WO2019080799A1 - 一种流量处理方法和用户面装置以及终端设备 - Google Patents

一种流量处理方法和用户面装置以及终端设备

Info

Publication number
WO2019080799A1
WO2019080799A1 PCT/CN2018/111222 CN2018111222W WO2019080799A1 WO 2019080799 A1 WO2019080799 A1 WO 2019080799A1 CN 2018111222 W CN2018111222 W CN 2018111222W WO 2019080799 A1 WO2019080799 A1 WO 2019080799A1
Authority
WO
WIPO (PCT)
Prior art keywords
network element
traffic
terminal device
user plane
data packet
Prior art date
Application number
PCT/CN2018/111222
Other languages
English (en)
French (fr)
Inventor
聂胜贤
辛阳
吴晓波
崇卫微
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP18869735.3A priority Critical patent/EP3691209B1/en
Publication of WO2019080799A1 publication Critical patent/WO2019080799A1/zh
Priority to US16/851,251 priority patent/US20200244557A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • H04L43/0823Errors, e.g. transmission errors
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2483Traffic characterised by specific attributes, e.g. priority or QoS involving identification of individual flows
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14Network analysis or design
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/10Active monitoring, e.g. heartbeat, ping or trace-route
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/32Flow control; Congestion control by discarding or delaying data units, e.g. packets or frames

Definitions

  • the embodiments of the present invention relate to the field of communications technologies, and in particular, to a traffic processing method, a user plane device, and a terminal device.
  • a mobile phone has a Wireless-Fidelity (Wi-Fi) hotspot, and other user devices (such as mobile phones, tablets, etc.) can pass the Wi-Fi. Hotspot access.
  • Wi-Fi Wireless-Fidelity
  • other user devices such as mobile phones, tablets, etc.
  • Wi-Fi hotspot access In this process, these users are not aware of whether the services they visit are implemented through the 3rd Generation Partnership Project (3GPP) network or the non-3GPP network. For them, Wi-Fi hotspots and ordinary Wireless Local Area Networks (WLANs) (that is, one of the non-3GPP access methods) are consistent.
  • 3GPP 3rd Generation Partnership Project
  • WLANs Wireless Local Area Networks
  • These users may open large-traffic services, such as online video, virtual reality (VR), and augmented reality. (Augmented Reality, AR) and other services.
  • AR Augmented Reality
  • the Wi-Fi hotspot opener may cause economic loss.
  • the prior art provides a solution for providing some parameter settings on the terminal side when the Wi-Fi hotspot is turned on. For example, the prior art provides the following solutions:
  • the hotspot opener can set parameters for the Wi-Fi hotspot through the above scheme, thereby controlling the consumption of traffic in an intuitive manner, and preventing economic loss caused by abnormal traffic consumption.
  • this method based on terminal parameter setting does not really solve the abnormal traffic problem.
  • the method of setting a password prevents the untrusted user equipment from being accessed
  • setting the maximum number of connections also prevents more user equipment from accessing.
  • the connected users can still use the large traffic service without prompting the hotspot opener; the traffic threshold can prevent the traffic from exceeding the threshold, but only after the large traffic has been consumed, the alarm will still be issued, which will still cause the economic loss of the opener.
  • the embodiment of the present application provides a traffic processing method, a user plane device, and a terminal device, which are used for accurately identifying abnormal traffic and improving traffic management effects.
  • the embodiment of the present application provides the following technical solutions:
  • the embodiment of the present application provides a traffic processing method, including: a user plane function network element receiving hotspot indication information sent by a terminal device, where the hot spot indication information includes a hotspot switch being opened; and the user plane function network element acquiring a feature parameter of the data packet, and the feature parameter of the first data packet is sent to the data analysis network element, where the first data packet is obtained by the user plane function network element during the hotspot switch of the terminal device The data obtained by the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the user plane function network element determines that the hotspot switch of the terminal device is opened by using the hot spot indication information sent by the terminal device, and the user plane function network element acquires the first data packet during the hotspot switch of the terminal device, and Sending the characteristic parameters of the first data packet to the data analysis network element.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the user plane function network element may determine whether the traffic corresponding to the first data packet acquired during the hotspot switch of the terminal device belongs to abnormal traffic, and thus may be Abnormal traffic is accurately identified to improve traffic management.
