Network data analytics function assisted detection and mitigation of network function anomaly
The NWDAF collaborates with cNFs for holistic anomaly detection and mitigation in 5G networks, addressing diverse control plane anomalies, enhancing detection accuracy and network reliability through global analysis and remedial actions.
Patent Information
- Application Number
- PCT/SE2025/050321
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-08
- Filing Date
- 2025-04-07
- Publication Date
- 2025-10-16
AI Technical Summary
Current solutions lack a comprehensive approach for anomaly detection and mitigation in the control plane of 5G networks, particularly in the Network Function (NF) domain, where diverse sources of abnormal behavior are prevalent due to complex network topologies and varied NF types, leading to performance degradation and security breaches.
A Network Data Analytics Function (NWDAF) is introduced to collaborate with Network Function consumers (cNFs) for holistic anomaly detection, utilizing vertical federated learning and global anomaly analysis to improve detection accuracy and provide remedial actions through Operations, Administration, and Management (OAM).
Enhances anomaly detection performance with reduced false alarms, improves network security and reliability by preventing anomaly propagation, and enables timely remediation of NF anomalies, thus maintaining network robustness and performance.
Smart Images

Figure SE2025050321_16102025_PF_FP_ABST
Abstract
Description
NETWORK DATA ANALYTICS FUNCTION ASSISTED DETECTION AND MITIGATION OF NETWORK FUNCTION ANOMALYTECHNICAL FIELD
[0001] Disclosed are embodiments related to network data analytics function assisted detection and mitigation of network function anomaly.BACKGROUND
[0002] The Third Generation Partnership Project (3GPP) has developed the Fifth Generation (5G) standard for cellular networks. 5G Core (5GC) refers to the core architecture of the 5G standard.
[0003] Anomalies in the network can cause performance degradation, inefficient resource utilization, and security breaches. Such incidents can happen in the user plane, i.e., user data traffic, or in the control plane, i.e., control data traffic. While user plane anomaly analysis is widely addressed and studied, the control plane has mostly been assumed to be a secure realm. Therefore, anomaly detection in the control plane caused by abnormal behavior from a Network Function (NF) is yet to be studied. Furthermore, unlike abnormal behavior in the user plane where the source is one or more of an Application Function (AF) and a user equipment (UE), in the control plane, the source can be very diverse. This is because of various NF types that are usually deployed and the complex network topology and configuration in 5GC.
[0004] In [FS_AIML_CN] (which covers some general statements on Analytics in 5GC and the Study on Core Network Enhanced Support for Artificial Intelligence (AI) / Machine Learning (ML)), there is a Key Issue, i.e., Key Issue #4, on NWDAF enhancements to support network abnormal behavior mitigation and prevention. This Key Issue identified the need for new network data analytics function (NWDAF) analytics to detect such abnormal behaviors (such as signaling storm). The present disclosure partially addresses this Key Issue and provides new signaling and architecture required for such solutions.
[0005] As pre-study discussions, a general architecture has been proposed about how vertical federated learning (VFL) can be applied in NWDAF to train an ML model to predict NF abnormal behavior. In one solution a co-located instance of NWDAF (a model training logical function (MTLF)) is associated to each NF to perform training in a distributed architecture and only using the training data collected for the associated NF. The approach is illustrated in FIG. 1 for the use case of Signaling Storm as an anomaly. FIG. 1 illustrates verticalfederated learning for abnormal behavior ML model training using co-located NWDAF (MTLF) instances. The “initial” local model is downloaded to different NFs and required features are specified to the NFs; intermediate data is provided by the NFs to the NWDAF server, and the NWDAF server sends the loss status to the NFs after processing the intermediate data.
[0006] REFERENCES1. [CPI- LESS] Ericsson CPI store, “Low Energy Scheduler Solution Overview”2. [Pyun20Root] Hahyung Pyun, et al., “Root causality analysis at early abnormal stage using principal component analysis and multivariate Granger causality,” Process Safety and Environmental Protection, v. 135, pp. 113-125, 2020.3. [Lin22Causal] Lin, X., Chen, Y., Li, G., & Yu, Y. (2022). A Causal Inference Look at Unsupervised Video Anomaly Detection. Proceedings of the AAAI Conference on Artificial Intelligence, 36(2), 1620-1629.4. [FS_AIML_CN] 3GPP TR 23.700-84 V0.2.0 (2024-03), Study on Core Network Enhanced Support for Artificial Intelligence (AI) / Machine Learning (ML)SUMMARY
[0007] There currently exist certain challenge(s). Anomaly detection, prediction, and mitigation for NWDAF are new features under development. At the moment, there are many solutions for local anomaly detection of individual ML tasks (within or outside an NF domain). However, there is no current solution for including an NWDAF into the anomaly detection pipeline and using its holistic knowledge to (i) improve the accuracy of the local anomaly detection, made by individual NF consumer, and (ii) provide suggestions to operations, administration and management (0AM) and other entities to take some remedial actions.
