System and method for managing subscriber identity in trace records in a network

WO2026202975A1PCT designated stage Publication Date: 2026-10-01JIO PLATFORMS LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2026/050582
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2026-03-30
Publication Date
2026-10-01

Smart Images

  • Figure IN2026050582_01102026_PF_FP_ABST
    Figure IN2026050582_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a system (108) and a method (600) for associating subscriber identity with trace records in a wireless communication network The method (600) includes capturing, by a Trace Collection Entity (202), a registration request message transmitted between a base station (204) and a first network entity (206), the registration request message comprising a temporary user identifier and a first set of network parameters. The method (600) includes extracting session management messages exchanged between the first network entity (206) and a second network entity (208) to obtain a permanent user identifier and tunnel information parameters and establishing a first mapping between the permanent user identifier and the tunnel information parameters. The method (600) includes extracting a context setup request message, creating a second mapping, generating a correlation mapping, and associating the permanent user identifier with trace records received from the base station (204).
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR MANAGING SUBSCRIBER IDENTITY IN TRACE RECORDS IN A NETWORK RESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.FIELD OF DISCLOSURE

[0002] The present disclosure relates generally to the field of telecommunications. In particular, the present disclosure relates to a system and a method for managing subscriber identity in trace records in a network.DEFINITIONS

[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.

[0004] The term “Trace Collection Entity (TCE)” used hereinafter in the specification refers to a network entity that captures and processes signalling messages for subscriber traceability.

[0005] The term “Globally Unique Temporary Identifier (GUTI)” used hereinafter in the specification refers to a temporary identifier assigned to a User Equipment (UE) for mobility management.

[0006] The term “Next Generation Cell Global Identifier (NCGI)” used hereinafter in the specification refers to a unique identifier for a cell in a 5G network to specify and differentiate individual cells within the New Radio (NR) network.

[0007] The term “Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID)” as used herein may refer to a unique identifier assigned to a User Equipment (UE) by the RAN in the NGAP layer. It is used to manage and distinguish individual UE connections within the RAN.

[0008] The term “Access and Mobility Management Function-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID)” as used herein may refer to a unique identifier assigned by the AMF to a UE in the NGAP layer for managing and tracking UE connections in the 5G core network

[0009] The term “Trace Recording Session Reference (TRSR)” as used herein may refer to a unique identifier used to track and manage tracing of a specific user session in a network. The TRSR allows for the collection and analysis of detailed subscriber or network activity data.

[0010] The term “Trace Reference (TR)” as used herein may refer to a unique identifier used to specify and distinguish a trace session in a network equipment. It enables accurate tracking and analysis of network events or subscriber activities.

[0011] The term “International Mobile Subscriber Identity (IMSI)” as used herein may refer to a unique identifier assigned to each mobile subscriber, used to securely identify and authenticate the subscriber within the mobile network.

[0012] The term “Access and Mobility Management Function (AMF)” used hereinafter in the specification refers to a network function responsible for managing UE registration, connection, and mobility.

[0013] The term “Session Management Function (SMF)” used hereinafter in the specification refers to a network function that controls session establishment and manages data paths.

[0014] The term “Subscription Permanent Identifier (SUPI)” used hereinafter in the specification refers to a globally unique identifier assigned to a subscriber in a 5G core network.

[0015] The term “User Plane Function (UPF)” used hereinafter in the specification refers to a network function that handles packet forwarding and data routing in the 5G core network.

[0016] The term “Tunnel Endpoint Identifier (TEID)” used hereinafter in the specification refers to an identifier used for distinguishing General Packet Radio Service Tunnelling Protocol (GTP) tunnels in the user plane.

[0017] The term “Base Station (gNB)” used hereinafter in the specification refers to a radio access node that provides connectivity between the UE and the core network.

[0018] The term “N2 interface” used hereinafter in the specification refers to the interface between the gNB and the AMF for control signalling.

[0019] The term “Nil interface” used hereinafter in the specification refers to the interface between the AMF and SMF for session management signalling.

[0020] These definitions are in addition to those expressed in the art.BACKGROUND OF DISCLOSURE

[0021] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0022] Wireless communication technology has rapidly evolved over the past few decades. The first generation of wireless communication technology was analog technology that offered only voice services. Further, when the second-generation (2G) technology was introduced, text messaging and data services became possible. The 3Gtechnology marked the introduction of high-speed internet access, mobile video calling, and location-based services. The fourth-generation (4G) technology revolutionized wireless communication with efficient data speeds, improved network coverage, and security. Currently, the fifth-generation (5G) technology is being deployed, with even efficient data speeds, low latency, and the ability to connect multiple devices simultaneously. The sixth generation (6G) technology promises to build upon these advancements, pushing the boundaries of wireless communication even further.

[0023] The increasing adoption of Fifth Generation (5G) networks has introduced advancements in network performance, security, and user experience. However, the usage of temporary identifiers, such as a Globally Unique Temporary Identifier (GUTI) presents a challenge in tracking subscribers across multiple registrations. In the 5G network, a User Equipment (UE) is assigned the GUTI for communication after initial registration, replacing the need to use the Subscription Permanent Identifier (SUPI) in subsequent interactions. While this enhances security by preventing unauthorized access to the SUPI, it inadvertently creates a blind spot in subscriber tracking after the initial registration.

[0024] A major problem with 5G networks is that trace records generated by a 5G base station (gNB) lack subscriber information such as the SUPI and the International Mobile Subscriber Identity (IMSI) because this information is sent transparently in encrypted Non-Access Stratum (NAS) container, preventing the gNB from accessing subscriber details. Similarly, gNb is not aware about the GUTI because it is also sent transparently in an encrypted Non-Access Stratum (NAS) container. As a result, subsequent network registrations or other procedure initiated by the UE using GUTI do not provide sufficient subscriber information in trace records, which hinders effective session analytics and subscriber tracking. Further, this creates difficulties in network debugging, fraud detection, and lawfulinterception efforts, as it becomes impossible to correlate multiple sessions to the same subscriber identity.

[0025] Existing solutions to address this challenge rely on trace collection mechanisms such as the Trace Collection Entity (TCE), which gathers trace records from the Radio Access Network (RAN) and Core Network elements. However, the trace records do not inherently contain the SUPI of the subscriber, making it difficult to maintain continuous session awareness. Some existing solutions involve manual correlation techniques, where operators attempt to map GUTI to SUPI using historical registration data, but these solutions lack real-time tracking capabilities. Another alternative involves modifying the network architecture to expose additional subscriber details, contradicting the 5G security principle of keeping SUPI concealed over the air interface.

[0026] In addition to the aforementioned challenges, traditional trace enrichment solutions often fail to capture and maintain subscriber identity correlations beyond the initial registration. Due to the dynamic nature of mobile sessions, the inability to track subscriber transitions across mobility events, session modifications, and service requests results in incomplete trace analysis. The gap affects troubleshooting efforts, making it challenging to diagnose call drops, service disruptions, and abnormal session behaviour. Moreover, conventional methods rely heavily on Core Network logs, which may not always be synchronized with RAN-level events, further complicating real-time trace enrichment.

[0027] There is, therefore, a need in the art to provide a method and a system that can overcome the shortcomings of the existing prior arts.OBJECTIVES OF THE PRESENT DISCLOSURE

[0028] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as listed herein below.

[0029] An objective of the present disclosure is to provide a method and a system to maintain subscriber awareness beyond the initial Subscriber Concealed Identifier (SUCI)-based registration by enabling continuous mapping of subscriber identities throughout the session lifecycle.

[0030] Another objective of the present disclosure is to provide a method and a system for deriving a Subscription Permanent Identifier (SUPI) from Globally Unique Temporary Identifier (GUTI) and enriching it in trace records, thereby eliminating blind spots in subscriber tracking during subsequent registrations.

[0031] Another objective of the present disclosure is to provide a method and a system to enhance trace collection by incorporating the SUPI into trace records, improving network analytics, debugging, and troubleshooting capabilities.

[0032] Another objective of the present disclosure is to provide a method and a system that probes N2 and Nil interfaces to observe authentication flows, ensuring seamless correlation between temporary and permanent subscriber identities.

