Detection method and apparatus, network device, storage medium and program product
Patent Information
- Application Number
- PCT/CN2026/085373
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2026-03-24
- Publication Date
- 2026-10-01
Smart Images

Figure CN2026085373_01102026_PF_FP_ABST
Abstract
Description
Testing methods, apparatus, network equipment, storage media and software products
[0001] Cross-reference to related applications
[0002] This disclosure claims priority to Chinese Patent Application No. 202510371028.4, filed in China on March 27, 2025, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This disclosure relates to the field of core network technology, and in particular to a detection method, apparatus, network equipment, storage medium, and program product. Background Technology
[0004] Currently, core network intelligence specifications have researched and defined solutions for control plane signaling control, enabling intelligent suppression of control plane signaling storms. This provides solutions for abnormal control plane signaling related to network connectivity, resource allocation, and handover decisions between network terminal devices. However, there are no solutions for detecting and handling abnormal user plane traffic. The inability to effectively suppress abnormal user plane traffic can lead to a series of problems, such as abnormal packets causing user equipment (UE) malfunctions, degraded user plane function (UPF) performance, and system errors. Summary of the Invention
[0005] The purpose of this disclosure is to provide a detection method, apparatus, network device, storage medium, and program product for detecting user plane anomalies and effectively suppressing abnormal situations.
[0006] One embodiment of this disclosure provides a detection method, wherein the method is executed by a first network element, the method comprising:
[0007] Collect first data from at least one second network element; wherein, the first data is user plane related data;
[0008] The first data is used as input to the first model to obtain the analysis results of the first model; wherein, the first model is used for user plane traffic analysis and / or prediction;
[0009] The analysis results are sent to the third network element.
[0010] Optionally, the detection method further includes:
[0011] Acquire historical data, which is user-related data;
[0012] The first model is obtained by training the model based on the historical data.
[0013] Optionally, in the detection method, the user plane related data includes one or more of the following:
[0014] User face information collected by the user face function;
[0015] Business quality information collected by the user-facing functionality;
[0016] Message statistics collected by user plane functions;
[0017] Base station service quality monitoring information;
[0018] Auxiliary information for the fourth network element.
[0019] Optionally, the detection method further includes:
[0020] A first request is obtained from the third network element, wherein the first request is used to request the analysis results.
[0021] Optionally, in the detection method, the first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function;
[0022] The analysis results sent to the third network element include result information at the granularity requested by the first request.
[0023] Optionally, in the detection method, the analysis results include one or more of the following:
[0024] User-facing functionality identifiers;
[0025] User face status information;
[0026] Message information;
[0027] Message statistics;
[0028] Message type information;
[0029] Abnormal statistics on user-side traffic.
[0030] One embodiment of this disclosure also provides a detection method, wherein the method is performed by a third network element, the method comprising:
[0031] Receive the analysis result sent by the first network element; wherein the analysis result is obtained by taking the first data of at least one second network element as input to the first model and performing user plane analysis and / or prediction by the first model.
[0032] Optionally, the detection method further includes:
[0033] Based on the analysis results, perform one or more of the following: user plane control, radio resource allocation, and radio resource adjustment.
[0034] Optionally, the detection method further includes:
[0035] A first request is sent to the first network element, the first request being used to request the analysis results.
[0036] Optionally, in the detection method, the first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function;
[0037] The analysis results include result information at the granularity requested by the first request.
[0038] Optionally, in the detection method, the third network element is a user plane function, and the execution of user plane control includes one or more of the following:
[0039] Control the number of downlink data reports sent;
[0040] Limit the sending of traffic packets.
[0041] Optionally, in the detection method, the third network element is a session management function, and the execution of user plane control includes one or more of the following:
[0042] Reselect user face function;
[0043] Send the first message for flow control to the user plane functionality.
[0044] Optionally, in the detection method, the third network element is a policy control function, and the execution of user plane control includes:
[0045] Send a second message to the session management function; wherein the second message indicates one or more of the following information:
[0046] The first piece of information is used to indicate the function to reselect the user face;
[0047] The second message is used to instruct the sending of the first message.
[0048] Optionally, in the detection method, the first message includes one or more of the following:
[0049] The third piece of information is used to instruct the user-face function to perform data gating or shaping.
[0050] The fourth piece of information is used to instruct the user plane function to adjust the bandwidth parameters;
[0051] The fifth piece of information is used to instruct the user plane function to adjust the Quality of Service (QoS) parameters.
[0052] Optionally, in the detection method, the third network element is a base station, and the execution of user plane control includes:
[0053] Perform wireless resource allocation or wireless resource adjustment.
