System and method for determining subscriber usage analytics data
By leveraging DNS server, user plane, and control plane gateway data, the system addresses the high costs and resource challenges of DPI-based analytics, offering efficient and cost-effective subscriber usage insights.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2026-03-05
AI Technical Summary
Existing systems for determining subscriber usage analytics data rely heavily on expensive deep packet inspection (DPI) solutions, which generate large volumes of data that are challenging to process and analyze in real-time, requiring significant storage and processing resources, and incur high operational costs.
A system and method that utilizes DNS server data, user plane gateway data, and control plane gateway data to determine subscriber usage analytics, combining these data sources to generate insights without relying on DPI, thereby reducing costs and resource requirements.
Enables efficient determination of subscriber usage analytics data, providing valuable insights into user behavior and network performance while optimizing network operations and reducing hardware and software expenses.
Smart Images

Figure IN2025051374_05032026_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR DETERMINING SUBSCRIBER USAGE ANALYTICS DATARESERVATION OF RIGHTS
[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD
[0002] The present disclosure relates generally to the field of communication systems. More particularly, the present disclosure relates to systems and methods for determining subscriber usage analytics data.DEFINITION
[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.
[0004] The term “Subscriber” refers to an individual or entity that has signed up for a service or network and is receiving or accessing it.
[0005] The term “Locality” refers to a specific geographic area or region where network services are provided and managed.
[0006] The term “Subscriber usage analytics” refers to the process of collecting, analyzing, and interpreting data related to how subscribers (users) interact with and use services provided by a network provider or a service provider.
[0007] The term “Subscriber usage analytics data” refers to information about how subscribers are using services, applications, etc. The subscriber usage analytics data is generated by performing subscriber usage analytics. This data typically identifies user behavior, preferences, and patterns.
[0008] The term “Deep Packet Inspection (DPI)” refers to a method for examining the data passing through a network device.
[0009] The term “Subscriber Data Record (SDR)” refers to a database that stores detailed information about a subscriber's activities, interactions, and service usage within the network.
[0010] The term “Domain Name Server (DNS) refers to a component of the network architecture that translates human-readable domain names into Internet Protocol (IP) addresses, which are required for locating and accessing websites and other resources on the Internet.
[0011] The term “User Plane Gateway” refers to a network element that is responsible for managing and routing user data traffic (or user plane traffic) in the network. The user plane gateway separates data handling from control signaling and supports high-speed data transfer for user applications. The user data traffic (or user plane traffic) refers to the data flow in the network that carries user information, such as web browsing activities, messages, or file downloads.
[0012] The term “Control Plane Gateway” refers to a network element responsible for managing control plane functions in the network. The control plane gateway is distinct from the user plane gateway, which handles actual data transfer. The control plane gateway focuses on signaling, network management, and control tasks necessary for establishing, maintaining, and managing connections and sessions.
[0013] The term “Domain Name” refers to a human-readable address used to identify a specific location or resource in the network.
[0014] The term “Internet Protocol (IP)” refers to a set of rules governing the data format sent over the Internet or other networks. IP is responsible for addressing androuting data packets so that they can travel across networks and reach their intended destinations.
[0015] The term “Internet Protocol (IP) address” refers to a unique numerical label assigned to each device connected to a network that uses the Internet Protocol for communication.
[0016] The term “Timestamp” refers to a data element that captures the exact moment in time when a specific event or action happens. It typically includes both the date and time and may also include time zone information.
[0017] The term “IP records” refers to the usage records of a particular subscriber per IP flow that are used in network management, security, and troubleshooting. The IP records help in tracking, identifying, and managing IP address usage within the network.
[0018] The term “User Equipment Identifier (UE ID) refers to a unique identifier assigned to a user equipment (UE) in the network. It is used in distinguishing individual devices or the user and facilitating communication within the network.
[0019] The term “Access Network ID” refers to a unique identifier used to locate the user based on the location of the last mile access network to which the user is connected.
[0020] The term “Gateway IP data record” refers to the data summary generated by the gateways in the network for each IP flow of individual users. This data is essential for managing network traffic, complying with the regulatory requirements and maintaining overall network performance.
[0021] The term “UE IP address” refers to the IP address assigned to the user equipment (UE) in the network. This IP address enables communication between the UE (such as a smartphone, tablet, or loT device) and other devices or services on the Internet or within the network.
[0022] The term “UE location” refers to the geographic position of the user equipment within the network. In this specification, the location will be represented interms of the radio access network ID to which the UE is attached during the data record generation.
[0023] The term “Server IP address” refers to a unique IP address assigned to the server, which allows clients and other servers to connect to it over the network.
[0024] The term “Domain IP address” refers to the IP address associated with a domain name. This IP address routes internet traffic to the correct server that hosts the content or service associated with that domain.
[0025] The term “Website” refers to a collection of related web pages and content that is accessible over the Internet.
[0026] The term “Web browser” refers to a software application that allows users to access, retrieve, and view content from the webpages of the Internet.
[0027] The term “DNS request” refers to a message request sent by a user via a web browser or an application to a DNS server to provide an IP address corresponding to a domain name.
[0028] The term “DNS response” refers to a response from the DNS server to the user that includes the IP address corresponding to the domain name user had requested.
[0029] The term “Data request” refers to a request made to access, retrieve, or manipulate data from a database, application, or service.
[0030] The term “Data response” refers to a response provided by the system, application, or server in response to the data request.
[0031] The term “Web application” refers to a software program that runs in a web browser to exchange information and deliver services remotely.
[0032] These definitions are in addition to those expressed in the art.BACKGROUND
[0033] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure.However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.
[0034] Subscriber usage analysis involves examining and interpreting the data regarding how individual users or subscribers utilize network resources. The subscriber usage analysis helps service providers and network administrators to understand subscriber behavior, optimize network performance, and manage resources effectively. The subscriber usage analysis is performed using deep packet inspection (DPI) to understand and manage how users utilize network resources. The DPI analyzes the data packets transmitted over the network to obtain insights into subscriber behaviors and network performance. The DPI generates large volumes of data, which can be challenging to process and analyze in real-time. Managing and storing the large volumes of data generated by the DPI can be complex and require significant storage and processing resources. Analyzing large traffic volumes can be challenging, as the DPI needs to scale efficiently to handle increasing amounts of data. Further, obtaining the subscriber usage analytics data from the network using the DPI is costly due to expenses for hardware, software, and ongoing operational costs.
