the robustness of the network and improve the user's service experience.
[0150] In some embodiments, optionally, the third network element may be a network function consumer, and the network function consumer may be, for example, a network function such as AMF, PCF or OAM.
[0151] In some embodiments, optionally, the second network element may be a network function (NF) such as a base station (gNB), WLAN, AMF or SMF that performs signaling interaction with the terminal.
[0152] In some embodiments, the third network element optionally receives signaling storm analysis results from the first network element. Optionally, the first network element may be a network development and support (NWDAF) controller, which can collect various data generated in the network and perform intelligent data analysis to ultimately generate corresponding data analysis results to detect or predict various events occurring in the network. Of course, the first network element may also be another network element capable of collecting target data and performing data analysis, and this application does not limit this.
[0153] In some embodiments, optionally, before the third network element receives the signaling storm analysis result, the method further includes: the third network element sending a signaling storm analysis request, where the signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
[0154] Optionally, the third network element sends a signaling storm analysis request to the first network element.
[0155] In some embodiments, optionally, the signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
[0156] The analysis identifier indicates the current analysis, i.e., signaling storm analysis. The analysis target indicates the target of the analysis, which may be information identifying one or a group of second network elements. For example, when the second network element is a base station, the analysis target may be a cell ID, a tracking area (TA) ID, an area of interest, etc. The analysis time may include at least one of the start time and the end time of the analysis. The analysis time may also be a periodic time, i.e., the analysis is a periodic analysis.
[0157] Alternatively, a signaling storm analysis request can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former (Nnwdaf_AnalyticsSubscription_Subscribe) uses a subscription-notification model, where the subscriber periodically or sporadically sends signaling storm analysis results to the NF consumer. The latter (Nnwdaf_AnalyticsInfo_Request) uses a request-response model, with a single request and a single reply.
[0158] A network element experiencing a signaling storm is characterized by abnormal resource usage (e.g., 100% CPU usage and 100% memory usage). Therefore, the triggering condition for a signaling storm analysis request can be determined by the resource usage of the network element.
[0159] In some embodiments, optionally, the sending of the signaling storm analysis request by the third network element includes:
[0160] The third network element obtains a network performance analysis result of the second network element;
[0161] When the network performance analysis result indicates that the second network element is in an abnormal resource usage state, the third network element triggers sending the signaling storm analysis request.
[0162] For example, if the resource usage of the second network element exceeds a certain threshold (such as CPU usage greater than 90%), it triggers the sending of the above-mentioned signaling storm analysis request.
[0163] In some embodiments, optionally, the third network element obtaining a network performance analysis result of the second network element includes:
[0164] The third network element sends a network performance analysis request, where the network performance analysis request is used to request a network performance analysis to be performed on the second network element;
[0165] The third network element receives the network performance analysis result of the second network element.
[0166] Optionally, the third network element sends a network performance analysis request to the first network element, and receives a network performance analysis result of the second network element from the first network element.
[0167] Of course, in some embodiments, the third network element may also analyze the network performance of the second network element by itself to obtain the network performance analysis result of the second network element.
[0168] In some embodiments, the analysis may optionally be signaling storm detection, and the signaling storm analysis result is a signaling storm detection result. The signaling storm analysis result may include at least one of an identifier of the second network element experiencing the signaling storm and a cause of the signaling storm. That is, the second network element is experiencing a signaling storm.
[0169] In some embodiments, the signaling storm analysis may optionally be a signaling storm prediction, and the signaling storm analysis result may be a signaling storm prediction result. The signaling storm analysis result may include at least one of an identifier of the second network element that is about to be subjected to a signaling storm and a cause of the signaling storm. That is, the second network element is predicted to be likely to be subjected to a signaling storm.
[0170] In some embodiments, optionally, the signaling storm analysis result further includes at least one of the following:
[0171] The level of the signaling storm is used to indicate the severity of the signaling storm, for example, it can be low, medium, or high;
[0172] The trend of the signaling storm is used to indicate the possible subsequent trend of the signaling storm, such as rising, falling, unknown, stable, etc.
[0173] The signaling type of the signaling storm is used to indicate the type of signaling that caused the signaling storm, such as RRC, NAS, etc.
[0174] Abnormal signaling message, used to indicate the signaling message that caused the signaling storm, such as RRC Reject;
[0175] The proportion of abnormal signaling to normal series;
[0176] Signaling storm duration, which indicates the possible duration of the signaling storm;
[0177] Abnormal terminal identification;
[0178] Abnormal terminal behavior;
[0179] Abnormal terminal position;
[0180] Terminal exception category.
[0181] In the embodiment of the present application, for signaling storm detection, mitigation measures can be taken:
[0182] The signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capabilities of the second network element, or when the terminal signaling storm is caused by an abnormal terminal, the mitigation goals of the signaling storm control operation are: 1) reducing the signaling of the second network element; 2) expanding the capacity of the second network element to enhance the ability of the second network element to process signaling.
[0183] For signaling storm prediction, you can take defensive measures:
[0184] The signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capability of the second network element, or when the terminal signaling storm is caused by an abnormal terminal, the defense goals of the signaling storm control operation are: 1) reducing the signaling of the second network element; 2) expanding the capacity of the second network element to enhance the ability of the second network element to process signaling.
[0185] It can be seen that the goals of signaling storm mitigation and protection are the same, but mitigation is more likely to be achieved through goal 1 because it can more quickly reduce the risk caused and enable the second network element to recover quickly. Defense is more likely to be achieved through goal 2 because it can reduce the processing of terminals by improving the processing capabilities of network elements, thereby reducing the impact on terminals.
[0186] The following describes the signaling storm control operation.
[0187] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal, and the signaling storm analysis result includes the abnormal terminal identifier and the abnormal terminal location, the third network element performs a signaling storm control operation based on the signaling storm analysis result, including: the third network element writes the abnormal terminal location into the mobility restriction of the abnormal terminal, and updates the mobility restriction of the abnormal terminal.
[0188] Optionally, the third network element may be an AMF or a PCF. When the third network element is an AMF, the AMF may update the UE's mobility restrictions through a UE configuration update message. When the third network element is a PCF, the PCF may trigger the AMF to perform the above operations to update the UE's mobility restrictions by updating the UE's mobility policy.
[0189] The beneficial effect of this solution is that the terminal will not select the corresponding cell according to the mobility restriction, or will not send signaling, thereby reducing the signaling for the abnormal terminal to access the second network element.
[0190] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation based on the signaling storm analysis result, including: the third network element assigns a target access category to the abnormal terminal, and sends a first indication message to the second network element that has suffered or is about to suffer a signaling storm, the first indication message being used to indicate access prohibition for the target access category.
[0191] Optionally, the third network element may be an AMF, and the second network element may be a RAN. The AMF may assign a target access category to the abnormal UE through a UE configuration update message. The AMF instructs the RAN to perform access barring for the target access category through an N2 message. The N2 message may be an overload control message, which includes the target access category so that the RAN can perform overload control based on the target access category.
[0192] The beneficial effect of this solution is that the third network element classifies all abnormal UEs into a special access category and then notifies the third network element of the access category. The RAN performs access barring (access bar) by broadcasting the access category. If the terminal belongs to the access category, the terminal no longer initiates uplink RRC signaling, thereby reducing the signaling required for abnormal terminals to access the second network element.
[0193] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal, and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: the third network element assigns an operator-defined access category to the abnormal terminal, and sends a second indication message to the second network element that has suffered or is about to suffer a signaling storm, the second indication message being used to indicate overload control of a high-priority RRC connection (the operator-defined access category is always high priority after being mapped to the RRC cause).