  • the method further includes: the user plane function network element
  • the terminal device sends a traffic abnormality notification, where the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic. Therefore, the terminal device can obtain the traffic abnormality notification, and the traffic abnormality notification can determine that the traffic corresponding to the first data packet belongs to the abnormal traffic, so that the terminal device can identify which data packets correspond to the abnormal traffic.
  • the user plane function network element sends a traffic abnormality notification to the terminal device, where the user plane function network element carries the traffic abnormality notification in a data packet.
  • the user plane function network element can send a traffic exception notification to the terminal device in the manner of a data packet.
  • the frame format of the specific data packet is not limited.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic, and includes: the user plane function network element from the data analysis network element Or the control plane network element receives the traffic abnormality notification. Therefore, the user plane function network element can determine which packets correspond to the abnormal traffic according to the traffic abnormality notification.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic, and the user plane function network element receives the data analysis network element. Or the type of service that the terminal device allows to use or disallow during use of the hotspot switch; the user plane function network element receives the data analysis network element or the first The service type of the data packet; the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic according to the service type that the terminal device allows or does not use during the hotspot switch.
  • the user plane function network element can use the service type that the terminal device allows or is not allowed to use during the opening of the hotspot switch, and matches the service category of the first data packet, and can identify the traffic corresponding to the first data packet by itself. Whether it is abnormal traffic.
  • the method further includes: the user plane function network element stops sending The data packet corresponding to the abnormal traffic, and buffering the data packet corresponding to the abnormal traffic.
  • the user plane function network element stops transmitting the data packet corresponding to the abnormal traffic, thereby reducing the traffic loss of the hotspot opener.
  • the method further includes: the user plane function network element receives a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic Abnormal; the user plane function network element discards, according to the traffic abnormality response, that the traffic corresponding to the first data packet belongs to abnormal traffic, and discards the data packet corresponding to the abnormal traffic buffered by the user plane function network element; or The user plane function network element determines, according to the traffic abnormality response, that the traffic corresponding to the first data packet does not belong to the abnormal traffic, and sends the abnormal traffic corresponding to the user plane function network element cache to the terminal device. Packet. When the traffic abnormality response determines that the traffic corresponding to the first data packet does not belong to the abnormal traffic, the user plane function network element sends the data packet corresponding to the cached abnormal traffic, so that the hotspot opener can provide traffic for the hotspot consumer.
  • the traffic abnormal response includes: abnormal traffic or no traffic Abnormal
  • the user plane function network element determines, according to the traffic abnormality response, that the
  • the method further includes: the user plane function network element receives a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic Abnormal; the user plane function network element sends the traffic abnormality response to the data analysis network element.
  • the data analysis network element can update the service type information that the terminal device is allowed to use when the Wi-Fi hotspot is turned on according to the abnormal traffic response, so that the online packet can be more accurately identified whether the data packet belongs to abnormal traffic.
  • the embodiment of the present application further provides a user plane device, including: a receiving module, configured to receive hotspot indication information sent by a terminal device, where the hotspot indication information includes a hotspot switch being opened, and an obtaining module, configured to acquire the first a characteristic parameter of the data packet, and sending the characteristic parameter of the first data packet to the data analysis network element, where the first data packet is data acquired by the user plane device during the hotspot switch of the terminal device And a determining module, configured to determine that the traffic corresponding to the first data packet belongs to an abnormal traffic.