[0035] Therefore, there is a need for systems and methods to determine subscriber usage analytics data without relying on expensive DPI solutions.OBJECTIVES
[0036] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as follows:
[0037] An objective of the present disclosure is to provide a system and a method for determining subscriber usage analytics data for each subscriber and each locality in a network.
[0038] Another objective of the present disclosure is to develop subscriber usage analytics data using call / subscriber data records from a domain name system (DNS) server and Internet Protocol (IP) records from a user plane gateway.
[0039] Yet another objective of the present disclosure is to determine subscriber usage analytics data using subscriber data record (SDR) from the control plane gateway.
[0040] Yet another objective of the present disclosure is to determine locality usage analytics data based on location details in the data records from the user / control plane gateway.
[0041] Yet another objective of the present disclosure is to identify the usage trend (both volumetric and time) of an application for each subscriber and each locality.
[0042] Other objectives and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.SUMMARY
[0043] In an exemplary embodiment, a system for determining subscriber usage analytics data for a subscriber and corresponding location in a network is disclosed. The system comprises a receiving unit configured to receive domain name system (DNS) data from a DNS server, receive network data from a user plane gateway and receive subscriber data from a control plane gateway. A generation unit is configured to combine the DNS data, the network data, and the subscriber data. The generation unit is configured to analyze the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network.
[0044] In some embodiments, the generation unit is configured to generate a report, based on the subscriber usage analytics data, indicating usage behavior and locality of the subscriber.
[0045] In some embodiments, the DNS data comprises at least one of a user equipment (UE) Internet Protocol (IP) address, a timestamp, a domain name, a website name, and a domain IP address, and a website IP address.
[0046] In some embodiments, the network data comprises at least one of a subscriber identifier (ID), a timestamp, an access network ID, an equipment IP address, a server IP address, a source port, a destination port, uplink (UL) volume, downlink (DL) volume, a time duration, and a time to live (TTL).
[0047] In some embodiments, the subscriber data comprises at least one of a subscriber identifier (ID), an equipment ID, an IP address, a radio access technology (RAT) type, location data, and handoff data.
[0048] In another exemplary embodiment, a method for determining subscriber usage analytics data for a subscriber and corresponding location in a network is disclosed. The method comprises receiving, by a receiving unit, domain name system (DNS) data from a DNS server and receiving, by the receiving unit, network data record from a user plane gateway. The method comprises receiving, by the receiving unit, subscriber data from a control plane gateway. The method comprises combining, by a generation unit, the DNS data, the network data, and the subscriber data. The method comprises analyzing, by the generation unit, the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network.
[0049] In yet another exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method for determining subscriber usage analytics data for a subscriber and corresponding location in a network is disclosed. The method comprises receiving, by a receiving unit, domain name system (DNS) data from a DNS server and receiving, by the receiving unit, network data record from a user plane gateway. The method comprises receiving, by the receiving unit, subscriber data from a control planegateway. The method comprises combining, by a generation unit, the DNS data, the network data, and the subscriber data. The method comprises analyzing, by the generation unit, the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network.BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWING
[0050] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes disclosure of electrical components, electronic components or circuitry commonly used to implement such components.
[0051] FIG. 1 illustrates an exemplary network architecture for implementing a system for determining subscriber usage analytics data in a network, in accordance with an embodiment of the present disclosure.
[0052] FIG. 2 illustrates an exemplary block diagram of the system for determining the subscriber usage analytics data for a subscriber and corresponding location in the network, in accordance with an embodiment of the present disclosure.
[0053] FIG. 3 illustrates an exemplary flow diagram of a method for determining the subscriber usage analytics data in the network, in accordance with an embodiment of the present disclosure.
[0054] FIG. 4 illustrates another exemplary flow diagram of a method for determining the subscriber usage analytics data for the subscriber and thecorresponding location in the network, in accordance with an embodiment of the present disclosure.
[0055] FIG. 5 illustrates an exemplary block diagram of a computer system in which or with which embodiments of the present disclosure may be implemented.
[0056] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 Network Architecture102 User104 User Equipment106 Network108 System112 Domain Name System (DNS) Server114 User Plane Gateway116 Control Plane Gateway200 Block Diagram202 Processor204 Memory206 Interface(s)208 Receiving Unit210 Generation Unit212 Database300 Flow Diagram301 Website / Web Browser400 Flow Diagram500 Computer System510 External Storage Device520 Bus530 Main Memory540 Read-Only Memory550 Mass Storage Device560 Communication Ports570 ProcessorDETAILED DESCRIPTION
[0057] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure aredescribed below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.
[0058] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.
[0059] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.
[0060] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.
[0061] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect ordesign described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.
[0062] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0063] The terminology used herein is to describe particular embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of theseterms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.
[0064] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment as well as other embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.
[0065] Subscriber usage analysis involves examining and interpreting data regarding how individual users or subscribers utilize network resources. The subscriber usage analysis helps service providers and network administrators to understand subscriber behavior, optimize network performance, and manage resources effectively. The subscriber usage analysis is performed using deep packet inspection (DPI) to understand and manage how users utilize network resources. The DPI analyzes the data packets transmitted over the network to obtain insights into subscriber behaviors and network performance. The DPI generates large volumes of data, which can be challenging to process and analyze in real-time. Managing and storing the large volume of data generated by the DPI can be complex and require significant storage and processing resources. Analyzing large traffic volumes can be challenging, as the DPI needs to scale efficiently to handle increasing amounts of data. Further, obtaining the subscriber usage analytics data from the network using the DPI is costly due to expenses for hardware, software, and ongoing operational costs.
[0066] Therefore, there is a need for systems and methods to determine the subscriber usage analytics data without relying on expensive DPI solutions.