[0194] Optionally, the third network element may be an AMF, and the second network element may be a RAN. The AMF may assign an operator-defined access category to the abnormal UE through a UE configuration update message. Since the RAN regards the operator-defined access category as a high-priority access, the AMF may instruct the RAN to implement access barring for high-priority access through an N2 message. The N2 message may be an overload control message, which includes a high-priority indication so that the RAN can perform overload control based on the high-priority access type.
[0195] The beneficial effect of this solution is that: the access category broadcast by the second network element performs access barring (access bar), and if the terminal belongs to the access category, the terminal no longer initiates uplink RRC signaling, thereby reducing the signaling for abnormal terminals to access the second network element.
[0196] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes a terminal abnormality category, the third network element performs a signaling storm control operation based on the signaling storm analysis result, including: the third network element sends a third indication information to the second network element that has suffered or is about to suffer a signaling storm, and the third indication information is used to indicate the start of overload control for the terminal abnormality category.
[0197] Optionally, the third network element may be an AMF, and the second network element may be a RAN. The AMF may instruct the RAN to perform access barring through an N2 message. The N2 message may be an overload control message.
[0198] The beneficial effect of this solution is that after receiving the notification, the second network element can start overload control, so as to reduce the number of UEs accessing the second network element.
[0199] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: the third network element sends a terminal parameter update (UPU) message to the abnormal terminal, and the terminal parameter update message is used to modify the S-NSSAI of the access slice of the abnormal terminal to a specific S-NSSAI; the third network element sends a fourth indication information to the second network element that has suffered or is about to suffer a signaling storm, and the fourth indication information is used to indicate the start of overload control of the specific S-NSSAI.
[0200] Optionally, the third network element may be an AMF, and the second network element may be a RAN. The AMF may allocate a new S-NSSAI to the abnormal UE through a UE configuration update message. The AMF may instruct the RAN to perform access barring for the new S-NSSAI through an N2 message. The N2 message may be an overload control message, which includes the new S-NSSAI, so that the RAN can perform overload control based on the S-NSSAI.
[0201] The beneficial effect of this solution is that the third network element first allocates a new S-NSSAI to the abnormal terminal and notifies the RAN to overload control the S-NSSAI, so that the terminal does not select the network element in the original S-NSSAI when selecting a network, thereby reducing the signaling requests of the abnormal terminal to the second network element.
[0202] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: the third network element releases the context of the abnormal terminal.
[0203] Optionally, the third network element may be an AMF, and the second network element may be a RAN. The AMF may instruct the RAN to perform RRC release on the abnormal terminal through an N2 message, and the RAN sends an RRC Release message to the UE according to the N2 message to release the UE's RRC connection. The N2 message may be a UE context release command message, which includes an identifier of the abnormal terminal.
[0204] The beneficial effect of this solution is that the third network element triggers the release of the context of the abnormal UE, thereby reducing the storage context of the abnormal terminal in the second network element and improving resource utilization.
[0205] Among them, the terminal signaling storm caused by an abnormal terminal can also be expressed as the terminal signaling storm caused by terminal aggregation, the terminal signaling storm caused by terminals sending a large amount of signaling at the same time, the terminal signaling storm caused by terminals being maliciously controlled, or the terminal signaling storm caused by terminal applications.
[0206] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capacity of the second network element, the third network element performs a signaling storm control operation based on the signaling storm analysis result, including: the third network element sends a fifth indication information to the second network element that has suffered or is about to suffer a signaling storm, and the fifth indication information is used to indicate the start of overload control.
[0207] Optionally, the third network element may be an AMF, and the second network element may be a RAN. The AMF may instruct the RAN to perform access barring through an N2 message. The N2 message may be an overload control message.
[0208] The beneficial effect of this solution is that after the second network element turns on overload control, it will reject the access of terminals according to a certain ratio, thereby extending the processing time in exchange for improved performance of the second network element.
[0209] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capacity of the second network element, the third network element performs a signaling storm control operation based on the signaling storm analysis result, including: the third network element instructs the second network element that has suffered or is about to suffer a signaling storm to perform RRC release on the existing inactive terminals, so as to obtain more resources to cope with the signaling storm by releasing the terminals.
[0210] Optionally, the third network element may be an AMF, and the second network element may be a RAN. The AMF may instruct the RAN to perform RRC release on certain UEs through an N2 message. The N2 message may be a UE context release command message.
[0211] The beneficial effect of this solution is that by releasing some UE contexts, the storage space on the second network element is expanded, thereby reducing the burden on the second network element.
[0212] In some embodiments, optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capacity of the second network element, the third network element performs a signaling storm control operation based on the signaling storm analysis result, including: the third network element expands resources for the second network element that has suffered or is about to suffer a signaling storm, and the expanded resources include adding more computing and storage capabilities to the virtual machine.
[0213] Optionally, the third network element may be OAM, and the second network element may be a core network element such as RAN, AMF, or SMF.
[0214] The beneficial effect of this solution is that the processing capability of the second network element is improved by expanding the computing and storage capabilities of the second network element.
[0215] The following describes the signaling storm analysis method and signaling storm control method of the present application with examples in combination with specific application scenarios.
[0216] Example 1 of this application:
[0217] In this embodiment of the present application, a gNB (i.e., the aforementioned second network element) is detected to determine whether it is experiencing a signaling storm. In this embodiment, the first network element performing signaling storm analysis is the NWDAF, and the third network element performing signaling storm control is the network function consumer (NF consumer).
[0218] Referring to FIG4 , the signaling storm analysis method and the signaling storm control method according to an embodiment of the present application include the following steps:
[0219] Step 1: A network function consumer (NF consumer) sends a signaling storm analysis request to the NWDAF, where the signaling storm analysis request is used to request a base station to perform a signaling storm analysis.
[0220] Optionally, the signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
[0221] The analysis flag indicates the current analysis, i.e., signaling storm analysis. The analysis target indicates the target of the analysis, which can be information identifying one or a group of gNBs, such as the cell ID, tracking area (TA) ID, or area of interest. The analysis time can include at least one of the start and end times of the analysis. The analysis time can also be periodic, indicating that the analysis is performed periodically.
[0222] Optionally, the NF consumer may send a network performance analysis request (see 3GPP TS 23.288 6.6) to the NWDAF in advance. The network performance analysis request is used to request network performance analysis of the gNB and receive the network performance analysis results of the gNB from the NWDAF, thereby obtaining the resource usage of the gNB. The NF consumer may trigger a signaling storm analysis for the gNB based on the resource usage of the gNB. Optionally, the signaling storm analysis request is triggered when the network performance analysis result indicates that the gNB is in an abnormal resource usage state. For example, if the resource usage of the gNB exceeds a certain threshold (such as CPU utilization greater than 90%), the signaling storm analysis request is triggered to be sent to the NWDAF.
[0223] Alternatively, a signaling storm analysis request can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former (Nnwdaf_AnalyticsSubscription_Subscribe) uses a subscription-notification model, where the subscriber periodically or sporadically sends signaling storm analysis results to the NF consumer. The latter (Nnwdaf_AnalyticsInfo_Request) uses a request-response model, with a single request and a single reply.
[0224] Step 2: NWDAF sends a first data collection request to OAM, where the first data collection request is used to collect first data of the gNB, where the first data is signaling feature data of the gNB.
[0225] The first data collection request can obtain the first data of the gNB from the OAM periodically or irregularly by calling the subscription service (refer to the service described in 3GPP TS28.532 Section 11.6.1.3).
[0226] In some embodiments, optionally, the NWDAF may also directly request the first data of the gNB from the gNB instead of indirectly obtaining it through OAM.
[0227] Step 3: The NWDAF obtains first data of the gNB from the OAM or gNB. The first data is signaling feature data of the gNB.