[0033] Another objective of the present disclosure is to provide a method and a system to allow GUTI-SUPI mapping even if probing begins after GUTI assignment, ensuring no loss of subscriber tracking data.

[0034] Other objectives and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.SUMMARY

[0035] In an exemplary embodiment, a method for associating subscriber identity with trace records in a wireless communication network is disclosed. The method includes capturing, by a Trace Collection Entity (TCE), a registration request message transmitted between a base station and a first network entity, the registration request message comprising a temporary user identifier and a first set of network parameters including a cell identifier and a radio access network user equipment identifier. The method includes extracting, by the TCE, session management messages transmitted between the first network entity and a second network entity, the session management messages comprising a permanent user identifier and one or more tunnel information parameters. The method includes establishing, by the TCE, a first mapping between the permanent user identifier and the one or more tunnel information parameters. The method includes extracting, by the TCE, a context setup request message transmitted between the first network entity and the base station, the context setup request message comprising a second set of network parameters including the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters. The method includes creating, by the TCE, a second mapping between the temporary user identifier and the second set of network parameters. The method includes generating, by the TCE, a correlation mapping comprising the permanent user identifier, the temporary user identifier, the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters based on the first mapping and the second mapping. The method includes receiving, by the TCE, one or more trace records from the base station and associating the permanent user identifier with the one or more trace records based on the correlation mapping.

[0036] In some embodiments, the temporary user identifier comprises a Globally Unique Temporary Identifier (GUTI) and the permanent user identifier comprises a Subscription Permanent Identifier (SUPI), wherein the registrationrequest message corresponds to at least one of a mobility registration update request or a service request transmitted from a user equipment.

[0037] In some embodiments, the registration request message is transmitted over an N2 interface, the session management messages are transmitted over an N11 interface, and the one or more tunnel information parameters comprise a User Plane Function (UPF) network address and a Tunnel Endpoint Identifier (TEID) associated with a user-plane tunnel over an N3 interface.

[0038] In some embodiments, extracting parameters from the registration request message comprises extracting the cell identifier, the radio access network user equipment identifier, and the temporary user identifier, and storing the extracted parameters together with a timestamp for subsequent correlation, wherein the correlation mapping further includes the timestamp.

[0039] In some embodiments, the session management messages comprise an Update Session Management context request and a corresponding response exchanged between the first network entity and the second network entity, the request including the permanent user identifier and the response including the one or more tunnel information parameters.

[0040] In some embodiments, the context setup request message includes an initial context setup request transmitted between the first network entity and the base station, the context setup request message further comprising a mobility management user equipment identifier associated with the first network entity.

[0041] In some embodiments, the correlation mapping further includes one or more parameters comprising the permanent user identifier, the temporary user identifier, the cell identifier, the radio access network user equipment identifier, a mobility management user equipment identifier, the one or more tunnel information parameters, and a timestamp.

[0042] In some embodiments, the one or more trace records received from the base station include at least one of a Trace Reference (TR), a Trace Recording Session Reference (TRSR), the radio access network user equipment identifier, or a mobility management user equipment identifier, wherein associating the permanent user identifier comprises extracting identifiers from the one or more trace records and matching the extracted identifiers with the correlation mapping.

[0043] In some embodiments, the method is performed by a probing platform configured to monitor signalling messages and generate the correlation mapping, and wherein the TCE obtains the permanent user identifier from the probing platform using one or more identifiers extracted from the trace records.

[0044] In an exemplary embodiment, a system for associating subscriber identity with trace records in a wireless communication network is disclosed. Thesystem includes a Trace Collection Entity (TCE) configured to capture a registration request message transmitted between a base station and a first network entity, extract session management messages transmitted between the first network entity and a second network entity, establish a first mapping between a permanent user identifier and one or more tunnel information parameters, extract a context setup request message transmitted between the first network entity and the base station, create a second mapping between a temporary user identifier and a second set of network parameters, generate a correlation mapping based on the first mapping and the second mapping, and receive one or more trace records from the base station and associate the permanent user identifier with the one or more trace records based on the correlation mapping.

[0045] In an exemplary embodiment, a computer program product includes a non-transitory computer-readable medium including instructions that, when executed by one or more processors, cause the one or more processors to execute a method for associating subscriber identity with trace records in a wireless communication network is disclosed. The method includes capturing, by a Trace Collection Entity (TCE), a registration request message transmitted between a base station and a first network entity, the registration request message comprising a temporary user identifier and a first set of network parameters including a cell identifier and a radio access network user equipment identifier. The method includes extracting, by the TCE, session management messages transmitted between the first network entity and a second network entity, the session management messages comprising a permanent user identifier and one or more tunnel information parameters. The method includes establishing, by the TCE, a first mapping between the permanent user identifier and the one or more tunnel information parameters. The method includes extracting, by the TCE, a context setup request message transmitted between the first network entity and the base station, the context setup request message comprising a second set of network parameters including the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters. The method includes creating, by the TCE, a second mapping between the temporary user identifier and the second set of network parameters. The method includes generating, by the TCE, a correlation mapping comprising the permanent user identifier, the temporary user identifier, the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters based on the first mapping and the second mapping. The method includes receiving, by the TCE, one or more trace records from the base station and associating the permanent user identifier with the one or more trace records based on the correlation mapping.

[0046] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure and are not restrictive.BRIEF DESCRIPTION OF DRAWINGS

[0047] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes the disclosure of electrical components, electronic components or circuitry commonly used to implement such components.

[0048] FIG. 1 illustrates an exemplary network architecture of a system for managing subscriber identity in trace records in a network, in accordance with an embodiment of the present disclosure.

[0049] FIG. 2A illustrates an exemplary diagram of a system architecture for managing subscriber identity in trace records in the network, in accordance with an embodiment of the present disclosure.

[0050] FIG. 2B illustrates an exemplary diagram of a system architecture of an alternative system for managing subscriber identity in trace records in the network, in accordance with an embodiment of the present disclosure.

[0051] FIG. 2C illustrates an exemplary block diagram of the system for managing subscriber identity in trace records in the network, in accordance with an embodiment of the present disclosure.

[0052] FIG. 3 illustrates an exemplary flow diagram of a method for managing subscriber identity in trace records in the network, in accordance with an embodiment of the present disclosure.

[0053] FIG. 4 illustrates another exemplary flow diagram of a method for managing subscriber identity in trace records in the network, in accordance with an embodiment of the present disclosure.

[0054] FIG. 5 illustrates another exemplary flow diagram of a method for managing subscriber identity in trace records in the network, in accordance with an embodiment of the present disclosure.

[0055] FIG. 6 illustrates an exemplary process flow of a method for method for selecting the policy control function in the network, in accordance with an embodiment of the present disclosure.

[0056] FIG. 7 illustrates an example computer system in which or with which the embodiments of the present disclosure may be implemented.

[0057] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network architecture102- 1 , 102-2... 102-N - User(s)104-1, 104-2... 104-N - User equipment(s)106 - Network108 - System200A - System architecture202 - Trace Collection Entity (TCE)203 - Probing platform204 - Base Station (gNB)206 - Access and Mobility Management Function (AMF)208 - Session Management Function (SMF)210 - User Plane Function (UPF)200C - Block diagram212 - One or more processor(s)214 - Memory216 - Interface(s)218 - Processing Unit220 - Database300 - Flow diagram400 - Flow diagram500 - Flow diagram600 - Computer system700 - Computer system710 - External Storage Device720 - Bus730 - Main Memory740 - Read Only Memory750 - Mass Storage Device760 - Communication Port770 - ProcessorDETAILED DESCRIPTION OF DISCLOSURE

[0058] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address all of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein.

[0059] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0060] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.

[0061] Also, it is noted that individual embodiments may be described as a process which is depicted as a flowchart, a flow diagram, a data flow diagram, astructure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0062] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive in a manner similar to the term “comprising” as an open transition word without precluding any additional or other elements.

[0063] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0064] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items.