[0067] The present disclosure aims to overcome the above-mentioned and other existing problems in this field of technology by providing a system and a method for determining subscriber usage analytics data. The system may determine the subscriber usage analytics data using call / subscriber data records from a domain name system (DNS) server and IP records from a user plane gateway. The system may combine the call / subscriber data record from the DNS server and the IP records from the user plane gateway to determine the subscriber usage analytics data for each subscriber in the network. The system may also use subscriber data records received from a control plane gateway to enrich the subscriber usage analytics data. Further, the system may determine the subscriber usage analytics data for locality in the network by using location data of the IP records from the user plane gateway and the subscriber data record from the control plane gateway. The system may provide the determined subscriber usage analytics data to network operators. The network operators may use the subscription usage analytics data to enhance service quality and optimize network performance.
[0068] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings FIGs. 1 to 5.
[0069] FIG. 1 illustrates an exemplary network architecture (100) for implementing a system (108) for determining subscriber usage analytics data in a network (106), in accordance with an embodiment of the present disclosure.
[0070] As illustrated in FIG. 1, one or more computing devices (104-1, 104- 2... 104-N) may be connected to the network (106). A person of ordinary skill in the art will understand that the one or more computing devices (104-1, 104-2... 104-N) may be collectively referred as computing devices (104) and individually referred as a computing device (104). One or more users (102-1, 102-2... 102-N) may provide one or more requests to the end server through the network (106). A person of ordinary skill in the art will understand that the one or more users (102-1, 102-2... 102-N) may be collectively referred as users (102) and individually referred as a user (102). Further,the computing devices (104) may also be referred to as a user equipment (UE) (104) or as UEs (104) throughout the disclosure.
[0071] In an embodiment, the user equipment (104) may include, but not be limited to, a mobile, a laptop, etc. Further, the user equipment (104) may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, audio aid, microphone, or keyboard. Furthermore, the user equipment (104) may include a mobile phone, smartphone, virtual reality (VR) devices, augmented reality (AR) devices, a laptop, a general-purpose computer, a desktop, a personal digital assistant, a tablet computer, and a mainframe computer. Additionally, input devices for receiving input from the user (102) such as a touchpad, touch-enabled screen, electronic pen, and the like may be used. A person of ordinary skill in the art will appreciate that the user equipment (104) may not be restricted to the mentioned devices and various other devices may be used.
[0072] Referring to FIG. 1, the user equipment (104) is configured to communicate with the network (106). In an embodiment, the network (106) may include at least one of a Third Generation (3G) Network, Fourth Generation (4G) network, Fifth Generation (5G) network, 6G network, WiFi Network, Fiber to the Home (FTTx) network, or the like which provides internet service to individual or to the subscriber home. The network (106) may enable the user equipment (104) to communicate with other devices in the network architecture (100). The network (106) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (106) may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.
[0073] In an embodiment, the network (106) may include at least one of a Third Generation (3G) Network, Fourth Generation (4G) network, Fifth Generation (5G)network, 6G network, WiFi Network, Fiber to the Home (FTTx) network, or the like which provides internet service to individuals or to the subscriber home. The network (106) may enable the user equipment (104) to communicate with other devices in the network architecture (100) and / or with the system (108). The network (106) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (106) may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.
[0074] In an embodiment, the network (106) may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. The network (106) may also include, by way of example but not limitation, one or more of a wireless network, a wired network, an Internet, an intranet, a public network, a private network, a packet- switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.
[0075] In an embodiment, the network architecture (100) further includes a system (108), a domain name system (DNS) server (112), a user plane gateway (114) and a control plane gateway (116).
[0076] The system (108) may receive DNS data record from the DNS server (112). In an aspect, the DNS server is responsible for resolving human-readable domain names (i.e., domain names in text format) to IP addresses that user devices use to communicate over the network (i.e., Internet). The DNS server provides DNS server data. The DNS server data record may include a user equipment IP address, a domainY1 name, a website, a domain IP address, and a timestamp. The DNS server (112) may track domain name requests, map domain access patterns, extract details (e.g., a DNS query, a DNS response, and timestamps), and log the extracted details in the database of the DNS server.
[0077] The system (108) may receive an Internet Protocol (IP) data record from the user plane gateway (114). In an aspect, the user plane gateway (114) is responsible for handling the user traffic between the subscribers and the network (e.g., Internet). In subscriber usage analytics, the user plane gateway (114) monitors all subscriber data passing through the user plane gateway (114). During the traffic monitoring, the user plane gateway (114) collects the data (i.e., IP data). The IP data record (or gateway IP data record) may include usage statics, a user identifier (ID), an access network ID, a user IP address, UE location, a server IP address, timestamp, source port, destination port, protocol, uplink volume, downlink volume, time duration, time to live (TTL), etc. The user plane gateway (114) may provide granular details (such as how much data is used, session duration, service reporting, subscriber activity, etc) for analytics and billing. The user plane gateway (114) may get the IP data through signaling, session establishment, and traffic inspection.
[0078] The system (108) may combine data from the DNS server data record and the IP data record. The combined data is analyzed to determine subscriber usage analytics data. The system (108) may generate a report of the subscriber usage analytics data based on the determined subscriber usage analytics data.
[0079] Further, the system (108) may fetch subscriber data record (SDR) from the control plane network function (116) to enrich the overall analytics data, such as the user mobility, user group, etc. The control plane network function is responsible for managing signaling and session management for subscribers in the network. The SDRs are structured records created by the control plane network function that comprises detailed metadata about subscriber sessions, such as session setup, modifications and teardown events, along with subscriber identity and control information. The controlplane network function performs session tracking, subscriber identification, session parameter collection, session usage, correlation between the user plane traffic (e.g., data usage) with signaling events and policy and charging rule application and association. The subscriber data record from the control plane network function may include a user identifier, user equipment identifier, IP address, radio access technology (RAT) type, location data, and handover data. The system (108) may determine the subscriber usage analytics data for each subscriber. Furthermore, the system (108) may determine the subscriber usage analytics data for each locality in the network (106) based on the location data of the user plane gateway (114) and / or the control plane gateway (116).