[0228] Among them, the signaling characteristic data can indicate the characteristics of the terminal's signaling failure (such as RRC Reject, RRC Release, etc.), reflecting the characteristics of the signaling storm.
[0229] Optionally, the signaling characteristic data includes at least one of the following information of the terminal served by the gNB: the number of RRC signaling failure messages, the number of all RRC signaling, the proportion of RRC signaling failure messages to all RRC signaling, the number of unresponsive RRC request messages, the number of all RRC request messages, and the proportion of unresponsive RRC request messages to all RRC request messages.
[0230] Optionally, the RRC signaling failure message includes at least one of the following: an RRC reject (Reject) message, an RRC release (Release) message.
[0231] Optionally, the RRC request message includes at least one of the following: an RRC setup request message, an RRC resume request message, an RRC reestablishment request message, an RRC reconfiguration complete message,
[0232] Optionally, the terminals served by the gNB may be all terminals served by the gNB or some of the terminals served by the gNB.
[0233] Optionally, the signaling feature data may be the signaling feature data of each terminal or the signaling feature data of all terminals. It should be noted that if the signaling feature data of each terminal is not counted but only the signaling feature data of all terminals is counted, the specific abnormal terminal cannot be located.
[0234] For example, when the signaling characteristic data is the signaling characteristic data of each of the terminals, the signaling characteristic data may be expressed as "UE ID1 (S-NSSAI1): number of RRC signaling failure messages: 10, number of all RRC signaling: 50; UE ID2 (S-NSSAI2): number of RRC signaling failure messages: 40, number of all RRC signaling: 60;..."
[0235] Exemplarily, when the signaling characteristic data is the signaling characteristic data of all the terminals, the signaling characteristic data may be expressed as "RAN1: number of RRC signaling failure messages: 1200, number of all RRC signaling: 18000; RAN2: number of RRC signaling failure messages: 8400, number of all RRC signaling: 12000;..."
[0236] Thus, optionally, the signaling characteristic data also includes at least one of an identifier and a category of the terminal served by the gNB. The category includes, for example, an access category and an access identifier. When the signaling characteristic data includes a terminal identifier, the specific abnormal terminal can be located.
[0237] Optionally, the signaling characteristic data further includes time period information, which is used to indicate a time period for collecting the signaling characteristic data.
[0238] A signaling storm may cause a large number of rejection messages to reject the terminal's request, or not process / discard the terminal's request, resulting in an increase in the number / proportion of unresponsive request messages. Therefore, the above signaling feature data can reflect the characteristics of the signaling storm.
[0239] Step 4: Optionally, the NWDAF may also send a second data collection request to the OAM or gNB or NF (e.g., AMF), where the second data collection request is used to collect second data, which is the terminal capacity information of the gNB.
[0240] The gNB's terminal capacity information indicates the number of terminals currently served by the gNB. This information can be expressed as the number of terminals served by a gNB or the number of terminals served by a group of gNBs (e.g., the number of terminals served by a TA or an Area of Interest).
[0241] Step 5: Optionally, the OAM or gNB or NF (e.g., AMF) sends second data to the NWDAF, where the second data is the terminal capacity information of the gNB.
[0242] Optionally, the second data also includes at least one of the identification and category of the terminal served by the gNB.
[0243] It should be noted that the first data request and the second data request in step can be combined into the same message, so that the NWDAF obtains the first data and the second data at the same time.
[0244] The gNB's terminal capacity information can be used to infer the cause of a signaling storm. For example, when there are a small number of terminals but a high amount of signaling, it may be due to a terminal abnormality. When there are a large number of terminals and a high amount of signaling, it may be due to insufficient gNB capacity.
[0245] Step 6: Optionally, the NWDAF sends a third data collection request to the NF (such as AMF, LCS, SMF or AF) to collect third data, where the third data is the first behavior data of the terminal served by the gNB.
[0246] The third data collection request can be made by calling the Event_Exposure event reporting service of the NF. It can be based on a subscription-notification model, where the subscriber will periodically or irregularly send the third data to the NWDAF. It can also be based on a request-response model, where each request is responded to once.
[0247] Step 7: Optionally, the NF sends third data to the NWDAF, where the third data is first behavior data of the terminal served by the gNB. The first behavior data can be used to analyze whether the terminal is abnormal.
[0248] In some embodiments, optionally, the first behavior data of the terminal includes at least one of mobility behavior data and session behavior data of the terminal.
[0249] For example, when the NF is AMF, the third data may include at least one of the following: terminal identification, single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI) of the current slice, terminal location, terminal category (such as type allocation code (TAC)), number of terminal registration updates, terminal access performance trend, and terminal location change trend.
[0250] In the case where the NF is a location service (LCS), the third data may include at least one of the following: an identifier of the terminal, a fine-grained location of the terminal, LCS quality of service (QoS), and a mobility event of the terminal.
[0251] In the case where NF is SMF or AF, the third data may include at least one of the following: terminal identification, terminal S-NSSAI, data network name (DNN), application identification, expected behavior (including expected terminal movement trajectory, whether the terminal is in a fixed position, terminal communication duration, terminal communication interval, terminal communication time, etc.), communication start / end time, uplink and downlink data rates, total traffic, PDU session identification, PDU inactivity time and status, terminal session performance trend, terminal communication trend, etc.
[0252] Step 8: Optionally, the NWDAF may also obtain fourth data, which is a behavior data analysis result of the second behavior data of the terminal served by the gNB. The second behavior data may be used to analyze whether the terminal is abnormal.
[0253] That is, NWDAF can also trigger the analysis of the existing second behavior data of the terminal by itself, and use this to infer the cause of the signaling storm. For example, if the signaling storm is caused by terminal abnormality, then the above behavior data analysis results will help to locate the abnormal terminal and the cause of the abnormality.
[0254] The terminal behavior analysis may include terminal abnormal behavior analysis (see 3GPP TS23.288 6.7.4) and terminal aggregation analysis (see 3GPP TS23.288 6.10). That is, the behavior data analysis result includes at least one of the following: terminal abnormal behavior analysis data and terminal aggregation analysis data.
[0255] The abnormal behavior analysis data of the terminal may include at least one of the following: abnormal location of the terminal, abnormal wake-up of the terminal, ping-pong effect of the terminal, and unknown wireless link failure of the terminal;
[0256] The terminal concentration analysis data may include at least one of the following: the number of terminals in a certain area, and the proportion of the concentrated terminals in the terminals requested for analysis.
[0257] Step 9: The NWDAF analyzes at least one of the first data, the second data, the third data, and the fourth data to obtain a signaling storm analysis result.
[0258] Optionally, the first data includes historical first data and current first data; the second data includes historical second data and current second data; the third data includes historical third data and current third data; and the fourth data includes historical fourth data and current fourth data.
[0259] NWDAF first performs machine learning based on the historical first data, historical second data, historical third data, and historical fourth data to obtain a signaling storm analysis model. When signaling storm analysis is required, the current first data, current second data, current third data, and current fourth data are input into the trained signaling storm analysis model for inference to obtain the signaling storm analysis results.
[0260] Optionally, the above-mentioned machine learning method can be a lightweight machine learning method, or it can be unsupervised learning or supervised learning. This application does not limit the specific machine learning method.
[0261] The signaling storm analysis result may include at least one of a signaling storm detection result and a signaling storm prediction result.