[0054] Optionally, in the detection method, the third network element is an application function.
[0055] Optionally, in the detection method, the analysis results include one or more of the following:
[0056] User-facing functionality identifiers;
[0057] User face status information;
[0058] Message information;
[0059] Message statistics;
[0060] Message type information;
[0061] Abnormal statistics on user-side traffic.
[0062] One embodiment of this disclosure also provides a detection device, wherein the device is applied to a first network element, and the device includes:
[0063] The acquisition module is used to acquire first data from at least one second network element; wherein, the first data is user plane related data;
[0064] The processing module is used to take the first data as input to the first model and obtain the analysis results of the first model; wherein, the first model is used for user plane traffic analysis and / or prediction;
[0065] The sending module is used to send the analysis results to the third network element.
[0066] One embodiment of this disclosure also provides a detection device, which is applied to a third network element, the device comprising:
[0067] A receiving module is used to receive the analysis results sent by a first network element; wherein the analysis results are obtained by taking the first data of at least one second network element as input to a first model and performing user plane analysis and / or prediction by the first model.
[0068] One embodiment of this disclosure also provides a network device, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, the program implementing the detection method as described in any of the preceding claims when executed by the processor.
[0069] One embodiment of this disclosure provides a readable storage medium, comprising: a program stored on the readable storage medium, the program being executed by a processor to implement the steps of the detection method as described in any of the preceding claims.
[0070] One embodiment of this disclosure also provides a computer program product, comprising computer instructions that, when executed by a processor, implement the steps of the detection method as described in any of the preceding claims.
[0071] The detection method described in this embodiment allows a first network element to analyze first data collected from at least one second network element using a pre-trained first model to obtain analysis results of user plane traffic analysis and / or prediction. The obtained analysis results are then sent to a third network element, enabling the third network element to obtain user plane anomalies based on the analysis results, or to obtain user plane anomalies based on the data in the analysis results, and to perform network processing based on the user plane anomalies to effectively suppress user plane anomalies. Attached Figure Description
[0072] Figure 1 is a schematic flowchart of the detection method according to one embodiment of this disclosure;
[0073] Figure 2 is a schematic diagram of one system structure using the detection method described in the embodiments of this disclosure;
[0074] Figure 3 is a schematic diagram of another system structure using the detection method described in the embodiments of this disclosure;
[0075] Figure 4 is a flowchart illustrating one embodiment of the method described in this disclosure.
[0076] Figure 5 is a schematic flowchart of the detection method according to another embodiment of this disclosure;
[0077] Figure 6 is a schematic diagram of the detection device according to one embodiment of the present disclosure;
[0078] Figure 7 is a schematic diagram of the detection device according to another embodiment of this disclosure. Detailed Implementation
[0079] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this disclosure.
[0080] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0081] The terms "first," "second," etc., used in this disclosure and in the claims are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this disclosure can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0082] The detection method described in this disclosure is applicable to, but not limited to, 5G Core Network (5GC) Artificial Intelligence (AI) / Machine Learning (ML) network systems.
[0083] One implementation of the system using this method is shown in Figure 1, which includes one or more of the following: Network Data Analytics Function (NWDAF), User Plane Function (UPF), Access and Mobility Management Function (AMF), Session Management Function (SMF), Application Function (AF), Radio Access Network (RAN), and UE.
[0084] Alternatively, the Network Data Analytics Function (NWDAF) can also be the Model Training Logical Function (MTLF).
[0085] To detect user plane anomalies and effectively suppress abnormal situations, this disclosure provides a detection method. A first network element can use a pre-trained first model to analyze first data collected from at least one second network element to obtain analysis results of user plane traffic analysis and / or prediction. The obtained analysis results are then sent to a third network element, enabling the third network element to obtain user plane anomalies based on the analysis results or based on the data in the analysis results. The third network element then performs network processing based on the user plane anomalies to effectively suppress them.
[0086] As shown in Figure 2, the detection method described in one embodiment of this disclosure is executed by a first network element. As shown in Figure 2, the method includes:
[0087] S201, collect first data from at least one second network element; wherein, the first data is user plane related data;
[0088] S202, the first data is used as input to the first model to obtain the analysis results of the first model; wherein, the first model is used for user plane traffic analysis and / or prediction;
[0089] S203, the analysis results are sent to the third network element.
[0090] Alternatively, user-face related data can also be described as user-face related information.
[0091] In this embodiment of the disclosure, the first network element includes one or more of NWDAF, MTLF and UPF.