  • a receiving module configured to receive hotspot indication information sent by a terminal device, where the hotspot indication information includes a hotspot switch being opened
  • an obtaining module configured to acquire the first a characteristic parameter of the data packet, and sending the characteristic parameter of the first data packet to the data analysis network element, where the first data packet is data acquired by the user plane device during the hotspot switch of the terminal device
  • a determining module configured to determine that the traffic corresponding to the first
  • the user plane device further includes: a sending module, wherein the sending module is configured to determine, by the determining module, that the traffic corresponding to the first data packet belongs to an abnormal traffic. Then, the traffic abnormality notification is sent to the terminal device, where the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the sending module is specifically configured to carry the traffic abnormality notification in a data packet.
  • the determining module is specifically configured to receive a traffic abnormality notification from the data analysis network element or the control plane network element.
  • the determining module includes: a receiving submodule, configured to receive the data analysis network element or the terminal device sent by the terminal device to allow use during a hotspot switch being opened Or the type of the service that is not allowed to be used; the service type of the first data packet sent by the data analysis network element or the terminal device; the abnormal traffic determination submodule, configured to be used according to the terminal device during the opening of the hotspot switch The traffic type corresponding to the first data packet is determined to be abnormal traffic.
  • the user plane device further includes: a traffic buffering module, configured to: after the determining module determines that the traffic corresponding to the first data packet belongs to abnormal traffic, stop sending the A packet corresponding to the abnormal traffic, and buffering the packet corresponding to the abnormal traffic.
  • a traffic buffering module configured to: after the determining module determines that the traffic corresponding to the first data packet belongs to abnormal traffic, stop sending the A packet corresponding to the abnormal traffic, and buffering the packet corresponding to the abnormal traffic.
  • the user plane device further includes: a traffic processing module, wherein the receiving module is further configured to receive a traffic abnormal response sent by the terminal device, and the traffic abnormal response
  • the traffic processing module is configured to: when the traffic corresponding to the first data packet belongs to abnormal traffic, discarding the abnormality of the cache of the user plane device according to the traffic abnormality response And transmitting, according to the traffic abnormality response, the data packet corresponding to the abnormal traffic buffered by the user plane device when the traffic corresponding to the first data packet does not belong to the abnormal traffic.
  • the user plane device further includes: a sending module, wherein the receiving module is further configured to receive a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes The traffic module is abnormal or has no traffic abnormality.
  • the sending module is configured to send the traffic abnormal response to the data analysis network element.
  • the component modules of the user plane device may also perform the steps described in the foregoing first aspect and various possible implementations, as described in the foregoing for the first aspect and various possible implementations. Description in the way.
  • the method for processing a traffic includes: the terminal device sends the hot spot indication information to the network element of the core network, where the hot spot indication information includes that the hotspot switch of the terminal device is opened; The traffic error notification sent by the core network element according to the hot spot indication information.
  • the terminal device needs to send the hot spot indication information to the core network element, so that the traffic abnormality notification can be received from the core network element, so that the terminal device can determine which data packets correspond to the abnormal traffic.
  • the method further includes: the terminal device transmitting, to the core network element, a service type that the terminal device is not allowed to use or allowed to use during the opening of the hotspot switch. Specifically, when the terminal device reports to the core network element, the first time the Wi-Fi hotspot information is sent to the core network element, the portable terminal is not allowed to be used during the Wi-Fi hotspot opening period. Business type or type of business allowed.
  • the method further includes: sending, by the terminal device, the core network element
  • the traffic abnormal response includes: the traffic is abnormal or there is no traffic abnormality.
  • the user can use the terminal device to determine whether there is a traffic abnormality to the core network element, so that the core network element can use the traffic abnormal response to perform subsequent traffic management.
  • the method further includes: the terminal device is configured to close according to the traffic abnormality notification.
  • the hotspot of the terminal device is closed; or the terminal device closes the connection of the hotspot user that generates the abnormal traffic; or the service type of the terminal device that prohibits the abnormal traffic from using the hotspot of the terminal device.