[0262] The output of the signaling storm detection result may include the cause of the signaling storm (for example, caused by insufficient processing capability of the second network element, or caused by an abnormal terminal), the identifier of the affected gNB (identifying the signaling storm target, which may identify a single gNB, for example, by a cell ID, or may identify multiple gNBs, for example, by identifiers such as TA, AoI, S-NSSAI, etc.). Optionally, the signaling storm detection result may also include at least one of the following: the level of the signaling storm (indicating the severity of the signaling storm, such as low, medium, and high), the trend of the signaling storm (the subsequent trend of the signaling storm, such as rising / falling / unknown / stable), the signaling type of the signaling storm (such as RRC), abnormal signaling messages (such as RRC Reject), the proportion of abnormal signaling in normal signaling, the duration of the signaling storm, the abnormal terminal identifier, the abnormal terminal behavior (if the cause is an abnormal terminal, it may include abnormal terminal location, abnormal terminal wake-up, ping-pong effect of the terminal, unknown wireless link failure of the terminal, etc.), abnormal terminal location, abnormal terminal category (available access category, access identifier, TAC, S-NSSAI, etc.).
[0263] The output of the signaling storm prediction result can be based on the above signaling storm detection result to add additional confidence (used to indicate the certainty of the prediction) and expected time (used to indicate the time when the signaling storm is predicted to occur).
[0264] It is particularly important to note that signaling storm prediction can be achieved in the following manner: NWDAF analyzes historical target data (at least one of the first data, second data, third data, and fourth data) and learns that the proportion of rejected signaling for gNB under a certain capacity is normally maintained at 2%. Based on the historical signaling storm analysis results (the administrator labels the signaling storm after it occurs), NWDAF learns that when the proportion of rejected signaling exceeds 10%, it indicates a signaling storm has occurred. NWDAF finds that the current proportion of rejected signaling is gradually increasing from 2% to 4% and has an upward trend. Therefore, NWDAF predicts that a signaling storm may occur in the gNB.
[0265] Step 10: NWDAF sends the above signaling storm analysis results to the NF consumer.
[0266] Step 11: Optionally, the NWDAF obtains updated target data (at least one of the first data, the second data, the third data, and the fourth data) from the NF / OAM.
[0267] Step 12: Optionally, the NWDAF generates an updated signaling storm analysis result based on the updated target data.
[0268] Step 13: Optionally, the NWDAF sends the updated signaling storm analysis result to NF consume.
[0269] Step 14: NF consumer performs signaling storm control based on the signaling storm analysis results.
[0270] Optionally, if the signaling storm analysis result is a signaling storm detection result, the NF consumer will be more inclined to use active terminal control for control; if the signaling storm analysis result is a signaling storm prediction result, the NF consumer will be more inclined to use passive gNB capability enhancement for control.
[0271] Please refer to Table 1, which shows an example of how NF consumer performs signaling storm control based on the signaling storm analysis results.
[0272] Table 1
[0273] Example 2 of this application:
[0274] In the embodiment of the present application, it is detected whether the AMF / SMF (i.e., the second network element mentioned above) is subjected to a signaling storm. In this embodiment, the first network element performing signaling storm analysis is the NWDAF, and the third network element performing signaling storm control is the NF consumer (network function consumer).
[0275] Referring to FIG5 , the signaling storm analysis method and the signaling storm control method according to an embodiment of the present application include the following steps:
[0276] Step 1: NF consumer (network function consumer) sends a signaling storm analysis request to NWDAF, where the signaling storm analysis request is used to request signaling storm analysis of AMF / SMF.
[0277] Optionally, the signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
[0278] The analysis identifier indicates the current analysis, i.e., signaling storm analysis. The analysis target indicates the target of the analysis, which can be information identifying one or a group of AMFs, such as the NF instance ID, NF type, or Area of Interest. The analysis time can include at least one of the start and end times of the analysis. The analysis time can also be periodic, meaning the analysis is performed periodically.
[0279] Optionally, the NF consumer may send a network performance analysis request to the NWDAF in advance (see 3GPP TS 23.288 6.5), where the network performance analysis request is used to request network performance analysis of the AMF / SMF and receive the network performance analysis result of the AMF / SMF from the NWDAF, thereby obtaining the resource usage of the AMF / SMF. The NF consumer may trigger a signaling storm analysis for the AMF / SMF based on the resource usage of the AMF / SMF. Optionally, when the network performance analysis result indicates that the AMF / SMF is in an abnormal resource usage state, the signaling storm analysis request is triggered to be sent. For example, if the resource usage of the AMF / SMF exceeds a certain threshold (such as CPU usage greater than 90%), the above-mentioned signaling storm analysis request is triggered to be sent to the NWDAF.
[0280] Alternatively, a signaling storm analysis request can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former (Nnwdaf_AnalyticsSubscription_Subscribe) uses a subscription-notification model, where the subscriber periodically or sporadically sends signaling storm analysis results to the NF consumer. The latter (Nnwdaf_AnalyticsInfo_Request) uses a request-response model, with a single request and a single reply.
[0281] Step 2: NWDAF sends a first data collection request to OAM / AMF / SMF, where the first data collection request is used to collect first data of AMF / SMF, where the first data is signaling characteristic data of the AMF / SMF.
[0282] The first data collection request can obtain the first data of AMF / SMF from OAM periodically or irregularly by calling a subscription service (refer to the service described in 3GPP TS28.532 Section 11.6.1.3).
[0283] For the first data collection request sent directly to AMF / SMF, the Event_Exposure event reporting service of AMF / SMF can be called. Based on the subscription-notification model, the subscriber will periodically or irregularly send the first data of AMF / SMF to NWDAF. It can also be based on the request-response model, with one request and one reply.
[0284] Step 3: NWDAF obtains first data of AMF / SMF from OAM / AMF / SMF. The first data is signaling characteristic data of the AMF / SMF.
[0285] The first data of AMF can be obtained from OAM or AMF. The first data of SMF can be obtained from OAM or SMF.
[0286] The signaling characteristic data can indicate characteristics of signaling failure of the terminal, reflecting characteristics of a signaling storm.
[0287] Optionally, the signaling characteristic data includes at least one of the following information of the terminal served by the AMF / SMF: the number of NAS signaling failure messages, the number of all NAS signaling, the proportion of NAS signaling failure messages to all NAS signaling, the number of unresponsive NAS request messages, the number of all NAS request messages, and the proportion of unresponsive NAS request messages to all NAS request messages.
[0288] In some embodiments, optionally, the NAS signaling failure message of the AMF includes at least one of the following: a registration reject (Registration Reject) message, a service reject (Service Reject) message, and an authentication reject (Authentication Reject) message.
[0289] In some embodiments, optionally, the NAS request message of the AMF includes at least one of the following: a registration request message, a service request message, and a control plane service request message.
[0290] In some embodiments, optionally, the NAS signaling failure message of the SMF includes at least one of the following: a protocol data unit (PDU) session establishment reject (PDU session establishment Reject) message, a PDU session modification reject (PDU session modification Reject) message, and a PDU session release reject (PDU session release Reject) message.
[0291] In some embodiments, optionally, the NAS request message of the AMF includes at least one of the following: a PDU session establishment request message, a PDU session modification request message, and a PDU session release request message.
[0292] Optionally, the terminals of the AMF / SMF service may be all terminals of the AMF / SMF service or some terminals of the AMF / SMF service.
[0293] Optionally, the signaling feature data may be the signaling feature data of each terminal or the signaling feature data of all terminals. It should be noted that if the signaling feature data of each terminal is not counted but only the signaling feature data of all terminals is counted, the specific abnormal terminal cannot be located.
[0294] Exemplarily, when the signaling characteristic data is the signaling characteristic data of each of the terminals, the signaling characteristic data may be expressed as "UE ID1 (S-NSSAI1): number of NAS signaling failure messages: 10, number of all NAS signaling: 50; UE ID2 (S-NSSAI2): number of NAS signaling failure messages: 40, number of all NAS signaling: 60;..."
[0295] Exemplarily, when the signaling characteristic data is the signaling characteristic data of all the terminals, the signaling characteristic data may be expressed as "AMF1: Number of NAS signaling failure messages: 1200, number of all NAS signalings: 18000; AMF2: Number of NAS signaling failure messages: 8400, number of all NAS signalings: 12000;..."