[0008] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges. Certain embodiments provide for a collaboration between NF consumers (cNF) and NWDAF for detection and containment of anomalies. Here cNF refers to a consumer of the NWDAF service, and it is not the terminology used in the Cloud Native NF — physical NF, or cNF-pNF (e.g. Session Management Function (SMF)-User Plane Function (UPF)) interaction. In certain embodiments, when a consumer NF detects abnormal behavior of an NF, a so-called flag report may be sent back to NWDAF to inform about the detected incident. NWDAF may use the flag report to perform a global anomaly detection usingits holistic view of the network, and together with the 0AM find proper remedies to contain the impact of the misbehaved NF on other NFs and other entities in 5GC.
[0009] Certain embodiments provide for a method for enabling NWDAF-assisted anomaly detection of NFs characterized by one or more of three functions. A first function may trigger an anomaly report from cNF to NWDAF based on at least some anomaly detection methods / criteria and with (optionally) some confidence report, being instructed by the NWDAF. A second function may execute an in-depth anomaly analysis in NWDAF using at least one other causally-connected NF, may perform the analysis over a longer period of time, and so on. A third function may generate a report to 0AM or other relevant network entities to handle the anomaly incident, based on at least analytics provided by NWDAF and / or a set of predefined actions
[0010] Certain embodiments may provide one or more of the following technical advantage(s). An NF anomaly is detected and the effect of the anomaly is not propagated to other NFs in 5GC to prevent degradation in network performance and mitigate the impact of the anomaly. An NF anomaly can happen because of software error, incompatible interfaces, update failure, invalid certificate, and so on. By applying certain embodiments disclosed in this disclosure, network security, robustness, and reliability will increase. Other advantages include:• Improved anomaly detection performance with fewer false alarms, due to NWDAF having a holistic view of the network.• Improved cNF’s capabilities for local anomaly detection through dynamic updates of the anomaly-detection instruction by NWDAF.• Improved capability of 0AM and other management entities to take proper action in the presence of some anomalies.• Improved readiness of the network for upcoming NF anomalies.
[0011] According to a first aspect, a computer- implemented method for improving anomaly detection, performed by a Network Function consumer (cNF) in communication with a Network Data Analytics Function (NWDAF), is provided. The method includes sending, towards the NWDAF, an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly. The method includes receiving an anomaly notification message comprising remediating instructions. The method includes performing the remediating instructions.
[0012] According to a second aspect, a computer-implemented method for improving anomaly detection, performed by a Network Data Analytics Function (NWDAF) in communication with a Network Function consumer (cNF), is provided. The method includes receiving, from the cNF, an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly. The method includes initiating an anomaly analysis.
[0013] According to a third aspect, a computer-implemented method for improving anomaly detection, performed by Operations, Administration and Management (0AM) in communications with a Network Data Analytics Function (NWDAF), is provided. The method includes receiving, from the NWDAF, an anomaly analytics report including a set of affected NFs and cNFs and an instruction context field. The method includes performing remediating actions. The method includes sending an anomaly notification message comprising remediating instructions to one or more of the NWDAF and one or more of the affected cNFs.
[0014] According to a fourth aspect, a network node for improving anomaly detection is provided. The network node includes processing circuitry configured to perform any one of the embodiments of the first, second, and third aspects. The network node includes power supply circuitry configured to supply power to the processing circuitry.
[0015] According to a fifth aspect, a network node for improving anomaly detection is provided. The network node includes an antenna configured to send and receive wireless signals. The network node includes radio front-end circuitry connected to the antenna and to processing circuitry, and configured to condition signals communicated between the antenna and the processing circuitry. The network node includes the processing circuitry being configured to perform any one of the embodiments of the first, second, and third aspects. The network node includes an input interface connected to the processing circuitry and configured to allow input of information into the UE to be processed by the processing circuitry. The network node includes an output interface connected to the processing circuitry and configured to output information from the UE that has been processed by the processing circuitry. The network node includes a battery connected to the processing circuitry and configured to supply power to the network node.BRIEF DESCRIPTION OF THE DRAWINGS
[0016] FIG. 1 illustrates vertical federated learning for abnormal behavior ML model training using co-located NWDAF (MTLF) instances.
[0017] FIG. 2 illustrates a flowchart according to certain embodiments.
[0018] FIG. 3 is a flowchart illustrating a process according to certain embodiments.
[0019] FIG. 4 is a flowchart illustrating a process according to certain embodiments.
[0020] FIG. 5 is a flowchart illustrating a process according to certain embodiments.
[0021] FIG. 6 is a block diagram of a communication system according to certain embodiments.
[0022] FIG. 7 is a block diagram of a user equipment according to certain embodiments.
[0023] FIG. 8 is a block diagram of a network node according to certain embodiments.
[0024] FIG. 9 is a block diagram of a virtualization environment according to certain embodiments.DETAILED DESCRIPTION
[0025] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.
