Supporting lawful interception

By incorporating application identifiers in NWDAF and NEF devices, the method addresses the lack of targeted LI in existing technologies, reducing resource overload and enhancing privacy by focusing on relevant data collection and processing.

WO2025209642A1PCT designated stage Publication Date: 2025-10-09TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/058893
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-02
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Current technologies lack a mechanism to specify application identifiers during Lawful Interception (LI) in Network Data Analytics Function (NWDAF) analytics, leading to resource overload and non-targeted information provision for Law Enforcement Monitoring.

Method used

Implement methods for NWDAF and Network Exposure Function (NEF) devices to receive requests with application identifiers, enabling targeted analytics and event notifications, reducing unnecessary data collection and enhancing privacy by excluding non-requested application usage.

Benefits of technology

Reduces the amount of analytics data received by Law Enforcement Monitoring Functions, allowing more efficient identification and processing of relevant information, while ensuring privacy by excluding non-targeted application usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024058893_09102025_PF_FP_ABST
    Figure EP2024058893_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a method for supporting Lawful Interception (LI) performed by a Network Data Analytics Function (NWDAF) device (206) that includes receiving (302), from an LI Administration Function (LI ADMF) device (204), a request for analytics associated with a target, wherein the request for analytics comprises information identifying the target and an application identifier identifying an application for which analytics are requested The method also includes providing (304), to a Mediation and Delivery Function (MDF) device (236), analytics information associated with usage data of the target and that is also associated with the application identifier.
Need to check novelty before this filing date? Find Prior Art

Description

SUPPORTING LAWFUL INTERCEPTIONTECHNICAL FIELD[OOO1] The disclosure relates to methods for supporting Lawful Interception (LI) by Network Data Analytics Function (NWDAF) devices and Network Exposure Function (NEF) devices. The disclosure also relates to network nodes configured to perform the same, as well as a corresponding computer program and a carrier of such computer program.BACKGROUND

[0002] Third Generation Partnership Program (3GPP) documents s3i230703, s3i240060, and s3i240061 have introduced the usage of a Point of Intercept (POI) function device in the Network Data Analytics Function (NWDAF). The NWDAF is defined by the 3GPP as a standard for using network data analytics in the Fifth Generation (5G) Core to drive network automation and service orchestration. The NWDAF collects data from 5G core network functions (NFs), operations, administration, and management (0AM) systems and user equipment (UE) through standard interfaces defined by 3GPP. NWDAF processes the data, and the analytics output is provided in statistical analytics and predictions. The document mentioned above describe an Intercept Related Information (IRI) POI in the NWDAF, capable of generating xIRIs regarding the data analytics related to a target UE (statistics and predictions). The data analytics include:• Observed service experience as defined in TS 23.288, e.g. V18.4.0 (2013-12-19), clause 6.4.• UE mobility as defined in TS 23.288, clause 6.7.2.• UE communication as defined in TS 23.288, clause 6.7.3.• Abnormal behavior as defined in TS 23.288, clause 6.7.5.• Data volume dispersion as defined in TS 23.288, clause 6.10.• Relative proximity as defined in TS 23.288, clause 6.19.• PDU session traffic as defined in TS 23.288, clause 6.20.

[0003] In 3GPP TS 23.288 V18.4.0 at Section 6.16, the Packet Flow Description (PFD) Determination analytics clause specifies the procedure in how NWDAF provides NWDAF-assisted PFD Determination analytics. These are provided in the form ofstatistics. In the section a high level view of the data collected and the way this is done is provided. Here is an extract that explains the purpose of the data that applies to a specific Data Network Name (DNN) or slice, and 2 data flows are reported to present the data flow.

[0004] 'To assist determination of PFDs for known application identifiers, if the related Service Level Agreement does not preclude, an NWDAF may perform data analytics on existing PFD information and user plane traffic and provide analytics results in the form of new or updated PFDs, e.g. IP 3-tuple list in PFD is new or updated, to an analytics consumer in the 5GC. The [Network Exposure Function] NEF / PFD Function (PFDF) as the consumer may forward new or updated PFD information provided by the NWDAF to the [User Plane Function] UPF via the [Session Management Function] SMF to detect a known application, as defined in TS 23.502 [3]." TS 23.288 V18.4.0 Section 6.16.1.