[0296] Thus, optionally, the signaling feature data also includes at least one of an identifier and a category of the terminal served by the AMF / SMF. The category includes, for example, TAC, S-NSSAI, etc. When the signaling feature data includes the identifier of the terminal, the specific abnormal terminal can be located.
[0297] Optionally, the signaling characteristic data further includes time period information, which is used to indicate a time period for collecting the signaling characteristic data.
[0298] A signaling storm may cause a large number of rejection messages to reject the terminal's request, or not process / discard the terminal's request, resulting in an increase in the number / proportion of unresponsive request messages. Therefore, the above signaling feature data can reflect the characteristics of the signaling storm.
[0299] Step 4: Optionally, NWDAF may also send a second data collection request to OAM / AMF / SMF or other NFs, where the second data collection request is used to collect second data, which is the terminal capacity information of AMF / SMF.
[0300] The terminal capacity information of the AMF / SMF is used to indicate the number of terminals currently served by the AMF / SMF. It can be expressed as the number of terminals served by one AMF / SMF or the number of terminals served by a group of AMF / SMFs (for example, the number of terminals served by one Area of Interest).
[0301] Step 5: OAM / AMF / SMF or other NF sends second data to NWDAF, where the second data is the terminal capacity information of AMF / SMF.
[0302] Optionally, the second data also includes at least one of the identification and category of the terminal served by the AMF / SMF.
[0303] The terminal capacity information of AMF / SMF can be used to infer the cause of the signaling storm. For example, when the number of terminals is small but the signaling is high, it may be caused by terminal abnormality. When the number of terminals is large and the signaling is high, it may be caused by insufficient AMF / SMF capacity.
[0304] It should be noted that the first data request and the second data request can be combined into the same message, so that the NWDAF obtains the first data and the second data at the same time.
[0305] Step 6: Optionally, NWDAF sends a third data collection request to NF (such as AMF, LCS, SMF or AF) to collect third data, where the third data is the first behavior data of the terminal served by AMF / SMF.
[0306] The third data collection request can be made by calling the Event_Exposure event reporting service of the NF. It can be based on a subscription-notification model, where the subscriber will periodically or irregularly send the third data to the NWDAF. It can also be based on a request-response model, where each request is responded to once.
[0307] Step 7: Optionally, the NF sends third data to the NWDAF, where the third data is the first behavior data of the terminal served by the AMF / SMF. The first behavior data can be used to analyze whether the terminal is abnormal.
[0308] In some embodiments, optionally, the first behavior data of the terminal includes at least one of mobility behavior data and session behavior data of the terminal.
[0309] For example, when the NF is AMF, the third data may include at least one of the following: the terminal identifier, the S-NSSAI of the current slice, the terminal location, the terminal category (such as the type allocation code (TAC)), the number of terminal registration updates, the terminal access performance trend, and the terminal location change trend.
[0310] In the case where the NF is a location service (LCS), the third data may include at least one of the following: an identifier of the terminal, a fine-grained location of the terminal, LCS quality of service (QoS), and a mobility event of the terminal.
[0311] In the case where NF is SMF or AF, the third data may include at least one of the following: terminal identification, terminal S-NSSAI, data network name (DNN), application identification, expected behavior (including expected terminal movement trajectory, whether the terminal is in a fixed position, terminal communication duration, terminal communication interval, terminal communication time, etc.), communication start / end time, uplink and downlink data rates, total traffic, PDU session identification, PDU inactivity time and status, terminal session performance trend, terminal communication trend, etc.
[0312] Step 8: Optionally, NWDAF may also obtain fourth data, which is a behavior data analysis result of the second behavior data of the terminal served by the AMF / SMF. The second behavior data may be used to analyze whether the terminal is abnormal.
[0313] That is, NWDAF can also trigger the analysis of the existing second behavior data of the terminal by itself, and use this to infer the cause of the signaling storm. For example, if the signaling storm is caused by terminal abnormality, then the above behavior data analysis results will help to locate the abnormal terminal and the cause of the abnormality.
[0314] The terminal behavior analysis may include terminal abnormal behavior analysis (see 3GPP TS23.288 6.7.4) and terminal aggregation analysis (see 3GPP TS23.288 6.10). That is, the behavior data analysis result includes at least one of the following: terminal abnormal behavior analysis data and terminal aggregation analysis data.
[0315] The abnormal behavior analysis data of the terminal may include at least one of the following: abnormal location of the terminal, abnormal wake-up of the terminal, ping-pong effect of the terminal, and unknown wireless link failure of the terminal;
[0316] The terminal concentration analysis data may include at least one of the following: the number of terminals in a certain area, and the proportion of the concentrated terminals in the terminals requested for analysis.
[0317] Step 9: The NWDAF analyzes at least one of the first data, the second data, the third data, and the fourth data to obtain a signaling storm analysis result.
[0318] Optionally, the first data includes historical first data and current first data; the second data includes historical second data and current second data; the third data includes historical third data and current third data; and the fourth data includes historical fourth data and current fourth data.
[0319] NWDAF first performs machine learning based on the historical first data, historical second data, historical third data, and historical fourth data to obtain a signaling storm analysis model. When signaling storm analysis is required, the current first data, current second data, current third data, and current fourth data are input into the trained signaling storm analysis model for inference to obtain the signaling storm analysis results.
[0320] Optionally, the above-mentioned machine learning method can be a lightweight machine learning method, or it can be unsupervised learning or supervised learning. This application does not limit the specific machine learning method.
[0321] The signaling storm analysis result may include at least one of a signaling storm detection result and a signaling storm prediction result.
[0322] Among them, the output of the signaling storm detection result may include the cause of the signaling storm (for example, caused by insufficient processing capacity of the second network element, or caused by an abnormal terminal), the identifier of the AMF / SMF suffered (identifying the signaling storm target, which can identify a single AMF / SMF, for example, through NF instance ID identification, or multiple AMF / SMFs, for example, through AoI, S-NSSAI, etc. identification). Optionally, the signaling storm detection result may also include at least one of the following: the level of the signaling storm (indicating the severity of the signaling storm, such as low, medium, and high), the trend of the signaling storm (the subsequent trend of the signaling storm, such as rising / falling / unknown / stable), the signaling type of the signaling storm (such as NAS), abnormal signaling messages (such as Registration Reject), the proportion of abnormal signaling to normal signaling, the duration of the signaling storm, the identifier of the abnormal terminal, the abnormal behavior of the terminal (if the cause is an abnormal terminal, it can include abnormal terminal location, abnormal terminal wake-up, ping-pong effect of the terminal, unknown radio link failure of the terminal, etc.), abnormal terminal location, and abnormal terminal category (identified by TAC, S-NSSAI, etc.).
[0323] The output of the signaling storm prediction result can be based on the above signaling storm detection result to add additional confidence (used to indicate the certainty of the prediction) and expected time (used to indicate the time when the signaling storm is predicted to occur).
[0324] It is particularly important to note that signaling storm prediction can be achieved in the following way: NWDAF analyzes historical target data (at least one of the first data, second data, third data and fourth data) and learns that the proportion of rejected signaling of AMF / SMF under a certain capacity is normally maintained at 2%. NWDAF knows based on the historical signaling storm analysis results (the administrator labels the signaling storm after it occurs) that when the proportion of rejected signaling exceeds 10%, it indicates that a signaling storm has occurred. NWDAF finds that the current proportion of rejected signaling has gradually increased from 2% to 4%, and has an upward trend. NWDAF predicts that the AMF / SMF may experience a signaling storm.
[0325] Step 10: NWDAF sends the above signaling storm analysis results to the NF consumer.