[0026] FIG. 2 shows a flowchart according to certain embodiments. The steps shown in the flowchart will be described in more detail below. Briefly, in Step 1, cNFs 202 may subscribe to the security and monitoring service of an NWDAF 204, which would be responsible for anomaly detection. Afterward, in Step 2, each cNF may follow the procedure instructed by the NWDAF (which may include some Al methods, among other approaches) to detect anomalies. Upon detecting an anomaly, the cNF may share the anomaly with the NWDAF, e.g., using the anomalyContext field in Step 3. In Step 4, the NWDAF may then give a reception acknowledgment and initiate an internal process for global anomaly detection (Step 5). This step can be handled, among other approaches, using a root causality analysis. Another approach, in addition to or as an alternative to the root causality analysis, could be having a global ML model in the NWDAF for anomaly detection. The results of this process will be shared with 0AM 206 in Step 6. 0AM will then take some remediating action itself, e.g., it may quarantine the anomalous NF and reconfigure the network, delete the anomalous / infected NF instance and spawn another clean NF instance, and so on. Afterward, 0AM may notify the affected cNFs along with some instructioncontext field that specifies actions to be made by the cNFs to reduce / prevent the risk. Examples of such instructions could be (i) modifying parameters of affected NFs and (ii) a temporal change to the anomaly detection frequency done by a cNF.
[0027] The 0AM’ s response (Steps 7 and 8 below) to an anomaly signal from the NWDAF (Step 6) may involve selecting from a set of predefined policies based on the received anomalynotification in Step 6. The notification to the cNF in step 9 may be sent by the 0AM directly, instead of sending it via NWDAF, e.g., if an asynchronous communication between cNFs and 0AM and NWDAF is used. In this scenario, 0AM is able to broadcast anomaly notifications to all affected cNFs.
[0028] The following steps correspond to those shown in FIG. 2.
[0029] Step 1: A cNF subscribes to NWDAF for anomaly detection service with the list of NFs to be monitored and informed about. A default choice can be all NFs of that consumer.
[0030] Step 2: NWDAF responds back with the proof points (features) to be collected for each NF to be monitored, Al methods for anomaly detection, and so on. This step includes an instruction for each NF individually. Examples of the instructions can be:• An ML model that can be used for anomaly detection and provides confidence on the detection.• A set of rules that specifies an anomaly can be reported only if the detection confidence is above a certain threshold or satisfies certain conditions.• A set of rules that specifies if some anomaly is detected but with a low confidence, cNF can ask NWDAF for an in-depth analysis of the incident and data.
[0031] Step 3 : cNF monitors for potential anomalies and reports identified issues using instructions provided in Step 2. Examples include:• If there is an identified issue with a predefined confidence / accuracy level, then cNF sends an anomaly signal with NF-ID and anomalyContext including at least evaluated confidence / accuracy level and (possibly) weights of the local ML model and other context that describes the detected anomaly.• If the confidence / accuracy level is below a certain threshold (which can be set during the subscription phase for each NF in Step 2), cNF may decide not to rely on local results and directly ask for global detection. In this case, cNF sends an anomaly signal with NF-ID and anomalyContext.
[0032] Existing methods, such as principal component analysis, unsupervised learning [Lin22Causal], and root causality analysis [Pyun20Root], can be employed for local anomaly detection. During the subscription process in Step 2, cNF may be informed of a specific procedure, including the method used, required data, and execution frequency, for local anomaly detection. As an alternative and / or additional embodiment, NWDAF can regularly collect required data and run the initial anomaly detection on behalf of a cNF. This can be agreed upon, for example, in the subscription phase in Steps 1 and 2.
[0033] In this step, some cNFs may try to send malicious anomaly reports to attack / overload NWDAF anomaly detection service. This can be detected, among other approaches, in Step 5 after the in-depth analysis of the data. Upon contradictions between anomaly reports sent by cNF and the detection results of NWDAF, NWDAF can report this to 0AM to take proper action regarding that cNF (e.g., in Steps 6 and 7). This can be handled, for example, by some credit scores to the reports coming from that cNF in future.
[0034] Step 4: NWDAF sends an ack to inform cNF that anomaly signal is received.
[0035] Step 5: NWDAF initiates an internal in-depth anomaly detection process. This can be facilitated by at least• Running anomaly detection over a longer-period of the data to improve the accuracy of the anomaly detection.• Performing root cause analysis or sparse reconstruction techniques, using observations from other NFs.• Cross-correlate the anomaly detection with other affected NFs.
[0036] The difference between Steps 3 and 5 is that Step 3 is limited to the local scope and data of each NF / cNF, whereas Step 5 uses global information available at NWDAF. This information includes access to at least anomaly reports of other NFs. A non-restrictive example is provided as a use case below.
[0037] Step 6: NWDAF sends an anomaly detection report to 0AM or other relevant entities. Other relevant entities can be, for instance, security solutions deployed in the network or network slices for example. Note that NWDAF may provide key performance indicator (KPI) related information to network slices. Then if KPIs for a certain slice were questionable, a detection alert can be sent to some security / management solution local to the slice or other more global solution that can prevent the attack impact of other entities sharing the slice resources.
[0038] The anomaly detection report of Step 6 includes optionally a list of potentially affected NFs and cNFs. This list can be obtained for instance via:• A causality graph that describes casual relationships among NFs. This graph can be obtained and maintained using various Causality Discovery methods.• An existing table / database that describes connections and relations of the NFs.