[0092] The second network element includes one or more of the following: UPF, AMF, SMF, RAN, Operation, Administration and Maintenance (OAM), Unified Data Management (UDM) / Unified Data Repository (UDR).
[0093] The third network element includes one or more of the following: UPF, RAN, SMF, Policy Control Function (PCF), and AF.
[0094] It should be noted that in the embodiments of this disclosure, user plane functions can be represented by the abbreviation UPF, but other representations are also possible; similarly, network data analysis functions can be represented by NWDAF, session management functions can be represented by SMF, and access and mobility management functions can be represented by AMF, but are not limited to NWDAF.
[0095] Using the detection method described in this embodiment, a first network element can analyze first data collected from at least one second network element using a pre-trained first model to obtain user plane traffic analysis and / or prediction results. The obtained analysis results are then sent to a third network element, enabling the third network element to determine user plane anomalies based on the analysis results, or to determine user plane anomalies based on the data in the analysis results, and to perform network processing based on the user plane anomalies. This approach enhances AI / ML networks, proposes a technology for user plane traffic analysis, and, based on a network processing scheme for user plane analysis, realizes one or more of user plane control, radio resource allocation, and radio resource adjustment based on user plane analysis.
[0096] In some embodiments of this disclosure, optionally, in step 202, the first model analyzes the first data, and the obtained analysis result is at least one of the following: terminal, terminal group, service flow, service area, and user plane function.
[0097] That is, to obtain the analysis results of one or more terminals, one or more terminal groups, one or more service flows, one or more service areas and / or one or more user plane functions.
[0098] In some embodiments, the method may optionally further include:
[0099] Acquire historical data, which is user-related data;
[0100] The first model is obtained by training the model based on the historical data.
[0101] Alternatively, in this embodiment of the disclosure, historical data can also be described as historical information.
[0102] In this embodiment, the first network element has the function of collecting historical data related to user plane traffic and model training. The model is trained based on the collected data to obtain a first model, which can be used to analyze user plane related data and effectively suppress abnormal user plane traffic.
[0103] Optionally, the first network element may collect historical data related to user plane traffic from one or more of the UPF, RAN and the fourth network element, wherein the fourth network element includes one or more of the AMF, SMF, OAM, PCF, UDM / UDR, etc.
[0104] Optionally, the historical data related to the user face includes one or more of the following:
[0105] User face information collected by the user face function;
[0106] Business quality information collected by the user-facing functionality;
[0107] Message statistics collected by user plane functions;
[0108] Base station service quality monitoring information;
[0109] Auxiliary information for the fourth network element.
[0110] In some embodiments, optionally, the user face information collected by the user face function includes one or more of the following:
[0111] This includes message bursts, malformed data, duplicate data, unknown traffic, distributed denial of service (DDoS) attacks, traffic hijacking, and traffic spoofing.
[0112] In some embodiments, optionally, the service quality information collected by the user plane function includes, but is not limited to, video stream quality information, such as latency and / or packet loss rate of the Real-time Transport Control Protocol (RTCP).
[0113] In some embodiments, optionally, the message statistics information collected by the user plane function includes one or more of the following: bandwidth, message length, packet loss, latency, jitter, message interval, and message retransmission.
[0114] Optionally, the auxiliary information of the fourth network element is the data used to assist in user plane analysis on the fourth network element.
[0115] In one embodiment, the fourth network element may optionally include an AMF, and the auxiliary information may include, but is not limited to, signaling related to user location, user access and / or user handover.
[0116] Optionally, the fourth network element includes SMF, and the auxiliary information includes, but is not limited to, session management data;
[0117] Optionally, the fourth network element includes OAM, and the auxiliary information includes, but is not limited to, network data that can only include user plane statistics, such as user plane statistics or statistics on the success or failure of user access signaling;
[0118] Optionally, the fourth network element includes PCF, and the auxiliary information includes, but is not limited to, user policy data or user policy information;
[0119] Optionally, the fourth network element includes UDM / UDR, and this auxiliary information includes, but is not limited to, user subscription data.
[0120] By adopting this implementation method, the first network element can obtain corresponding user plane related data from multiple network elements by collecting the aforementioned user plane related data. The collected user plane related data is more accurate and comprehensive, making the training of the first model more accurate.
[0121] Optionally, in some embodiments of this disclosure, the method further includes:
[0122] A first request is obtained from the third network element, wherein the first request is used to request the analysis results.