[0326] Step 11: Optionally, the NWDAF obtains updated target data (at least one of the first data, the second data, the third data, and the fourth data) from the NF / OAM.
[0327] Step 12: Optionally, the NWDAF generates an updated signaling storm analysis result based on the updated target data.
[0328] Step 13: Optionally, the NWDAF sends the updated signaling storm analysis result to NF consume.
[0329] Step 14: NF consumer performs signaling storm control based on the signaling storm analysis results.
[0330] Optionally, if the signaling storm analysis result is a signaling storm detection result, the NF consumer will be more inclined to use active terminal control for control; if the signaling storm analysis result is a signaling storm prediction result, the NF consumer will be more inclined to use passive AMF / SMF capability enhancement for control.
[0331] Please refer to Table 2, which is an example of how an NF consumer performs signaling storm control based on the signaling storm analysis results. Table 2 may also include the signaling storm control method in Table 1 in Example 1 (excluding the last two solutions in Table 1), and may additionally include the following solutions.
[0332] Table 2
[0333] The signaling storm analysis method provided in the embodiment of the present application can be executed by a signaling storm analysis device. In the embodiment of the present application, the signaling storm analysis device executing the signaling storm analysis method is used as an example to illustrate the signaling storm analysis device provided in the embodiment of the present application.
[0334] Referring to FIG6 , an embodiment of the present application further provides a signaling storm analysis device 60 , including:
[0335] An acquisition module 61 is used to acquire target data;
[0336] A first analysis module 62 is configured to analyze the target data to obtain a signaling storm analysis result;
[0337] The signaling storm analysis result includes at least one of an identifier of a second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, and the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm.
[0338] In an embodiment of the present application, a signaling storm caused by terminal signaling is analyzed in the network element based on the target data to obtain a signaling storm analysis result, so that the signaling storm can be controlled according to the signaling storm analysis result, thereby enhancing the robustness of the network and improving the user's service experience.
[0339] Optionally, the signaling storm cause is further used to indicate that the terminal signaling storm is caused by insufficient processing capability of the second network element, or that the terminal signaling storm is caused by an abnormal terminal.
[0340] Optionally, the signaling storm cause may also indicate a more specific cause, for example, the terminal signaling storm is caused by terminal aggregation, the terminal signaling storm is caused by the terminal sending a large amount of signaling at the same time, the terminal signaling storm is caused by the terminal being maliciously controlled, the terminal signaling storm is caused by terminal application, the terminal signaling storm is caused by insufficient CPU of the second network element, or the terminal signaling storm is caused by insufficient memory of the second network element, etc.
[0341] Optionally, the target data includes first data, which is signaling characteristic data of the second network element.
[0342] Optionally, the signaling characteristic data includes at least one of the following information of the terminal served by the second network element: the number of target signaling failure messages, the number of all target signalings, the proportion of target signaling failure messages to all target signalings, the number of unresponsive target request messages, the number of all target request messages, and the proportion of unresponsive target request messages to all target request messages.
[0343] Optionally, the target signaling failure message includes at least one of the following: a radio resource control RRC reject message, an RRC release message, a registration reject message, a service reject message, an authentication reject message, a protocol data unit PDU session establishment reject message, a PDU session modification reject message, and a PDU session release reject message;
[0344] The target request message includes at least one of the following: RRC establishment request message, RRC recovery request message, RRC reconstruction request message, RRC reconfiguration completion message, registration request message, service request message, control plane service request message, PDU session establishment request message, PDU session modification request message, and PDU session release request message.
[0345] Optionally, the signaling characteristic data further includes at least one of an identifier of a terminal served by the second network element, a category of the terminal, and time period information, and the time period information is used to indicate a time period for collecting the signaling characteristic data.
[0346] Optionally, the signaling storm analysis result further includes at least one of the following: level of the signaling storm, trend of the signaling storm, signaling type of the signaling storm, abnormal signaling messages, proportion of abnormal signaling to normal series, and duration of the signaling storm.
[0347] Optionally, the acquisition module 61 is configured to send a first data collection request to the OAM or the second network element; and receive the first data from the OAM or the second network element.
[0348] Optionally, the target data includes second data, and the second data is terminal capacity information of the second network element.
[0349] Optionally, the acquisition module 61 is configured to send a second data collection request to the OAM or the second network element; and receive the second data from the OAM or the second network element.
[0350] Optionally, the target data includes third data, and the third data is first behavior data of the terminal served by the second network element.
[0351] Optionally, the first behavior data of the terminal includes at least one of mobility behavior data and session behavior data of the terminal.
[0352] Optionally, the signaling storm analysis result further includes at least one of the following: abnormal terminal identification, abnormal terminal behavior, abnormal terminal location, and abnormal terminal category.
[0353] Optionally, the signaling storm analysis device 60 further includes:
[0354] A first sending module is used to send a third data collection request to the AMF, SMF or UDM;
[0355] The first receiving module is used to receive the third data from the AMF, SMF or UDM.
[0356] Optionally, the target data includes fourth data, and the fourth data is a behavior data analysis result of second behavior data of the terminal served by the second network element.
[0357] Optionally, the behavior data analysis result includes at least one of the following: terminal abnormal behavior analysis data and terminal aggregation analysis data.
[0358] Optionally, the signaling storm analysis result further includes at least one of the following: abnormal terminal identification, abnormal terminal behavior, abnormal terminal location, and abnormal terminal category.
[0359] Optionally, the signaling storm analysis device 60 further includes:
[0360] The second analysis module is used to analyze the second behavior data of the terminal served by the second network element to obtain the behavior data analysis result.
[0361] Optionally, the signaling storm analysis device 60 further includes:
[0362] A second receiving module is configured to receive a signaling storm analysis request sent by a third network element;
[0363] The acquisition module 61 is configured to acquire the target data in response to the signaling storm analysis request;
[0364] The signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
[0365] Optionally, the signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
[0366] Optionally, the target data includes: current target data and historical target data;
[0367] The first analysis module 62 is configured to obtain a signaling storm analysis model based on the historical target data; and perform analysis based on the signaling storm analysis model and the current target data.
[0368] Optionally, the signaling storm analysis device 60 further includes:
[0369] The second sending module is used to send the signaling storm analysis result to the third network element.
[0370] Optionally, the third network element includes a network function consumer.
[0371] The signaling storm analysis device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
[0372] The signaling storm analysis device provided in the embodiment of the present application can implement each process implemented in the method embodiment of Figure 2 and achieve the same technical effect. To avoid repetition, it will not be described here.
[0373] The signaling storm control method provided in the embodiment of the present application can be executed by a signaling storm control device. In the embodiment of the present application, the signaling storm control device executing the signaling storm control method is used as an example to illustrate the signaling storm control device provided in the embodiment of the present application.
[0374] Referring to FIG. 7 , an embodiment of the present application further provides a signaling storm control device 70 , including:
[0375] A first receiving module 71 is configured to receive a signaling storm analysis result, where the signaling storm analysis result includes at least one of an identifier of a second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, where the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm;
[0376] The control module 72 is configured to perform signaling storm control operations according to the signaling storm analysis result.
[0377] In the embodiment of the present application, controlling the signaling storm according to the signaling storm analysis result can enhance the robustness of the network and improve the user's service experience.
[0378] Optionally, the signaling storm cause may also indicate a more specific cause, for example, the terminal signaling storm is caused by terminal aggregation, the terminal signaling storm is caused by the terminal sending a large amount of signaling at the same time, the terminal signaling storm is caused by the terminal being maliciously controlled, the terminal signaling storm is caused by terminal application, the terminal signaling storm is caused by insufficient CPU of the second network element, or the terminal signaling storm is caused by insufficient memory of the second network element, etc.