[0039] As an additional and / or alternative embodiment, the detection of potentially affected NFs and cNFs can be done by the 0AM by using the anomaly detection report provided by NWDAF. In this case Step 6 may not include these NFs.
[0040] Step 7: OAM performs risk evaluations using other related context information and can take remediating actions. Non- limiting examples of those actions could be to reconfigure the anomalous NF to put it in a quarantine slice, respawning a clean instance of the affected NF, increasing the log-level in the affected NF, initiating upgrade / patch of software running in the NF, and so on. In addition, it defines the set of specific remediations for some cNFs / NFs in instructioncontext targeted to them.
[0041] Step 8: OAM sends the defined instructioncontext for affected cNFs and NFs to NWDAF.
[0042] Step 9: NWDAF informs the subscribed cNFs that have the NF-ID in their monitoring list with the instructioncontext provided by OAM.
[0043] Use Case
[0044] Certain embodiments have immediate application to NWDAF-based anomaly detection services, e.g., in Signaling Storm use case, which is an important use case in 3GPP discussions.
[0045] To better illustrate the difference between local anomaly detection in cNF and global detection method employed by NWDAF and the benefit of using its holistic view, in the following we provide another example. Suppose every cell is a cNF that has a NF for giving scheduling resources to UEs that are newly joined or being handed over from another cell. Call this NF, h-NF. Also, suppose that there is a train that passes many cells (cNFs) and has stops inside some of the cells. At some stop points, h-NF of the corresponding cell may detect and report an anomaly due to spike in the number of newly joined / handed-over UEs. This is local anomaly detection. Due to limited data (this cNF and h-NF is unaware of similar spikes that happened some minutes ago on other cells along the trajectory of the train), this decision can be subject to a greater error. Once this is reported to NWDAF, NWDAF may realize (e.g., via causality analysis) that this spike is natural and happened due to the moving train, not any unforeseen attack or other security threats. Here, NWDAF uses its holistic knowledge, which is unavailable (due to privacy and security reasons) to individual NF and cNFs. NWDAF then generates a report to OAM with supporting information and analytics. OAM can decide to temporarily increase the resources available to the affected NF, maybe even inform the next cNF to be prepared for such spike in some minutes in future. That information can be encapsulated in instructioncontext of Step 9, for example.
[0046] In another example scenario, we could consider that the SMF node is found to be behaving anomalously. In this case, the NFs like UPF and Access and Mobility Management Function (AMF) that the SMF interacts with to realize functionality can get affected leading tobad customer experience. In this case, the local anomaly detection can flag that the SMF is found to be anomalous but will not identify that the nodes that rely on SMF signaling will also start to fail because of this initial failure. The local anomaly detection will also not identify whether the problem started from the SMF or another node for e.g., the Policy and Control Function (PCF) that the SMF relies on. Thus, having a global view from the NWDAF could shed light on the causal relationships and allow us to take more comprehensive measures / remediations to address the issue versus just having a local view.
[0047] Any of the procedures or parts thereof described herein may be implemented in a network node (such as network node 610, network node 700).
[0048] FIG. 3 illustrates a process 300 for improving anomaly detection. The process may be performed by a Network Function consumer (cNF) in communication with a Network Data Analytics Function (NWDAF), and may start at step s302.
[0049] Step s302 comprises sending, towards the NWDAF, an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly.
[0050] Step s304 comprises receiving an anomaly notification message comprising remediating instructions.
[0051] Step s306 comprises performing the remediating instructions.
[0052] In some embodiments, the method further includes sending, towards the NWDAF, a subscription request to an anomaly detection service for a set of NFs; and receiving, from the NWDAF, a response to the subscription comprising instructions for each NF in the set of NFs. In some embodiments, the method further includes receiving an acknowledgment from the NWDAF of the anomaly detection message. In some embodiments, the anomaly notification message is received from the NWDAF. In some embodiments, the anomaly notification message is received from Operations, Administration and Management (0AM).
[0053] In some embodiments, the method further includes receiving a global machine learning (ML) model for anomaly detection from the NWDAF, storing the global ML model as a local ML model, and using the local ML model for anomaly detection. Sending, towards the NWDAF, an anomaly detection message is performed as a result of using the local ML model for anomaly detection. In some embodiments, the method further includes training the local ML model using local data on the cNF.
[0054] FIG. 4 illustrates a process 400 for improving anomaly detection. The process may be performed by a Network Data Analytics Function (NWDAF) in communication with a Network Function consumer (cNF), and may start at step s402.
[0055] Step s402 comprises receiving, from the cNF, an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly.
[0056] Step s404 comprises initiating an anomaly analysis.