  • the core network element includes at least one of a control plane function network element, a user plane function network element, a policy network element, and a data analysis network element.
  • the embodiment of the present application further provides a traffic processing method, where the method includes: the data analysis network element acquires a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch; Receiving, by the network element, a feature parameter of the first data packet sent by the user plane function network element, where the first data packet is a data packet acquired by the user plane function network element during the opening of the hotspot switch of the terminal device; Determining, by the data analysis network element, a service type of the first data packet according to a characteristic parameter of the first data packet; the data analysis network element is configured according to a service type that is allowed or not allowed to be used by the terminal device during a hotspot switch being opened.
  • the data analysis network element may determine whether the traffic corresponding to the first data packet acquired during the hotspot switch of the terminal device belongs to abnormal traffic, and may be abnormal. Accurate identification of traffic to improve traffic management.
  • the method further includes: the data analysis network element to a control plane function network element or the user
  • the surface function network element sends a traffic abnormality notification, where the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the data analysis network element acquires a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch, and the data analysis network element determines the location according to the training data.
  • the service type of the terminal device that is allowed to be used or not allowed to be used during the opening of the hotspot switch; or the data analysis network element receives the service that the terminal device sends or prohibits to use during the opening of the hotspot switch Types of.
  • the method further includes: the data analysis network element receiving a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality;
  • the data analysis network element updates the service type that the terminal device allows or does not allow to use during the hotspot switch opening according to the traffic abnormality response.
  • the embodiment of the present application further provides a traffic processing method, where the method includes: the data analysis network element acquires a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch; The network element sends, to the user plane function network element or the control plane function network element, a service type that is allowed to be used by the terminal device during the opening of the hotspot switch; the data analysis network element receives the first data packet sent by the user plane function network element a characteristic parameter, the first data packet is data acquired by the user plane function network element during a hotspot switch of the terminal device; the data analysis network element is determined according to a characteristic parameter of the first data packet The service type of the first data packet; the data analysis network element sends the service type of the first data packet to the user plane function network element or the control plane function network element.
  • the data analysis network element acquires a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch, and the data analysis network element determines the location according to the training data.
  • the type of service that the terminal device allows or does not allow during the hotspot switch is turned on.
  • the embodiment of the present application provides a traffic processing method, where the method includes: a control plane function network element receives hot spot indication information sent by a terminal device, where the hot spot indication information includes a hotspot switch is turned on; The element receives the feature parameter of the first data packet sent by the user plane function network element, and sends the feature parameter of the first data packet to the data analysis network element, where the first data packet is the user plane function network element The data obtained during the hotspot switch of the terminal device is opened; the control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the control plane function network element may determine whether the traffic corresponding to the first data packet acquired during the hotspot switch of the terminal device belongs to abnormal traffic, so that the traffic may be Abnormal traffic is accurately identified to improve traffic management.
  • the method further includes: the control plane function network element is directed to the terminal The device sends a traffic abnormality notification, where the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the control plane function network element sends a traffic abnormality notification to the terminal device, where the control plane function network element carries the traffic abnormality notification in the control signaling.
  • the control signaling may use, but is not limited to, two kinds of process messages as exemplified below, one is a service request process initiated by the network side, and the Paging message carries a traffic abnormality notification to the UE, and the PDU Session initiated by the network side.
  • the Modification process sends a traffic exception notification to the UE through the PDU Session Modification Accept message.
  • control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic, and includes: the control plane function network element from the data analysis network element or the The user plane function network element receives the traffic exception notification.
  • the control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic, and includes: the control plane function network element receives the data analysis network element or the a service type that is sent by the terminal device to be used or not allowed to be used during the opening of the hotspot switch; the control plane function network element receives the first data sent by the data analysis network element or the terminal device
  • the service type of the packet is determined by the control device function network element according to the service type that the terminal device allows or does not allow during the hotspot switch to be opened, and determines that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic, and includes: the control plane function network element receives the a service type that the terminal device allows to use or not to use during the opening of the hotspot switch; the control plane function network element receives a service type of the first data packet sent by the data analysis network element or the terminal device; The control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic according to the service type that the terminal device allows or does not allow to use during the hotspot switch is turned on.
