PCF-centric solution to mitigate abnormal network behavior
The PCF in wireless communication networks uses NWDAF analytics to identify and mitigate signaling storms by updating policies, addressing network congestion and delays, enhancing network performance.
Patent Information
- Application Number
- PCT/SE2025/050703
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-07
- Filing Date
- 2025-07-31
- Publication Date
- 2026-02-12
AI Technical Summary
Existing wireless communication networks lack effective solutions for predicting, detecting, preventing, and mitigating network abnormal behaviors such as signaling storms, which can cause congestion and processing delays, reducing available bandwidth and increasing user response times.
The Policy Control Function (PCF) in the core network receives analytics reports from the Network Data Analytics Function (NWDAF) to identify the source of network abnormal behavior, whether from UE or NF activity, and initiates actions like updating UE route selection policies or notifying other network functions to mitigate or prevent signaling storms.
This approach efficiently manages network traffic by dynamically updating policies, reducing the impact of signaling storms, thereby improving data rate, response time, and latency in wireless communication networks.
Smart Images

Figure SE2025050703_12022026_PF_FP_ABST
Abstract
Description
PCF-CENTRIC SOLUTION TO MITIGATE ABNORMAL NETWORK BEHAVIORBACKGROUND
[0001] The present disclosure relates to wireless communication networks, and in particular to detection and handling of abnormal behavior in wireless communication networks.
[0002] The Network Data Analytics Function (NWDAF) is a Network Function (NF) in a 5G core network (5GC) which provides statistics and predictions for the previous and the future states of the network. The NWDAF generates analytics reports in response to request from network entities, such as an Operations, Administration and Maintenance (0AM) or any other NF.
[0003] Several types of analytics reports, which are identified by analytics IDs, are already supported by NWDAF. These include user equipment (UE) mobility reports, user data congestion reports, network performance reports, UE related abnormal behavior reports, and others. For each analytics ID, the NWDAF trains a machine learning (ML) model that is used to perform inference and to generate analytics reports.
[0004] While prediction of abnormal UE behavior by the NWDAF is already covered in the 3GPP standards, no analytics report existed previously for network abnormal behaviors.
[0005] Key Issue #4 discussed in [Error! Reference source not found.] describes a problem to be addressed as to provide solutions for prediction, detection, prevention, and mitigation of network abnormal behaviors, such as a signalling storm, with the assistance of NWDAF. A "signalling storm" refers to a large increase in control plane signaling traffic in a network. Control plane signaling represents overhead traffic in a network. An unexpectedly large increase in control plane signaling, such as during a signalling storm, can cause congestion in the network and / or may cause processing delays in various network nodes and / or network functions. Such congestion and / or delays may result in a reduction of bandwidth available for user plane communication, longer response times for users, and other problems.
[0006] In particular, the following issues are to be addressed:• Identify scenarios that can result in a signalling storm situation.• Whether and how existing analytics or new analytics can be used to assist detection and / or prediction of signalling storms, including aspects of input / output data that needs to be collected / provided by the NWDAF.• What NF(s) will be consumer of such analytics and whether and how they can use them.• Whether and how a signalling storm can be prevented and / or mitigated based on the inputs provided by NWDAF.
[0007] Figure 1 is a sequence diagram that describes the procedure for NWDAF- assisted network abnormal behavior mitigation and prevention discussed in Solution #35.
[0008] Data sources that may provide data for this analytics report are the Access and Mobility Management Function (AMF), the 0AM, the Session Management Function (SMF), the Network Repository Function (NRF), and the Service Communication Proxy (SCP) function. NF service consumers include the AMF, the SMF, and the NRF. However, the role of the Policy Control Function (PCF) in the mitigation and / or prevention of signalling storms is yet to be studied.SUMMARY
[0009] A method of operating a PCF in a core network of a wireless communication network includes receiving an analytics report describing a predicted network abnormal behavior in the wireless communication network, and initiating an action to mitigate and / or prevent the network abnormal behavior.
[0010] The method may further include subscribing to receive the analytics report from a NWDAF in the core network.
[0011] The network abnormal behavior may include a signalling storm.