[0065] In modem telecommunications networks, managing subscription plans efficiently is essential for ensuring uninterrupted service and optimizing network resource allocation. Telecommunication service providers offer a wide range of prepaid and postpaid plans that include data, voice, Short Message Service(SMS), and additional value-added services. Users often subscribe to multiple subscription plans, leading to the need for a structured approach to handling plan transitions when an active plan expires or is fully consumed. Further, he users may face service disruptions, unnecessary data loss, or manual intervention to switch between plans.

[0066] Conventional telecommunication systems lack an efficient mechanism to manage multiple subscription plans seamlessly. When the active subscription plan is exhausted, the user must manually activate a new plan, which can lead to temporary service disruptions. Prepaid users risk losing their remaining data balance if they switch plans before expiry, while postpaid users may incur unexpected overage charges due to a lack of proactive plan activation. Furthermore, network operators experience an increased load when multiple users attempt to activate new plans simultaneously, leading to delays and inefficient resource management. The absence of an automated, intelligent solution results in frequent service interruptions, customer dissatisfaction, and increased operational complexity for telecom providers.

[0067] Furthermore, the lack of automation makes it difficult for the users to smoothly transition between different subscription plans. The conventional method may allow limited queue-based processing but fail to dynamically shift plans based on real-time data consumption or user needs. Additionally, the conventional method does not provide a robust framework for both prepaid and postpaid users, leading to fragmented provisioning logic across different subscriber categories.

[0068] To address the above-mentioned issue, the present disclosure provides a method and a system to provision the subscription plan for a user in a network. The present disclosure automates the management of subscription plans by implementing a stacked and queued-based provisioning system. The present disclosure further ensures that active subscription plans are stored in a stacked data bucket, while future plans (next in line to the active plan) are held in a queued data bucket for seamless activation when required. The present disclosure extracts subscription plan identifiers to determine whether a plan should be activated immediately or scheduled for later use. The plan identifiers may include a queue identifier and a stack identifier. If an active subscription plan expires or is fully consumed, the next queued plan is automatically moved to the stacked data bucket and activated without user intervention. Additionally, the user has the flexibility to manually switch subscription plans, pause a subscription plan, or activate an addon pack as needed. The present disclosure also integrates with a charging function (CHF) to ensure prepaid users do not lose their remaining balance when switching plans and that postpaid users avoid unnecessary overage charges. By automating plan transitions and optimizing resource allocation, the present disclosureeliminates manual intervention, enhances billing accuracy, and significantly improves the overall telecom service experience for users and operators alike.

[0069] The present disclosure relates to a system and a method for managing subscriber identity in trace records in a network. The conventional approach of using temporary identifiers, such as the Globally Unique Temporary Identifier (GUTI), poses challenges in tracking subscribers across multiple registrations and other mobility procedures, as the GUTI is periodically updated and not directly linked to the Subscription Permanent Identifier (SUPI) in standard signalling interactions. The limitation results in difficulties in maintaining accurate subscriber traceability, affecting network monitoring, troubleshooting, and lawful interception processes. The present disclosure enables accurate correlation of subscriber identifiers by capturing session management messages and establishing mappings between mobility and tunnel parameters. The present disclosure thus ensures enhanced traceability, improved network monitoring, and efficient subscriber identification across different network entities.

[0070] The various embodiments throughout the disclosure will be explained in more detail with reference to FIGS. 1- 7.

[0071] FIG. 1 illustrates an exemplary network architecture (100) of a system (108) for managing subscriber identity in trace records in a network (106), in accordance with an embodiment of the present disclosure.

[0072] As illustrated in FIG. 1, the network architecture (100) may include one or more user equipments (UEs) (104-1, 104-2... 104-N) associated with one or more users (102-1, 102-2... 102-N) in an environment. A person of ordinary skill in the art will understand that one or more users (102-1, 102-2... 102-N) may collectively referred to as the users (102). Similarly, a person of ordinary skill in the art will understand that one or more UEs (104-1, 104-2... 104-N) may be collectively referred to as the UE (104). Although only three UEs (104) are depicted in FIG. 1, however, any number of the UE (104) may be included without departing from the scope of the ongoing description. In an example, the UE (104) may be an Internet of Things (loT) device.

[0073] In an embodiment, the UE (104) may include smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such an embodiment, the UE (104) may include, but is not limited to, smartphones, smart watches, smart sensors (e.g., mechanical, thermal, electrical, magnetic, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart television (TV), computers, smart security system, smart home system, other devices for monitoring or interacting with or for the users (102) and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE (104) may include,but not limited to, intelligent, multi-sensing, network-connected devices, which may integrate seamlessly with each other and / or with a central server or a cloudcomputing system or any other device that is network-connected.

[0074] Additionally, in some embodiments, the UE (104) may include, but is not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a tablet device, and so on), a wearable computer device (e.g., a headmounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with wireless communication capabilities, and the like. In an embodiment, the UE (104) may include, but is not limited to, any electrical, electronic, electromechanical, or equipment, or a combination of one or more of the above devices, such as virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general -purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other computing device, wherein the UE (104) may include one or more inbuilt or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user (102) or the entity such as touchpad, touch-enabled screen, electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE (104) may not be restricted to the mentioned devices and various other devices may be used.

[0075] Referring to FIG. 1 , the UE (104) may communicate with the system (108) through the network (wireless communication network) (106) for sending or receiving various types of data. In an embodiment, the network (106) may include at least one of a fifth-generation (5G) network, a sixth-generation (6G) network, or the like. The network (106) may enable the UE (104) to communicate with other devices in the network architecture (100) and / or with the system (108). The network (106) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (106) may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.

[0076] In an embodiment, the network (106) may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. The network (106) may also include, by way of example but not limitation, one or more of a wireless network, a wired network, an internet, an intranet, a public network, aprivate network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.

[0077] In an embodiment, the UE (104) is communicatively coupled with the network (106). The network (106) may receive a connection request from the UE (104). The network (106) may send an acknowledgment of the connection request to the UE (104). The UE (104) may transmit a plurality of signals in response to the connection request.

[0078] The system (108) operates by facilitating communication between the UE (104) and the network (106) to ensure accurate tracking of subscriber identities in trace records. When the UE (104) connects to the network (106), the UE (104) initiates a registration process, during which temporary identifiers such as the Globally Unique Temporary Identifier (GUTI) are assigned. The system (108) captures session management messages exchanged between the UE (104) and the network (106) and utilizes a Trace Collection Entity (TCE) to extract and correlate the Subscription Permanent Identifier (SUPI) with mobility and the user’s N3 tunnel parameters. By leveraging correlation mapping, the system (108) enables the accurate identification of subscribers across different network entities, ensuring enhanced traceability and network monitoring.

[0079] Although FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).

[0080] FIG. 2A illustrates a system architecture (200A) for managing subscriber identity in trace records in the network (106), in accordance with an embodiment of the present disclosure.

[0081] In the context of the present disclosure, the following terms are used. A 'temporary user identifier' may comprise, for example, a Globally Unique Temporary Identifier (GUTI). A 'permanent user identifier' may comprise, for example, a Subscription Permanent Identifier (SUPI). A 'first network entity' (206) may correspond to an Access and Mobility Management Function (AMF), and a 'second network entity' (208) may correspond to a Session Management Function (SMF). The 'first set of network parameters' may include, for example, a cell identifier such as a Next Generation Cell Global Identifier (NCGI) and a Radio Access Network UE-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID). The 'second set of network parameters' may include, for example, anAccess and Mobility Management Function UE-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, and one or more tunnel information parameters including a User Plane Function N3 Internet Protocol (UPF N3 IP) address and a Tunnel Endpoint Identifier (TEID).

[0082] The architecture (200A) comprises a Trace Collection Entity (TCE) (202), an Access and Mobility Management Function (AMF) (206), a Session Management Function (SMF) (208), a User Plane Function (UPF) (210), a base station (204), and the User Equipment (UE) (104).