[0005] The section further states:• "The consumer of these analytics shall indicate in the request or subscription: o -Analytics ID = " PFD Determination"; o -Target of Analytics Reporting: "any UE"; o -Application identifier; o -Analytics Filter Information optionally containing: o -S-NSSAI; o -DNN;"

[0006] The NWDAF collects information on user data traffic from various Network Functions (NFs) for a specific Single Network Slice Selection Assistance Information (S- NSSAI), DNN, Application ID and retrieves the existing PFDs from the NEF(PFDF).

[0007] A procedure for NWDAF-assisted PFD Determination is shown in Figure 1, which is taken from Figure 6.16.4-1 of Section 6.16.4 of TS 23.288 referenced above. In Figure 1, the following steps are described in the following excerpt from Section 6.16.4:"1. The Consumer NF (NEF(PFDF))

[0102] requests or subscribes to the NWDAF

[0104] to request PFD Determination analytics for a known application identifier. The Target of Analytics Reporting is set to Any UE.The Analytics Filter Information may optionally include the S-NSSAI and / or DNN.2. The NWDAF

[0104] fetches currently stored PFD information in use from UDR via NEF(PFDF) for the Application ID provided in step 1, as listed in Table 6.16.2-1.3. The NWDAF

[0104] collects information from the UPF

[0108] (event "UserDataUsageMeasures") as listed in Table 6.16.2-1 either via SMF

[0106] (Option 1) or directly from UPF

[0108] (Option 2) as defined in clause 5.8.2.17 of TS 23.501 [2]. NWDAF

[0104] discovers the SMF

[0106] (Option 1) or UPF

[0108] (Option 2) through NRF as defined in clause 4.15.4.5.3 of TS 23.502 [3]. The event "UserDataUsageMeasures" is defined in clause 5.2.26.2 of TS 23.502 [3], the subscription to the event may include an Application ID set to a value that allows the NWDAF

[0104] to retrieve input information to derive PFD Determination Analytics for the Application ID that is provided by the consumer.NOTE: The Application ID provided by the consumer and the Application ID provided to the UPF to retrieve input data for PFD Determination Analytics can be different ones.4. UPF

[0108] reports the data directly to NWDAF

[0104] .5. The NWDAF

[0104] derives PFD Determination analytics, e.g. new or updated PFD information for the existing Application ID. When the consumer provides the preferred level of accuracy, the NWDAF

[0104] provides PFD Determination Analytics that reaches this level to the consumer.6. In the case that PFD information for the existing Application ID is new or to be updated, the NWDAF

[0104] notifies PFD Determination analytics to the consumer NF

[0102] (i.e. NEF(PFDF)) with PFD Information."

[0008] As shown in the excerpt above, the Application ID is reported in all events collected by the NWDAF as an identifier of the AF application for which the collected data applies.

[0009] Moreover a Policy and Charging Function (PCF) performs the steps to register and is notified of start / stop of application traffic by Npcf_PolicyAuthorization_Notify messages containing: NotificationCorrelationld, Eventld set to "start / stop of application traffic", Eventinformation including the Applications as described in Figure 4.16.14.2 of 3GPP TS 23.502 V18.0.0 (2022-12-21).SUMMARY

[0010] An object of the invention is to enable a reduction of an amount of analytics data received by a Law Enforcement Monitoring Function (LEMF) and Mediation DeliveryFunction (MDF) to decrease the likelihood of resource overload, as well as to enable a provision of more targeted and relevant information to support Lawful Interception (LI).

[0011] The present disclosure provides methods for supporting LI by Network Data Analytics Function (NWDAF) devices and Network Exposure Function (NEF) devices. When a request for information is received from a LI Administration Function (LI ADMF) device that identifies a target, the request also includes an application identifier associated with an application for which information is requested. A NWDAF device receives a request for analytics that includes the target and the application identifier and provide to a Mediation and Delivery Function (MDF) device analytics information associated with usage data of the target that is also associated with the application identifier. A NEF device receives a request for information about events from the LI ADMF device, which includes information identifying the target and an application identifier. The NEF device subscribes to one or more network functions for information associated with the application, and then provides, to the MDF device, a notification about the event associated with the application and the target.

[0012] In an embodiment, a method for supporting LI performed by a NWDAF device includes receiving, from an LI ADMF device, a request for analytics associated with a target, wherein the request for analytics comprises information identifying the target and an application identifier identifying an application for which analytics are requested. The method also includes providing, to an MDF device, analytics information associated with usage data of the target and that is also associated with the application identifier.

[0013] In an embodiment, the request for analytics comprises a request for Packet Flow Description (PFD) Determination analytics, and wherein the analytics associated with the usage data of the target provided to the MDF device comprises PFD Determination analytics associated with the application identifier.

