Provisioning enhanced packet flow descriptions by application functions
The introduction of Advanced Packet Classification Rules (APCR) in PFDs addresses the limitations of existing PFDs by enabling accurate classification of encrypted traffic using binary patterns and metrics, enhancing the UPF's ability to detect application traffic in 5G networks.
Patent Information
- Application Number
- PCT/IB2024/054342
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-09
- Filing Date
- 2024-05-04
- Publication Date
- 2025-08-14
AI Technical Summary
Existing Packet Flow Descriptions (PFDs) in 5G networks are insufficient for accurate packet detection due to the unavailability of URL and domain names under encryption, and they fail to leverage the advanced heuristics and machine learning capabilities of User Plane Functions (UPFs).
Introduce Advanced Packet Classification Rules (APCR) that include signatures or classification models, such as binary patterns and metrics, to enhance packet detection, enabling the UPF to classify packets associated with applications or services.
Enhances packet detection accuracy by allowing classification of encrypted traffic using advanced heuristics and machine learning models, improving the UPF's capability to identify application traffic flows.
Smart Images

Figure IB2024054342_14082025_PF_FP_ABST
Abstract
Description
[0001] PROVISIONING ENHANCED PACKET FLOW DESCRIPTIONS BY APPLICATION FUNCTIONS
[0002] RELATED APPLICATIONS
[0003] The present application claims priority to European Application No. EP 24382129.5 filed on February 9, 2024, the disclosure of which is incorporated herein by reference in its entirety herein.
[0004] TECHNICAL FIELD
[0005] The present disclosure relates generally to packet flow descriptions (PFDs) for packet filtering in wireless communication networks and, more particularly, to provisioning of enhanced PFDs by an application function (AF) to enable detection of packets belonging to traffic flows associated with applications and services provided by the AF.
[0006] BACKGROUND
[0007] Fifth Generation (5G) networks according to the Third Generation Partnership Project (3GPP) standards use Packet Flow Descriptions (PFDs) to enable the detection of application traffic by the User Plane Function (UPF). A PFD is a set of information enabling the detection of application traffic. A PFD typically includes a unique PFD identifier (PFD ID) in the scope of an application identifier (APP ID) and one or more of the following PFD parameters:
[0008] • 3-tuple(s) including protocol, server side IP address and port number;
[0009] • the significant parts of the Uniform Resource Locator (URL) to be matched, e.g., host name; and
[0010] • a domain name matching criteria and information about applicable protocol(s). The UPF uses the information in the PFD to filter and classify packets and apply Policy and Charging Control (PCC) Rules provided by a Policy Control Function (PCF).
[0011] PFDs are typically provided by Application Service Providers (ASPs) to enable detection of traffic flows belonging to their applications. PFDs enable the UPF to perform application detection when accurate and updated PFDs are provided by the ASP and then to apply enforcement actions as instructed in the PCC Rules. The current implementation of PFDs is based on shallow packet inspection and attempts to match the PFD parameters provided by the ASP with information extracted from the packets in an application traffic flow to identify the application or type of application.
[0012] The existing PFD parameters currently defined in the standards are frequently insufficient for accurate packet detection. The URL and domain name are frequently unavailable due to the use of encryption. The server IP addresses alone do not allow traffic differentiation where the servers host multiple services / applications and in many cloud implementations. Further, the standard packet detection parameters fail to take full advantage of the UPF capabilities, which may have the ability to use advanced heuristics and / or machine learning (ML) models to classify application traffic. SUMMARY
[0013] The present disclosure extends the PFD definition to support a new type of parameter to be used for packet detection. This new parameter, referred to herein as the Advanced Packet Classification Rule (APCR), allows the network to store a signature or classification model that can be used to detect packets associated with an application or service. The signature may include binary patterns in the header or payload of data packets, or metrics that characterize a packet flow associated with a service or application. The new APCR allows the ASP to provision not only standard PFDs, but also signatures or ML models that can be used for packet detection.
[0014] A first aspect of the disclosure comprises methods implemented by a PFD management node in a wireless communication network of distributing enhanced PFDs for classification of packets transmitted over the wireless communication network. In one embodiment, the method comprises receiving, from an AF, an enhanced PFD associated with an application or service provided by the AF. The enhanced PFD includes a parameter indicative of a signature or classification model to be used by a user plane network node for classifying packets belonging to traffic flows associated with the service. The method further comprises distributing the enhanced PFD to the user plane network node for use in classifying packets belonging to the traffic flow associated with the service.
[0015] A second aspect of the disclosure comprises a PFD management node configured to distribute enhanced PFDs for classification of packets transmitted over the wireless communication network. In one embodiment, the PFD management node is configured to receive, from an AF, an enhanced PFD associated with an application or service provided by the AF. The enhanced PFD includes a parameter indicative of a signature or classification model to be used by a user plane network node for classifying packets belonging to traffic flows associated with the service. The PFD management node is further configured to distribute the enhanced PFD to the user plane network node for use in classifying packets belonging to the traffic flow associated with the service.