[0083] In an embodiment, the UE (104) initiates a mobility registration request or the service request, which is transmitted over an air interface to the base station (204). In an embodiment, the base station (204) is a gNodeB (gNB) in a 5G network. The base station (204) then forwards the mobility registration request or the service request to the AMF (206) over an N2 interface. The mobility registration request or the service request includes a first set of parameters including a Globally Unique Temporary Identifier (GUTI), a Next Generation Cell Global Identifier (NCGI), and a Radio Access Network UE-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID). The RAN-UE-NGAP-ID is an identifier within 5G networks, specifically used in the communication between the gNB (204) and the AMF (206) over the NGAP interface.

[0084] In an embodiment, the TCE (202) is configured to probe the N2 interface to capture the mobility registration request or the service request. Upon capturing the mobility registration request or the service request, the TCE (202) stores the GUTI, the NCGI, and the RAN-UE-NGAP-ID.

[0085] In an embodiment, the AMF (206) communicates with the SMF (208) over an Nil interface to update a session management context. The communication includes a session management message comprising a Subscription Permanent Identifier (SUPI). The TCE (202) is configured to probe the Nil interface to capture the session management message.

[0086] In an embodiment, the TCE (202) extracts the SUPI from the session management message and obtains tunnel information parameters, including a User Plane Function (UPF) N3 IP address (210) and a Tunnel Endpoint Identifier (TEID), which are also included in the session management message. The tunnel information parameters are extracted from the session management message exchanged between the AMF (206) and the SMF (208) over the N11 interface.

[0087] In an embodiment, the TCE (202) establishes a first mapping between the SUPI and the tunnel information parameters (UPF N3 IP address and TEID).

[0088] In an embodiment, the AMF (206) sends an initial context setup request message to the base station (204) over the N2 interface. The initial contextsetup request message includes an Access and Mobility Management Function User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the UPF N3 IP address, and the UPF TEID. The AMF-UE-NGAP-ID is used by the AMF (206) to identify a specific UE during communication with the gNB (204) over the N2 interface. The TCE (202) is configured to capture this message by probing the N2 interface.

[0089] In an embodiment, the TCE (202) creates a second mapping between the GUTI and the plurality of network parameters (AMF-UE-NGAP-ID, NCGI, RAN-UE-NGAP-ID, UPF N3 IP address, and TEID) from the initial context setup request message.

[0090] In an embodiment, the TCE (202) generates a correlation mapping comprising the SUPI, the GUTI, the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, the UPF N3 IP address, and the UPF TEID based on the first mapping and the second mapping.

[0091] In an embodiment, the base station (204) streams trace records to the TCE (202). Each trace record includes a trace reference (TR) and a trace recording session reference (TRSR). Additionally, at least one trace record for a user session will include the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID.

[0092] In an embodiment, the TCE (202) associates the corresponding SUPI with the trace records based on the correlation mapping. The association is performed by identifying the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID present in the trace record and using these identifiers to look up the corresponding SUPI in the correlation mapping. Further, the TCE will map the SUPI to all trace records of the user session identified by a combination of the TR and the TRSR.

[0093] FIG. 2B illustrates an alternative system architecture (200B) for managing subscriber identity in trace records in the network (106), wherein a probing platform (203) may be used to offload the processing tasks from the Trace Collection Entity (TCE) (202).

[0094] In an embodiment, the architecture (200B) comprises the User Equipment (UE) (104), the base station (204), the Access and Mobility Management Function (AMF) (206), the Session Management Function (SMF) (208), the User Plane Function (UPF) (210), the probing platform (203), and the TCE (202).

[0095] In an embodiment, the UE (104) initiates a mobility registration request or the service request, which is transmitted over an air interface to the base station (204). The base station (204) forwards the request to the AMF (206) over the N2 interface.

[0096] In an embodiment, unlike FIG. 2A where the TCE (202) directly probes the N2 and Nil interfaces, in FIG. 2B, the probing platform (203) is configured to probe the N2 and Nil interfaces. The probing platform (203) captures the mobility registration request or the service request from the N2 interface, storing the Globally Unique Temporary Identifier (GUTI), the Next Generation Cell Global Identifier (NCGI), and the Radio Access Network UE-NGAP-ID.

[0097] In an embodiment, the AMF (206) communicates with the SMF (208) over the Nil interface. The probing platform (203) captures the session management message, which includes the Subscription Permanent Identifier (SUPI), the User Plane Function (UPF) N3 IP address (210), and the Tunnel Endpoint Identifier (TEID).

[0098] In an embodiment, the probing platform (203) extracts the SUPI and the tunnel information parameters and establishes a first mapping between the SUPI and the tunnel information parameters.

[0099] In an embodiment, the AMF (206) sends an initial context setup request message to the base station (204) over the N2 interface. The probing platform (203) captures this message, which includes the AMF -UE-NGAP-ID, the NCGI, the RAN-UE-NGAP-ID, the UPF N3 IP address, and the TEID.

[0100] In an embodiment, the probing platform (203) creates a second mapping between the GUTI and the second set of network parameters from the initial context setup request message.

[0101] In an embodiment, the probing platform (203) generates a correlation mapping comprising the SUPI, the GUTI, the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, the UPF N3 IP address, and the TEID, based on the first and second mappings.

[0102] In an embodiment, the base station (204) streams trace records to the TCE (202). Each trace record includes the trace reference (TR) and the trace recording session reference (TRSR). Additionally, the at least one trace record for each user session will include the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID.

[0103] In an embodiment, the TCE (202) queries the probing platform (203) to retrieve the SUPI corresponding to the NCGI, the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID received in the trace records including the timestamp. The probing platform (203) responds to the query with the SUPI, based on the correlation mapping.

[0104] In an embodiment, the TCE (202) associates the corresponding SUPI with the trace records based on the received SUPI from the probing platform (203).

[0105] In an embodiment, the introduction of the probing platform (203) in FIG. 2B allows for distributed processing, wherein the probing platform (203) handles the capture and correlation of signalling messages, while the TCE (202) focuses on receiving and managing the trace records. This architecture enables the system (108) to scale more effectively and manage higher volumes of trace data.

[0106] FIG. 2C illustrates an exemplary block diagram (200C) of a system (108) for managing subscriber identity in trace records in the network (106) in accordance with an embodiment of the present disclosure. FIG. 2C is explained in conjunction with the FIG. 1 and FIGS. 2A and 2B.

[0107] The system (108) comprises a processor (212), a memory (214), an interface (216), a processing unit (218) and a database (220). The system (108) may further include or implement a Trace Collection Entity (TCE) (202), which may be realized as a functional module within the processing unit (218) or as a standalone entity.

[0108] Referring to FIG. 2C, in an embodiment, the system (108) may include one or more processor(s) (212). The one or more processor(s) (212) may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) (212) may be configured to fetch and execute computer-readable instructions stored in the memory (214) of the system (108). The memory (214) may be configured to store one or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (214) may comprise any non-transitory storage device including, for example, volatile memory such as random-access memory (RAM), or non-volatile memory such as erasable programmable read-only memory (EPROM), flash memory, and the like.

[0109] In an embodiment, the system (108) may include an interface(s) (216). The interface(s) (216) may comprise a variety of interfaces, for example, interfaces for data input and output devices (VO), storage devices, and the like. The interface(s) (216) may facilitate communication through the system (108). The interface(s) (216) may also provide a communication pathway for one or more components of the system (108). Examples of such components include, but are not limited to, the processing unit (218) and the database (220).

[0110] In an embodiment, the interface(s) (216) facilitates communication between the system (108) and external entities including the User Equipment (UE) (104), the base station (204), the Access and Mobility Management Function (AMF) (206), the Session Management Function (SMF) (208), and the User Plane Function (UPF) (210). The interface(s) (216) may support communication over oneor more interfaces including an N2 interface, an N11 interface, and a trace records streaming interface.

[0111] In an embodiment, the Trace Collection Entity (TCE) (202) may comprise a processing engine (218) configured to execute various operations related to subscriber identity correlation and trace record management. Alternatively, the processing engine (218) may be implemented as a standalone component within the system (108) and may perform the functions of the TCE (202).