[0014] In an embodiment, the PFD Determination analytics are based on information received from a NEF device.

[0015] In an embodiment, the PFD Determination analytics comprises information about a port, an internet protocol address, and a traffic flow descriptor of the usage data associated with the application identifier.

[0016] In an embodiment, the information identifying the target is a Subscription Permanent Identifier (SUPI).

[0017] In an embodiment, the usage data of the target is usage data that was received from one or more network function devices after the request for analytics was received.

[0018] In an embodiment, the method further includes receiving, from the LI ADMF device a request for additional analytics associated with both the target and the application identifier, sending a subscription request to one or more network function devices for additional usage data of the target, receiving additional usage data from the one or more network function devices, and providing additional analytics information to the MDF device based on the additional usage data.

[0019] In an embodiment, the one or more network function devices comprise one or more of a Policy and Charging Function (PCF) device, a Session Management Function (SMF) device, a User Plane Function (UPF) device, a Unified Data Management (UDM), an Access and Mobility Management Function (AMF) device, or an NEF device.

[0020] In an embodiment, the additional usage data is received from the PCF device, SMF device, UPF device, UDM, or AMF device via the NEF device.

[0021] In an embodiment, a network node is provided that implements a NWDAF device and includes a processor configured to cause the network node to receive, from an LI ADMF device, a request for analytics associated with a target, wherein the request for analytics comprises information identifying the target and an application identifier identifying an application for which analytics are requested, and provide, to an MDF device, analytics information associated with usage data of the target and that is also associated with the application identifier.

[0022] In an embodiment, a method for supporting LI performed by an NEF device is provided. The method includes receiving from an LI ADMF device a notification request for information about events associated with an application and a target, the notification request comprises information identifying the target and an application identifier identifying the application. The method also includes providing a subscription request to a PCF device for information about events associated with the application, wherein the subscription request comprises the information identifying the target and the application identifier. The method also includes receiving, from the PCF device, a notification about an event associated with the application, the notification comprising the information identifying the target and the application identifier, and a notificationtype. The method also includes providing, to an MDF device, the notification about the event associated with the application.

[0023] In an embodiment, the method further includes providing, to the LI ADMF device, a notification request acknowledgement.

[0024] In an embodiment, the information identifying the target is a SUPI.

[0025] In an embodiment, a network node is provided that implements an NEF that comprises a processor that is configured to cause the network node to receive from an LI ADMF device a notification request for information about events associated with an application and a target, the notification request comprises information identifying the target and an application identifier identifying the application. The network node also provides a subscription request to a PCF device for information about events associated with the application, wherein the subscription request comprises the information identifying the target and the application identifier. The network node also receives, from the PCF device, a notification about an event associated with the application, the notification comprising the information identifying the target and the application identifier, and a notification type. The network node also provides, to an MDF device, the notification about the event associated with the application.

[0026] In an embodiment, a computer program is provided that includes instructions which when executed on at least one processor cause a network node to carry out the methods described in the preceding embodiments. A carrier is also provided that contains the computer program where the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium.

[0027] An advantage provided by the above described embodiments is that by enabling an LI ADMF device to specify an application for which analytics information or event notification information is requested, the total amount thereof is reduced, and enables the Law Enforcement Agency (LEA) to more easily identify and process relevant and targeted information. The embodiments also provide privacy enhancements where non-requested application usage of the targets is excluded from LI.BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.

[0029] Figure 1 shows a message sequence chart for a procedure for Network Data Analytics Function (NWDAF) assisted Packet Flow Data (PFD) Determination analytics according to some embodiments of the present disclosure;

[0030] Figure 2 shows an exemplary Lawful Intercept (LI) architecture with Fifth Generation (5G) core Network Functions (NFs) according to some embodiments of the present disclosure;

[0031] Figure 3 shows a message sequence chart of a method for supporting LI by a NWDAF device according to some embodiments of the present disclosure;

[0032] Figure 4 shows a message sequence chart of a method for supporting LI by a Network Exposure Function (NEF) device according to some embodiments of the present disclosure;

[0033] Figure 5 shows another message sequence chart of a method for supporting LI by a NEF device according to some embodiments of the present disclosure;

[0034] Figure 6 is a schematic block diagram of a network node according to some embodiments of the present disclosure;

[0035] Figure 7 is a schematic block diagram that illustrates a virtualized embodiment of the network node of Figure 6 according to some embodiments of the present disclosure;

[0036] Figure 8 is a schematic block diagram of the network node of Figure 6 according to some other embodiments of the present disclosure.DETAILED DESCRIPTION

[0037] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.