[0123] In this embodiment, the first network element collects first data from at least one second network element based on a first request from the third network element. This first data is then used as input to the first model to obtain analysis results for user plane traffic analysis and / or prediction. In this way, the first network element's analysis of user plane-related data is based on request-response and request-execution, making the performed analysis more aligned with consumer needs.
[0124] In some embodiments, the first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function; wherein, in step S203, the analysis results sent to the third network element include result information at the granularity requested by the first request.
[0125] For example, when the first request is for an analysis result at the granularity of one or more terminals, in step S203, the analysis result sent to the third network element includes the results of user plane traffic analysis and / or prediction for one or more terminals; when the first request is for an analysis result at the granularity of one or more user plane functions, in step S203, the analysis result sent to the third network element includes the results of user plane traffic analysis and / or prediction for one or more user plane functions. Using this method, based on the request from the third network element, the analysis result sent by the first network element to the third network element is at the granularity of at least one of terminal, terminal group, service flow, service area, and user plane function, enabling the third network element to obtain user plane information based on the requested granularity, thereby facilitating effective suppression of abnormal user plane traffic at the requested granularity.
[0126] Optionally, in step S201, the first data collected from at least one second network element, i.e., the user plane related data collected, includes one or more of the following:
[0127] User face information collected by the user face function;
[0128] Business quality information collected by the user-facing functionality;
[0129] Message statistics collected by user plane functions;
[0130] Base station service quality monitoring information;
[0131] Auxiliary information for the fourth network element.
[0132] In this embodiment, optionally, the second network element includes one or more of the following: user plane function, base station, and fourth network element.
[0133] The user plane information, service quality information, message statistics, service quality monitoring information, and auxiliary information of the fourth network element collected by the user plane function are identical to those included in the historical data collected during the training of the first model. Therefore, they will not be repeated here.
[0134] Using the method described in this embodiment, in step S202, after the first data collected by at least one second network element is input into the first model, the first model is used to analyze the first data to obtain the analysis result of the user plane traffic at the current time, and / or to obtain the analysis result of the user plane traffic prediction for a preset time period after the current time.
[0135] Optionally, in this embodiment of the disclosure, the analysis results include one or more of the following:
[0136] User-facing functionality identifiers;
[0137] User face status information;
[0138] Message information;
[0139] Message statistics;
[0140] Message type information;
[0141] Abnormal statistics on user-side traffic.
[0142] The identifier for the user face function is used to indicate the user face function corresponding to the analysis results.
[0143] User plane status information is used to indicate changes in user plane status. This user plane status may include changes in bandwidth and / or traffic, etc. The user plane status information may include the user plane status identifier ID indicating the change and / or the user plane status change index, etc.
[0144] Message information is used to indicate the basic parameter information of the transmitted message, including one or more of the following: message count, message bandwidth, and message type. The message type includes one or more of the following parameters: message header, retransmission, and flow pattern.
[0145] Message statistics are used to indicate information related to the transmission parameters of the transmitted messages, including one or more of the following parameters: message length, packet loss, delay, jitter, message interval, and message retransmission.
[0146] The abnormal statistics of user plane traffic are obtained by statistically analyzing one or more of the above-mentioned user plane status information, message information, message statistics information and message type information, such as abnormal situations of user plane traffic, predicted data transmission errors, predicted burst traffic changes of messages, and changes in bandwidth requirements.
[0147] In this embodiment of the disclosure, the combination of one or more of the user plane status information, packet information, packet statistics information, and packet type information in the above analysis results can reflect the user plane traffic situation and identify user plane traffic anomalies; the above-mentioned user plane traffic anomaly statistics can directly reflect the abnormal situation of user plane traffic. Thus, the third network element that obtains the above analysis results can, based on the analysis results, execute one or more of the following: user plane control, radio resource allocation, and radio resource adjustment, to effectively suppress user plane anomalies.
[0148] In some embodiments, the third network element is a User Plane Function (UPF), which performs user plane control, including one or more of the following:
[0149] Control the number of downlink data reports sent;
[0150] Limit the sending of traffic packets.
[0151] Alternatively, controlling the number of downlink data reports sent can also be described as adjusting the number of downlink data reports sent, or reducing the number of downlink data reports sent.
[0152] In one embodiment, optionally, the third network element is a UPF. As a consumer, the UPF can directly obtain abnormal statistical information on user plane traffic such as downlink traffic, UE, UE group, and service area based on the analysis results, or obtain the abnormal statistical information based on the obtained analysis results and control, adjust or reduce the number of downlink data reports (DLDRs) sent.
[0153] Optionally, the UPF can control, adjust, or reduce the number of DLDRs sent by adjusting one or more of the parameters such as the number of messages sent, the timing length, and the delay.