[0016] A third aspect of the disclosure comprises a PFD management node in a wireless communication network configured to distribute enhanced PFDs for classification of packets transmitted over the wireless communication network. The PFD management node comprises network interface circuitry for communicating with other network nodes and processing circuitry. The processing circuitry is configured to receive, from an AF, an enhanced PFD associated with an application or service provided by the AF. The enhanced PFD includes a parameter indicative of a signature or classification model to be used by a user plane network node for classifying packets belonging to traffic flows associated with the service. The processing circuitry is further configured to distribute the enhanced PFD to the user plane network node for use in classifying packets belonging to the traffic flow associated with the service. A fourth aspect of the disclosure comprises a computer program for a PFD management node configured to provide model-based PFDs. The computer program comprises executable instructions that, when executed by processing circuitry in the PFD management node, causes the PFD management node to perform the method according to the first aspect.
[0017] A fifth aspect of the disclosure comprises a carrier containing a computer program according to the fourth aspect. The carrier is one of an electronic signal, optical signal, radio signal, or a non-transitory computer readable storage medium.
[0018] A sixth aspect of the disclosure comprises methods implemented by an AF of provisioning PFDs to enable detection by a user plane network node of packets belonging to traffic flows associated with an application or service provided by the AF. In one embodiment, the method comprises sending, to a PFD management node, an enhanced PFD associated with the application or service provided by the AF. The enhanced PFD includes a parameter indicative of a signature or classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the application or service.
[0019] A seventh aspect of the disclosure comprises an application server in a wireless communication network configured to provision PFDs to enable detection by a user plane network node of packets belonging to traffic flows associated with the application server. The user plane node is configured to send, to a PFD management node, an enhanced PFD associated with the application or service provided by the application server. The enhanced PFD includes a parameter indicative of a signature or classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the application or service.
[0020] An eighth aspect of the disclosure comprises an application server in a wireless communication network configured to provision PFDs to enable detection by a user plane network node of packets belonging to traffic flows associated with the application server. The processing circuitry is configured to send, to a PFD management node, an enhanced PFD associated with the application or service provided by the application server. The enhanced PFD includes a parameter indicative of a signature or classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the application or service.
[0021] A ninth aspect of the disclosure comprises a computer program for an application server configured to support packet filtering based on enhanced PFDs. The computer program comprises executable instructions that, when executed by processing circuitry in an application server, causes the application server to perform the method according to the first aspect.
[0022] A tenth aspect of the disclosure comprises a carrier containing a computer program according to the ninth aspect. The carrier is one of an electronic signal, optical signal, radio signal, or a non-transitory computer readable storage medium. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 illustrates a wireless communication network implementing enhanced PFDs as herein described.
[0024] Figure 2 illustrates an exemplary PFD procedure for provisioning and using enhanced PFDs.
[0025] Figures 3A and 3B comprise a signal flow diagram illustrating a PFD procedure for provisioning and using enhanced PFDs.
[0026] Figure 4 illustrates a method implemented by a PFD management node of distributing enhanced PFDs provided by an AF.
[0027] Figure 5 illustrates a method implemented by an AF of provisioning enhanced PFDs for detection of packets belonging to traffic flows associated with applications or services provided by the AF.
[0028] Figure 6 illustrates a network node that can be configured to implement functionality of a PFD management node or AF as herein described.
[0029] DETAILED DESCRIPTION
[0030] The present disclosure is directed to Packet Flow Descriptions (PFDs) enabling the detection of application traffic by a UPF in a wireless communication network. PFDs are typically provided by Application Service Providers (ASPs) to enable detection of traffic flows belonging to their applications. PFDs enable the UPF to detect Internet Protocol (IP) traffic associated with an application or service and to apply enforcement actions as instructed in applicable Policy and Charging Control (PCC) Rules.
[0031] An exemplary embodiment of the disclosure will be described in the context of a 5G wireless communication network. Those skilled in the art will appreciate that the methods and apparatus herein described are not limited to use in 5G networks but may also be used in wireless communication networks operating according to other standards. More generally, the present disclosure is appliable to any wireless communication network that uses PFDs or equivalent features to detect and classify IP traffic associated with applications or services provided by an ASP.
[0032] Figure 1 illustrates an exemplary wireless communication network 10. The wireless communication network 10 comprises a radio access network (RAN) 20 and a core network 30 employing a service-based architecture. The RAN 20 comprises one or more base stations 25 providing radio access to user equipment (UEs) 15 operating within the wireless communication network 10. The base stations 25 are also referred to as gNodeBs (gNBs). The core network 30 provides a connection between the RAN 20 and other packet data networks, such as the IMS or the Internet.