[0080] In an embodiment, the user equipment (104) is communicatively coupled with the end server website / web browser (e.g., website / web browser (301) as shown in FIG. 3) through the network (106). The website / web browser may receive a connection request from the UE (104). The website / web browser may send an acknowledgment of the connection request to the UE (104). The UE (104) may transmit a plurality of signals in response to the connection request. For these UE communications, the DNS server (112) and the user plane gateway (114) generate DNS server data records (e.g., subscriber IP, requested domain, DNS query time, DNS response, DNS server IP, etc.) and IP data records (e.g., subscriber IP, UE IP address, gateway IP, session start / end time, interface, access point name, etc.), respectively, and provide them to the system (108). Additionally, the control plane gateway (116) may provide the SDR (e.g., subscriber ID, session start / end time, total data used, QoS parameters, service type, roaming information, gateway IP, UE IP address, etc.) to the system (108) for the subscriber. The system (108) may be configured for determining subscriber usage analytics data using the DNS server data record, the IP data record and the SDR from the respective nodes.
[0081] Although FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may include fewercomponents, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).
[0082] FIG. 2 illustrates an exemplary block diagram (200) of the system (108) for determining the subscriber usage analytics data for a subscriber and corresponding location in the network (106), in accordance with an embodiment of the present disclosure. FIG. 2, with reference to FIG. 1, illustrates the system (108).
[0083] Referring to FIG. 2, in an embodiment, the system (108) may include one or more processor(s) (202). The one or more processor(s) (202) may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) (202) may be configured to fetch and execute computer-readable instructions stored in a memory (204) of the system (108). The memory (204) may be configured to store one or more computer-readable instructions or routines in a non- transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (204) may comprise any non-transitory storage device including, for example, volatile memory such as random-access memory (RAM), or non-volatile memory such as erasable programmable read only memory (EPROM), flash memory, and the like.
[0084] In an embodiment, the system (108) may include an interface(s) (206). The interface(s) (206) may comprise a variety of interfaces, for example, interfaces for data input and output devices (I / O), storage devices, and the like. The interface(s) (206) may facilitate communication through the system (108). The interface(s) (206) may also provide a communication pathway for one or more components of the system (108). Examples of such components include, but are not limited to, a database (212).
[0085] The system (108) may include a receiving unit (208), a generation unit (210), and the database (212).
[0086] The receiving unit (208) may receive domain name system (DNS) data (also referred to as DNS server data record) from the DNS server (112). In an aspect, the DNS data provides domain names, i.e., unique Internet Protocol (IP) with a timestamp of the domain name.
[0087] The DNS data may include a UE IP address, a domain name, a website name, a domain IP address, a website IP address, and a timestamp. In an aspect, the DNS data refers to the information generated from DNS queries and responses that occur between the UEs (e.g., mobile devices) and one or more DNS servers as users access internet resources through the network (106). In an aspect, the UE IP address refers to the unique Internet Protocol (IP) address assigned to the UE when the UE connects to the network (e.g., 4G LTE or 5G). The UE IP address allows the UE to communicate over the network and access internet services. In an aspect, the domain name refers to a human-friendly address used to identify a location on the network (e.g., Internet). It’s what the user types into a browser to visit a website. For example, example.com, abc.com, xyz.com, etc. In an aspect, the website name refers to a name representing the website, the title of the website, but commonly, it’s the domain used to access the website. For example, In an aspect, the domain IP addressrefers to the numerical IP address that corresponds to the domain name. The DNS translates domain names to these IP addresses, so the UE locates and communicates with the websites. For example, the domain name “example.com” has the IP address 93.184.216.34. In an aspect, the website IP address refers to the IP address of the server where the website is hosted. The website IP address is the numeric address that the UEs use to connect to that website on the network (e.g., Internet). For example, the website domain, such as www.x z.co has the website IP address, i.e., 52.45.9.128. In an aspect, the timestamp refers to a record of the exact time and date when the useraccessed the website. For example, the timestamp: date = 2025-08-18 and time = 15:12:05.120.
[0088] In an example, when the user enters a DNS query (e.g., the website www.abc.com) in the web browser at the timestamp (e.g., 2022-08-26 10:03:20.123). The user device does not directly use the website name to connect. The domain name resolution is used to translate the human-readable domain name, i.e., text format (e.g., www.abc.com). into a numerical IP address (e.g., 99.234,217.48) to route the user request to a web server hosting the website ivww.abc.com. Upon receiving the request “w vw.abc.com”. the DNS server responds with an IP address for wwiv.abc.com (e.g., 99.234,217.48) at timestamp (e.g., 2022-08-26 10:03:20.130). The timestamps corresponding to the DNS query (e.g., 2022-08-26 10:03:20.123) and the DNS response (e.g., 2022-08-26 10:03:20.130) are maintained in a database of the DNS server.
[0089] The receiving unit (208) may receive network data (also referred to as Internet Protocol (IP) data record) from the user plane gateway (114). In an aspect, the network data (i.e., IP data record) provides usage statistics and a user identity along with the timestamp, an access network ID providing location information and a unique IP address assigned to the UE.