[0154] In another embodiment, optionally, the third network element is a UPF. As a consumer, in response to a traffic burst initiated by the Access Stratum (AS), based on the analysis results provided by the first network element, it performs a traffic restriction message sending, that is, it sends a downlink traffic suppression request, such as discarding some messages according to the analysis results, in order to control the message sending of the UPF interface, reduce the number of abnormal message sending, and avoid excessive paging signaling.
[0155] In some embodiments of this disclosure, optionally, the third network element is a Session Management Function (SMF), and the execution of user plane control includes one or more of the following:
[0156] Reselect user face function;
[0157] Send the first message for flow control to the user plane functionality.
[0158] Optionally, sending a first message for flow control to the user plane function can be a first message for flow restriction, a first message for flow adjustment, or a first message for flow reduction.
[0159] In one implementation, the analysis results provided by the first network element may include user plane traffic information that meets preset conditions within a preset time period, so as to continuously monitor the user plane traffic selected or filtered based on the preset conditions. As a consumer, the SMF can perform a UPF reselection process to distribute the UPF load based on abnormal traffic patterns in the user plane traffic information (such as abnormal round-trip time (RTT) and abnormal packets per second (PPS)).
[0160] In another implementation, optionally, the SMF, as a consumer, can obtain the predicted changes or errors in user plane traffic based on the analysis results provided by the first network element, and take preventable actions to avoid the error by sending traffic restriction messages, traffic control messages, traffic adjustment messages, or traffic reduction messages to the user plane function.
[0161] The first message includes one or more of the following:
[0162] The third piece of information is used to instruct the user-face function to perform data gating or shaping.
[0163] The fourth piece of information is used to instruct the user plane function to adjust the bandwidth parameters;
[0164] The fifth piece of information is used to instruct the user plane function to adjust the Quality of Service (QoS) parameters.
[0165] In some embodiments of this disclosure, optionally, the third network element is a policy control function (PCF), and the execution of user plane control includes:
[0166] Send a second message to the session management function; wherein the second message indicates one or more of the following information:
[0167] The first piece of information is used to indicate the function to reselect the user face;
[0168] The second message is used to instruct the sending of the first message.
[0169] The first message includes one or more of the following:
[0170] The third piece of information is used to instruct the user-face function to perform data gating or shaping.
[0171] The fourth piece of information is used to instruct the user plane function to adjust the bandwidth parameters;
[0172] The fifth piece of information is used to instruct the user plane function to adjust QoS parameters.
[0173] In this implementation, optionally, the PCF, as the message receiver, can obtain the predicted changes or errors in user plane traffic based on the analysis results provided by the first network element, and send a second message to the SMF to execute relevant policies. That is, the second message sends policy information to the SMF instructing the reselection of user plane functions, and / or sends policy information to the SMF instructing the sending of the first message, so as to take preventable actions to avoid the error.
[0174] In some embodiments of this disclosure, optionally, the third network element is a base station RAN, and the execution of user plane control includes:
[0175] Perform wireless resource allocation or wireless resource adjustment.
[0176] In this implementation, the RAN, acting as the message receiver, obtains the predicted sudden traffic changes or APP encoding / decoding anomalies based on the analysis results sent from the first network element, and performs radio resource allocation or radio resource adjustment to effectively suppress the abnormal situation of the user plane.
[0177] Specifically, the wireless resource allocation can be performed by allocating wireless resources to the terminal based on the analysis results; the wireless resource adjustment can be performed by adjusting the wireless resources already allocated to the terminal based on the analysis results.
[0178] Optionally, the radio resource allocation or adjustment performed by the RAN can be notified to the terminal in real time via the user plane.
[0179] In one embodiment of this disclosure, optionally, the third network element is an AF. The AF can obtain the above-mentioned analysis results from the first network element. In this way, the third network element can open one or more of the analysis results, including the identifier of the user plane function, user plane status information, message information, message statistics information, message type information, and abnormal statistics of user plane traffic, to the AF network element to realize the opening of user plane information.
[0180] In one embodiment of this disclosure, as shown in FIG1, the first network element can be NWDAF (MTLF); in another embodiment, as shown in FIG3, the first network element can be UPF, or the NWDAF and UPF can be integrated into one unit, or the NWDAF portion can be added to the UPF.