[0038] Network Node: As used herein, a "network node" can be any type of apparatus / device in a core network or any apparatus / device that implements a core network function. Some examples of a core network node include a computer or server host for e.g., a Mobility Management Entity (MME), a Packet Data Network Gateway (P-GW), a Service Capability Exposure Function (SCEF), a Home Subscriber Server (HSS), or the like. Some other examples of a core network node include a node implementing an Access and Mobility Management Function (AMF), a User Plane Function (UPF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a Network Function (NF) Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), or the like. In the following description, when stating that any of these functions, such as Lawful Intercept (LI) Administration Function (ADMF) device or an NEF device, perform an action, such as receiving / matching / performing / configuring then it is to be understood that it is in practice the network node / computer / server host / LI ADMF device / NEF device that hosts the LI ADMF or NEF, respectively, that performs the action. It shall also be understood that the LI ADMF may also be the abbreviation for LI Administrative Function.

[0039] Note that the description given herein focuses on a Third Generation Partnership Project (3GPP) cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.

[0040] Note that the description given herein focuses on a 3GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.

[0041] Various problems with the current existing techniques described in the background. While application identifiers in the context of NWDAF-assisted Packet Flow Data (PFD) Determination analytics is known, there is no mechanism to tackle or specify application identifiers when performing LI of NWDAF analytics. Additionally, relevant START / STOP events of the Application (reported to the NEF by PCF) aren't considered as Intercept Related Information (xIRI) messages.

[0042] The present disclosure provides methods for supporting LI by NWDAF devices and NEF devices. When a request for information is received from a LI ADMF device that identifies a target, the request also includes an application identifier associated with an application for which information is requested. A NWDAF device receives a request for analytics that includes the target and the application identifier and provide, to a Mediation and Delivery Function (MDF) device, analytics information associated withusage data of the target that is also associated with the application identifier. A NEF device receives a request for information about events from the LI ADMF device, which includes information identifying the target and an application identifier. The NEF device subscribes to one or more network functions for information associated with the application, and then provides to the MDF device a notification about the event associated with the application and the target.

[0043] There are three embodiments disclosed herein that are interrelated. An application ID is used to narrow down data of interest collected by NWDAF device in fact this item is reported in almost all events collected by NWDAF device. The proposed solution adds the Application ID as a target to be used together with SUPI to limit the analytics collecting and target a specific application and not all the UE statistics. The SUPI may be in the form of an International Mobile Subscriber Identifier (IMSI) or a Network Access Identifier (NAI).

[0044] Another embodiment is that the NWDAF device collects data from the NEF device, the NEF device collects application data from a UDM this data is useful for the PFD Determination analytics use case. The PFD Determination is added to the list of statistics to be collected to cover the identification of applications used by the subscriber. The PFD Determination analytics collect new or updated PFDs, e.g., IP 3- tuple list in PFD is new or updated (IP Flow or Traffic descriptor field contain a 3-tuple destination address, port and protocol) or Application ID or Domain descriptor.

[0045] Another embodiment is the ability to monitor the usage of Mobile Apps (MA) connected to an Application Function (AF) that are registered on the network and are connected to NEF monitoring Npcf_PolicyAuthorization Service API, particularly the START / STOP events. For those MA, the NEF device will register for the events and forward them on its POI function including in the messages the Application identifier.

[0046] An advantage provided by the above described embodiments is that by enabling an LI ADMF device to specify an application for which analytics information or event notification information is requested, the total amount thereof is reduced, and enables the Law Enforcement Agency (LEA) to more easily identify and process relevant and targeted information. The embodiments also provide privacy enhancements where non-requested application usage of the targets are excluded from LI.

[0047] Figure 2 shows an exemplary Lawful Intercept (LI) architecture with Fifth Generation (5G) core Network Functions (NFs) according to some embodiments of thepresent disclosure where interaction between any two NFs is represented by a point-to- point reference point / interface.

[0048] Seen from the access side the 5G network architecture shown in Figure 2 comprises one or more UEs (e.g., UE 210-1, 210-2, individually or collectively referred to as UE 210) connected to either a Radio Access Network (RAN) 234 as well as an AMF216. Typically, the RAN 234 comprises base stations, e.g. such as eNBs or gNBs or similar. Seen from the core network side, the 5GC NFs shown in Figure 2 include a NSSF device 224, an AUSF device 228, a UDM 218, a UPF device 230, the AMF device 216, a SMF device 226, a PCF device 220, an Application Function (AF) 222, Network Repository Function (NRF) 214, NWDAF device 206, and a NEF device 212.