  • the method further includes: the control plane function network element notifying the user The surface function network element stops transmitting the traffic corresponding to the first data packet, and buffers the traffic corresponding to the first data packet.
  • the method further includes: the control plane function network element receiving a traffic abnormality response sent by the terminal device, where the traffic abnormality response includes: abnormal traffic or no traffic abnormality;
  • the control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic according to the traffic abnormality response, the control plane function network element notifies the user plane function network element to discard the cached abnormal traffic.
  • the control plane function network element determines, according to the traffic abnormality response, that the traffic corresponding to the first data packet does not belong to abnormal traffic.
  • the control plane function network element notifies the user plane function The network element forwards the buffer corresponding to the abnormal traffic.
  • the method further includes: the control plane function network element receiving a traffic abnormality response sent by the terminal device, where the traffic abnormality response includes: abnormal traffic or no traffic abnormality;
  • the control plane function network element forwards the traffic abnormality response to the data analysis network element.
  • the embodiment of the present application provides a communication device, where the communication device may include an entity such as a chip, the communication device includes: a processor and a memory; the memory is configured to store an instruction; and the processor is configured to execute the The instructions in the memory cause the communication device to perform the method of any of the first to sixth aspects described above.
  • a terminal device includes: a sending module, configured to send hotspot indication information to a core network element, where the hotspot indication information includes a hotspot switch being opened, and an obtaining module, configured to acquire the core network The network element sends an abnormality notification of the traffic according to the hot spot indication information.
  • the sending module is further configured to send, to the core network element, a service type that the terminal device does not allow or allow to use during the opening of the hotspot switch. Specifically, when the terminal device reports to the core network element, the first time the Wi-Fi hotspot information is sent to the core network element, the portable terminal is not allowed to be used during the Wi-Fi hotspot opening period. Business type or type of business allowed.
  • the sending module is further configured to: after the acquiring module acquires the traffic abnormality notification sent by the core network element according to the hot spot indication information, send the traffic abnormality to the core network element In response, the traffic abnormal response includes: abnormal traffic or no traffic abnormality.
  • the terminal device further includes: an exception processing module, configured to: after the obtaining module acquires the traffic abnormality notification sent by the core network element according to the hot spot indication information, according to the traffic The exception notification closes the hotspot; or, closes the connection of the hotspot user that generated the abnormal traffic; or, the service type that prohibits the abnormal traffic is used to use the hotspot.
  • an exception processing module configured to: after the obtaining module acquires the traffic abnormality notification sent by the core network element according to the hot spot indication information, according to the traffic The exception notification closes the hotspot; or, closes the connection of the hotspot user that generated the abnormal traffic; or, the service type that prohibits the abnormal traffic is used to use the hotspot.
  • the core network element includes at least one of a control plane function network element, a user plane function network element, a policy network element, and a data analysis network element.
  • the embodiment of the present application further provides a data analysis network element, where the data analysis network element includes: an obtaining module, configured to acquire a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch.
  • a receiving module configured to receive a feature parameter of the first data packet sent by the user plane function network element, where the first data packet is data acquired by the user plane function network element during the hotspot switch of the terminal device a service type determining module, configured to determine, according to a characteristic parameter of the first data packet, a service type of the first data packet, and an abnormal traffic determining module, configured to allow, according to the terminal device, the use of the hotspot switch or The service type that is not allowed to be used determines that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the data analysis network element further includes: a sending module, configured to: after the abnormal traffic determining module determines that the traffic corresponding to the first data packet belongs to abnormal traffic, to the control plane
  • the function network element or the user plane function network element sends a traffic abnormality notification, where the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the acquiring module is specifically configured to determine, according to the training data, a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch; or receive the sending by the terminal device The type of service that the terminal device allows or disallows during use of the hotspot switch.