[0181] Referring to Figure 4, the first network element can be a UPF, or in other words, the NWDAF and UPF can be integrated into one unit. In this embodiment, the UPF can obtain predicted burst traffic changes based on the collected first data and the first model. For example, if abnormal downlink traffic is detected, it can perform traffic restriction packet transmission processing based on the abnormal downlink traffic, discarding some packets. Using this embodiment, the UPF, as a consumer, also has the function of monitoring or predicting abnormal packets and suppressing user plane anomalies locally based on the monitored or predicted abnormal packets.
[0182] It should be noted that the situation in which NWDAF and UPF are combined into one unit (i.e., the first network element is UPF) in the embodiments disclosed herein can also be applied to embodiments where the third network element is SMF, RAN, PCF and AF, etc., which will not be described in detail here.
[0183] The detection method described in this embodiment can realize user plane traffic analysis and network processing based on the analysis results to effectively suppress abnormal user plane situations, such as controllable transmission of DLDR (Downlink Data Report) messages from UPF to SMF, UPF reselection by SMF, and notification of RAN to perform radio resource optimization measures.
[0184] One embodiment of this disclosure also provides a detection method, executed by a third network element, as shown in Figure 5, the method comprising:
[0185] S501, receive the analysis result sent by the first network element; wherein the analysis result is obtained by taking the first data of at least one second network element as input to the first model and performing user plane analysis and / or prediction by the first model.
[0186] Using the detection method described in this embodiment, the first network element can use a pre-trained first model to analyze the first data collected from at least one second network element, obtain the analysis results of user plane traffic analysis and / or prediction, and send the obtained analysis results to the third network element, so that the third network element can perform network processing based on the analysis results, so as to effectively suppress abnormal user plane situations.
[0187] Optionally, the detection method further includes:
[0188] Based on the analysis results, perform one or more of the following: user plane control, radio resource allocation, and radio resource adjustment.
[0189] Optionally, the detection method further includes:
[0190] A first request is sent to the first network element, the first request being used to request the analysis results.
[0191] Optionally, in the detection method, the first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function;
[0192] The analysis results include result information at the granularity requested by the first request.
[0193] Optionally, in the detection method, the third network element is a user plane function, and the execution of user plane control includes one or more of the following:
[0194] Control the number of downlink data reports sent;
[0195] Limit the sending of traffic packets.
[0196] Optionally, in the detection method, the third network element is a session management function, and the execution of user plane control includes one or more of the following:
[0197] Reselect user face function;
[0198] Send the first message for flow control to the user plane functionality.
[0199] Optionally, in the detection method, the third network element is a policy control function, and the execution of user plane control includes:
[0200] Send a second message to the session management function; wherein the second message indicates one or more of the following information:
[0201] The first piece of information is used to indicate the function to reselect the user face;
[0202] The second message is used to instruct the sending of the first message.
[0203] Optionally, in the detection method, the first message includes one or more of the following:
[0204] The third piece of information is used to instruct the user-face function to perform data gating or shaping.
[0205] The fourth piece of information is used to instruct the user plane function to adjust the bandwidth parameters;
[0206] The fifth piece of information is used to instruct the user plane function to adjust QoS parameters.
[0207] Optionally, in the detection method, the third network element is a base station, and the execution of user plane control includes:
[0208] Perform wireless resource allocation or wireless resource adjustment.
[0209] Optionally, in the detection method, the third network element is an application function.
[0210] Optionally, in the detection method, the analysis results include one or more of the following:
[0211] User-facing functionality identifiers;
[0212] User face status information;
[0213] Message information;
[0214] Message statistics;
[0215] Message type information;
[0216] Abnormal statistics on user-side traffic.
[0217] In this embodiment of the disclosure, the first network element includes one or more of NWDAF, MTLF and UPF.
[0218] The second network element includes one or more of the following: UPF, AMF, SMF, RAN, Operation, Administration and Maintenance (OAM), Unified Data Management (UDM) / Unified Data Repository (UDR).
[0219] The third network element includes one or more of the following: UPF, RAN, SMF, Policy Control Function (PCF), and AF.
[0220] The specific implementation of the detection method described in this disclosure when applied to a third network element can be described in conjunction with the detailed description of the specific implementation when applied to a first network element, and will not be repeated here.
[0221] One embodiment of this disclosure also provides a detection device applied to a first network element, as shown in FIG6, the device comprising:
[0222] The acquisition module 601 is used to acquire first data from at least one second network element; wherein, the first data is user plane related data;
[0223] The processing module 602 is used to take the first data as input to the first model and obtain the analysis results of the first model; wherein, the first model is used for user plane traffic analysis and / or prediction;
[0224] The sending module 603 is used to send the analysis results to the third network element.