[0049] Reference point representations of the 5G network architecture are used to develop detailed call flows in the normative standardization. The N1 reference point is defined to carry signaling between the UE 210 and AMF 216. The reference points for connecting between the RAN 234 and AMF 216 and between the RAN 234 and UPF 230 are defined as N2 and N3, respectively. N4 is used by the SMF 226 and UPF 230 so that the UPF 230 is set using the control signal generated by the SMF 226, and the UPF 230 reports its state to the SMF 226. N6 is the reference point for the connection between the Data Network (DN) 232.

[0050] The NWDAF device 206 includes a POI function 208 and the NEF device 212 includes a POI function 213 that are functions that detect target communications inbound or outbound from the respective NWDAF device 206 or NEF device 212 derives the intercept related information or communications content from the target communications and delivers the POI output to the Mediation and Delivery function (MDF) 236 via the X2 (Intercept Related Information -xIRI) or X3 (Content of Communication - xCC) protocols. In the present disclosure, the X2 protocol that carries xIRI related information is the relevant protocol.

[0051] The MDF 236 receives the data from the POI functions 208 and 213 before forwarding the LI data to Law Enforcement Monitoring Function (LEMF) 238 that is associated with the Law Enforcement Agency (LEA) 202.

[0052] The LI ADMF 204 receives information about warrants for LI from the LEA 202 and sends requests for information identifying a target (e.g., device and or subscriber) as well as an application identifier associated with an application.

[0053] Figure 3 shows a message sequence chart of a method for supporting LI by NWDAF device 206 according to some embodiments of the present disclosure.

[0054] At 302, the LI ADMF device 204 sends a request for analytics to NWDAF device 206. The request for analytics is an ActivateTask message. The request for analytics is provided to the NWDAF device 206 via the XI interface and the request, in addition to including information identifying the target, also includes an application identifier identifying an application associated with the analytics. In an embodiment, information about the types of analytics requested are included in the ActivateTask message as a task object including a list of analytics identifiers. In other embodiments, the analytics identifiers are provided to the NWDAF 206 by the LI ADMF 204 in a separate message. Analytics identifiers are values or strings that identify type of analytics to be performed or collected by the NWDAF 206. The application identifier is associated with one or more applications, and the information identifying the target can for example be a SUPI which identifies a subscriber. In an embodiment, the application identifier and the SUPI form a Targetidentifier structure in the ActivateTask message that identifies the target of the task. The Targetidentifier structure includes two fields, one of which includes the SUPI and the other a ServiceType field that specifies the service to be intercepted, and in an embodiment, the application identifier is included in the ServiceType field.

[0055] In an embodiment, the NWDAF device 206 will have already determined some analytics about usage data associated with the target and the application identifier before the warrant was received and the request received at step 302 (e.g., according to the process of Figure 1 above). In an embodiment, once the request for analytics is received at 302, any existing analytics are provided to the MDF 236 at 304 as an xIRI message, where the analytics information provided to the MDF 236 is associated with usage data of the target and that is also associated with the application identifier.

[0056] In another embodiment, the NWDAF device 206 performs analytics on usage data that is received after the request for analytics is received, and thus the analytics information provided at step 304 is analytics information based on target usage of the application associated with the application identifier after the request for analytics is received.

[0057] In an embodiment, the request for analytics comprises a request for PFD Determination analytics and the analytics information provided to the MDF 236 at 304includes PFD Determination analytics associated with the application identifier and the target.

[0058] In an embodiment, the PFD Determination analytics are based on information received from a NEF device 212. In an embodiment, the PFD Determination analytics comprises information about a port, an internet protocol address, and a traffic flow descriptor of the usage data associated with the application identifier.

[0059] Optionally, at 306, the LI ADMF 204 issues a request for additional analytics, either to capture different types of analytics or to capture analytics about usage data for an additional target or additional application identifier. In an embodiment, the message at 306 is a ModifyTask message that includes a different list of analytics identifiers than was previously provided to the NWDAF 206. At 308, the NWDAF 206 may then optionally send a subscription request to one or more NFs 301 for additional usage data of the target. The NFs 301 could, for example, by one or more of a PCF device 220, a SMF device 226, a UPF device 230, a UDM 218, an AMF device 216, or an NEF device 212.

[0060] At 310, the NWDAF device 206 optionally receives the usage data from the NFs 301 and then the NWDAF device 206 at 312 optionally sends the additional analytics information based on the additional usage data to the MDF 236.