[0090] The network data may include usage statistics, a subscriber identifier (ID), an access network ID, an equipment IP address, UE location, a server IP address, timestamp, a source port, a destination port, protocol, uplink volume, downlink volume, time duration, time to live (TTL), etc. In an aspect, the network data (i.e., IP data record) refers to a log or record of internet activity that shows how the UE (e.g., a phone, tablet, or computer) uses the network to access the network services. In an aspect, the usage statistics refer to measurable information about how the user or the UE consumes the network resources, for example, data volume, time spent online, frequency of access, and types of services used. In an aspect, the subscriber identifier refers to a unique value assigned to the user (i.e., subscriber) that allows the networkto recognize, authenticate, and manage the user across its services and infrastructure. In an aspect, the access network ID refers to an identifier used to distinguish or specify the access network through which the user or the UE is connected to the network (e.g., Internet or core network). In an aspect, the equipment IP address refers to the IP address assigned to equipment or device (e.g., UE) connected to the network. In an aspect, the UE location refers to information about the geographical or logical position of the UE (e.g., mobile phone, tablet, or loT device) within the network. In an aspect, the server IP address refers to the IP address assigned to the server that provides services, resources, or data to other devices over the network. In an aspect, the timestamp refers to the recorded date and time at which a specific event, action, or data packet occurs or is captured within the network. In an aspect, the source port refers to the port number assigned to the sending application or process on a source device during a network communication. The source port may be a numeric identifier (between 0 and 65535) used by the source device to specify which application or process sent the data. In an aspect, the destination port refers to the port number on the receiving device that indicates which application or service the incoming network traffic is intended for. The destination port is a numerical value (between 0 and 65535) used in the header of a network packet that indicates the receiving service or application to deliver the data. In an aspect, the protocol refers to a set of rules that defines how data is formatted and transmitted between UEs on the network. The protocol indicates how communication is happening. In an aspect, the uplink volume refers to the amount of data sent from the user / UE to the network (i.e., outbound traffic). For example, uploading a file to the cloud or sending a message. In an aspect, the downlink volume refers to the amount of data received by the user / UE from the network (i.e., inbound traffic). For example, streaming a video or loading a web page. In an aspect, the time duration refers to the length of time that a session, a connection, or the data transfer lasts in the network. In an aspect, TTL refers to a mechanism that limits the lifespan of data packets or records on the network. TTL is a counter or timestamp that's decremented as the data travelsthrough network devices. When the counter reaches zero, the data is discarded. This prevents packets from circulating endlessly due to routing loops or other issues. TTL is used in the DNS to manage how long cached data is considered valid.
[0091] The receiving unit (208) may receive subscriber data (also referred to as subscriber data record (SDR)) from the control plane network function (116). The subscriber data may include subscriber identifier (ID), the equipment ID, the IP address, a radio access technology (RAT) type, location data, and handover data. In an aspect, the subscriber data refers to the information associated with the user's subscription that is necessary for providing services, identification, authentication, routing, call handling, charging, and network management in the network. In an aspect, the subscriber identifier refers to a unique value used to identify a specific user or device (i.e., subscriber) within the network. It allows the network to track, authenticate, and manage individual subscribers. The subscriber identifier comprises, but is not limited to, International Mobile Subscriber Identity (IMSI), Mobile Station International Subscriber Directory Number (MSISDN), Subscription Permanent Identifier (SPI), Globally Unique Temporary Identifier (GUTI), etc.
[0092] In an aspect, the RAT type refers to a specific wireless communication standard or technology used by the UE (e.g., smartphone, modem) to connect to the network. The RAT type comprises, but is not limited to, Global System for Mobile (GSM), Universal Mobile Telecom Service (UMTS), Long Term Evolution (LTE), New Radio (NR), Code Division Multiple Access (CDMA), Evolved UMTS Terrestrial Radio Access (E-UTRAN), etc.
[0093] In an aspect, the location data refers to information that indicates where the subscriber or the UE was located (geographically or within the network) when an event occurred (e.g., call, data session, SMS). The location data can be either a geographical location or a network-based location. The location data comprises, but is not limited to, cell identifier, tracking area code (TAC), location area code (LAC), latitude, longitude, cell global identifier (CGI), ETRAN-CGI (E-CGI), etc. In an aspect, thehandover data refers to the information related to the transfer of an ongoing connection (e.g., a voice call, video session, or data session) from one cell or radio access point to another as the user moves through the network.
[0094] The generation unit (210) may combine data from the DNS data (i.e., DNS server data record), the network data (i.e., IP data record), and the subscriber data (i.e., SDR). The generation unit (210) may analyze the combined data to determine subscriber usage analytics data for the subscriber and a corresponding location in the network (106). Combining these three records would provide per-subscriber usage analytics data for the whole network. From the location details in the network data (i.e., gateway IP record data), the analysis of the combined data may provide usage analytics for the locality as well. To determine subscriber usage analytics, the DNS data (representing what domains a subscriber is accessing), the network data (comprising IP addresses, data volumes, and timestamps), and the subscriber data (mapping network activity to individual users, their locations, and service plans). By combining the DNS data, the network data and the subscriber data, a comprehensive view is provided for each subscriber’s activity, i.e., what services they are using (e.g., streaming or gaming), when they are using them, how much data they consume, and from which location in the network. This enables deeper insights into user behavior and network performance. For example, DNS data such as Time: 2025-08-18 08:00, domain queried = wvvw.abc.com, the network data such as source IP: 192.168.1.101, data volume: 3.2 GB downloaded, location: cell tower 55 / local node A12 and the subscriber data such as IP: 192.168.1.101 assigned to the user (e.g., John), address - 123 Main Street, Springfield and plan - 100 Mbps fiber. By combining the DNS, network, and subscriber data, the analysis provides information such as John, located in Springfield and connected via Node A12, who accessed the website abc.com at 8:00 AM and consumed 3.2 GB of data. This activity contributes to peak usage in the area and indicates high video streaming usage in Node Al 2 during morning hours.
[0095] Based on the determined subscriber usage analytics data, the generation unit (210) may generate a report of the subscriber usage analytics data for each subscriber and each network locality. The report indicates usage behavior and the locality of the subscriber. The subscriber usage analytics involves collecting, processing, and analyzing data related to subscribers to determine how subscribers use network services, applications, and resources. The subscriber usage analytics provides usage patterns, behavioral insights, and performance metrics. The usage patterns include trends such as how subscribers use services and applications (e.g., peak usage times, data consumption, highly used applications, etc.). The behavioral insights include user preferences for service demand and content access. The performance metrics include latency, throughput, and error rates for the subscriber usage. The subscriber usage analytics data provides valuable insights into usage patterns, helps optimize network performance, and supports informed decision-making related to network resources.