[0225] Optionally, in the detection device, the processing module 602 is further configured to:
[0226] Acquire historical data, which is user-related data;
[0227] The first model is obtained by training the model based on the historical data.
[0228] Optionally, in the detection device, the user plane related data includes one or more of the following:
[0229] User face information collected by the user face function;
[0230] Business quality information collected by the user-facing functionality;
[0231] Message statistics collected by user plane functions;
[0232] Base station service quality monitoring information;
[0233] Auxiliary information for the fourth network element.
[0234] Optionally, in the detection device, the acquisition module 601 is further used for:
[0235] A first request is obtained from the third network element, wherein the first request is used to request the analysis results.
[0236] Optionally, in the detection device, the first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function;
[0237] The analysis results sent to the third network element include result information at the granularity requested by the first request.
[0238] Optionally, in the detection device, the analysis results include one or more of the following:
[0239] User-facing functionality identifiers;
[0240] User face status information;
[0241] Message information;
[0242] Message statistics;
[0243] Message type information;
[0244] Abnormal statistics on user-side traffic.
[0245] One embodiment of this disclosure also provides a detection device applied to a third network element, as shown in FIG7, the device comprising:
[0246] The receiving module 701 is used to receive the analysis results sent by the first network element; wherein the analysis results are obtained by taking the first data of at least one second network element as input to the first model and performing user plane analysis and / or prediction by the first model.
[0247] Optionally, the detection device further includes a control module 702 for:
[0248] Based on the analysis results, perform one or more of the following: user plane control, radio resource allocation, and radio resource adjustment.
[0249] Optionally, the detection device further includes a transmitting module 703, used for:
[0250] A first request is sent to the first network element, the first request being used to request the analysis results.
[0251] Optionally, in the detection device, the first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function;
[0252] The analysis results include result information at the granularity requested by the first request.
[0253] Optionally, in the detection device, the third network element is a user plane function, and the control module 702 performs user plane control, including one or more of the following:
[0254] Control the number of downlink data reports sent;
[0255] Limit the sending of traffic packets.
[0256] Optionally, in the aforementioned detection device, the third network element is a session management function, and the control module 702 performs user plane control, including one or more of the following:
[0257] Reselect user face function;
[0258] Send the first message for flow control to the user plane functionality.
[0259] Optionally, in the detection device, the third network element is a policy control function, and the execution of user plane control includes:
[0260] Send a second message to the session management function; wherein the second message indicates one or more of the following information:
[0261] The first piece of information is used to indicate the function to reselect the user face;
[0262] The second message is used to instruct the sending of the first message.
[0263] Optionally, in the detection device, the first message includes one or more of the following:
[0264] The third piece of information is used to instruct the user-face function to perform data gating or shaping.
[0265] The fourth piece of information is used to instruct the user plane function to adjust the bandwidth parameters;
[0266] The fifth piece of information is used to instruct the user plane function to adjust QoS parameters.
[0267] Optionally, in the detection device, the third network element is a base station, and the control module 702 performs user plane control, including:
[0268] Perform wireless resource allocation or wireless resource adjustment.
[0269] Optionally, in the aforementioned detection device, the third network element is an application function.
[0270] Optionally, in the detection device, the analysis results include one or more of the following:
[0271] User-facing functionality identifiers;
[0272] User face status information;
[0273] Message information;
[0274] Message statistics;
[0275] Message type information;
[0276] Abnormal statistics on user-side traffic.
[0277] It should be noted that the embodiments of this device are devices corresponding to the embodiments of the above methods. All implementations in the embodiments of the above methods are applicable to the embodiments of this device and can achieve the same technical effect.
[0278] One embodiment of this disclosure also provides a network device, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, the program implementing the detection method as described in any of the preceding claims when executed by the processor.
[0279] The network device described in this embodiment can be a first network element or a third network element. For details on the specific implementation of the detection method by the processor of the first network element or the third network element, please refer to the detailed description of the detection method above, which will not be repeated here.
[0280] One embodiment of this disclosure also provides a readable storage medium, wherein a program is stored on the readable storage medium, and when the program is executed by a processor, it implements the steps of the detection method as described in any of the preceding claims.
[0281] In this embodiment of the disclosure, the readable storage medium is applied to the first network element or the third network element. When applied to the first network element or the third network element, the execution steps in the corresponding detection method are as described in detail above, and will not be repeated here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0282] This disclosure also provides a computer program product, including computer instructions. When executed by a processor, these computer instructions implement the various processes of the method embodiments shown in FIG1 or FIG5 above, and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0283] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0284] Obviously, those skilled in the art can make various modifications and variations to this disclosure without departing from its spirit and scope. Therefore, if such modifications and variations fall within the scope of the claims of this disclosure and their equivalents, this disclosure is also intended to include such modifications and variations.