[0033] In the 5G network architecture, the core network 30 comprises a plurality of Network Functions (NFs) to perform the various functions of the core network 30. The NFs include, for example, a User Plane Function (UPF) 35, an Access And Mobility Management Function (AMF) 40, a Session Management Function (SMF) 45, a Policy Control Function (PCF) 50, a Charging Function 55, a Network Exposure Function (NEF) 60, a Network Repository Function 65, a Unified Data Repository 70, a Network Data Analytics Function (NWDAF) 75, and an Application Function (AF) 80. These NFs comprise logical entities that reside in one or more core network nodes, which may be implemented by one or more processors, hardware, firmware, or a combination thereof. The functions may reside in a single core network node or may be distributed among two or more core network nodes.
[0034] The roles of the various NFs in the core network have been defined in 3GPP standard TS 23.501 and TS 23.503. The network functions that may be of interest for the present disclosure are the following.
[0035] The PCF 50 supports a unified policy framework to govern network behavior. It also implements a Front End (PCF FE) to access subscription information relevant for policy decisions stored in the UDR 80. The PCF 50 provides PCC rules to the SMF 45, UPF 35 and / or other entities that enforce policy and charging decisions according to the policies of the network operator. In 5G, the PCF 50 may also store and provide Network Slice Selection Policies (NSSPs) to the UE 15 that are used to assist network slice selection.
[0036] The UPF 35 handles the user data traffic including packet inspection, packet routing and forwarding, traffic usage reporting, and Quality of Service (QoS) handling for the user plane (e.g., rate enforcement for uplink (UL) and / or downlink (DL)). The UPF 35 receives PFDs from the NEF 60 through the SMF 45. Generally, the SMF 45 receives the PFDs from the NEF 60 and converts the PFDs to application filters for use in detecting and classifying packets. The filters are contained in PDRs sent from the SMF 45 to the UPF 35.
[0037] The UPF 35 optionally includes Deep Packet Inspection (DPI) functionality. DPI technology comprises inspecting / analyzing the contents of the IP data packets beyond the so called IP 5 tuples. The IP 5 tuples comprise the heading elements of an IP data packet including the IP source address, IP destination address, source transport address, destination transport address, and protocol over IP (e.g. Transport Control Protocol (TCP), Uniform Datagram Protocol (UDP)). In simple terms, DPI technology enables the UPF 35 to inspect and analyze the application layer information conveyed by Internet Protocol (IP) data packets. As a result of the DPI analysis, the UPF 35 can obtain service classification information according to a configured tree of rules so that the IP packets are assigned to a particular service session or application, and appropriate PCC rules are applied.
[0038] The SMF 45 is responsible for the establishment, modification and termination of packet data sessions and control of the UPFs 35. The SMF 45 provides PFDs obtained from the NEF 60 to the UPF 35 for classification of the user IP data. SMF 45 interacts with the UPF 35 over N4 reference point using Packet Forwarding Control Protocol (PFCP) procedures.
[0039] The NEF 60 provides information relating to the capability of NFs with the 5G CN 30 to external NFs and facilitates information exchange between internal and external NFs. The NEF 60 serves as the operator network entry point for ASPs. From 3GPP Release 15 (Rel-15) forward, the NEF 60 incorporates the Packet Flow Descriptor Function (PFDF) functionality, which is intended to manage the PFDs provided by ASPs and distribute them to the SMFs 45. In Fourth Generation (4G) network, the PFDF had been a standalone NF that stored the PFDs. In 5G networks, the NEF 60 manages and distributes the PFDs, which are stored in the UDR 70.
[0040] The NRF 65 provides registration services that allow NFs to register with the NRF 65. The NRF 65 stores NF profiles for each registered NF that include a unique identifier (ID), version, and capabilities of the NFs. The NRF 65 provides a discovery service to enable consumer NFs to discover services provided by other NFs.
[0041] The UDR 80 provides storage and retrieval of subscription data by the Unified Data Management (UDM) function (not shown)(the evolution of Home Subscriber Service (HSS) in 5G architecture), storage and retrieval of policy data by the PCF 50, and storage and retrieval of structured data for exposure, and application data (including PFDs) for application detection, application request information for multiple UEs, by the NEF 60.
[0042] The AF 80 comprises an application server of an ASP providing an application or service to network users. The AF 80 can be located in the 5G CN 30 or may be external to the 5G CN 30.
[0043] The NFs as herein described can be slice specific (i.e. , not shared by more than one slice), or they can be shared by multiple network slices, or they can be shared by all network slices. As an example, the SMF 45 and UPF 35 are typically slice specific. Isolation requirements play an important role on how the slices are designed and deployed.
[0044] One aspect of the present disclosure relates to the management of PFDs for detection and classification of traffic flows. A PFD is a set of information enabling the detection of application traffic. Each PFD may be identified by a unique PFD ID in the scope of a particular application identifier. There may be different PFD types associated to an application identifier.