  • the receiving module is further configured to receive a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality; the data analysis network And updating, according to the traffic abnormality response, a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch.
  • the embodiment of the present application further provides a data analysis network element, including: an obtaining module, configured to acquire a service type that is allowed or not allowed to be used by the terminal device during the opening of the wireless fidelity hotspot switch; and a sending module, configured to: Transmitting, to the user plane function network element or the control plane function network element, a service type that is allowed to be used by the terminal device during the opening of the hotspot switch; and receiving, by the receiving module, the feature parameter of the first data packet sent by the user plane function network element
  • the first data packet is data that is acquired by the user plane function network element during the hotspot switch of the terminal device;
  • the service type determining module is configured to determine, according to the feature parameter of the first data packet, The service type of the first data packet;
  • the sending module is further configured to send the service type of the first data packet to the user plane function network element or the control plane function network element.
  • the acquiring module is specifically configured to determine, according to the training data, a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch.
  • the embodiment of the present invention provides a control plane function network element, including: a receiving module, configured to receive hot spot indication information sent by a terminal device, where the hot spot indication information includes a hotspot switch is turned on; the receiving module further And a sending module, configured to send a feature parameter of the first data packet to the data analysis network element, where the first data packet is the user The data obtained by the surface function network element during the hotspot switch of the terminal device is opened; the abnormal traffic determination module is configured to determine that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the sending module is further configured to: after the abnormal traffic determining module determines that the traffic corresponding to the first data packet belongs to abnormal traffic, send a traffic abnormality notification to the terminal device.
  • the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the sending module is specifically configured to carry the traffic abnormality notification in the control signaling.
  • the control signaling may use, but is not limited to, two kinds of process messages as exemplified below, one is a service request process initiated by the network side, and the Paging message carries a traffic abnormality notification to the UE, and the PDU Session initiated by the network side.
  • the Modification process sends a traffic exception notification to the UE through the PDU Session Modification Accept message.
  • the abnormal traffic determining module is specifically configured to receive a traffic abnormality notification from the data analysis network element or the user plane function network element.
  • the abnormal traffic determining module is configured to receive the data analysis network element or the terminal device sent by the terminal device to allow or not use during the hotspot switch being turned on.
  • the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the abnormal traffic determining module is configured to receive, by the terminal device, a service type that is allowed to be used or not allowed by the terminal device during the opening of the hotspot switch; Determining, by the data analysis network element, a service type of the first data packet sent by the network element or the terminal device; determining, according to a service type that the terminal device allows or does not use during a hotspot switch, determining the first data packet The corresponding traffic belongs to abnormal traffic.
  • the sending module is further configured to: after the abnormal traffic notification module determines that the traffic corresponding to the first data packet belongs to abnormal traffic, notify the user plane function network element to stop And sending the traffic corresponding to the first data packet, and buffering the traffic corresponding to the first data packet.
  • the receiving module is further configured to receive a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: a traffic abnormality or no traffic abnormality; the sending module And when, according to the traffic abnormality response, determining that the traffic corresponding to the first data packet belongs to abnormal traffic, notifying the user plane function network element to discard the data packet corresponding to the buffered abnormal traffic; or, according to the traffic The abnormal response determines that the traffic corresponding to the first data packet does not belong to the abnormal traffic, and notifies the user plane function network element to forward the data packet corresponding to the cached abnormal traffic.
  • the receiving module is further configured to receive a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality;
  • the function network element forwards the traffic anomaly response to the data analysis network element.
  • the embodiment of the present application provides a terminal device, where the terminal device may include an entity such as a terminal chip, where the terminal device includes: a processor and a memory; the memory is used to store an instruction; and the processor is configured to execute The instructions in the memory cause the terminal device to perform the method of any of the preceding third aspects.