[0061] Figures 4 and 5 show message sequence charts of methods for supporting LI by a Network Exposure Function (NEF) device according to some embodiments of the present disclosure.

[0062] In Figure 4, an LI ADMF device 204 at step 402 sends a notification request for information about events associated with an application and a target to the NEF device 212, where the notification request comprises information identifying the target (e.g., a SUPI) and an application identifier identifying the application. In an embodiment, the notification request is a LI Application Notify Task Creation request that in addition to identifying the type of events to be notified about, also includes the SUPI and the application identifier(s) (e.g., an ApplicationlDList).

[0063] The NEF device 212 at step 404 then provides a subscription request to a PCF device 220 for information about events associated with the application, where the subscription request comprises the information identifying the target and the application identifier. The subscription request also identifying the type of events to be subscribedto. In an embodiment, the subscription request is a Npcf_PolicyAuthorization_Subscribe message that includes the SUPI and the ApplicationlDList.

[0064] Optionally, at step 406 the PCF device 220 sends back a Npcf_PolicyAuthorization_Subscribe Acknowledgement message to the NEF device 212, and optionally at step 408, the NEF device 212 sends to the LI ADMF device 204, over the XI interface, an LI Application Notify Registration Response Acknowledgement message.

[0065] In an embodiment, the method shown in Figure 5 occurs after the NEF device 212 has subscribed to event notifications at the PCF device 220 according to the method depicted in Figure 4. In Figure 5, the PCF device 220, when an event that meets the criteria of the subscription request (e.g., type of event, target, application identifier, etc.) occurs, the PCF device 220 at step 502 provides a notification message to the NEF device 212 that includes information identifying the target and the application identifier, and a notification type. In an embodiment, the message is a Npcf_PolicyAuthorization_Notify message that includes the SUPI, an AppDetection Report, an adNotifyType, and an afAppID.

[0066] The NEF device 212 then reports the information included in the notification message to the MDF 236 via the X2 interface as xIRI at step 504.

[0067] In an embodiment, the notification types are Application ID start and stop operations for a UE using information already available on the PCF node (received from the AMF). This is an implementation that involves the NEF node that receives according to the standard already the START / STOP events of registered applications.

[0068] Start and stop messages, when an application is used on the equipment is forwarded to MDF 236 by NEF device 212 with 2 additional X-IRI messages. The Application Detection Control (ADC) uses deterministic identification based on IP addresses used that are associated with an app to generate the X-IRI START message.

[0069] ADC also generates the X-IRI START message and after that a timer for the next message in this flow shall be set and once the timer expires without new messages the X-IRI STOP message for the application should be sent assuming the App is not active anymore.

[0070] In Figure 4, the registration of the NEF device 212 towards the PCF device 220 for the target shall be done and in this way the NEF forwards to the Element of LI (ELI) (e.g., the POI 213 that is associated with the NEF device 212) the notificationsthat the PCF device 220 gathers regarding registered application. With regard to the Start or Stop indications, the "adNotifType" value from the notification message sent to the MDF 236 has a value of either "APP_START" or "APP_STOP".

[0071] The "Application ID tag" shall be reported for a certain destination IP address with the level of trust that we expect on this analysis based on the domain inspector results for the IP packet analyzed. Two new X-IRI messages shall be generated that contain changes to the IP address list for a certain application and another one that shall state that the application has started or stopped. The Application ID tag is shown below in for the Npcf_PolicyAuthorization Service API: info: title: Npcf_PolicyAuthorization Service API version: 1.3.0-alpha.l description: |PCF Policy Authorization Service.AppDetectionReport: description: >Indicates the start or stop of the detected application traffic and the application identifier of the detected application traffic.Type: object required:- adNotifType- afAppId properties: adNotifType:$ref: '# / components / schemas / AppDetectionNotifType' afAppId:$ref: '# / components / schemas / AfAppId'

[0072] Figure 6 is a schematic block diagram of a network node 600 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The network node 600 may be, for example, a network node that implements all or part of the functionality of the NWDAF device 206 or NEF device 212 as described herein, and may in the future thus be a network node according to any future telecommunication network standard, such as the emerging 3GPP 6thGenerationnetwork. As illustrated, the network node 600 includes a control system 602 that includes one or more processors 604 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory / computer readable storage medium 606, and a network interface 608. The one or more processors 604 are also referred to herein as processing circuitry.

[0073] The one or more processors 604 operate to provide one or more functions of a network node 600 as described herein. In some embodiments, the function(s) are implemented in one or more computer programs 610 that are stored, e.g., in the computer readable storage medium 606 and executed by the one or more processors 604.