[0112] In an embodiment, the processing unit (218) or the TCE (202) is configured to capture a registration request message transmitted between the base station (204) and the AMF (206). The registration request message corresponds to at least one of a mobility registration update request or a service request initiated by the UE (104). The registration request message comprises a temporary user identifier, such as a Globally Unique Temporary Identifier (GUTI), and a first set of network parameters including a Next Generation Cell Global Identifier (NCGI) and a Radio Access Network UE-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID). In an embodiment, the mobility registration update request or the service request is utilized for obtaining the temporary user identifier and the first set of network parameters during an initial access or mobility procedure. The first set of network parameters, including the NCGI and the RAN-UE-NGAP-ID, provides a unique identification context for the UE (104) within the network (106) and is used for correlating subsequent signalling messages associated with the UE (104).

[0113] In an embodiment, the processing unit (218) is configured to extract one or more session management messages transmitted between the AMF (206) and the SMF (208) over the Nil interface. The one or more session management messages comprise an Update Session Management context request and a corresponding response. The request message comprises a permanent user identifier, such as a Subscription Permanent Identifier (SUPI), and the response message comprises one or more tunnel information parameters. The tunnel information parameters include a User Plane Function (UPF) (210) N3 Internet Protocol (IP) address and a Tunnel Endpoint Identifier (TEID) associated with a user-plane tunnel over an N3 interface. In an embodiment, the Update Session Management context request and the corresponding response are utilized for obtaining the permanent user identifier and the one or more tunnel information parameters associated with the UE (104). The permanent user identifier and the one or more tunnel information parameters are used for establishing a mapping between subscriber identity and user-plane communication parameters within the network (106).

[0113] In an embodiment, the processing unit (218) is configured to extract one or more session management messages transmitted between the AMF (206) and the SMF (208) over the Nil interface. The one or more session managementmessages comprise an Update Session Management context request and a corresponding response. The request message comprises a permanent user identifier, such as a Subscription Permanent Identifier (SUPI), and the response message comprises one or more tunnel information parameters. The tunnel information parameters include a User Plane Function (UPF) (210) N3 Internet Protocol (IP) address and a Tunnel Endpoint Identifier (TEID) associated with a user-plane tunnel over an N3 interface. In an embodiment, the Update Session Management context request and the corresponding response are utilized for obtaining the permanent user identifier and the one or more tunnel information parameters associated with the UE (104). The permanent user identifier and the one or more tunnel information parameters are used for establishing a mapping between subscriber identity and user-plane communication parameters within the network (106). In some embodiments, the one or more tunnel information parameters may include at least one of a UPF N3 IP address, a TEID, or other tunnel -related parameters associated with user-plane communication.

[0114] In an embodiment, the processing unit (218) is configured to establish a first mapping between the SUPI and the one or more tunnel information parameters, including the UPF (210) N3 IP address and the TEID. The first mapping enables correlation of the permanent user identifier with user-plane routing information.

[0115] In an embodiment, the processing unit (218) or the TCE (202) operates on a plurality of network data parameters for correlating subscriber identity with trace records. The network data parameters include:• GUTI: Assigned by the AMF (206) for temporary subscriber identification.• SUPI: A unique and permanent identifier associated with the UE (104). • NCGI: Identifies the specific cell where the UE (104) operates.• RAN-UE-NGAP-ID: A unique identifier assigned by the base station (204) for session management.• AMF-UE-NGAP-ID: Assigned by the AMF (206) for tracking the UE (104) in the control plane.• UPF N3 IP address (210): Represents the UPF (210) IP address for routing user data.• TEID: Identifies tunnels used for transporting user traffic between the UPF (210) and the base station (204)• Trace Reference (TR) and Trace Recording Session Reference (TRSR):Identifiers used to correlate trace sessions.

[0116] In an embodiment, the processing unit (218) is configured to extract a context setup request message transmitted between the AMF (206) and the base station (204) over the N2 interface. The context setup request message corresponds to an initial context setup request and comprises a second set of network parametersincluding an AMF-UE-NGAP-ID, the NCGI, the RAN-UE-NGAP-ID, the UPF (210) N3 IP address, and the TEID.

[0117] In an embodiment, the processing unit (218) is configured to create a second mapping between the temporary user identifier (GUTI) and the second set of network parameters extracted from the context setup request message. The second mapping enables association of temporary identifiers with control-plane and user-plane parameters.

[0118] In an embodiment, the processing unit (218) is configured to generate a correlation mapping based on the first mapping and the second mapping. The correlation mapping comprises the SUPI, the GUTI, the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and the one or more tunnel information parameters including the UPF (210) N3 IP address and the TEID. In some embodiments, the correlation mapping further includes a timestamp associated with extracted parameters. In some embodiments, the correlation mapping is indexed using the timestamp to distinguish between multiple sessions associated with the UE (104) across different time instances.

[0119] In an embodiment, the processing unit (218) is configured to receive one or more trace records from the base station (204) via the trace records streaming interface. Each trace record includes at least one of a Trace Reference (TR), a Trace Recording Session Reference (TRSR), the RAN-UE-NGAP-ID, or the AMF-UE-NGAP-ID.

[0120] In an embodiment, the processing unit (218) is configured to associate the permanent user identifier (SUPI) with the one or more trace records based on the correlation mapping. The association is performed by extracting identifiers from the trace records, including the NCGI, the RAN-UE-NGAP-ID, and the AMF-UE-NGAP-ID, and matching the extracted identifiers with corresponding entries in the correlation mapping to determine the SUPI associated with the trace records.

[0121] In an embodiment, the database (220) is configured to store one or more mappings including the first mapping, the second mapping, and the correlation mapping. The database (220) may further store trace records and associated subscriber identity information to enable efficient retrieval and correlation.

[0122] In an embodiment, the system (108) may further comprise a probing platform (203) configured to monitor signalling messages on the N2 interface and the Nil interface and generate the correlation mapping. In such an embodiment, the TCE (202) is configured to obtain the permanent user identifier (SUPI) from the probing platform (203) based on one or more identifiers extracted from the trace records.

[0123] In an embodiment, the system (108) enables accurate association of subscriber identity with trace records by correlating temporary and permanent identifiers across control-plane and user-plane signalling procedures. The system (108) thereby enhances traceability, network monitoring, and subscriber-level analytics in the network (106).

[0124] FIG. 3 illustrates an exemplary flow diagram of a method (300) for managing subscriber identity in trace records in the network (106) in accordance with an embodiment of the present disclosure. FIG. 3 is explained in conjunction with the FIG. 1 and FIGS. 2A-2C.

[0125] At step 302, the method (300) includes receiving, by the processing unit (218) or the Trace Collection Entity (TCE) (202), a mobility registration request or a service request from the User Equipment (UE) (104). The request includes a Globally Unique Temporary Identifier (GUTI) and is transmitted to the base station (204), which is the gNodeB (gNB), and subsequently forwarded to the AMF (206) over the N2 interface. The TCE (202) probes the N2 interface and captures the mobility registration request or the service request.

[0126] At step 304, the method (300) includes analyzing, by the processing unit (218) or the TCE (202), the captured mobility registration request or the service request to extract a Next Generation Cell Global Identifier (NCGI), a Radio Access Network UE-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID), and the GUTI. The extracted parameters are stored along with a timestamp to ensure uniqueness across base stations (204) and to facilitate correlation in subsequent steps.

[0127] At step 306, the method (300) includes monitoring, by the TCE (202), a session management context modification request transmitted from the AMF (206) to the Session Management Function (SMF) (208) over the Nil interface. The request includes the Subscription Permanent Identifier (SUPI) of the UE (104). The TCE (202) captures the request and extracts the SUPI.

[0128] At step 308, the method (300) includes capturing, by the TCE (202), a corresponding session management context modification response transmitted from the SMF (208) to the AMF (206) over the Nil interface. The response includes tunnel information parameters comprising a User Plane Function (UPF) (210) N3 IP address and a Tunnel Endpoint Identifier (TEID). The TCE (202) extracts and stores the tunnel information parameters.

[0129] At step 310, the method (300) includes creating, by the TCE (202), an initial correlation mapping between the extracted SUPI and the UPF N3 IP address (210) along with the corresponding UPF TEID.