[0379] Optionally, the signaling storm control device 70 further includes:
[0380] The first sending module is used to send a signaling storm analysis request, where the signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
[0381] Optionally, the signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
[0382] Optionally, the first sending module is used to obtain a network performance analysis result of the second network element; when the network performance analysis result indicates that the second network element is in an abnormal resource usage state, trigger the sending of the signaling storm analysis request.
[0383] Optionally, the first sending module is used to send a network performance analysis request, where the network performance analysis request is used to request a network performance analysis of the second network element; and receive a network performance analysis result of the second network element.
[0384] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes an abnormal terminal identifier, the control module 72 is used to assign a target access category to the abnormal terminal and send a first indication message to the second network element that has suffered or is about to suffer a signaling storm, wherein the first indication message is used to indicate access prohibition for the target access category.
[0385] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes an abnormal terminal identifier, the control module 72 is used to assign an operator-defined access category to the abnormal terminal and send a second indication message to the second network element that has suffered or is about to suffer a signaling storm, and the second indication message is used to indicate overload control of a high-priority RRC connection.
[0386] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes the terminal abnormality category, the control module 72 is used to send a third indication information to the second network element that has suffered or is about to suffer a signaling storm, and the third indication information is used to indicate the start of overload control for the terminal abnormality category.
[0387] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal and the signaling storm analysis result includes an abnormal terminal identifier, the control module 72 is used to send a terminal parameter update message to the abnormal terminal, and the terminal parameter update message is used to modify the single network slice selection auxiliary information S-NSSAI of the access slice of the abnormal terminal to a specific S-NSSAI; and send a fourth indication message to the second network element that has suffered or is about to suffer a signaling storm, and the fourth indication message is used to indicate the start of overload control of the specific S-NSSAI.
[0388] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capacity of the second network element, the control module 72 is used to send a fifth indication information to the second network element that has suffered or is about to suffer a signaling storm, and the fifth indication information is used to indicate the start of overload control.
[0389] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capability of the second network element, the control module 72 is used to instruct the second network element that has suffered or is about to suffer a signaling storm to perform RRC release on the existing inactive terminals.
[0390] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capability of the second network element, the control module 72 is used to modify the slice to which the second network element that has suffered or is about to suffer a signaling storm belongs.
[0391] Optionally, when the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capability of the second network element, the control module 72 is configured to expand resources for the second network element that suffers or is about to suffer the signaling storm.
[0392] The signaling storm control device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
[0393] The signaling storm control device provided in the embodiment of the present application can implement each process implemented in the method embodiment of Figure 3 and achieve the same technical effect. To avoid repetition, it will not be described here.
[0394] As shown in Figure 8, an embodiment of the present application further provides a communication device 80, including a processor 81 and a memory 82, wherein the memory 82 stores a program or instruction that can be run on the processor 81. For example, when the communication device 80 is a first network element, the program or instruction is executed by the processor 81 to implement the various steps of the above-mentioned signaling storm analysis method embodiment, and can achieve the same technical effect. When the communication device 80 is a third network element, the program or instruction is executed by the processor 81 to implement the various steps of the above-mentioned signaling storm control method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0395] An embodiment of the present application further provides a communications device, including a processor and a communications interface, wherein the communications interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the method embodiment shown in Figure 2 or Figure 3. This communications device embodiment corresponds to the method embodiment performed by the first network element or the third network element described above, and each implementation process and implementation method of the method embodiment described above are applicable to this communications device embodiment and can achieve the same technical effects.
[0396] Specifically, the embodiment of the present application further provides a network-side device. As shown in FIG9 , the network-side device 90 includes a processor 91, a network interface 92, and a memory 93. The network interface 92 is, for example, a common public radio interface (CPRI).
[0397] Specifically, the network side device 90 of the embodiment of the present application also includes: instructions or programs stored in the memory 93 and executable on the processor 91. The processor 91 calls the instructions or programs in the memory 93 to execute the methods executed by the modules shown in FIG6 or FIG7 and achieve the same technical effect. To avoid repetition, it will not be described here.
[0398] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the above-mentioned signaling storm analysis method or signaling storm control method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0399] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0400] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned signaling storm analysis method or signaling storm control method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0401] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0402] An embodiment of the present application further provides a computer program product, including computer instructions, which, when executed by a processor, implement the various processes of the above-mentioned signaling storm analysis method or signaling storm control method, and can achieve the same technical effect. To avoid repetition, they are not described here.
[0403] An embodiment of the present application further provides a wireless communication system, including: a first network element and a third network element, wherein the first network element can be used to execute the steps of the above-mentioned signaling storm analysis method, and the third network element can be used to execute the steps of the above-mentioned signaling storm control method.
[0404] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0405] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.
[0406] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.
Claims
1. A signaling storm analysis method, comprising: The first network element obtains target data; The first network element performs analysis according to the target data to obtain a signaling storm analysis result; The signaling storm analysis result includes at least one of an identifier of a second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, and the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm.
2. The method according to claim 1, wherein The signaling storm cause is further used to indicate that the terminal signaling storm is caused by insufficient processing capability of the second network element, or that the terminal signaling storm is caused by an abnormal terminal.
3. The method according to claim 1 or 2, wherein The target data includes first data, and the first data is signaling characteristic data of the second network element.
4. The method according to claim 3, wherein: The signaling characteristic data includes at least one of the following information of the terminal served by the second network element: the number of target signaling failure messages, the number of all target signalings, the proportion of target signaling failure messages to all target signalings, the number of unresponsive target request messages, the number of all target request messages, and the proportion of unresponsive target request messages to all target request messages.
5. The method according to claim 4, wherein: The target signaling failure message includes at least one of the following: a radio resource control RRC reject message, an RRC release message, a registration reject message, a service reject message, an authentication reject message, a protocol data unit PDU session establishment reject message, a PDU session modification reject message, and a PDU session release reject message; The target request message includes at least one of the following: RRC establishment request message, RRC recovery request message, RRC reconstruction request message, RRC reconfiguration completion message, registration request message, service request message, control plane service request message, PDU session establishment request message, PDU session modification request message, and PDU session release request message.
6. The method according to any one of claims 3 to 5, wherein: The signaling characteristic data further includes at least one of an identifier of a terminal served by the second network element, a category of the terminal, and time period information, where the time period information is used to indicate a time period for collecting the signaling characteristic data.
7. The method according to any one of claims 3 to 6, wherein: The signaling storm analysis result further includes at least one of the following: the level of the signaling storm, the trend of the signaling storm, the signaling type of the signaling storm, abnormal signaling messages, the proportion of abnormal signaling to normal series, and the duration of the signaling storm.
8. The method according to any one of claims 3 to 7, wherein: The first network element obtains target data, including: The first network element sends a first data collection request to the operation, administration and maintenance OAM or the second network element; The first network element receives the first data from the OAM or the second network element.
9. The method according to any one of claims 1 to 8, wherein: The target data includes second data, where the second data is the number of service terminals of the second network element.
10. The method of claim 9, wherein: The first network element obtains target data, including: The first network element sends a second data collection request to the OAM or the second network element; The first network element receives the second data from the OAM or the second network element.
11. The method according to any one of claims 1 to 10, wherein: The target data includes third data, and the third data is first behavior data of the terminal served by the second network element.
12. The method of claim 11, wherein: The first behavior data of the terminal includes at least one of mobility behavior data and session behavior data of the terminal.
13. The method according to claim 11 or 12, wherein: The signaling storm analysis result further includes at least one of the following: abnormal terminal identification, abnormal terminal behavior, abnormal terminal location, and abnormal terminal category.
14. The method according to any one of claims 11 to 13, wherein: Before the first network element performs analysis based on the target data, the method further includes: The first network element sends a third data collection request to the access mobility management function AMF, the session management function SMF or the unified data management UDM; The first network element receives the third data from the AMF, SMF or UDM.