[0074] Figure 7 is a schematic block diagram that illustrates a virtualized embodiment of the network node 600 according to some embodiments of the present disclosure. This discussion is equally applicable to other types of network nodes. Further, other types of network nodes may have similar virtualized architectures. Again, optional features are represented by dashed boxes.

[0075] As used herein, a "virtualized" network node is an implementation of the network node 600 in which at least a portion of the functionality of the network node 600 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). As illustrated, in this example, the network node 600 may include the control system 602 as described above. The network node 600 includes one or more processing nodes 700 coupled to or included as part of a network(s) 702. If present, the control system 602 is connected to the processing node(s) 700 via the network 702. Each processing node 700 includes one or more processors 704 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory / computer readable storage medium 706, and a network interface 708.

[0076] In this example, functions 710 of the network node 600 described herein are implemented at the one or more processing nodes 700 or distributed across the one or more processing nodes 700 and the control system 602 in any desired manner. In some particular embodiments, some or all of the functions 710 of the network node 600 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environment(s) hosted by the processing node(s) 700. As will be appreciated by one of ordinary skill in the art, additionalsignaling or communication between the processing node(s) 700 and the control system 602 is used in order to carry out at least some of the desired functions 710.

[0077] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of network node 600 or a node (e.g., a processing node 700) implementing one or more of the functions 710 of the network node 600 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).

[0078] Figure 8 is a schematic block diagram of the network node 600 according to some other embodiments of the present disclosure. The network node 600 includes one or more modules NWDAF device 206 or NEF device 212, each of which is implemented in software. The module(s) NWDAF device 206 or NEF device 212 provide the functionality of the network node 600 described herein. This discussion is equally applicable to the processing node 700 of Figure 7 where the modules NWADF device 206 or NEF device 212 may be implemented at one of the processing nodes 700 or distributed across multiple processing nodes 700 and / or distributed across the processing node(s) 700 and the control system 602.

[0079] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitrymay be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0080] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).

[0081] At least some of the following abbreviations may be used in this disclosure. If there is an inconsistency between abbreviations, preference should be given to how it is used above. If listed multiple times below, the first listing should be preferred over any subsequent listing(s).

[0082] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.

Claims

CLAIMS1. A method for supporting Lawful Interception, LI, performed by a Network Data Analytics Function, NWDAF, device (206) the method comprising: receiving (302), from an LI Administration Function, LI ADMF, device (204) a request for analytics associated with a target, wherein the request for analytics comprises information identifying the target and an application identifier identifying an application for which analytics are requested; and providing (304), to a Mediation and Delivery Function, MDF, device (236) analytics information associated with usage data of the target and that is also associated with the application identifier.

2. The method of claim 1, wherein the request for analytics comprises a request for Packet Flow Description, PFD, Determination analytics, and wherein the analytics associated with the usage data of the target provided to the MDF device (236) comprises PFD Determination analytics associated with the application identifier.

3. The method of claim 2, wherein the PFD Determination analytics are based on information received from a Network Exposure Function, NEF, device (212).

4. The method of any of claims 2 to 3, wherein the PFD Determination analytics comprises information about a port, an internet protocol address, and a traffic flow descriptor of the usage data associated with the application identifier.

5. The method of any of claims 1 to 4, wherein the information identifying the target is a Subscription Permanent Identifier, SUPI.

6. The method of any of claims 1 to 5, wherein the usage data of the target is usage data that was received from one or more network function devices (301) after the request for analytics was received.

7. The method of any of claims 1 to 6, comprising:receiving (306), from the LI ADMF device (204), a request for additional analytics associated with both the target and the application identifier; sending (308) a subscription request to the one or more network function devices (301) for additional usage data of the target; receiving (310) the additional usage data from the one or more network function devices (301); providing (312) the additional analytics information to the MDF device (236) based on the additional usage data.

8. The method of claim 7, wherein the one or more network function devices (301) comprise one or more of a Policy and Charging Function, PCF, device (220), a Session Management Function, SMF, device (226), a User Plane Function, UPF, device (230), a Unified Data Management, UDM, (218), an Access and Mobility Management Function, AMF, device (216), or a Network Exposure Function, NEF, device (212).

9. The method of claim 8, wherein the additional usage data is received from the PCF device (220), SMF device (226), UPF device (230), UDM (218) or AMF device (216) via the NEF device (212).