[0130] At step 312, the method (300) includes monitoring, by the TCE (202), an initial context setup request transmitted from the AMF (206) to the basestation (204) over the N2 interface. The initial context setup request includes a NAS registration accept or service accept message and parameters including the AMF-UE-NGAP-ID, the NCGI, the RAN-UE-NGAP-ID, the UPF (210) N3 IP address, and the TEID. The TCE (202) extracts these parameters and correlates the AMF-UE-NGAP-ID, UPF (210) N3 IP address, and TEID with the previously extracted NCGI and RAN-UE-NGAP-ID from step 304.

[0131] At step 314, the method (300) includes generating, by the TCE (202), a correlation mapping by combining the mappings from step 310 and step 312. The correlation mapping comprises the SUPI, the GUTI, the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, the UPF (210) N3 IP address, and the TEID.

[0132] FIG. 4 illustrates another exemplary flow diagram of a method (400) for managing subscriber identity in trace records in the network (106) in accordance with an embodiment of the present disclosure. FIG. 4 is explained in conjunction with the FIG. 3.

[0133] At step 402, the method (400) includes initiating parallel trace record generation after RRC session establishment for registration. The gNB (204) begins streaming trace records to the TCE (202). Each trace record contains a Trace Reference (TR) and Trace Recording Session Reference (TRSR). One of these trace records includes UE context details, specifically the RAN-UE-NGAP-ID and AMF-UE-NGAP-ID.

[0134] At step 404, the method (400) includes performing SUPI lookup and enrichment. The gNB (204) will forward the registration request to the AMF (206) as shown in the method (300) and start streaming of trace records towards the TCE (202).

[0135] At step 406, the method (400) involves the continuous streaming of trace records from the gNB (204) to the TCE (202). Each trace record includes a Trace Reference (TR) and a Trace Recording Session Reference (TRSR). Notably, one of these trace records contains UE context details, specifically the Radio Access Network UE-NGAP Identifier (RAN-UE-NGAP-ID) and the AMF-UE-NGAP-ID. The TCE (202) extracts NCGI, RAN-UE-NGAP-ID, and AMF-UE-NGAP-ID from NGAP trace records, along with a timestamp. The TCE (202) then queries the correlation mapping created in step 314 of FIG. 3 to obtain the corresponding SUPI. Once retrieved, the TCE (202) enriches the trace records by adding the SUPI.

[0136] In an alternative embodiment, the method (400) includes an implementation where the probing platform (203) (shown in FIG. 2B) is responsible for probing trace records and executing the correlation algorithm. In this case, the method (300) and method (400) is performed by the probing platform (203), which derives the mapping defined in step 314 of FIG. 3.

[0137] Further, if the probing platform (203) is used, the method (300) includes the TCE querying the probing platform with NCGI, RAN-UE-NGAP-ID, AMF-UE-NGAP-ID, and a timestamp. The probing platform (203) performs a lookup using the correlation mapping from step 314 of FIG. 3 and returns the corresponding SUPI to the TCE (202). The TCE (202) then enriches the trace records by adding the SUPI.

[0138] Alternatively, the method (300) includes an operator-defined approach where the probing platform (203) directly pushes the mapping of the derived IDs from step 314 of FIG. 3 to the TCE (202) instead of waiting for a query from the TCE (202).

[0139] FIG. 5 illustrates another exemplary flow diagram of a method (500) for managing subscriber identity in trace records in the network (106) in accordance with an embodiment of the present disclosure. FIG. 5 is explained in conjunction with the FIGS. 3 and 4.

[0140] At step 502, the method (500) includes the Trace Collection Entity (TCE) (202) initiating a query to the Probing Platform (203) to retrieve the Subscription Permanent Identifier (SUPI) associated with specific trace record parameters. The query comprises the Next Generation Cell Global Identifier (NCGI), the Radio Access Network UE-NGAP Identifier (RAN-UE-NGAP-ID), the Access and Mobility Management Function UE-NGAP Identifier (AMF-UE-NGAP-ID), and the timestamp, wherein the identifiers are obtained from the trace records as described in FIG. 4.

[0141] At step 504, the method (500) involves the probing platform (203) receiving the query and checking its stored correlation mapping. The Probing Platform (203) utilizes the received NCGI, RAN-UE-NGAP-ID, AMF-UE-NGAP-ID, and timestamp to look up the corresponding SUPI based on the previously created correlation mapping in step 314 of FIG. 3 to identify the SUPI corresponding to the received identifiers.

[0142] At step 506, the method (500) concludes with the probing platform (203) returning the identified SUPI to the Trace Collection Entity (TCE) (202). The TCE (202) associates the received SUPI with the corresponding trace records to enrich the trace records with subscriber identity information.

[0143] FIG. 6 illustrates an exemplary process flow of a method (600) for associating subscriber identity with trace records in the network (106), in accordance with an embodiment of the present disclosure. FIG. 6 is described in conjunction with FIGS. 1, 2A-2C, 3, 4, and 5. In an embodiment, the method (600) is implemented by the processing unit (218) or the Trace Collection Entity (TCE) (202) of the system (108).

[0144] At step 602, the method (600) is initiated. The initiation may correspond to establishment of a communication session between the User Equipment (UE) (104) and the network (106), such as during a mobility registration procedure or a service request procedure.

[0145] At step 604, a registration request message is captured. In particular, the processing unit (218) or the TCE (202) captures a mobility registration request or a service request transmitted between the base station (204) and the Access and Mobility Management Function (AMF) (206) over the N2 interface, as described in FIG. 3. The registration request message comprises a temporary user identifier, such as a Globally Unique Temporary Identifier (GUTI), and a first set of network parameters including a Next Generation Cell Global Identifier (NCGI) and a Radio Access Network UE-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID).

[0146] At step 606, parameters are extracted from the registration request message. The processing unit (218) or the TCE (202) analyzes the captured message to extract the GUTI, the NCGI, and the RAN-UE-NGAP-ID. The extracted parameters are stored, optionally along with a timestamp, to ensure uniqueness across base stations (204) and to facilitate subsequent correlation operations, as described in FIG. 3.

[0147] At step 608, session management messages are monitored and captured. The processing unit (218) or the TCE (202) monitors signalling messages exchanged between the AMF (206) and the Session Management Function (SMF) (208) over the N11 interface. The captured messages include a session management request message comprising a permanent user identifier, such as a Subscription Permanent Identifier (SUPI), and a corresponding response message comprising one or more tunnel information parameters, including a User Plane Function (UPF) (210) N3 Internet Protocol (IP) address and a Tunnel Endpoint Identifier (TEID), as described in FIG. 3.

[0148] At step 610, a first mapping is established. The processing unit (218) or the TCE (202) establishes a mapping between the SUPI and the tunnel information parameters, including the UPF (210) N3 IP address and the TEID. This mapping enables correlation of the permanent user identifier with user-plane routing information and forms a basis for subsequent mapping operations.

[0149] At step 612, a context setup request message is captured. The processing unit (218) or the TCE (202) captures an initial context setup request transmitted between the AMF (206) and the base station (204) over the N2 interface. The context setup request message includes a second set of network parameters comprising an Access and Mobility Management Function UE-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the UPF (210) N3 IP address, and the TEID.

[0150] At step 614, a second mapping is created. The processing unit (218) or the TCE (202) creates a mapping between the temporary user identifier (GUTI) and the second set of network parameters extracted from the context setup request message. This mapping associates the temporary user identifier with control-plane identifiers and user-plane tunnel parameters corresponding to the same user session.

[0151] In an embodiment, a correlation mapping is generated. The processing unit (218) or the TCE (202) combines the first mapping and the second mapping to generate a correlation mapping comprising the SUPI, the GUTI, the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and the tunnel information parameters including the UPF (210) N3 IP address and the TEID. The correlation mapping provides a unified relationship between temporary and permanent identifiers across control-plane and user-plane signalling.

[0152] In an embodiment, trace records are received. The processing unit (218) or the TCE (202) receives one or more trace records from the base station (204) via a trace records streaming interface. Each trace record includes at least one of a Trace Reference (TR), a Trace Recording Session Reference (TRSR), the RAN-UE-NGAP-ID, or the AMF-UE-NGAP-ID, and at least one trace record includes UE context information.