[0057] In some embodiments, the method further includes causing an anomaly notification message comprising remediating instructions to be sent towards the cNF based on the anomaly analysis. In some embodiments, initiating an anomaly analysis comprises performing the anomaly analysis. In some embodiments, the method further includes receiving, from the cNF, a subscription request to an anomaly detection service for a set of NFs; and sending, towards the cNF, a response to the subscription comprising instructions for each NF in the set of NFs. In some embodiments, the method further includes sending towards the cNF an acknowledgment of the anomaly detection message. In some embodiments, causing an anomaly notification message comprising remediating instructions to be sent towards the cNF comprises sending the anomaly notification message from the NWDAF towards the cNF. In some embodiments, causing an anomaly notification message comprising remediating instructions to be sent towards the cNF comprises communicating with Operations, Administration and Management (0AM) such that the anomaly notification message is sent from 0AM towards the cNF. In some embodiments, the method further includes sending, towards Operation, Administration and Management (0AM) an anomaly analysis report including a set of affected NFs and cNFs and an instruction context field. In some embodiments, the method further includes receiving, from one or more additional cNFs, additional anomaly detection messages comprising additional Network Function (NF) identifiers and additional anomaly context fields, and wherein performing the anomaly analysis is further based on the additional anomaly detection messages.
[0058] In some embodiments, the method further includes providing a global machine learning (ML) model for anomaly detection and provisioning the global ML model for anomaly detection to the cNF
[0059] FIG. 5 illustrates a process 500 for improving anomaly detection. The process may be performed by Operations, Administration and Management (0AM) in communications with a Network Data Analytics Function (NWDAF), and may start at step s502.
[0060] Step s502 comprises receiving, from the NWDAF, an anomaly analysis report including a set of affected NFs and cNFs and an instruction context field.
[0061] Step s504 comprises performing remediating actions.
[0062] Step s506 comprises sending an anomaly notification message comprising remediating instructions to one or more of the NWDAF and one or more of the affected cNFs.
[0063] Figure 6 shows an example of a communication system 600 in accordance with some embodiments.
[0064] In the example, the communication system 600 includes a telecommunication network 602 that includes an access network 604, such as a radio access network (RAN), and a core network 606, which includes one or more core network nodes 608. The access network 604 includes one or more access network nodes, such as network nodes 610a and 610b (one or more of which may be generally referred to as network nodes 610), or any other similar 3rdGeneration Partnership Project (3GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 602 includes one or more Open- RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network 602 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network 602, including one or more network nodes 610 and / or core network nodes 608.
[0065] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O- CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an O-2 interface defined by the O-RAN Alliance or comparable technologies.The network nodes 610 facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs 612a, 612b, 612c, and 612d (one or more of which may be generally referred to as UEs 612) to the core network 606 over one or more wireless connections.
[0066] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 600 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 600 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.
[0067] The UEs 612 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 610 and other communication devices. Similarly, the network nodes 610 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 612 and / or with other network nodes or equipment in the telecommunication network 602 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 602.
[0068] In the depicted example, the core network 606 connects the network nodes 610 to one or more host computing systems, such as host 616. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 606 includes one or more core network nodes (e.g., core network node 608) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 608. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDE), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).
[0069] The host 616 may be under the ownership or control of a service provider other than an operator or provider of the access network 604 and / or the telecommunication network 602. The host 616 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.
[0070] As a whole, the communication system 600 of Figure 6 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.
[0071] In some examples, the telecommunication network 602 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network 602 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 602. For example, the telecommunications network 602 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.
[0072] In some examples, the UEs 612 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 604 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 604. Additionally, a UE may be configured for operating in single- or multi-RAT or multi- standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved- UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).
[0073] In the example, the hub 614 communicates with the access network 604 to facilitate indirect communication between one or more UEs (e.g., UE 612c and / or 612d) and network nodes (e.g., network node 610b). In some examples, the hub 614 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 614 may be a broadband router enabling access to the core network 606 for the UEs. As another example, the hub 614 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 610, or by executable code, script, process, or other instructions in the hub 614. As another example, the hub 614 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 614 may be a content source. For example, for a UE that is a VR device, display, loudspeaker, or other media delivery device, the hub 614 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 614 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 614 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.
[0074] The hub 614 may have a constant / persistent or intermittent connection to the network node 610b. The hub 614 may also allow for a different communication scheme and / or schedule between the hub 614 and UEs (e.g., UE 612c and / or 612d), and between the hub 614 and the core network 606. In other examples, the hub 614 is connected to the core network 606 and / or one or more UEs via a wired connection. Moreover, the hub 614 may be configured to connect to an M2M service provider over the access network 604 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 610 while still connected via the hub 614 via a wired or wireless connection. In some embodiments, the hub 614 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 610b. In other embodiments, the hub 614 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 610b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.
[0075] Figure 7 shows a UE 700 in accordance with some embodiments. The UE 700 presents additional details of some embodiments of the UE 612 of Figure 1. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelesslywith network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage / playback device, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), an Augmented Reality (AR) or Virtual Reality (VR) device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3 GPP), including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.
[0076] A UE may support device-to-device (D2D) communication, for example by implementing a 3 GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle- to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).
[0077] The UE 700 includes processing circuitry 702 that is operatively coupled via a bus 704 to an input / output interface 706, a power source 708, a memory 710, a communication interface 712, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 7. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0078] The processing circuitry 702 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 710. The processing circuitry 702 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signalprocessor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 702 may include multiple central processing units (CPUs).
[0079] In the example, the input / output interface 706 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 700. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.