[0045] A PFD typically includes the PFD ID and one or more of the following PFD parameters:
[0046] • 3-tuple(s) including protocol, server side IP address and port number;
[0047] • the significant parts of the URL to be matched, e.g., host name;
[0048] • a domain name matching criteria and information about applicable protocol(s). The UPF 35 uses the information in the PFD to filter and classify packets and apply PCC rules provided by the PCF 50.
[0049] Management of PFDs is described in the 3GPP standard TS 23.503, § 6.1.2.3.1 , v.17.5.0. Generally, PFDs are managed by the ASP through the NEF 60 or other PFDF. In 5G networks, The PFDF functionality is implemented as a service provided by the NEF 60. In some embodiment, the PFDF may be a standalone NF or integrated with another NF. The NEF / PFDF receives PFD(s) from the ASP, stores the PFD(s) in the UDR 70, and provides the PFDs to the SMFs 45, either at the request from the ASP (push mode) or at the request of the SMF 45 (pull mode). The PFDs are provided by the SMF 45 to the UPF 35 over the N4 interface using PFD management procedures.
[0050] The current implementation of PFDs is based on shallow packet inspection and attempts to match the PFD parameters provided by the ASP with information extracted from the IP packets in an application traffic flow to identify the application or type of application associated with a traffic flow. These existing PFD parameters reference a standard type of data that an Application Service Provider (ASP) can provide and be understandable by the mobile network operator (MNO) but fail to take full advantage of all of the UPF capabilities, which may have heuristics or machine learning modes to classify application traffic. Further, the MNO relies on the ASPs to properly define and update PFDs for applications provided by the ASP.
[0051] One aspect of the present disclosure is the introduction of a new type of PFD that takes advantage of advanced classification capabilities of the UPF 35 to enable detection and classification of application traffic based on a signature or classification model provided by the ASP. In one embodiment, the PFD definition is extended to support a new type of parameter denoted as the Advanced Packet Classification Rule (APCR) that allows the ASP to provide a signature or classification model to the NEF 60 to be used by the UPF 35 to detect and identify packet flows associated with an application or service provided by the ASP. The NEF 60 can then distribute the signature or classification model to the UPF 53 via the SMF 45. The UPF 35 can apply the classification model or advanced heuristics based on the signatures to detect and classify packets belonging to the application or service provided by the ASP.
[0052] The new types of Packet Flow Descriptors (PFDs) contemplated include:
[0053] • User plane classification model: including the type of model (e.g., decision tree ML model) and the address of the model (e.g., URL to retrieve the model).
[0054] • Binary patterns: such as a specific binary-coded value in either the protocol header or payload.
[0055] • Metrics: Empirical patterns, which characterize a particular protocol or application, such as bit and IP connectivity patterns of the packets in a packet data unit (PDU) session. The new PFDs can be provisioned by the ASP to enable MNOs to properly classify the
[0056] UE traffic based on AF-provided PFDs to the NEF 60. The new PFDs further allow the MNO to classify encrypted traffic through PFDs using advanced heuristics and / or ML models supported in the UPF 35.
[0057] Figure 2 illustrates one exemplary procedure 100 for implementing enhanced PFDs as herein described. The AF 80 sends a request to the NEF 60 to obtain information about supported packet detection capabilities (block 110). In cases, where the network supports advanced heuristics and classification models, the AF 80 provides an enhanced PFD associated with an application or service to the NEF 60 (block 120). The enhanced PFD includes an APCR containing signatures and / or a classification model to be used for packet detection and classification. In some embodiments, the APCR may contain information (e.g., address) for retrieving the signatures and / or classification model. The NEF 60 stores the signatures and / or classification model (or information for retrieving the signatures and / or classification model) in the UDR 70 (block 130). This information may, for example, be stored as an extension of the existing application data structure. The NEF 60 distributes the enhanced PFDs to the UPF 35 via the SMF 45 (block 140). In some embodiments, the UPF 35 optionally retrieves the signatures and / or classification model (block 150). Once the signatures and / or classification model are loaded, the UPF 35 can apply the classification model or advanced heuristics based on the signatures to detect and classify packets associated with the application or service provided by the ASP.
[0058] Figures 3A and 3B is a more detailed signal flow diagram for one exemplary implementation of enhanced PFDs. Before PFD provisioning is triggered, the UPF 35 registers or updates its registration with the NRF 65 by sending a registration request message (e.g., Nnrf_Registration Request) to the NRF 70 (S1). The registration request or update requests includes a UPF instance identifier (UPF-ID) and an indication of support for advanced traffic classification capability. The NRF 70 stores the supported traffic classification capability in the UPF Profile and sends a registration response message (e.g., Nnrf_Registration Response) in answer to the registration request indicating successful registration (S2, S3).