[0153] In an embodiment, subscriber identity is associated with trace records. The processing unit (218) or the TCE (202) extracts identifiers including the NCGI, the RAN-UE-NGAP-ID, and the AMF-UE-NGAP-ID from the trace records and matches the extracted identifiers with the correlation mapping to determine the corresponding SUPI. The determined SUPI is then associated with the trace records to enrich the trace records with subscriber identity information.

[0154] In an embodiment, the method (600) may be performed in a distributed manner using the probing platform (203), as described in FIG. 2B and FIG. 5. In such an embodiment, the probing platform (203) monitors signalling messages, generates the correlation mapping, and stores the correlation mapping for subsequent retrieval.

[0155] In such an embodiment, the processing unit (218) or the TCE (202) extracts identifiers from the trace records and queries the probing platform (203) using the extracted identifiers, including the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and a timestamp, to retrieve the corresponding SUPI, as described in FIG. 5.

[0156] Upon receiving the SUPI from the probing platform (203), the processing unit (218) or the TCE (202) associates the SUPI with the corresponding trace records to enrich the trace records with subscriber identity information.

[0157] In an embodiment, the method (600) enables correlation of temporary and permanent identifiers across control-plane and user-plane signallingprocedures, thereby providing enhanced traceability, improved monitoring, and subscriber-level visibility within the network (106).

[0158] FIG. 7 illustrates a computer system (700) in which or with which the embodiments of the present disclosure may be implemented.

[0159] As shown in FIG. 7, the computer system (700) may include an external storage device (710), a bus (720), a main memory (730), a read-only memory (740), a mass storage device (750), communication port(s) (760), and a processor (770). A person skilled in the art will appreciate that the computer system may include more than one processor and communication ports. The processor (770) may include various modules associated with embodiments of the present disclosure. The communication port(s) (760) may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication port(s) (760) may be chosen depending on a network (106), such a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system connects.

[0160] The main memory (730) may be random access memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (740) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or Basic Input / Output System (BIOS) instructions for the processor (770). The mass storage device (750) may be any current or future mass storage solution which can be used to store information and / or instructions. Exemplary mass storage device (750) includes, but is not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces), one or more optical discs, Redundant Array of Independent Disks (RAID) storage, e.g., an array of disks.

[0161] The bus (720) communicatively couples the processor (770) with the other memory, storage, and communication blocks. The bus (720) may be, e.g., a Peripheral Component Interconnect / Peripheral Component Interconnect Extended bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (770) to the computer system.

[0162] Optionally, operator and administrative interfaces, e.g., a display, keyboard, joystick, and a cursor control device, may also be coupled to the bus (720) to support direct operator interaction with the computer system. Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) (760). The componentsdescribed above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system limit the scope of the present disclosure.

[0163] In an exemplary embodiment, a computer program product includes a non-transitory computer-readable medium including instructions that, when executed by one or more processors, cause the one or more processors to execute a method for associating subscriber identity with trace records in a wireless communication network is disclosed. The method includes capturing, by a Trace Collection Entity (TCE), a registration request message transmitted between a base station and a first network entity, the registration request message comprising a temporary user identifier and a first set of network parameters including a cell identifier and a radio access network user equipment identifier. The method includes extracting, by the TCE, session management messages transmitted between the first network entity and a second network entity, the session management messages comprising a permanent user identifier and one or more tunnel information parameters. The method includes establishing, by the TCE, a first mapping between the permanent user identifier and the one or more tunnel information parameters. The method includes extracting, by the TCE, a context setup request message transmitted between the first network entity and the base station, the context setup request message comprising a second set of network parameters including the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters. The method includes creating, by the TCE, a second mapping between the temporary user identifier and the second set of network parameters. The method includes generating, by the TCE, a correlation mapping comprising the permanent user identifier, the temporary user identifier, the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters based on the first mapping and the second mapping. The method includes receiving, by the TCE, one or more trace records from the base station and associating the permanent user identifier with the one or more trace records based on the correlation mapping.

[0164] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made, and many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be implemented merely as illustrative of the disclosure and not as a limitation.

[0165] The present disclosure provides a technical advancement in subscriber identity association for trace records in a wireless communication network by introducing a structured correlation mechanism that maps temporaryand permanent user identifiers across control-plane and user-plane signalling interfaces. Unlike conventional approaches where trace records lack direct association with permanent subscriber identity due to the use of temporary identifiers such as Globally Unique Temporary Identifier (GUTI), the present disclosure enables dynamic correlation of Subscription Permanent Identifier (SUPI) with trace records by leveraging signalling messages exchanged over N2 and Nil interfaces and tunnel information associated with an N3 interface. The present disclosure enables accurate reconstruction of subscriber identity by establishing multi-level mappings between identifiers including GUTI, SUPI, Next Generation Cell Global Identifier (NCGI), Radio Access Network UE-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID), Access and Mobility Management Function UE-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), and tunnel parameters. The present disclosure enhances traceability, improves network monitoring and diagnostics, reduces ambiguity in subscriber identification, and enables scalable and efficient analysis of trace data in fifth-generation (5G) and next-generation communication networks.ADVANTAGES OF THE PRESENT DISCLOSURE

[0166] The present disclosure, as described above, offers several significant technical advantages that enhance the functionality and efficiency of the network, including, but not limited to:• Enhancing traceability by establishing a comprehensive correlation mapping between subscriber identifiers and network parameters.• Minimizing latency in subscriber tracking by enabling real-time enrichment of trace records with SUPI and associated identifiers.• Optimizing network diagnostics by leveraging passive monitoring and automated correlation across multiple interfaces.• Improving UE session analysis by ensuring seamless integration of mobility and session management trace records.• Providing an algorithm that enriches the SUPI in trace records received from the 5G NR (gNB) without adding any overhead to the 5G Core Network's AMF or the 5G NR gNB, thereby offering a significant advantage over the conventional method.• Comparing the standard-based approach, in which the gNB initiates a trace session for a subscriber by sending a trigger to the AMF, the AMF then retrieves the SUPI for that session and notifies the TCE with the SUPI details, requiring development across multiple network elements, including the gNB, the AMF, and the TCE.• Ensuring that the proposed approach remains agnostic to the AMF and the gNB, thereby eliminating the need for any modifications or additional development in the AMF or the gNB.• Avoiding signalling overhead at the network elements, where the existing standard-based approach introduces extra transaction processing for both the AMF and the 5G NR node, as the gNB must trigger the AMF, and the AMF must retrieve the UE context to obtain the SUPI and report it to the TCE.• Overcoming the challenges by probing the N2 and Nil interfaces at the AMF and utilizing the proposed algorithm at the TCE to enrich the SUPI, thereby mitigating the SUPI mapping overhead at the AMF and the gNB while leveraging the TCE for this feature.• Maintaining continuous subscriber awareness beyond the initial registration phase and throughout the entire lifecycle of a subscriber's connection. • Enabling the retrieval of the GUTI-SUPI mapping even if the algorithm is activated after the GUTI was initially assigned, thereby ensuring that no loss of subscriber context occurs.• Ensuring vendor-agnostic compatibility by eliminating the requirement for any modifications at the 5G NR or the 5G Core Network, thus making the solution adaptable to any radio or core network vendor.• Expediting service delivery when integrating a new RAN vendor into the 5G network by streamlining the deployment process and minimizing integration complexities.• Addressing the challenges posed by the proprietary trace record designs and SUPI enrichment algorithms used by various RAN vendors for GUTI- related procedures, ensuring a standardized SUPI enrichment method across the entire network.• Eliminating the need for any vendor-specific modifications to the RAN for SUPI enrichment, thereby facilitating a seamless onboarding process and enhancing overall network agility.• Fully adhering to security guidelines by ensuring that plaintext IMSI is never exposed over the radio interface, thereby maintaining compliance with security protocols.