  • the embodiment of the present application provides a chip system, where the chip system includes a processor for supporting a network device to implement functions involved in the foregoing aspects, such as, for example, transmitting or processing data involved in the foregoing method. And / or information.
  • the chip system further includes a memory for storing necessary program instructions and data of the network device.
  • the chip system can be composed of chips, and can also include chips and other discrete devices.
  • a fourteenth aspect of the embodiments of the present application provides a computer readable storage medium having instructions stored therein that, when executed on a computer, cause the computer to perform the methods described in the above aspects.
  • a fifteenth aspect of the embodiments of the present application provides a computer program product comprising instructions which, when run on a computer, cause the computer to perform the methods described in the above aspects.
  • FIG. 1 is a schematic structural diagram of a 5G system according to an embodiment of the present disclosure
  • FIG. 2 is a schematic block diagram of a flow processing method according to an embodiment of the present application.
  • FIG. 3 is a schematic block diagram of another flow processing method according to an embodiment of the present disclosure.
  • FIG. 4 is a schematic block diagram of another flow processing method according to an embodiment of the present disclosure.
  • FIG. 5 is a schematic block diagram of another flow processing method according to an embodiment of the present disclosure.
  • FIG. 6 is a schematic block diagram of another flow processing method according to an embodiment of the present disclosure.
  • FIG. 7 is a schematic flowchart of interaction between multiple network elements in a scenario applied to a traffic processing method according to an embodiment of the present disclosure
  • FIG. 8 is a schematic diagram of an interaction process between multiple network elements in a scenario applied to a traffic processing method according to an embodiment of the present disclosure
  • FIG. 9 is a schematic flowchart of interaction between multiple network elements in a scenario applied by the traffic processing method according to the embodiment of the present disclosure.
  • FIG. 10-a is a schematic structural diagram of a user plane device according to an embodiment of the present application.
  • FIG. 10-b is a schematic structural diagram of another user plane device according to an embodiment of the present application.
  • FIG. 10-c is a schematic structural diagram of another user plane device according to an embodiment of the present disclosure.
  • FIG. 10-d is a schematic structural diagram of another user plane device according to an embodiment of the present application.
  • 11-a is a schematic structural diagram of a terminal device according to an embodiment of the present application.
  • 11-b is a schematic structural diagram of another terminal device according to an embodiment of the present application.
  • 12-a is a schematic structural diagram of a data plane analysis network element according to an embodiment of the present application.
  • 12-b is a schematic structural diagram of another data plane analysis network element according to an embodiment of the present application.
  • FIG. 13 is a schematic structural diagram of another data plane analysis network element according to an embodiment of the present application.
  • FIG. 14 is a schematic structural diagram of a control plane function network element according to an embodiment of the present disclosure.
  • FIG. 15 is a schematic structural diagram of a user plane device according to an embodiment of the present application.
  • FIG. 16 is a schematic structural diagram of another terminal device according to an embodiment of the present disclosure.
  • FIG. 17 is a schematic structural diagram of another data plane analysis network element according to an embodiment of the present application.
  • FIG. 18 is a schematic structural diagram of another control plane function network element according to an embodiment of the present disclosure.
  • "and/or” is merely an association relationship describing an associated object, indicating that there may be three relationships.
  • a and/or B may indicate that A exists separately, and A and B exist simultaneously, and B cases exist alone.
  • a plurality means two or more than two.
  • “/” may refer to a relationship between and/or.
  • the traffic processing method provided by the embodiment of the present application can be applied to a third generation mobile communication (3Generation, 3G) system, a fourth generation mobile communication (4Generation, 4G) system, and a fifth generation mobile communication (5th generation, 5G).
  • 3G third generation mobile communication
  • 4G fourth generation mobile communication
  • 5G fifth generation mobile communication
  • FIG. 1 is a schematic diagram of a system architecture of a 5G system applied to a traffic processing method according to an embodiment of the present application.