[0059] After the UPF 35 has registered with the NRF 65, the NEF 60 initiates discovery of UPF instances by sending a discovery request message (e.g., Nnrf_Discovery Request) to the NRF 65 (S4). The discovery request message includes the NF type (e.g., NFType=UPF) and the filter criteria (e.g., AOI, S-NSSAI, DNN). The NRF 65 returns the requested information to the NEF 60 in a discovery response message (e.g., Nnrf_Discovery Response) (S5). The information returned includes a list of UPF instances. Each entry in the list includes the UPF instance identifier (UPF-ID) and the UPF profile (e.g., NFProfile) including advanced traffic classification capability for each matching UPF 35.
[0060] Before provisioning PFDs by the AF 80, it exchanges information about its capabilities with the NEF 60. The AF 80 sends an information request (e.g. Nnef_PFDManagement_Query Request) to the NEF 60 to determine whether the network supports advanced packet classification features, such as classification models and / or advanced heuristics (S6). The information request may include an indication of the classification capabilities supported by the AF 80. The indication may, for example, comprise a list of supported classification capabilities. The NEF 60 answers with a query response (e.g. Nnef_PFDManagement_Query Response) identifying the supported classification capabilities of the UPFs 35 (S7). Following the exchange of capabilities, the AF 80 can provision PFDs to the NEF 80 by sending a provisioning request (e.g., Nnef_PFDManagement_Create Request) (S8). If support for classification models and / or advance heuristics is indicated, the AF 80 may include a APCR that identifies a classification model or signature to be used for detecting packets associated with an application or service offered by the AF 80. Otherwise, the AF 80 may send a conventional PFD to the NEF 60. In some scenarios, the AF 80 may provide both types of PFDs to the NEF 60. After receiving the provisioning request, the NEF 60 checks whether the AF 80 is authorized to perform this request and, if so, sends a provisioning response indicating that the PFD was accepted (S9).
[0061] In some embodiments, the AF 80 may, alternatively, send the enhanced PFD to the NEF 60 in a provisioning request without first querying the NEF 60 to learn the UPF capabilities. The enhanced PFD may include an APCR in addition to the traditional elements in a PFD. In this case, the NEF 60 may ignore the APCR in the enhanced PFD.
[0062] When the NEF 60 receives the enhanced PFD from the AF 80, the NEF 60 sends the new PFD to the UDR 70 in a store request message (e.g., Nudr_Store Request) (S10). The UDR stores information contained in the APCR as an extension of the existing Application Data structure (S11) and answers the store request message with a store response message (e.g., Nudr_Store Response) indicating that the enhanced PFD has been successfully stored (S12).
[0063] Either before or after the new PFDs are stored in the UDR 70, the NEF 60 distributes the new enhanced PFDs to the UPFs 35 listed in the discovery response at step S5 using conventional PFD management procedures (S13). As previously noted, the new PFDs include information to enable the UPF 35 to use a classification model or advanced heuristics to classify packets associated with an application or service provided by the AF 80 even when the application traffic is encrypted. The information contained in the enhanced PFDs may include a classification model and / or signatures, or information on how to retrieve the classification model and / or signatures. The signatures may contain binary patterns and / or metrics that can be used by the UPF to detect packets associated with the application or service provided by the AF 80, even where the application traffic is encrypted. The UPF 35 retrieves the classification model and / or signatures to be used to detect and classify traffic flows for the corresponding application (S14).
[0064] The exemplary syntax for the enhanced PFDs shown below allows flexible combination (logical AND, logical OR), which may comprise a User Plane Classification model only, a binary pattern only, metrics only, or some combination thereof. Additionally, the exemplary syntax adds support for filtering traffic per direction (uplink, downlink, or both) and specifies the protocol stack (e.g., Ethernet, Internet protocol (IP), User Datagram Protocol (UDP), Transport Control Protocol (TCP), etc.).
[0065] "extendedRules": [ / / the elements are joined by logical OR (||)
[0066] { rules: [ / / the elements are joined by logical AND (&&)
[0067] { type: string (“User Plane Classification model”, “binary”, “metrics”) value: depends_on_the_type
[0068] }, ] stack: string (ethernet, ip, tcp, udp) direction: uplink, downlink, both
[0069] },
[0070] ],
[0071] "pfdld": "pfdldl"
[0072] This new type of PFD allows the AF 80 to define a user plane classification model (e.g., ML model) so traffic matching this model will be classified into that PFD and consequently into the target application identifier (externalAppId). An example PFD identifying a user plane classification model is shown below:
[0073] "pfdDatas": [
[0074] {
[0075] "pfds": [
[0076] {
[0077] "extendedRules":
[0078] { rules:
[0079] { type: userPlaneClassificationModel value: model_type: decision_tree addressjnformation: e.g. URL to retrieve the model
[0080] },
[0081] },
[0082] "pfdld": "pfdldl"
[0083] }
[0084] ],
[0085] "externalAppId": "facebook",
[0086] "self":
[0087] " / 3gpp_t8_pfd_management / v1 / facebook / transactions / 13dbf2992f3cf3005dc645caef790b6c c1 f3b994bb911 c4e642e04070db33d54"
[0088] }
[0089] ]
[0090] In this particular example, traffic which matches the User Plane Classification model will be classified into pfdldl and consequently into the target application (Facebook).