[0012] The method may further include determining whether the predicted network abnormal behavior is caused by UE activity or NF activity in the wireless communication network.
[0013] Initiating the action in response to determining that the predicted network abnormal behavior is caused by NF activity may include notifying an 0AM function in the core network of the predicted network abnormal behavior.
[0014] In some embodiments, in response to determining that the predicted network abnormal behavior is caused by UE activity, initiating the action may include performing the action to mitigate and / or prevent the network abnormal behavior.
[0015] The method may further include evaluating the action prior to triggering the action to mitigate and / or prevent the network abnormal behavior. Evaluating the action may include evaluating the action using NDT emulation.
[0016] In some embodiments, evaluating the action includes determining the impact of the action on a KPI associated with the wireless communication network.
[0017] The action may include updating one or more UE route selection policy and / or PCC rules to prevent and / or mitigate the network abnormal behavior. In some embodiments, the action includes updating one or more PCC rules relating to ATSSS to prevent and / or mitigate the network abnormal behavior.
[0018] In some embodiments, the action to mitigate and / or prevent the network abnormal behavior includes notifying one or more target NFs in the core network to prepare for the network abnormal behavior.
[0019] A network node for implementing a policy control function, PCF, of a core network of a wireless communication network, the network node includes processing circuitry, and power supply circuitry configured to supply power to the processing circuitry, wherein the processing circuitry is configured to perform operations including receiving an analytics report describing a predicted network abnormal behavior in the wireless communication network, and initiating an action to mitigate and / or prevent the network abnormal behavior.
[0020] Some embodiments described herein provide solutions to resolve the issue of the role of the PCF by including the PCF in the process of mitigating and preventing abnormal behavior, such as a signalling storm, with assistance from the NWDAF.BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 is a sequence diagram that describes a procedure for NWDAF- assisted network abnormal behavior mitigation and prevention.
[0022] Figure 2 is a signal flow diagram that illustrates operations for mitigation and prevention of network abnormal behavior.
[0023] Figure 3 is a flowchart that illustrates operations for mitigation and prevention of network abnormal behavior.
[0024] Figure 4 shows an example of a communication system 400 in accordance with some embodiments.
[0025] Figure 5 shows a UE in accordance with some embodiments.
[0026] Figure 6 shows a network node in accordance with some embodiments.
[0027] Figure 7 is a block diagram illustrating a virtualization environment in which functions implemented by some embodiments may be virtualized.DETAILED DESCRIPTION OF EMBODIMENTS
[0028] A signalling storm can happen due to different root causes, such as NF failure, security breaches, software error, massive UE access, etc. If UEs are the source of the signalling storm, the PCF is a relevant entity in the network to trigger actions to mitigate / prevent the impact of the signalling storm in the network.
[0029] Some embodiments provide systems / methods that may mitigate and / or prevent the impact of network abnormal behavior, such as a signalling storm, in the network with the assistance of the NWDAF. The main intervention entity in these embodiments is the PCF, which is responsible for applying rules, such as a UE Route Selection Policy (URSP) and Policy and Charging Control (PCC) to control traffic flow in UE and the core network.
[0030] The PCF subscribes to receive analytics reports about network abnormal behavior, such as a possible signalling storm, from the NWDAF. Upon receipt of such analytics reports, the PCF may prepare, trigger and / or perform actions to mitigate / prevent the impact of the signalling storm. The following steps may be performed by the PCF when it receives analytics report from NWDAF about signalling storm:• Evaluate actions on a Network Digital Twin platform and measure the impact of the actions.• Inform the impacted NFs to be prepared to trigger preventive actions, such as to choose another service provider, etc.