[0080] In some embodiments, the power source 708 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source 708 may further include power circuitry for delivering power from the power source 708 itself, and / or an external power source, to the various parts of the UE 700 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source 708. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 708 to make the power suitable for the respective components of the UE 700 to which power is supplied.
[0081] The memory 710 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 710 includes one or more application programs 714, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 716. The memory 710 may store, for use by the UE 700, any of a variety of various operating systems or combinations of operating systems.
[0082] The memory 710 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD- DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 710 may allow the UE 700 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 710, which may be or comprise a device-readable storage medium.
[0083] The processing circuitry 702 may be configured to communicate with an access network or other network using the communication interface 712. The communication interface 712 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 722. The communication interface 712 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 718 and / or a receiver 720 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 718 and receiver 720 may be coupled to one or more antennas (e.g., antenna 722) and may share circuit components, software or firmware, or alternatively be implemented separately.
[0084] In the illustrated embodiment, communication functions of the communication interface 712 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code DivisionMultiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.
[0085] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 712, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).
[0086] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.
[0087] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE 700 shown in Figure 7.
[0088] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0089] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.
[0090] Figure 8 shows a network node 800 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).
[0091] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).
[0092] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).
[0093] The network node 800 includes a processing circuitry 802, a memory 804, a communication interface 806, and a power source 808. The network node 800 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 800 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 800 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 804 for different RATs) and some components may be reused (e.g., a same antenna 810 may be shared by different RATs). The network node 800 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 800, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 800.
[0094] The processing circuitry 802 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application- specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 800 components, such as the memory 804, to provide network node 800 functionality.
[0095] In some embodiments, the processing circuitry 802 includes a system on a chip (SOC). In some embodiments, the processing circuitry 802 includes one or more of radio frequency (RF) transceiver circuitry 812 and baseband processing circuitry 814. In someembodiments, the radio frequency (RF) transceiver circuitry 812 and the baseband processing circuitry 814 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 812 and baseband processing circuitry 814 may be on the same chip or set of chips, boards, or units.
[0096] The memory 804 may comprise any form of volatile or non-volatile computer- readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computerexecutable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 802. The memory 804 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 802 and utilized by the network node 800. The memory 804 may be used to store any calculations made by the processing circuitry 802 and / or any data received via the communication interface 806. In some embodiments, the processing circuitry 802 and memory 804 is integrated.
[0097] The communication interface 806 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 806 comprises port(s) / terminal(s) 816 to send and receive data, for example to and from a network over a wired connection. The communication interface 806 also includes radio front-end circuitry 818 that may be coupled to, or in certain embodiments a part of, the antenna 810. Radio front-end circuitry 818 comprises filters 820 and amplifiers 822. The radio front-end circuitry 818 may be connected to an antenna 810 and processing circuitry 802. The radio front-end circuitry may be configured to condition signals communicated between antenna 810 and processing circuitry 802. The radio front-end circuitry 818 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 818 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 820 and / or amplifiers 822. The radio signal may then be transmitted via the antenna 810. Similarly, when receiving data, the antenna 810 may collect radio signals which are then converted into digital data by the radio front-end circuitry 818. The digital data may be passed to theprocessing circuitry 802. In other embodiments, the communication interface may comprise different components and / or different combinations of components.
[0098] In certain alternative embodiments, the network node 800 does not include separate radio front-end circuitry 818, instead, the processing circuitry 802 includes radio front-end circuitry and is connected to the antenna 810. Similarly, in some embodiments, all or some of the RF transceiver circuitry 812 is part of the communication interface 806. In still other embodiments, the communication interface 806 includes one or more ports or terminals 816, the radio front-end circuitry 818, and the RF transceiver circuitry 812, as part of a radio unit (not shown), and the communication interface 806 communicates with the baseband processing circuitry 814, which is part of a digital unit (not shown).
[0099] The antenna 810 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 810 may be coupled to the radio front-end circuitry 818 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 810 is separate from the network node 800 and connectable to the network node 800 through an interface or port.
[0100] The antenna 810, communication interface 806, and / or the processing circuitry 802 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 810, the communication interface 806, and / or the processing circuitry 802 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.
[0101] The power source 808 provides power to the various components of network node 800 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 808 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 800 with power for performing the functionality described herein. For example, the network node 800 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 808. As a further example, the power source 808 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.
[0102] Embodiments of the network node 800 may include additional components beyond those shown in Figure 8 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 800 may include user interface equipment to allow input of information into the network node 800 and to allow output of information from the network node 800. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 800. In some embodiments providing a core network node, such as core network node 108 of FIG. 6, some components, such as the radio front-end circuitry 818 and the RF transceiver circuitry 812 may be omitted.
[0103] A network node, such as network node 800, may comprise: processing circuitry (PC) 802, which comprises one or more processors (P) (e.g., one or more general purpose microprocessors and / or one or more other processors, such as an application specific integrated circuit (ASIC), field-programmable gate arrays (FPGAs), and the like), which processors may be co-located in a single housing or in a single data center or may be geographically distributed (e.g., network node 800 may be a distributed, cloud computing system comprising two or more computers or a monolithic computing system consisting of a single computer).