Claims

CLAIMSWe claim:

1. A method (600) for associating subscriber identity with trace records in a wireless communication network, the method (600) comprising:capturing (602), by a Trace Collection Entity (TCE) (202), a registration request message transmitted between a base station (204) and a first network entity (206), the registration request message comprising a temporary user identifier and a first set of network parameters including a cell identifier and a radio access network user equipment identifier;extracting (604), by the TCE (202), session management messages transmitted between the first network entity (206) and a second network entity (208), the session management message comprising a permanent user identifier and one or more tunnel information parameters;establishing (606), by the TCE (202), a first mapping between the permanent user identifier and the one or more tunnel information parameters;extracting (608), by the TCE (202), a context setup request message transmitted between the first network entity (206) and the base station (204), the context setup request message comprising a second set of network parameters including the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters;creating (610), by the TCE (202), a second mapping between the temporary user identifier and the second set of network parameters;generating (612), by the TCE (202), a correlation mapping comprising the permanent user identifier, the temporary user identifier, the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters based on the first mapping and the second mapping; andreceiving (614), by the TCE (202), one or more trace records from the base station (204) and associating the permanent user identifier with the one or more trace records based on the correlation mapping.

2. The method (600) as claimed in claim 1, wherein the temporary user identifier comprises a Globally Unique Temporary Identifier (GUTI) and the permanent user identifier comprises a Subscription Permanent Identifier (SUPI), wherein the registration request message corresponds to at least one of a mobility registration update request or a service request transmitted from a user equipment.

3. The method (600) as claimed in claim 1, wherein:the registration request message is transmitted over an N2 interface; the session management messages are transmitted over an Nil interface; andthe one or more tunnel information parameters comprise a User Plane Function (UPF) (210) network address and a Tunnel Endpoint Identifier (TEID) associated with a user-plane tunnel over an N3 interface.

4. The method (600) as claimed in claim 1, wherein extracting parameters from the registration request message comprises extracting the cell identifier, the radio access network user equipment identifier, and the temporary user identifier, storing the extracted parameters together with a timestamp for subsequent correlation, and wherein the correlation mapping further includes the timestamp.

5. The method (600) as claimed in claim 1, wherein the session management messages comprises an Update Session Management context request and a corresponding response exchanged between the first network entity (206) and the second network entity (208) over an Nil interface, the request including the permanent user identifier and the response including the one or more tunnel information parameters.

6. The method (600) as claimed in claim 1, wherein the context setup request message includes an initial context setup request transmitted over the N2 interface, the context setup request message further comprising a mobility management user equipment identifier associated with the first network entity (206).

7. The method (600) as claimed in claim 1, wherein the correlation mapping further includes one or more parameters comprising:the permanent user identifier;the temporary user identifier;the cell identifier;the radio access network user equipment identifier;the mobility management user equipment identifier;the one or more tunnel information parameters; andthe timestamp.

8. The method (600) as claimed in claim 1, wherein the one or more trace records received from the base station (204) include at least one of:a Trace Reference (TR);a Trace Recording Session Reference (TRSR);the radio access network user equipment identifier; orthe mobility management user equipment identifier,and wherein associating the permanent user identifier comprises extracting identifiers from the one or more trace records and matching the extracted identifiers with the correlation mapping.

9. The method (600) as claimed in claim 1, wherein the method (600) is performed by a probing platform (203) configured to monitor signalling messages on the N2 and Nil interfaces and generate the correlation mapping, and wherein the TCE (202) obtains the permanent user identifierfrom the probing platform (203) using one or more identifiers extracted from the trace records.

10. A system (108) for associating subscriber identity with trace records in a wireless communication network, the system (108) comprising:a Trace Collection Entity (TCE) (202) configured to:capture a registration request message transmitted between a base station (204) and a first network entity (206), the registration request message comprising a temporary user identifier and a first set of network parameters including a cell identifier and a radio access network user equipment identifier;extract session management messages transmitted between the first network entity (206) and a second network entity (208), the session management messages including a request message comprising a permanent user identifier and a response message comprising one or more tunnel information parameters; establish a first mapping between the permanent user identifier and the one or more tunnel information parameters;extract a context setup request message transmitted between the first network entity (206) and the base station (204), the context setup request message comprising a second set of network parameters including the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters;create a second mapping between the temporary user identifier and the second set of network parameters;generate a correlation mapping comprising the permanent user identifier, the temporary user identifier, the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters based on the first mapping and the second mapping; andreceive one or more trace records from the base station (204) and associating the permanent user identifier with the one or more trace records based on the correlation mapping.

11. The system (108) as claimed in claim 10, wherein the temporary user identifier comprises a Globally Unique Temporary Identifier (GUTI) and the permanent user identifier comprises a Subscription Permanent Identifier (SUPI), and wherein the registration request message corresponds to at least one of a mobility registration update request or a service request transmitted from a user equipment.

12. The system (108) as claimed in claim 10, wherein:the registration request message is transmitted over an N2 interface; the one or more session management messages are transmitted over an N11 interface; andthe one or more tunnel information parameters comprise a User Plane Function (UPF) (210) network address and a Tunnel Endpoint Identifier (TEID) associated with a user-plane tunnel over an N3 interface.

13. The system (108) as claimed in claim 10, wherein the TCE (202) is further configured to extract parameters from the registration request message including the cell identifier, the radio access network user equipment identifier, and the temporary user identifier, store the extracted parameters together with a timestamp for subsequent correlation, and include the timestamp in the correlation mapping.

14. The system (108) as claimed in claim 10, wherein the session management message comprises an Update Session Management context request and a corresponding response exchanged between the first network entity (206) and the second network entity (208) over the Nil interface, the request including the permanent user identifier and the response including the one or more tunnel information parameters.

15. The system (108) as claimed in claim 10, wherein the context setup request message includes an initial context setup request transmitted over the N2 interface, the context setup request message further comprising a mobility management user equipment identifier associated with the first network entity (206).

16. The system (108) as claimed in claim 10, wherein the correlation mapping further includes one or more parameters comprising:the permanent user identifier;the temporary user identifier;the cell identifier;the radio access network user equipment identifier;the mobility management user equipment identifier;the one or more tunnel information parameters; andthe timestamp.

17. The system (108) as claimed in claim 10, wherein the one or more trace records received from the base station (204) include at least one of:a Trace Reference (TR);a Trace Recording Session Reference (TRSR);the radio access network user equipment identifier; orthe mobility management user equipment identifier,and wherein the TCE (202) is further configured to extract identifiers from the one or more trace records and match the extracted identifiers with the correlation mapping to determine the permanent user identifier corresponding to the one or more trace records.

18. The system (108) as claimed in claim 10, wherein the system (108) further comprises a probing platform (203) configured to monitor signalling messages on the N2 and Nil interfaces and generate the correlation mapping, and wherein the TCE (202) obtains the permanent user identifierfrom the probing platform (203) using one or more identifiers extracted from the trace records.

19. A computer program product comprising a non-transitory computer- readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method (600) for associating subscriber identity with trace records in a wireless communication network, the method (600) comprising:capturing (602), by a Trace Collection Entity (TCE) (202), a registration request message transmitted between a base station (204) and a first network entity (206), the registration request message comprising a temporary user identifier and a first set of network parameters including a cell identifier and a radio access network user equipment identifier;extracting (604), by the TCE (202), session management messages transmitted between the first network entity (206) and a second network entity (208), the session management message comprising a permanent user identifier and one or more tunnel information parameters;establishing (606), by the TCE (202), a first mapping between the permanent user identifier and the one or more tunnel information parameters;extracting (608), by the TCE (202), a context setup request message transmitted between the first network entity (206) and the base station (204), the context setup request message comprising a second set of network parameters including the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters;creating (610), by the TCE (202), a second mapping between the temporary user identifier and the second set of network parameters;generating (612), by the TCE (202), a correlation mapping comprising the permanent user identifier, the temporary user identifier, the cell identifier, the radio access network user equipment identifier, and the one or more tunnel information parameters based on the first mapping and the second mapping; andreceiving (614), by the TCE (202), one or more trace records from the base station (204) and associating the permanent user identifier with the one or more trace records based on the correlation mapping.