[0031] According to some embodiments, the PCF consumes an analytics report relating to a signalling storm and acts accordingly to mitigate / prevent the impact of the signalling storm. This process may include the following operations:• The PCF subscribes to NWDAF to receive predictions of signalling storm(s) in the network. The prediction may contain source NF(s) and / or subscription permanent identifier(s) (SUPI) associated with UE(s), target NF(s) and the root cause.• The PCF receives an analytics report from NWDAF and, based on the analytics report, decides what actions to trigger if the source of the signallingstorm is / are SUPI(s). The actions may include updating PCC / URSP rules and / or, if Access Traffic Steering, Switching and Splitting (ATSSS) is enabled, updating PCC rules with respect to the ATSSS rules.• Before triggering an action, the PCF may optionally evaluate the action, for example, using a Network Digital Twin (NDT). The PCF may evaluate multiple actions and choose one or more actions based on the results of the evaluation.• Regardless of whether the source of the signalling storm is / are SUPI(s), the PCF may inform the target NF(s) to be prepared for the possible signalling storm effects. Preparation strategies could cover NF horizontal scaling, filtering, etc.
[0032] If the source of the signalling storm is / are NF(s), then the PCF may inform 0AM and delegate the task of mitigating or preventing the signalling storm to the 0AM.
[0033] Certain embodiments may provide one or more of the following technical advantage(s).
[0034] Network abnormal behavior can be due to several root causes. UE-related reasons for signalling storm in the network is one of the most important reasons. For instance, a drastic increase in the number of UEs connected to the network at certain times and locations e.g., train stations, cultural events, etc., can be one of the common sources of a signalling storm. In case a massive number of UEs is the source of a signalling storm, the PCF is the best network entity to prevent / mitigate the impact, for example, by controlling traffic flow through updating network policies. One potential benefit of the embodiments described herein is to handle a signalling storm caused by a massive number of UEs in an efficient way. Without considering PCF as the main entity to prevent / mitigate a signalling storm, less efficient enforcement, such as sending a request to PCF to update the policies, querying SMF, etc., might be triggered, which in turn might cause more signaling in the control plane.
[0035] Because prevention and / or mitigation of signalling storms is done by updating policies in a dynamic manner, some embodiments provide a smooth solution with limited updates needed to the functionality of entities in the network. Moreover, an operator can have impact over how prevention and mitigation is done, which makes the solution more flexible and manageable.
[0036] The teachings of certain embodiments may improve the data rate, response time and / or latency of communications in a wireless communication network.
[0037] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.
[0038] According to some embodiments, the PCF triggers actions to prevent or mitigate network abnormal behavior, such as a signalling storm in the network. For a signalling storm, the actions that are triggered by the PCF may be based on a prediction received from the NWDAF in an analytics report as shown in Table 1.Table 1 - Signalling storm prediction.
[0039] As shown in Table 1, an analytics report that contains a prediction of potential network abnormal behavior, such as a signalling storm, may include a target NF ID, which indicates the target of a signalling storm predicted by the NWDAF, an abnormality ID, which indicates a potential cause of the network abnormal behavior, a source SUPI / NF list that indicates SUPI(s) of the UE(s) or NF(s) which are predicted to cause the signalling storm, and a confidence score that indicates a confidence in the prediction. This information may be used by the PCF to determine what action to take in response to the prediction.
[0040] In some embodiments, two basic scenarios are discussed, namely, when the source of the signalling storm is either an NF or one or more UEs. If the source of signalling storm is an NF, then the PCF will inform the NRF, the 0AM, and / or the target NF. The PCF may delegate the actions to be triggered for prevention and / or mitigation of the impact of abnormal behavior in the network.
[0041] If the source of the signalling storm is UEs, then the PCF may attempt to prevent or mitigate the effects of abnormal behavior by, for example, updating PCC or URSP rules.
[0042] Figure 2 is a signal flow diagram and Figure 3 is a flowchart that illustrates operations for mitigation and prevention of network abnormal behavior, such as signalling storms, by the PCF based on analytics reports from the NWDAF. In the figures,optional steps / actions / features are indicated with dashed lines. Like numbers in the figures refer to like elements.
[0043] Referring to Figure 2, a core network 100, such as a 5GC network, includes a PCF 110, an NWDAF 120, an NDT 130, an NF 140 that may be affected by network abnormal behavior (referred to as a target NF) and an 0AM 150.