[0104] Figure 9 is a block diagram illustrating a virtualization environment 900 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 900 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 900 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface. Virtualization may facilitate distributed implementations of a network node, UE, core network node, or host.
[0105] Applications 902 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.
[0106] Hardware 904 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 906 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 908a and 908b (one or more of which may be generally referred to as VMs 908), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 906 may present a virtual operating platform that appears like networking hardware to the VMs 908.
[0107] The VMs 908 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 906. Different embodiments of the instance of a virtual appliance 902 may be implemented on one or more of VMs 908, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.
[0108] In the context of NFV, a VM 908 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs 908, and that part of hardware 904 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 908 on top of the hardware 904 and corresponds to the application 902.
[0109] Hardware 904 may be implemented in a standalone network node with generic or specific components. Hardware 904 may implement some functions via virtualization. Alternatively, hardware 904 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 910, which, among others, oversees lifecycle management of applications 902. In some embodiments, hardware 904 is coupled to one or more radio units that eachinclude one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 912 which may alternatively be used for communication between hardware nodes and radio units.
[0110] Although the computing devices described herein (e.g., UEs, network nodes) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.
[0111] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to theprocessing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.EMBODIMENTSGroup A EmbodimentsAl. A computer-implemented method for improving anomaly detection, performed by a Network Function consumer (cNF) in communication with a Network Data Analytics Function (NWDAF), the method comprising: sending, towards the NWDAF, an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly; receiving an anomaly notification message comprising remediating instructions; and performing the remediating instructions.A2. The computer-implemented method of embodiment Al, further comprising: sending, towards the NWDAF, a subscription to an anomaly detection service for a set of NFs; and receiving, from the NWDAF, a response to the subscription comprising instructions for each NF in the set of NFs.A3. The computer-implemented method of any one of embodiments A1-A2, further comprising receiving an acknowledegment from the NWDAF of the anomaly detection message.A4. The computer- implemented method of any one of embodiments Al -A3, wherein the anomaly notification message is received from the NWDAF.A5. The computer- implemented method of any one of embodiments Al -A3, wherein the anomaly notification message is received from Operations and Management (0AM).B EmbodimentsB 1. A computer-implemented method for improving anomaly detection, performed by a Network Data Analytics Function (NWDAF) in communication with a Network Function consumer (cNF), the method comprising: receiving, from the cNF, an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly; and initiating an anomaly analysis.Bia. The computer-implemented method of embodiment B 1 , further comprising causing an anomaly notification message comprising remediating instructions to be sent towards the cNF based on the anomaly analysis.Bib. The computer-implemented method of any one of embodiments Bl and Bia, wherein initiating an anomaly analysis comprises performing the anomaly analysis.B2. The computer-implemented method of any one of embodiments Bl, Bia, and Bib, further comprising: receiving, from the cNF, a subscription to an anomaly detection service for a set of NFs; and sending, towards the cNF, a response to the subscription comprising instructions for each NF in the set of NFs.B3. The method of any one of embodiments B1-B2, further comprising sending towards the cNF an acknowledegment of the anomaly detection message.B4. The computer-implemented method of any one of embodiments B1-B3, wherein causing an anomaly notification message comprising remediating instructions to be sent towards the cNF comprises sending the anomaly notification message from the NWDAF towards the cNF.B5. The computer-implemented method of any one of embodiments B1-B3, wherein causing an anomaly notification message comprising remediating instructions to be sent towards the cNF comprises communicating with Operations and Management (0AM) such that the anomaly notification message is sent from 0AM towards the cNF.B6. The computer-implemented method of any one of embodiments B1-B5, further comprising sending, towards Operation and Management (0AM) an anomaly analysis report including a set of affected NFs and cNFs and an instruction context field.B7. The computer-implemented method of any one of embodiments B1-B6, further comprising receiving, from one or more additional cNFs, additional anomaly detection messages comprising additional Network Function (NF) identifiers and additional anomalycontext fields, and wherein performing the anomaly analysis is further based on the additional anomaly detection messages.Group C EmbodimentsCl. A computer- implemented method for improving anomaly detection, performed by Operations and Management (0AM) in communications with a Network Data Analytics Function (NWDAF), the method comprising: receiving, from the NWDAF, an anomaly analysis report including a set of affected NFs and cNFs and an instruction context field; performing remediating actions; and sending an anomaly notification message comprising remediating instructions to one or more of the NWDAF and one or more of the affected cNFs.Group D EmbodimentsDI. A network node (610, 800) for improving anomaly detection, the network node comprising: processing circuitry configured to perform any of the steps of any of the Group A, Group B, and Group C embodiments; and power supply circuitry configured to supply power to the processing circuitry.D2. A network node (610, 800) for improving anomaly detection, the network node comprising: an antenna configured to send and receive wireless signals; radio front-end circuitry connected to the antenna and to processing circuitry, and configured to condition signals communicated between the antenna and the processing circuitry; the processing circuitry being configured to perform any of the steps of any of the Group A, Group B, and Group C embodiments; an input interface connected to the processing circuitry and configured to allow input of information into the UE to be processed by the processing circuitry; an output interface connected to the processing circuitry and configured to output information from the UE that has been processed by the processing circuitry; anda battery connected to the processing circuitry and configured to supply power to the network node.