[0091] This new type of PFD also allows the AF 80 to define binary pattern so traffic matching this pattern will be classified into that PFD and consequently into the target application identifier (externalAppId). An example PFD providing a binary patten for advanced heuristics is shown below.
[0092] "pfdDatas": [
[0093] {
[0094] "pfds": [
[0095] {
[0096] "extendedRules":
[0097] { rules: { type: binary value: 0xAF43BB73D5A
[0098] }, stack: tcp direction: uplink
[0099] },
[0100] "pfdld": "pfdldl"
[0101] }
[0102] ],
[0103] "externalAppid": "skype",
[0104] "self":
[0105] " / 3gpp_t8_pfd_management / v1 / skype / transactions / 13dbf2992f3cf3005dc645caef790b6cc1 f 3b994bb911 c4e642e04070db33d54"
[0106] }
[0107] ]
[0108] In this particular example, uplink TCP traffic which matches the binary pattern (in hex format) 0xAF43BB73D5A will be classified into pfdldl and consequently into the target application (Skype).
[0109] The enhanced PFD further the AF 80 to define a certain metric so traffic matching this metric will be classified into that PFD and consequently into the target application identifier (externalAppid). An example PFD providing metrics for advanced heuristics is shown below.
[0110] "pfdDatas": [
[0111] {
[0112] "pfds": [
[0113] {
[0114] "extendedRules":
[0115] { rules:
[0116] { type: metrics value: chunk_window_size: 6 rule: CHUNK_WINDOW.accLen > 80941
[0117] },
[0118] { type: metrics value: chunk_window_size: 6 rule: CHUNK WINDOW.dlRate <= 7269775
[0119] },
[0120] { type: metrics value: chunk_window_size: 6 rule: CHUNK WINDOW.iaTime <= 15
[0121] }, stack: tcp direction: both },
[0122] "pfdld": "pfdld2"
[0123] }
[0124] ],
[0125] "externalAppId": "youtube-hd",
[0126] "self": " / 3gpp_t8_pfd_management / v1 / google / transactions / 13dbf2992f3cf3005dc645caef790b6cc1 f3b994bb911 c4e642e04070db33d55"
[0127] }
[0128] ]
[0129] In this particular example, TCP traffic which matches the three metrics rules defined above (logical AND) will be classified into pfdld2 and consequently into the target application (YouTube video in high definition). The above three rule metrics are as follows:
[0130] • For a chunk of 6 consecutive packets matching the application (YouTube), the accumulated packet length (in bytes) is higher than a certain value (80941 bytes), AND
[0131] • For a chunk of 6 consecutive packets matching the application (YouTube), the downlink bit rate (in bps) is lower or equal than a certain value (7269775 bps), AND
[0132] • For a chunk of 6 consecutive packets matching the application (YouTube), the average packet interarrival time (in ms) is lower or equal than a certain value (15 ms).
[0133] Figure 4 illustrates a method 200 implemented by a NEF 60 or other PFD management node in a wireless communication network of distributing enhanced PFDs for classification of packets transmitted over the wireless communication network. In one embodiment of the method 200, the NEF 60 optionally receives a request for supported packet detection capabilities from the AF 80 (block 210). The NEF 60 sends, to the AF 80 and responsive to the request, an indication of support for enhanced packet detection based on a classification model or signature (block 220). The NEF 60 receives, from an AF 80, an enhanced PFD associated with a service provided by the AF 80 (block 230). The enhanced PFD includes a parameter indicative of a signature or classification model to be used by a user plane network node (e.g., UPF 35) for classifying packets belonging to traffic flows associated with the service. The NEF 60 further distributes the enhanced PFD to the user plane network node for use in classifying packets belonging to the traffic flow associated with the service (block 240).