[0044] Referring to Figures 2 and 3, the PCF 110 may subscribe to the analytics ID at the NWDAF 120 to receive prediction about potential network abnormal behavior, such as signalling storms in the network (202). Analytics reports may also be provided for other types of network abnormal behavior. For example, network abnormal behavior can include unexpected or undesired behavior network functions due to software failure or failed software updates, interface mismatch, security failures such as the use of expired certificates, etc., which may cause signalling storms or other network abnormal behavior.
[0045] At 204, the PCF 110 receives an analytics report associated with the analytics ID relating to a potential or predicted network abnormal behavior, such as a signalling storm, from the NWDAF 120.
[0046] At 206, the PCF 110 may determine whether the network abnormal behavior is caused by UE activity or NF activity. The source of the network abnormal behavior may be determined directly from the analytics report. For example, as shown above, the analytics report may include a field for "Source SUPI / NF list" which identifies the source of the signalling storm or other network abnormal behavior and an "Abnormality ID" field that identifies the potential cause of the abnormality (e.g. massive UE / frequent access, NF abnormal signalling, etc.).
[0047] If the source of the signalling storm is / are UE(s), then the PCF 110 may optionally evaluate candidate actions on an NDT 130 to know what actions are best to trigger (208). An NDT 130 is an emulated, software replica of a physical communication network, such as a New Radio / 5GC network. The use of an NDT 130 may enable prototyping and / or testing of potential changes to a network before they are actually implemented in the network.
[0048] During this step, the PCF 110 will be able to measure the impact of actions on different key performance indicators (KPI) in the network as a guideline to select one or more actions.
[0049] At 210, the PCF 110 triggers one or more actions to mitigate / prevent the network abnormal behavior. For example, in the case of a signalling storm, the actions may include updating URSP / PCC rules or considering ATSSS rules if ATSSS is enabled.
[0050] Optionally, the PCF 110 may inform one or more target NF(s) 140 to, for example, re-select other NF service providers to prevent or mitigate a predicted signalling storm (212, Figure 2).
[0051] If the source of the signalling storm is / are other NF(s), then at 214 (Figure2), the PCF may notify the 0AM 150 of the predicted network abnormal behavior, as the 0AM 150 has the authority to re-configure NF(s) in case of failure or misbehavior in the core network.
[0052] Figure 4 shows an example of a communication system 400 in accordance with some embodiments.
[0053] In the example, the communication system 400 includes a telecommunication network 402 that includes an access network 404, such as a radio access network (RAN), and a core network 406, which includes one or more core network nodes 408. The access network 404 includes one or more access network nodes, such as network nodes 410a and 410b (one or more of which may be generally referred to as network nodes 410), or any other similar 3rdGeneration Partnership Project (3GPP) access nodes or non- 3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 402 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network 402 that supports an ORAN specification (e.g., a specification published by the O- RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network 402, including one or more network nodes 410 and / or core network nodes 408.
[0054] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O-CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or anycombination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the O- RAN Alliance or comparable technologies. The network nodes 410 facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs 412a, 412b, 412c, and 412d (one or more of which may be generally referred to as UEs 412) to the core network 406 over one or more wireless connections.
[0055] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 400 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 400 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.
[0056] The UEs 412 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 410 and other communication devices. Similarly, the network nodes 410 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 412 and / or with other network nodes or equipment in the telecommunication network 402 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 402.
[0057] In the depicted example, the core network 406 connects the network nodes 410 to one or more host computing systems, such as host 416. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples,network nodes may be directly coupled to hosts. The core network 406 includes one more core network nodes (e.g., core network node 408) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 408. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).
[0058] The host 416 may be under the ownership or control of a service provider other than an operator or provider of the access network 404 and / or the telecommunication network 402. The host 416 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.
[0059] As a whole, the communication system 400 of Figure 4 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.
[0060] In some examples, the telecommunication network 402 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network402 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 402. For example, the telecommunications network 402 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.
[0061] In some examples, the UEs 412 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 404 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 404. Additionally, a UE may be configured for operating in single- or multi-RAT or multistandard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi -radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).