Claims
CLAIMS:
1. A computer-implemented method for improving anomaly detection, performed by a Network Function consumer (cNF) (202) in communication with a Network Data Analytics Function (NWDAF) (204), the method comprising: sending, towards the NWDAF (204), an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly; receiving an anomaly notification message comprising remediating instructions; and performing the remediating instructions.
2. The computer- implemented method of claim 1, further comprising: sending, towards the NWDAF, a subscription request to an anomaly detection service for a set of NFs; and receiving, from the NWDAF, a response to the subscription comprising instructions for each NF in the set of NFs.
3. The computer-implemented method of any one of claims 1-2, further comprising receiving an acknowledgment from the NWDAF of the anomaly detection message.
4. The computer-implemented method of any one of claims 1-3, wherein the anomaly notification message is received from the NWDAF.
5. The computer-implemented method of any one of claims 1-3, wherein the anomaly notification message is received from Operations, Administration and Management (0AM) (206).
6. The computer-implemented method of any one of claims 1-5, further comprising receiving a global machine learning (ML) model for anomaly detection from the NWDAF, storing the global ML model as a local ML model, and using the local ML model for anomaly detection, wherein sending, towards the NWDAF, an anomaly detection message is performed as a result of using the local ML model for anomaly detection.
7. The computer-implemented method of claim 6, further comprising training the localML model using local data on the cNF.
8. A computer-implemented method for improving anomaly detection, performed by a Network Data Analytics Function (NWDAF) (204) in communication with a Network Function consumer (cNF) (202), the method comprising: receiving, from the cNF, an anomaly detection message comprising a Network Function (NF) identifier and an anomaly context field that indicates the context of an anomaly; and initiating an anomaly analysis.
9. The computer-implemented method of claim 8, further comprising causing an anomaly notification message comprising remediating instructions to be sent towards the cNF based on the anomaly analysis.
10. The computer-implemented method of any one of claims 8-9, wherein initiating an anomaly analysis comprises performing the anomaly analysis.
11. The computer-implemented method of any one of claims 8-10, further comprising: receiving, from the cNF, a subscription request to an anomaly detection service for a set of NFs; and sending, towards the cNF, a response to the subscription comprising instructions for each NF in the set of NFs.
12. The method of any one of claims 8-11, further comprising sending towards the cNF an acknowledgment of the anomaly detection message.
13. The computer-implemented method of any one of claims 8-12, wherein causing an anomaly notification message comprising remediating instructions to be sent towards the cNF comprises sending the anomaly notification message from the NWDAF towards the cNF.
14. The computer-implemented method of any one of claims 8-12, wherein causing an anomaly notification message comprising remediating instructions to be sent towards the cNF comprises communicating with Operations, Administration and Management (0AM) (206) such that the anomaly notification message is sent from 0AM towards the cNF.
15. The computer-implemented method of any one of claims 8-14, further comprising sending, towards Operations, Administration and Management (0AM) an anomaly analysis report including a set of affected NFs and cNFs and an instruction context field.
16. The computer-implemented method of any one of claims 8-15 further comprising receiving, from one or more additional cNFs, additional anomaly detection messages comprising additional Network Function (NF) identifiers and additional anomaly context fields, and wherein performing the anomaly analysis is further based on the additional anomaly detection messages.
17. The computer-implemented method of any one of claims 8-16, further comprising providing a global machine learning (ML) model for anomaly detection and provisioning the global ML model for anomaly detection to the cNF.
18. A computer-implemented method for improving anomaly detection, performed by Operations, Administration and Management (0AM) (206) in communications with a Network Data Analytics Function (NWDAF) (204), the method comprising: receiving, from the NWDAF (204), an anomaly analytics report including a set of affected NFs and cNFs (202) and an instruction context field; performing remediating actions; and sending an anomaly notification message comprising remediating instructions to one or more of the NWDAF (204) and one or more of the affected cNFs (202).
19. A network node (610, 800) for improving anomaly detection, the network node comprising: processing circuitry configured to perform any one of claims 1-18; and power supply circuitry configured to supply power to the processing circuitry.
20. A network node (610, 800) for improving anomaly detection, the network node comprising: an antenna configured to send and receive wireless signals; radio front-end circuitry connected to the antenna and to processing circuitry, and configured to condition signals communicated between the antenna and the processing circuitry;the processing circuitry being configured to perform any one of claims 1-18; an input interface connected to the processing circuitry and configured to allow input of information into the UE to be processed by the processing circuitry; an output interface connected to the processing circuitry and configured to output information from the UE that has been processed by the processing circuitry; and a battery connected to the processing circuitry and configured to supply power to the network node.
Citation Information
Patent Citations
Automating 5G slices using real-time analytics
US11483218B2
System and method of closed loop analytics for network automation
US20210014141A1
Method and device for providing network analytics information in wireless communication network
US20230269141A1
Improved analytic generation in a wireless communication network
WO2024008318A1
System and method for policy computation for user data congestion in wireless network
WO2025022449A1