[0096] In an aspect, the database (212) is configured to store program instructions. The database (212) is configured to store the data received from the receiving unit (208) and the generation unit (210). The program instructions include a program that implements a method to determine subscriber usage analytics data in accordance with embodiments of the present disclosure and may implement other embodiments described in this specification. The database (212) may be configured to store the report of the subscriber usage analytics data for each subscriber and each locality. The database (212) may include any computer-readable medium known in the art including, for example, volatile memory, such as Static Random Access Memory (SRAM) and Dynamic Random Access Memory (DRAM), and / or nonvolatile memory, such as Read Only Memory (ROM), erasable programmable ROM, flash memories, hard disks, optical disks, and magnetic tapes.
[0097] Although FIG. 2 shows exemplary components of the system (108), in other embodiments, the system (108) may include fewer components, differentcomponents, differently arranged components, or additional functional components than depicted in FIG. 2. Additionally, or alternatively, one or more components of the system (108) may perform functions described as being performed by one or more other components of the system (108).
[0098] FIG. 3 illustrates an exemplary flow diagram (300) for determining subscriber usage analytics data in the network (106), in accordance with an embodiment of the present disclosure. FIG. 3, with reference to FIG. 1, illustrates the following steps:
[0099] At step (302), the DNS server (112) may receive a DNS request from the UE (104). In an aspect, the user (102) enters a domain name (e.g., www.abc.com) into a web browser (301) or any web-based application. The DNS request is sent to get an IP address of the domain name.
[0100] At step (304), the DNS server (112) may send a DNS response to the UE (104). The DNS response includes the IP address of the domain name.
[0101] At step (306), the UE (104) may send a data request to the website or the web browser (301) (e.g., (www.abc.com)). In an aspect, the data request is initiated by the user (102) to access, manipulate, or retrieve data from various sources on a website or through a web browser.
[0102] At step (308), the UE (104) may receive a data response from the website or the web browser (301). In an aspect, on receiving the data request from the UE (104), the web browser (301) may establish a connection with a webserver using the IP address. On establishing a secure connection with the webserver, the web browser (301) may send the received data request to the webserver. The webserver may process the data request. The webserver may retrieve the data for the data request. The webserver may send a response comprising the retrieved data to the web browser (301) or the website. Then, the website or the web browser (301) may send the response to the UE (104). In an aspect, the website or web browser (301) may display the data corresponding to the data request.
[0103] At step (310), the DNS server (112) may send the DNS server data record to the system (108). The DNS server data record may include the UE IP address, the requested domain name, the domain IP address, the timestamp, etc. At step 312, the user plane gateway (114) may send IP data records to the system (108). The IP data record may include UE identifiers, UE IP address, UE address, server IP address, timestamp, etc.
[0104] At step (314), the control panel gateway (116) may send the SDR data to the system (108). The SDR data may include user identity, equipment identity, IP address, RAT type, location, handoff, etc.
[0105] At step (316), the system (108) may combine the received DNS server data record, the gateway IP record and the SDR data. The system (108) may analyze the combined data to determine the subscriber usage analytics data. Based on the determined subscriber usage analytics data, the system (108) may generate a report of the subscriber usage analytics data.
[0106] In an aspect, the system (108) may analyze the combined data to enrich the subscriber usage analytics data. Based on the determined subscriber usage analytics data, the system (108) may generate a report of the subscriber usage analytics data. By combining the DNS server data record, the gateway IP record, and the subscriber data record, the system (108) may determine subscriber usage analytics data for each subscriber in the network (106). Furthermore, the system (108) may determine usage analytics for the locality based on the location details of the gateway IP record.
[0107] The combined data comprises data from the DNS server data record, the gateway IP record and the SDR data. In an example, the combined data is used for correlating subscriber information across different areas of the network (e.g., cellular network) for subscriber / session tracking, analytics or billing. The DNS server data (e.g., subscriber IP, requested domain, i.e., w ewi^com, DNS query time, DNS response, DNS server IP) shows what domain the subscriber is trying to reach. The gateway IP record (e.g., subscriber ID, UE IP address, gateway IP, session start / endtime, interface, access point name (APN), etc.) maps the subscriber sessions to network entry points. The SDR data (e.g., subscriber ID, session start / end time, UE IP address, gateway IP, total data used, QoS parameters, roaming information, APN, service type (VoIP, video), etc. The combined data is formed by using the common fields such as UE IP address, subscriber ID, and session time. The combined data is used to map DNS requests to subscribers, to track which gateway handles the traffic, to correlate usage data with domain access, to perform billing, security and QoS analysis.
[0108] In an aspect, one or more learning methods are applied to the combined data to determine the subscriber usage analytics data per subscriber and per locality. The one or more learning methods comprise, but are not limited to, a clustering method, a time-series analysis, an anomaly detection method, a classification method, a regression analysis, and a pattern recognition analysis. The combined data is shown in Table 1 :Table 1
[0109] In the clustering method, subscribers or geographic areas with similar usage patterns are grouped. For example, for subscribers, grouping subscribers into clusters such as heavy video streamers, frequent voice callers, or low-data users helps design targeted data plans. For locality, regions with similar network usage profiles (e.g., urban business districts vs. rural residential areas) are identified to allow tailored infrastructure upgrades.
[0110] In the time-series analysis, the subscriber data is analyzed to detect trends and patterns (e.g., seasonal patterns). For example, tracking daily data consumption persubscriber to predict when a subscriber might exceed their data limits. Peak network usage hours in a city area are monitored to optimize bandwidth allocation during rush hours.
[0111] In the anomaly detection method, unusual or unexpected patterns in the subscriber data are identified to indicate problems or fraud. For example, sudden spikes in data usage per subscriber that might indicate account compromise or unauthorized tethering are detected. Noticing abnormal drops in network activity in a locality signaling potential outages or infrastructure issues.
[0112] In the classification method, subscribers or locations are assigned to predefined categories based on the subscriber behavior. For example, subscribers are categorized as prepaid or postpaid, then further identified as behavioral subgroups, e.g., "low-usage prepaid users," "high-spending postpaid users," or "prepaid users with regular top-ups. " This helps the network operator target upsell opportunities for prepaid users likely to switch to postpaid or design retention campaigns for high-value postpaid users nearing the end of their contracts.