[0062] In the example, the hub 414 communicates with the access network 404 to facilitate indirect communication between one or more UEs (e.g., UE 412c and / or 412d) and network nodes (e.g., network node 410b). In some examples, the hub 414 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 414 may be a broadband router enabling access to the core network 406 for the UEs. As another example, the hub 414 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 410, or by executable code, script, process, or other instructions in the hub 414. As another example, the hub 414 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 414 may be a content source. For example, for a UE that is a VR device, display, loudspeaker, or other media delivery device, the hub 414 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 414 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 414 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.
[0063] The hub 414 may have a constant / persistent or intermitent connection to the network node 410b. The hub 414 may also allow for a different communication scheme and / or schedule between the hub 414 and UEs (e.g., UE 412c and / or 412d), and between the hub 414 and the core network 406. In other examples, the hub 414 is connected to the core network 406 and / or one or more UEs via a wired connection. Moreover, the hub 414 may be configured to connect to an M2M service provider over the access network 404 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 410 while still connected via the hub 414 via a wired or wireless connection. In some embodiments, the hub 414 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 410b. In other embodiments, the hub 414 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 410b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.
[0064] Figure 5 shows a UE 500 in accordance with some embodiments. The UE 500 presents additional details of some embodiments of the UE 412 of Figure 1. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage / playback device, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), an Augmented Reality (AR) or Virtual Reality (VR) device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB- loT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.
[0065] A UE may support device-to-device (D2D) communication, for example by implementing a 3 GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which maynot, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).
[0066] The UE 500 includes processing circuitry 502 that is operatively coupled via a bus 504 to an input / output interface 506, a power source 508, a memory 510, a communication interface 512, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 5. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0067] The processing circuitry 502 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 510. The processing circuitry 502 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 502 may include multiple central processing units (CPUs).
[0068] In the example, the input / output interface 506 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 500. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interfaceport as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.
[0069] In some embodiments, the power source 508 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source 508 may further include power circuitry for delivering power from the power source 508 itself, and / or an external power source, to the various parts of the UE 500 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source 508. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 508 to make the power suitable for the respective components of the UE 500 to which power is supplied.
[0070] The memory 510 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 510 includes one or more application programs 514, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 516. The memory 510 may store, for use by the UE 500, any of a variety of various operating systems or combinations of operating systems.
[0071] The memory 510 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 510 may allow the UE 500 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing acommunication system may be tangibly embodied as or in the memory 510, which may be or comprise a device-readable storage medium.
[0072] The processing circuitry 502 may be configured to communicate with an access network or other network using the communication interface 512. The communication interface 512 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 522. The communication interface 512 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 518 and / or a receiver 520 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 518 and receiver 520 may be coupled to one or more antennas (e.g., antenna 522) and may share circuit components, software or firmware, or alternatively be implemented separately.
[0073] In the illustrated embodiment, communication functions of the communication interface 512 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / intemet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.
[0074] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 512, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).
[0075] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.
[0076] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE 500 shown in Figure 5.
[0077] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0078] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remotecontroller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.
[0079] Figure 6 shows a network node 600 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).
[0080] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O- RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).
[0081] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi- cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).
[0082] The network node 600 includes a processing circuitry 602, a memory 604, a communication interface 606, and a power source 608. The network node 600 may be composed of multiple physically separate components (e.g., aNodeB component and a RNCcomponent, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 600 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 600 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 604 for different RATs) and some components may be reused (e.g., a same antenna 610 may be shared by different RATs). The network node 600 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 600, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 600.
[0083] The processing circuitry 602 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 600 components, such as the memory 604, to provide network node 600 functionality.
[0084] In some embodiments, the processing circuitry 602 includes a system on a chip (SOC). In some embodiments, the processing circuitry 602 includes one or more of radio frequency (RF) transceiver circuitry 612 and baseband processing circuitry 614. In some embodiments, the radio frequency (RF) transceiver circuitry 612 and the baseband processing circuitry 614 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 612 and baseband processing circuitry 614 may be on the same chip or set of chips, boards, or units.
[0085] The memory 604 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a DigitalVideo Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 602. The memory 604 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 602 and utilized by the network node 600. The memory 604 may be used to store any calculations made by the processing circuitry 602 and / or any data received via the communication interface 606. In some embodiments, the processing circuitry 602 and memory 604 is integrated.