[0134] Some embodiments of method 200 further comprise sending the enhanced PFD to a data storage node in the wireless communication network to store as application data for the application. In some embodiments of method 200, the parameter identifies one or more binary patterns in a header and / or payload of data packets to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
[0135] In some embodiments of method 200, the parameter identifies one or more protocol metrics characterizing a packet flow to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
[0136] In some embodiments of method 200, the parameter identifies a classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
[0137] Figure 5 illustrates a method 300 implemented by an AF 80 of provisioning PFDs to enable detection by a user plane network node of packets belonging to traffic flows associated with a service provided by the AF 80. In one embodiment, the AF 80 optionally sends a request for supported packet detection capabilities to the NEF 60 or other PFD management node (block 310). The AF 80 optionally receives, responsive to the request, an indication of support for enhanced packet detection based on a signature or classification model from the PFD management node (block 320). The AF 80 sends, to the PFD management node, an enhanced PFD associated with the service provided by AF (block 330). The enhanced PFD includes a parameter indicative of a signature or classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
[0138] In some embodiments of method 300, the parameter identifies one or more binary patterns in a header and / or payload of data packets to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
[0139] In some embodiments of method 300, the parameter identifies one or more protocol metrics characterizing a packet flow to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
[0140] In some embodiments of method 300, the parameter identifies a classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
[0141] An apparatus can perform any of the methods herein described by implementing any functional means, modules, units, or circuitry. In one embodiment, for example, the apparatuses comprise respective circuits or circuitry configured to perform the steps shown in the method figures. The circuits or circuitry in this regard may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. For instance, the circuitry may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory may include program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein, in several embodiments. In embodiments that employ memory, the memory stores program code that, when executed by the one or more processors, carries out the techniques described herein.
[0142] Figure 6 illustrates a network node 400 that can be configured to implement functionality of the PFD management node or UPF 35. The network node 400 generally comprises network interface circuitry 420 for communicating with other NFs over a communication network, processing circuitry 430 for controlling the operation of the network node 400, and memory 440 for storing programs and data needed for operation by the network node 400.
[0143] The network interface circuitry 420 couples the network node 400 to a communication network to enable communication with other NFs to implement distribution and use of enhanced PFDs as herein described. The network interface circuitry 420 may comprise a wired or wireless interface operating according to any standard, such as the Ethernet, Wireless Fidelity (WiFi) and Synchronous Optical Networking (SONET) standards.
[0144] The processing circuitry 430 controls the overall operation network node 400. The processing circuitry 430 may comprise one or more microprocessors, hardware, firmware, or a combination thereof. The processing circuitry 430 is configured to perform the PFD procedures as shown and described. In one embodiment, the core network node 400 is configured as a NEF 60 or other PFD management node and the processing circuitry 430 is configured to perform the method of Figure 4. In another embodiment, the core network node 400 is configured as an AF 80 and the processing circuitry 430 is configured to perform the method of Figure 5.
[0145] Memory 440 comprises both volatile and non-volatile memory for storing computer program code and data needed by the processing circuitry 430 for operation. Memory 440 may comprise any tangible, non-transitory computer-readable storage medium for storing data including electronic, magnetic, optical, electromagnetic, or semiconductor data storage. Memory 440 stores computer program 450 comprising executable instructions that configure the processing circuitry 430 to implement one or more of the method herein described. A computer program 450 in this regard may comprise one or more code modules corresponding to the means or units described above. In general, computer program instructions and configuration information are stored in a non-volatile memory, such as a ROM, erasable programmable read only memory (EPROM) or flash memory. Temporary data generated during operation may be stored in a volatile memory, such as a random access memory (RAM). In some embodiments, computer program 450 for configuring the processing circuitry 430 as herein described may be stored in a removable memory, such as a portable compact disc, portable digital video disc, or other removable media. The computer program 450 may also be embodied in a carrier such as an electronic signal, optical signal, radio signal, or computer readable storage medium.
[0146] In one embodiment, the computer program 450 configures the processing circuitry 430 of the core network node 400 to perform the method of Figure 4. In another embodiment, computer program 450 configures the processing circuitry 430 of the core network node 400 to perform the method of Figure 5.
[0147] Those skilled in the art will also appreciate that embodiments herein further include corresponding computer programs. A computer program comprises instructions which, when executed on at least one processor of an apparatus, cause the apparatus to carry out any of the respective processing described above. A computer program in this regard may comprise one or more code modules corresponding to the means or units described above.
[0148] Embodiments further include a carrier containing such a computer program. This carrier may comprise one of an electronic signal, optical signal, radio signal, or computer readable storage medium.
[0149] In this regard, embodiments herein also include a computer program product stored on a non-transitory computer readable (storage or recording) medium and comprising instructions that, when executed by a processor of an apparatus, cause the apparatus to perform as described above.
[0150] Embodiments further include a computer program product comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by a computing device. This computer program product may be stored on a computer readable recording medium.
Claims
CLAIMSWhat is claimed is:1 . A method (200) implemented by a Packet Flow Description (PFD) management node in a wireless communication network of distributing enhanced PFDs for classification of packets transmitted over the wireless communication network, the method (200) comprising: receiving (230), from an application function, an enhanced PFD associated with a service provided by the application function, wherein the enhanced PFD includes a parameter indicative of a signature or classification model to be used by a user plane network node for classifying packets belonging to traffic flows associated with the service; and distributing (240) the enhanced PFD to the user plane network node for use in classifying packets belonging to the traffic flows associated with the service.
2. The method (200) of claim 1 , further comprising: prior to receiving the enhanced PFD from the application function, receiving (210) a request for supported packet detection capabilities from the application function; and sending (220), to the application function and responsive to the request, an indication of support for enhanced packet detection based on a signature or classification model.