[0113] In the regression analysis, relationships between variables are used to predict future values such as usage or revenue. For example, future data consumption is predicted to proactively offer plan upgrades. The network load is forecasted in certain areas to plan capacity expansion in the future.
[0114] In the pattern recognition, recurring behaviors or sequences in subscriber activity are detected. For example, recognizing a subscriber who regularly streams music during commuting hours to offer personalized streaming bundles. Daily patterns of high mobile data use in business districts are identified during work hours.
[0115] In this way, the system (108) may combine data records from the DNS server (112), the user plane gateway (114) and the control plane gateway (116) to generate the report of subscriber usage analytics data for each subscriber and each locality of the network (106).
[0116] In an aspect, the subscriber usage analytics data may assist the network operator to determine the application usage trend (both volumetric and time) per subscriber and per locality.
[0117] FIG. 4 illustrates another exemplary flow diagram of a method (400) for determining subscriber usage analytics data for the subscriber and the corresponding location in the network (106), in accordance with an embodiment of the present disclosure. FIG. 4, with reference to FIGs. 1-3, illustrates the following steps:
[0118] At step (402), the method (400) includes receiving, by the receiving unit (208), the DNS data from the DNS server (112). The DNS data provides information such as what services, websites, or applications the subscriber is trying to access. In an aspect, the DNS data comprises at least one of a UE Internet Protocol (IP) address, a timestamp, a domain name, a website name, a domain IP address, and a website IP address.
[0119] At step (404), the method (400) includes receiving, by the receiving unit (208), the network data from the user plane gateway (114). The network data is also referred to as an IP data record. The network data provides information about subscribers’ data sessions, enabling service providers to measure, track, and analyze individual user activity across the network. In an aspect, the network data comprises at least one of a subscriber identifier (ID), a timestamp, an access network ID, an equipment IP address, a server IP address, a source port, a destination port, uplink (UL) volume, downlink (DL) volume, a time duration, and a time to live (TTL).
[0120] At step (406), the method (400) includes receiving, by the receiving unit (208), subscriber data from the control plane gateway (116). The subscriber data provides information that uniquely identifies and characterizes the user within the network. The subscriber data is used to link network activity (e.g., IP sessions, DNS queries, and data usage) to specific individuals or accounts, allowing service providers to generate per-user insights. In an aspect, the subscriber data comprises at least one ofa subscriber identifier (ID), an equipment ID, an IP address, a radio access technology (RAT) type, location data, and handoff data.
[0121] At step (408), the method (400) includes combining, by the generation unit (210), the DNS data, the network data, and the subscriber data. In an aspect, the DNS data, the network data and the subscriber data are combined to generate combined data.
[0122] At step (410), the method (400) includes analyzing, by the generation unit (210), the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network (106). Combining DNS data, the network data and the subscriber data provides the usage analytics data per subscriber and a locality for the whole network.
[0123] The method (400) further comprises generating, by the generation unit (210), a report indicating usage behavior and locality of the subscriber based on the subscriber usage analytics data. In an aspect, the report indicating usage behavior and locality of the subscriber is a summary generated using the subscriber usage analytics data. The report provides data such as what the subscriber is doing (usage behavior, e.g., browsing, streaming, gaming) and where they are doing it from (locality, e.g., city, neighborhood, or network node). The report helps service providers understand individual and regional usage patterns for network optimization, service improvements, or targeted offers.
[0124] In an example, a subscriber name = Jane Smith subscriber ID = 453201, Location = Downtown Los Angeles (Node LA-32) and Plan = 300 Mbps Fiber. The subscriber usage behavior summary is given in the Table 2.Table 2
[0125] The subscriber usage behavior analytics provides a report that Jane is part of a high-usage cluster in Node LA-32. Peak usage in the locality is between 6 PM and 10 PM. 65% of users in the area show similar streaming patterns.
[0126] In an embodiment, a method for providing subscriber usage analytics in the network (106). The method includes receiving DNS data record (DNSDR) (e.g., user equipment IP address, requested domain / website, domain / website IP address, timestamp, etc.) from a DNS server. The method includes receiving an IP data record (IPDR) (e.g., User IP address, server IP address, timestamp, Source / Destination Port, Protocol, UL / DL Volume, Time duration, TTL, etc.) from a gateway (such as a user plane gateway). The method includes fetching subscriber data record (SDR) (e.g., user identity, equipment identity, IP address, RAT type, location, handoff, etc.) from a control plane network function, specifically required for the mobility network, for example, 3G, 4G, 5G or Wi-Fi. Further, IPDR and SDR may be merged in a single record if the user plane and the control plane are not separate. The method further combines the DNS data record from the DNS server, the IP data record from thegateway, and the subscriber data record from the control plane to provide subscriber usage analytics per subscriber and per locality.
[0127] FIG. 5 illustrates an exemplary computer system (500) in which or with which embodiments of the present disclosure may be implemented.
[0128] As shown in FIG. 5, the computer system (500) may include an external storage device (510), a bus (520), a main memory (530), a read-only memory (540), a mass storage device (550), communication port(s) (560), and a processor (570). A person skilled in the art will appreciate that the computer system may include more than one processor and communication ports. The processor (570) may include various modules associated with embodiments of the present disclosure. The communication port(s) (560) may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication port(s) (560) may be chosen depending on a network, such a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system connects.
[0129] The main memory (530) may be random access memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (540) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or Basic Input / Output System (BIOS) instructions for the processor (570). The mass storage device (550) may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage device (550) includes, but is not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces), one or more optical discs, Redundant Array of Independent Disks (RAID) storage, e.g., an array of disks.
[0130] The bus (520) communicatively couples the processor (570) with the other memory, storage, and communication blocks. The bus (520) may be, e.g., a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (570) to the computer system.
[0131] Optionally, operator and administrative interfaces, e.g., a display, keyboard, joystick, and a cursor control device, may also be coupled to the bus (520) to support direct operator interaction with the computer system. Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) (560). Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system limit the scope of the present disclosure.