[0086] The communication interface 606 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 606 comprises port(s) / terminal(s) 616 to send and receive data, for example to and from a network over a wired connection. The communication interface 606 also includes radio front-end circuitry 618 that may be coupled to, or in certain embodiments a part of, the antenna 610. Radio front-end circuitry 618 comprises filters 620 and amplifiers 622. The radio front-end circuitry 618 may be connected to an antenna 610 and processing circuitry 602. The radio front-end circuitry may be configured to condition signals communicated between antenna 610 and processing circuitry 602. The radio front-end circuitry 618 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 618 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 620 and / or amplifiers 622. The radio signal may then be transmitted via the antenna 610. Similarly, when receiving data, the antenna 610 may collect radio signals which are then converted into digital data by the radio front-end circuitry 618. The digital data may be passed to the processing circuitry 602. In other embodiments, the communication interface may comprise different components and / or different combinations of components.
[0087] In certain alternative embodiments, the network node 600 does not include separate radio front-end circuitry 618, instead, the processing circuitry 602 includes radio front-end circuitry and is connected to the antenna 610. Similarly, in some embodiments, all or some of the RF transceiver circuitry 612 is part of the communication interface 606. In still other embodiments, the communication interface 606 includes one or more ports or terminals 616, the radio front-end circuitry 618, and the RF transceiver circuitry 612, as part of a radiounit (not shown), and the communication interface 606 communicates with the baseband processing circuitry 614, which is part of a digital unit (not shown).
[0088] The antenna 610 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 610 may be coupled to the radio front-end circuitry 618 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 610 is separate from the network node 600 and connectable to the network node 600 through an interface or port.
[0089] The antenna 610, communication interface 606, and / or the processing circuitry 602 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 610, the communication interface 606, and / or the processing circuitry 602 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.
[0090] The power source 608 provides power to the various components of network node 600 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 608 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 600 with power for performing the functionality described herein. For example, the network node 600 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 608. As a further example, the power source 608 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.
[0091] Embodiments of the network node 600 may include additional components beyond those shown in Figure 6 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 600 may include user interface equipment to allow input of information into the network node 600 and to allow output of information from the network node 600. This may allow a user toperform diagnostic, maintenance, repair, and other administrative functions for the network node 600. In some embodiments providing a core network node, such as core network node 108 of FIG. 4, some components, such as the radio front-end circuitry 618 and the RF transceiver circuitry 612 may be omitted.
[0092] Figure 7 is a block diagram illustrating a virtualization environment 700 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 700 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 700 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface. Virtualization may facilitate distributed implementations of a network node, UE, core network node, or host.
[0093] Applications 702 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.
[0094] Hardware 704 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 706 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 708a and 708b (one or more of which may be generally referred to as VMs 708), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 706 may present a virtual operating platform that appears like networking hardware to the VMs 708.
[0095] The VMs 708 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 706. Different embodiments of the instance of a virtual appliance 702 may be implemented on one or more of VMs 708, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.
[0096] In the context of NFV, a VM 708 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non- virtualized machine. Each of the VMs 708, and that part of hardware 704 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 708 on top of the hardware 704 and corresponds to the application 702.
[0097] Hardware 704 may be implemented in a standalone network node with generic or specific components. Hardware 704 may implement some functions via virtualization. Alternatively, hardware 704 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 710, which, among others, oversees lifecycle management of applications 702. In some embodiments, hardware 704 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 712 which may alternatively be used for communication between hardware nodes and radio units.
[0098] Although the computing devices described herein (e.g., UEs, network nodes) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosedherein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.
[0099] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.
[0100] References[1] 3GPP TS 23.288 V18.6.0 (2024-06), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Architecture enhancement for 5G System (5GS) to support network data analytics services (Release 18)”.[2] 3GPP TR 23.700-84 VI.0.0 (2024-06), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Core NetworkEnhanced Support for Artificial Intelligence (Al) / Machine Learning (ML) (Release 19)”.