3. The method (200) of claim 1 or 2, further comprising sending (230) the enhanced PFD to a data storage node in the wireless communication network to store as application data for the application.
4. The method (200) of any one of claims 1 - 3, wherein the parameter identifies one or more binary patterns in a header and / or payload of data packets to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
5. The method (200) of any one of claims 1 - 3, wherein the parameter identifies one or more protocol metrics characterizing a packet flow to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
6. The method (200) of any one of claims 1 - 3, wherein the parameter identifies a classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
7. A method (300) implemented by an application (AF) of provisioning Packet Flow Descriptions (PFDs) to enable detection by a user plane network node of packets belonging to traffic flows associated with a service provided by the AF, the method (300) comprising:sending (330), to a Packet Flow Description (PFD) management node, an enhanced PFD associated with the service provided by AF; and wherein the enhanced PFD includes a parameter indicative of a signature or classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
8. The method (300) of claim 10, further comprising: prior to sending the enhanced PFD to the PFD management node, sending (310) a request for supported packet detection capabilities to the PFD management node; and receiving (320), from the PFD management node and responsive to the request, an indication of support for enhanced packet detection based on a signature or classification model.
9. The method (300) of 13 or 14, wherein the parameter identifies one or more binary patterns in a header and / or payload of data packets to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
10. The method (300) of 13 or 14, wherein the parameter identifies one or more protocol metrics characterizing a packet flow to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.11 . The method (300) of 13 or 14, wherein the parameter identifies a classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
12. A Packet Flow Description (PFD) management node (60, 400) in a wireless communication network supporting packet filtering by user plane network nodes, the PFD management node being configured to: receive from an application function an enhanced PFD associated with a service provided by the application function, wherein the enhanced PFD includes a parameter indicative of a signature or classification model to be used by a user plane network node for classifying packets belonging to traffic flows associated with the service; and distribute the enhanced PFD to the user plane network node for use in classifying packets belonging to the traffic flow associated with the service.
13. The PFD management node (60, 400) of claim 18, wherein the processing circuitry is further configured to perform the method of any one of claims 2 - 6.
14. A Packet Flow Description (PFD) management node (60, 400) in a wireless communication network supporting packet filtering by user plane network nodes, the PFD management node comprising: network interface circuitry (420) enabling the PFD management node to communicate with other control plane network nodes over a communication network; and processing circuitry (430) for controlling operation of the PFD management node, the processing circuitry being configured to: receive, from an application function, an enhanced PFD associated with a service provided by the application function, wherein the enhanced PFD includes a parameter indicative of a signature or classification model to be used by a user plane network node for classifying packets belonging to traffic flows associated with the service; and distribute the enhanced PFD to the user plane network node for use in classifying packets belonging to the traffic flow associated with the service.
15. The PFD management node (60, 400) of claim 20, wherein the processing circuitry (430) is further configured to perform the method of any one of claims 2 - 6.
16. An application server (80, 400) configured to provision Packet Flow Descriptions (PFDs) for detecting packets belonging to traffic flows associated with a service provided by the application server, the application server being configured to:: send, to a Packet Flow Description (PFD) management node, an enhanced PFD associated with the service provided by AF; and wherein the enhanced PFD includes a parameter indicative of a signature or classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service.
17. The application server (80, 400) of claim 26, wherein the processing circuitry is further configured to perform the method of any one of claims 2 - 6.
18. An application server (80, 400) configured to provision Packet Flow Descriptions (PFDs) for detecting packets belonging to traffic flows associated with a service provided by the application server, the application server comprising: network interface circuitry (420) enabling the PFD management node to communicate with other control plane network nodes over a communication network; and processing circuitry (430) for controlling operation of the PFD management node, the processing circuitry being configured to:send, to a Packet Flow Description (PFD) management node, an enhanced PFD associated with the service provided by AF; and wherein the enhanced PFD includes a parameter indicative of a signature or classification model to be used by the user plane network node for classifying packets belonging to traffic flows associated with the service..
19. The application server (80, 400) of claim 28, wherein the processing circuitry (430) is further configured to perform the method of any one of claims 2 - 6.
20. A computer program (450) comprising instructions that, when executed by processing circuitry (430) in a network node (35, 45, 80, 85, 400), causes the network node to perform the method of any one of claims 1 - 11 .21 . A carrier containing the computer program (450) of embodiment 30, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.
22. A non-transitory computer-readable storage medium (450) containing a computer program (450) comprising executable instructions that, when executed by a processing circuit in a network node (35, 45, 80, 85, 400) causes the network node to perform any one of the methods of claims 1 - 11.
Citation Information
Patent Citations
Classifying Traffic Data
US20220417121A1
Packet flow descriptor provisioning
US20230262098A1
EP24382129A