Claims
1. A detection method, executed by a first network element, the method comprising: Collect first data from at least one second network element; wherein, the first data is user plane related data; The first data is used as input to the first model to obtain the analysis results of the first model; wherein, the first model is used for user plane traffic analysis and / or prediction; The analysis results are sent to the third network element.
2. The detection method according to claim 1, further comprising: Acquire historical data, which is user-related data; The model is trained based on the historical data to obtain the first model.
3. The detection method according to claim 1 or 2, wherein, The user-plane related data includes one or more of the following: User face information collected by the user face function; Business quality information collected by the user-facing functionality; Message statistics collected by user plane functions; Base station service quality monitoring information; Auxiliary information for the fourth network element.
4. The detection method according to claim 1, further comprising: A first request is obtained from the third network element, wherein the first request is used to request the analysis results.
5. The detection method according to claim 4, wherein, The first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function; The analysis results sent to the third network element include result information at the granularity requested by the first request.
6. The detection method according to claim 1, wherein, The analysis results include one or more of the following: User-facing functionality identifiers; User face status information; Message information; Message statistics; Message type information; Abnormal statistics on user-side traffic.
7. A detection method, performed by a third network element, the method comprising: Receive the analysis result sent by the first network element; wherein the analysis result is obtained by taking the first data of at least one second network element as input to the first model and performing user plane analysis and / or prediction by the first model.
8. The detection method according to claim 7, further comprising: Based on the analysis results, perform one or more of the following: user plane control, radio resource allocation, and radio resource adjustment.
9. The detection method according to claim 7, further comprising: A first request is sent to the first network element, the first request being used to request the analysis results.
10. The detection method according to claim 9, wherein, The first request is used to request the analysis results at a granularity of at least one of terminal, terminal group, service flow, service area, and user plane function; The analysis results include result information at the granularity requested by the first request.
11. The detection method according to claim 8, wherein, The third network element is a user plane function, and the execution of user plane control includes one or more of the following: Control the number of downlink data reports sent; Limit the sending of traffic packets.
12. The detection method according to claim 8, wherein, The third network element is a session management function, and the execution of user plane control includes one or more of the following: Reselect user face function; Send the first message for flow control to the user plane functionality.
13. The detection method according to claim 8, wherein, The third network element is a policy control function, and the execution of user plane control includes: Send a second message to the session management function; wherein the second message indicates one or more of the following information: The first piece of information is used to indicate the function to reselect the user face; The second message is used to instruct the sending of the first message.
14. The detection method according to claim 12 or 13, wherein, The first message includes one or more of the following: The third piece of information is used to instruct the user-face function to perform data gating or shaping. The fourth piece of information is used to instruct the user plane function to adjust the bandwidth parameters; The fifth piece of information is used to instruct the user plane function to adjust the Quality of Service (QoS) parameters.
15. The detection method according to claim 8, wherein, The third network element is a base station, and the execution of user plane control includes: Perform wireless resource allocation or wireless resource adjustment.
16. The detection method according to claim 7, wherein, The third network element is an application function.
17. The detection method according to claim 7, wherein, The analysis results include one or more of the following: User-facing functionality identifiers; User face status information; Message information; Message statistics; Message type information; Abnormal statistics on user-side traffic.
18. A detection device applied to a first network element, the device comprising: The acquisition module is used to acquire first data from at least one second network element; wherein, the first data is user plane related data; The processing module is used to take the first data as input to the first model and obtain the analysis results of the first model; wherein, the first model is used for user plane traffic analysis and / or prediction; The sending module is used to send the analysis results to the third network element.
19. A detection device applied to a third network element, the device comprising: A receiving module is used to receive the analysis results sent by a first network element; wherein the analysis results are obtained by taking the first data of at least one second network element as input to a first model and performing user plane analysis and / or prediction by the first model.
20. A network device, comprising: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the detection method as described in any one of claims 1 to 6, or implements the detection method as described in any one of claims 7 to 17.
21. A readable storage medium, comprising: The readable storage medium stores a program that, when executed by a processor, implements the steps of the detection method as described in any one of claims 1 to 6, or implements the steps of the detection method as described in any one of claims 7 to 17.
22. A computer program product comprising computer instructions that, when executed by a processor, implement the steps of the detection method as claimed in any one of claims 1 to 6, or implement the steps of the detection method as claimed in any one of claims 7 to 17.