Claims
CLAIMS1. A method of operating a policy control function, PCF, in a core network of a wireless communication network, the method comprising: receiving (204) an analytics report describing a predicted network abnormal behavior in the wireless communication network; and initiating (210) an action to mitigate and / or prevent the network abnormal behavior.
2. The method of Claim 1, further comprising: subscribing (202) to receive the analytics report from a network data analytics function, NWDAF, in the core network.
3. The method of Claim 1 or 2, wherein the network abnormal behavior comprises a signalling storm.
4. The method of any of Claims 1 to 3, further comprising: determining whether the predicted network abnormal behavior is caused by user equipment, UE, activity or network function, NF, activity in the wireless communication network.
5. The method of Claim 4, wherein in response to determining that the predicted network abnormal behavior is caused by NF activity, initiating the action comprises notifying (214) an Operations, Administration and Maintenance, 0AM, function in the core network of the predicted network abnormal behavior.
6. The method of Claim 4, wherein, in response to determining that the predicted network abnormal behavior is caused by UE activity, initiating the action comprises performing (210) the action to mitigate and / or prevent the network abnormal behavior.
7. The method of Claim 6, further comprising, prior to triggering the action to mitigate and / or prevent the network abnormal behavior, evaluating (208) the action.
8. The method of Claim 7, wherein evaluating the action comprises evaluating the action using a network digital twin, NDT, emulation.
9. The method of Claim 8, wherein evaluating the action comprises determining an impact of the action on a key performance indicator, KPI, associated with the wireless communication network.
10. The method of any of Claims 6 to 9, wherein the action comprises updating one or more user equipment, UE, route selection policy, URSP, and / or policy and charging control, PCC, rules to prevent and / or mitigate the network abnormal behavior.
11. The method of Claim 10, wherein the action comprises updating one or morePCC rules relating to access traffic steering, switching and splitting, ATSSS, to prevent and / or mitigate the network abnormal behavior.
12. The method of any of Claims 1 to 11, wherein the action to mitigate and / or prevent the network abnormal behavior comprises notifying one or more target network functions, NF, in the core network to prepare for the network abnormal behavior.
13. A network node for implementing a policy control function, PCF, of a core network of a wireless communication network, the network node comprising: processing circuitry; and power supply circuitry configured to supply power to the processing circuitry; wherein the processing circuitry is configured to perform operations comprising: receiving (204) an analytics report describing a predicted network abnormal behavior in the wireless communication network; and initiating (210) an action to mitigate and / or prevent the network abnormal behavior.
14. The network node of Claim 13, wherein the processing circuitry is further configured to subscribe (202) to receive the analytics report from a network data analytics function, NWDAF, in the core network.
15. The network node of Claim 13 or 14, wherein the network abnormal behavior comprises a signalling storm.
16. The network node of any of Claims 13 to 15, wherein the processing circuitry is further configured to determine whether the predicted network abnormal behavior is caused by user equipment, UE, activity or network function, NF, activity in the wireless communication network.
17. The network node of Claim 16, wherein, in response to determining that the predicted network abnormal behavior is caused by NF activity, the processing circuitry is further configured to initiate the action comprises notifying (214) an Operations, Administration and Maintenance, 0AM, function in the core network of the predicted network abnormal behavior.
18. The network node of Claim 16, wherein, in response to determining that the predicted network abnormal behavior is caused by UE activity, initiating the action comprises performing (210) the action to mitigate and / or prevent the network abnormal behavior.
19. The network node of Claim 18, wherein the processing circuitry is further configured to evaluate (208) the action prior to triggering the action to mitigate and / or prevent the network abnormal behavior.
20. The network node of Claim 19, wherein evaluating the action comprises determining an impact of the action on a key performance indicator, KPI, associated with the wireless communication network.
Citation Information
Patent Citations
Policy determining method and apparatus
US20240064066A1
System and method for reducing network component loads
US20240080704A1
Systems and methods for providing analytics from a network data analytics function based on network policies
US20250126065A1
Communication method and communication apparatus
WO2023169101A1
Handling of multiple analytics reports by a network node
WO2024156375A1