[0132] The exemplary computer system (500) is configured to execute a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method for determining subscriber usage analytics data for a subscriber and corresponding location in a network is disclosed. The method comprises receiving, by a receiving unit, domain name system (DNS) data from a DNS server and receiving, by the receiving unit, network data record from a user plane gateway. The method comprises receiving, by the receiving unit, subscriber data from a control plane gateway. The method comprises combining, by a generation unit, the DNS data, the network data, and the subscriber data. The method comprises analyzing, by the generation unit, the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network.
[0133] The present disclosure provides technical advancements related to subscriber usage data analytics. The advancement addresses the limitations of existing solutions by generating a light-weight subscriber usage analytics report for eachsubscriber and each locality by combining data records of the DNS server, the user plane gateway, and the control plane gateway. The light-weight subscriber analytics report comprises only aggregated and essential data. Data records (i.e., usage metrics per subscriber and per locality) are intelligently aggregated to minimize data volume and computational complexity, enabling efficient storage and faster processing. This also helps the network operator to understand usage trends (both volumetric and time) for each subscriber and each locality. Consequently, the light-weight subscriber usage analytics report reduces memory, storage and central processing unit (CPU) usage, while also scaling efficiently with minimal infrastructure even when handling a large volume of subscribers.
[0134] While the foregoing describes various embodiments of the invention, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the invention is determined by the claims that follow. The invention is not limited to the described embodiments, versions or examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.ADVANTAGES OF THE PRESENT INVENTION
[0135] The present disclosure described herein above has several technical advantages including, generating a light-weight subscriber usage analytics report for each subscriber and each locality by combining data records of the DNS server (112), the user plane gateway (114), and the control plane gateway (116). helping the network operator to understand usage trend (both volumetric and time) of any web application for each subscriber and each locality.analyzing the subscriber data instantly, enabling faster decision-making and more responsive service delivery. requiring fewer computational resources and reducing the load on the infrastructure. - easily adapting to increasing subscriber data without major changes or delays. managing and processing the large volume of subscriber data efficiently. reducing operational costs through lower resource usage. enabling the offering of services based on the subscriber's behavior and preferences. enhancing overall customer satisfaction by identifying and resolving issues proactively. improving network performance and allocating resources effectively.
Claims
CLAIMS1. A system (108) for determining subscriber usage analytics data for a subscriber and corresponding location in a network (106), the system (108) comprising: a receiving unit (208) configured to: receive domain name system (DNS) data from a DNS server (112); receive network data from a user plane gateway (114); receive subscriber data from a control plane gateway (116); and a generation unit (210) configured to: combine the DNS data, the network data, and the subscriber data; and analyze the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network.
2. The system (108) as claimed in claim 1, wherein the generation unit (210) is configured to generate a report, based on the subscriber usage analytics data, indicating usage behavior and locality of the subscriber.
3. The system (108) as claimed in claim 1, wherein the DNS data comprises at least one of a user equipment (UE) Internet Protocol (IP) address, a timestamp, a domain name, a website name, a domain IP address, and a website IP address.
4. The system (108) as claimed in claim 1, wherein the network data comprises at least one of a subscriber identifier (ID), a timestamp, an access network ID, an equipment IP address, a server IP address, a source port, a destination port, uplink (UL) volume, downlink (DL) volume, a time duration, and a time to live (TTL).
5. The system (108) as claimed in claim 1 , wherein the subscriber data comprises at least one of a subscriber identifier (ID), an equipment ID, an IP address, a radio access technology (RAT) type, location data, and handoff data.
6. A method (400) for determining subscriber usage analytics data for a subscriber and corresponding location in a network (106), the method (400) comprising: receiving (402), by a receiving unit (208), domain name system (DNS) data from a DNS server (112); receiving (404), by the receiving unit (208), network data record from a user plane gateway (114); receiving (406), by the receiving unit (208), subscriber data from a control plane gateway (116); combining (408), by a generation unit (210), the DNS data, the network data, and the subscriber data; and analyzing (410), by the generation unit (210), the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network (106).
7. The method (400) as claimed in claim 6, comprising: based on the subscriber usage analytics data, generating, by the generation unit (210), a report indicating usage behavior and locality of the subscriber.
8. The method (400) as claimed in claim 6, wherein the DNS data comprises at least one of a user equipment (UE) Internet Protocol (IP) address, a timestamp, a domain name, a website name, a domain IP address, and a website IP address.
9. The method (400) as claimed in claim 6, wherein the network data comprises at least one of a subscriber identifier (ID), a timestamp, an access network ID, an equipment IP address, a server IP address, a source port, a destination port, uplink (UL) volume, downlink (DL) volume, a time duration, and a time to live (TTL).
10. The method (400) as claimed in claim 6, wherein the subscriber data comprises at least one of a subscriber identifier (ID), an equipment ID, an IP address, a radio access technology (RAT) type, location data, and handoff data.
11. A user equipment (UE) (104) communicatively coupled with a system (108), the coupling comprises of: receiving, by the system (108), a connection request from UE (104); sending, by the system (108), an acknowledgment of the connection request to the UE (104); and transmitting a plurality of signals in response to the connection request, wherein the system (108) is configured to determine subscriber usageanalytics data for a subscriber and corresponding location in a network (106), as claimed in claim 1.
12. A computer program product comprising a non- transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method (400) for determining subscriber usage analytics data for a subscriber and corresponding location in a network (106), the method (400) comprising: receiving (402), by a receiving unit (208), domain name system (DNS) data from a DNS server (112); receiving (404), by the receiving unit (208), network data record from a user plane gateway (114); receiving (406), by the receiving unit (208), subscriber data from a control plane gateway (116); combining (408), by a generation unit (210), the DNS data, the network data, and the subscriber data; and analyzing (410), by the generation unit (210), the combined data to determine the subscriber usage analytics data for the subscriber and a corresponding location in the network (106).
Citation Information
Patent Citations
Subscriber data management logs parsing and conversion to analytics use cases
US10694367B1
Categorizing IP-based network traffic using DNS data
US20150304199A1