15. The method according to any one of claims 1 to 14, wherein: The target data includes fourth data, and the fourth data is a behavior data analysis result of second behavior data of the terminal served by the second network element.
16. The method of claim 15, wherein: The behavior data analysis result includes at least one of the following: terminal abnormal behavior analysis data and terminal aggregation analysis data.
17. The method according to claim 15 or 16, wherein The signaling storm analysis result further includes at least one of the following: abnormal terminal identification, abnormal terminal behavior, abnormal terminal location, and abnormal terminal category.
18. The method according to any one of claims 15 to 17, wherein: Before the first network element performs analysis based on the target data, the method further includes: The first network element analyzes second behavior data of the terminal served by the second network element to obtain the behavior data analysis result.
19. The method of claim 1, wherein: The first network element acquiring target data includes: The first network element obtains the target data in response to the signaling storm analysis request; The signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
20. The method according to any one of claims 1 to 19, wherein: Before the first network element obtains the target data, the method includes: The first network element receives a signaling storm analysis request sent by a third network element; The signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
21. The method according to claim 19 or 20, wherein The signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
22. The method according to any one of claims 1 to 21, wherein: The target data includes: current target data and historical target data; The first network element performs analysis based on the target data, including: The first network element obtains a signaling storm analysis model according to the historical target data; The first network element performs analysis according to the signaling storm analysis model and the current target data.
23. The method according to any one of claims 1 to 22, wherein: After the first network element performs analysis based on the target data to obtain a signaling storm analysis result, the method further includes: The first network element sends the signaling storm analysis result to the third network element.
24. The method of claim 20 or 23, wherein: The third network element includes a network function consumer.
25. A method for controlling a signaling storm, comprising: The third network element receives a signaling storm analysis result, where the signaling storm analysis result includes at least one of an identifier of the second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, where the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm. The third network element performs a signaling storm control operation according to the signaling storm analysis result.
26. The method of claim 25, wherein: Before the third network element receives the signaling storm analysis result, the method further includes: The third network element sends a signaling storm analysis request, where the signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
27. The method of claim 26, wherein: The signaling storm analysis request includes at least one of the following: an analysis identifier, an analysis target, and an analysis time.
28. The method of claim 26 or 27, wherein The third network element sending the signaling storm analysis request includes: The third network element obtains a network performance analysis result of the second network element; When the network performance analysis result indicates that the second network element is in an abnormal resource usage state, the third network element triggers sending the signaling storm analysis request.
29. The method of claim 28, wherein: The third network element obtains the network performance analysis result of the second network element, including: The third network element sends a network performance analysis request, where the network performance analysis request is used to request a network performance analysis to be performed on the second network element; The third network element receives the network performance analysis result of the second network element.
30. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal, and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element assigns a target access category to the abnormal terminal, and sends first indication information to the second network element that suffers or is about to suffer a signaling storm, where the first indication information is used to indicate access barring for the target access category.
31. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal, and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element assigns an operator-defined access category to the abnormal terminal, and sends second indication information to the second network element that suffers or is about to suffer a signaling storm, where the second indication information is used to instruct overload control of a high-priority RRC connection.
32. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal, and the signaling storm analysis result includes single network slice selection assistance information S-NSSAI, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element sends third indication information to the access mobility management function AMF, where the third indication information is used to instruct to enable overload control of the S-NSSAI.
33. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal, and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element sends a terminal parameter update message to the abnormal terminal, where the terminal parameter update message is used to modify the single network slice selection auxiliary information S-NSSAI of the access slice of the abnormal terminal to a specific S-NSSAI; The third network element sends fourth indication information to the access mobility management function AMF, where the fourth indication information is used to indicate that overload control for the specific S-NSSAI is enabled.
34. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by an abnormal terminal, and the signaling storm analysis result includes an abnormal terminal identifier, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element releases the context of the abnormal terminal.
35. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capability of the second network element, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element sends fifth indication information to the second network element that has suffered or is about to suffer a signaling storm, where the fifth indication information is used to instruct to start overload control.
36. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capability of the second network element, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element instructs the second network element that has suffered or is about to suffer a signaling storm to perform RRC release on the existing inactive terminals.
37. The method according to any one of claims 25 to 29, wherein: When the signaling storm cause indicates that the terminal signaling storm is caused by insufficient processing capability of the second network element, the third network element performs a signaling storm control operation according to the signaling storm analysis result, including: The third network element expands resources for the second network element that suffers or is about to suffer a signaling storm.
38. A signaling storm analysis device, comprising: Acquisition module, used to obtain target data; A first analysis module is used to analyze the target data to obtain a signaling storm analysis result; The signaling storm analysis result includes at least one of an identifier of a second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, and the signaling storm cause includes indication information indicating that the signaling storm is a terminal signaling storm.
39. The apparatus of claim 38, wherein The target data includes first data, and the first data is signaling characteristic data of the second network element.
40. The apparatus of claim 39, wherein The signaling storm analysis result further includes at least one of the following: the level of the signaling storm, the trend of the signaling storm, the signaling type of the signaling storm, abnormal signaling messages, the proportion of abnormal signaling to normal series, and the duration of the signaling storm.
41. The device according to any one of claims 38 to 40, wherein: The target data includes second data, where the second data is the number of service terminals of the second network element.
42. The device according to any one of claims 38 to 41, wherein The target data includes third data, and the third data is first behavior data of the terminal served by the second network element.
43. The device according to any one of claims 38 to 42, wherein: The target data includes fourth data, and the fourth data is a behavior data analysis result of second behavior data of the terminal served by the second network element.
44. The apparatus of claim 42 or 43, wherein The signaling storm analysis result further includes at least one of the following: abnormal terminal identification, abnormal terminal behavior, abnormal terminal location, and abnormal terminal category.
45. A signaling storm control device, comprising: a first receiving module, configured to receive a signaling storm analysis result, the signaling storm analysis result including at least one of an identifier of a second network element that has suffered or is about to suffer a signaling storm and a signaling storm cause, the signaling storm cause including indication information indicating that the signaling storm is a terminal signaling storm; A control module is used to perform signaling storm control operations according to the signaling storm analysis result.
46. The apparatus of claim 45, wherein Also includes: The first sending module is used to send a signaling storm analysis request, where the signaling storm analysis request is used to request a signaling storm analysis to be performed on the second network element.
47. The apparatus of claim 46, wherein: Also includes: an acquisition module, configured to acquire a network performance analysis result of the second network element; The triggering module is used to trigger the first sending module to send the signaling storm analysis request when the network performance analysis result indicates that the second network element is in an abnormal resource usage state.
48. A communication device, comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the signaling storm analysis method as described in any one of claims 1 to 24 are implemented, or when the program or instruction is executed by the processor, the steps of the signaling storm control method as described in any one of claims 25 to 37 are implemented.
49. A readable storage medium storing a program or instruction, wherein the program or instruction, when executed by a processor, implements the signaling storm analysis method as described in any one of claims 1 to 24, or implements the steps of the signaling storm control method as described in any one of claims 25 to 37.
50. A computer program product, comprising computer instructions, which, when executed by a processor, implement the steps of the signaling storm analysis method according to any one of claims 1 to 24, or, when executed by a processor, implement the steps of the signaling storm control method according to any one of claims 25 to 37.
Citation Information
Patent Citations
Signaling congestion processing method, device, base station and system
CN104684020A
Signaling storm prediction method and device, equipment and medium
CN117041159A
5G signaling storm prediction method and equipment based on grey prediction model, and medium
CN117527612A
Method and apparatus for analyzing signaling traffic
US20140105032A1
Security enhancements for cellular communication systems
US20230136287A1