10. A network device (600) that implements a Network Data Analytics Function, NWDAF, (206) and comprises a processor (604) configured to cause the network node (600) to: receive (302), from a Lawful Intercept Administration Function, LI ADMF, device (204) a request for analytics associated with a target wherein the request for analytics comprises information identifying the target and an application identifier identifying an application for which analytics are requested; and provide (304), to a Mediation and Delivery Function, MDF, device (236) analytics information associated with usage data of the target and that is also associated with the application identifier.

11. The network node (600) of claim 10, wherein the request for analytics comprises a request for Packet Flow Description, PFD, Determination analytics, and wherein theanalytics associated with the usage data of the target provided to the MDF device (236) comprises PFD Determination analytics associated with the application identifier.

12. The network node (600) of claim 11, wherein the PFD Determination analytics are based on information received from a Network Exposure Function, NEF, device (212).

13. The network node (600) of any of claims 11 to 12, wherein the PFD Determination analytics comprises information about a port, an internet protocol address, and a traffic flow descriptor of the usage data associated with the application identifier.

14. The network node (600) of any of claims 10 to 13, wherein the information identifying the target is a Subscription Permanent Identifier, SUPI.

15. The network node (600) of any of claims 10 to 14, wherein the usage data of the target subscriber is usage data that was received from one or more network functions (301) after the request for analytics was received.

16. The network node (600) of any of claims 10 to 15, wherein the processor (604) is configured to cause the network node (600) to: receive (306), from the LI ADMF device (204), a request for additional analytics associated with the target subscriber and the application identifier; send (308) a subscription request to one or more network functions (301) for additional usage data of the target subscriber; receive (310) additional usage data from the one or more network functions (301); and provide (312) additional analytics information to the MDF device (236) based on the additional usage data.

17. The network node (600) of claim 16, wherein the one or more network functions (301) comprise one or more of a Policy and Charging Function, PCF, device (220), a Session Management Function, SMF, device (226), a User Plane Function, UPF, device(230), a Unified Data Management, UDM, (218), an Access and Mobility Management Function, AMF, device (216), or a Network Exposure Function, NEF, device (212).

18. The network node (600) of claim 17, wherein the usage data is received from the PCF device (220), SMF device (226), UPF device (230), UDM (218) or AMF device (216) via the NEF device (212).

19. A method for supporting Lawful Intercept, LI, performed by a Network Exposure Function, NEF, device (212) the method comprising: receiving (402), from an LI Administration Function, LI ADMF, device (204), a notification request for information about events associated with an application and a target, the notification request comprising information identifying the target and an application identifier identifying the application; providing (404) a subscription request to a Policy and Charging Function, PCF, device (220) for information about events associated with the application, wherein the subscription request comprises the information identifying the target and the application identifier; receiving (502), from the PCF device (220), a notification about an event associated with the application, the notification comprising the information identifying the target and the application identifier, and a notification type; and providing (504), to a Mediation and Delivery Function, MDF, device (236), the notification about the event associated with the application.

20. The method of claim 19, further comprising: providing (408), to the LI ADMF device (204), a notification request acknowledgement.

21. The method of any of claims 19 to 20, wherein the information identifying the target is a Subscription Permanent Identifier, SUPI.

22. A network node (600) that implements a Network Exposure Function, NEF, (212) the network node (600) comprising a processor (604) configured to cause the network node (600) to:receive (402), from a Lawful Intercept Administration Function, LI ADMF, device (204), a notification request for information about events associated with an application and a target, the notification request comprising information identifying the target and an application identifier identifying the application; provide (404) a subscription request to a Policy and Charging Function, PCF, device (220) for information about events associated with the application, wherein the subscription request comprises the information identifying the target and the application identifier; receive (502), from the PCF device (220), a notification about an event associated with the application, the notification comprising the information identifying the target and the application identifier and a notification type; and provide (504), to a Mediation and Delivery Function, MDF, device (236), the notification about the event associated with the application.

23. The network node (600) of claim 22, wherein the processor (604) is further configured to: provide (408), to the LI ADMF device (204), a notification request acknowledgement.

24. The network node (600) of any of claims 22 to 23, wherein the information identifying the target is a Subscription Permanent Identifier, SUPI.

25. A computer program (610) comprising instructions which, when executed on at least one processor (604), cause a network node (600) to carry out the method according to any of claims 1 to 9 or 19 to 21.

26. A carrier containing the computer program (610) of claim 25, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (606).

Citation Information

Patent Citations

  • Network data collection method from application function device for network data analytic function

    US20200322821A1

  • Methods, devices relating to lawful interception

    WO2023143738A1