  • the 5G system architecture is divided into two parts: the access network and the core network.
  • the access network is used to implement functions related to wireless access, and the access network includes a Radio Accessing Network (RAN).
  • the core network can be divided into a user plane and a control plane.
  • the core network user plane includes a User Plane Function (UPF) network element;
  • the core network control plane includes a core network access and mobility management function (Access and Mobility Management). Function, AMF) network element, session management function (SMF) network element, policy control function (PCF) network element, network data analysis function (NetWork Data Analytics Function, NWDAF) network element.
  • AMF User Plane Function
  • SMF session management function
  • PCF policy control function
  • NWDAF Network Data Analysis Function
  • the user equipment User Equipment, UE
  • the data network may also be included in the 5G system.
  • UPF User Equipment
  • NWDAF NWDAF and the like, and is not illustrated one by one.
  • the AMF network element is mainly responsible for mobility management in the mobile network, such as user location update, user registration network, user switching, and the like.
  • the SMF network element is mainly responsible for session management in the mobile network.
  • the specific functions of the SMF network element may include: assigning an Internet Protocol (IP) address to the user, and selecting a UPF network element that provides a packet forwarding function.
  • IP Internet Protocol
  • the SMF manages the data transmission of the UPF, and is responsible for transmitting the information such as the feature vector, the traffic abnormality result, and the data type between the NWDAF and the UPF, and can complete the signaling interaction with the UE to obtain the hotspot state, for example, obtaining.
  • the alarm UE traffic is abnormal.
  • the RAN refers to a base station, and the UE accesses the network through the base station.
  • the UPF network element is responsible for performing traffic processing on user packets, such as forwarding and accounting. It is used to transmit data in the network, including service data that the hotspot user accesses the network through the hotspot opener and transmits.
  • the PCF network element is responsible for providing policies to the AMF network element and the SMF network element, such as a quality of service (QoS) policy and a slice selection policy.
  • the PCF network element is directly connected to the AMF, the SMF, and the NWDAF.
  • the PCF can determine the service processing policy according to the analysis result of the NWDAF. For example, the PCF determines whether the alarm is generated by the SMF or the UPF, and whether the alarm is implemented through the 3GPP network signaling or the data packet.
  • the terminal device includes but is not limited to: user equipment (UE), user unit, user station, mobile station, mobile station, remote station, remote terminal device, mobile terminal device, user terminal device, terminal device, and wireless communication device.
  • user agent user device, cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), with Wireless communication function handheld device, computing device, processing device connected to wireless modem, in-vehicle device, wearable device, terminal device device in the Internet of Things, home appliance, virtual reality device, terminal device device in future 5G network or future A terminal device device or the like in an evolved public land mobile network (PLMN).
  • PLMN evolved public land mobile network
  • the terminal device is used as an example for the UE.
  • the UE accesses the data network by establishing a Packet Data Unit (PDU) session between the UE to the RAN, the RAN to the UPF network element, and the UPF network element to the DN.
  • PDU Packet Data Unit
  • the UE1 refers to the user equipment 1 as a hotspot opener, for example, the UE1 acts as an opener of the Wi-Fi hotspot and connects to the base station through the wireless interface.
  • the UE1 is a Wi-Fi hotspot opener, and the UE2/3/4/5 is used as a hotspot user to access the hotspot of the UE1 through the WLAN, and the traffic generated by the network is used by the network.
  • Billing is included in the bill of UE1.
  • the NWDAF network element is configured to receive the data features in the network for training, obtain the data model, receive the data characteristics reported in the network in real time, obtain the service type of the current data according to the data model, and obtain the permitted or not allowed use of the hotspot.
  • the data service type set can be combined with the service type of the real-time data packet based on the data service type that is allowed or not allowed to be used, that is, the current data can be judged to be abnormal traffic.
  • the NWDAF network element can also send the information obtained by the analysis to other network elements (such as the PCF network element, the SMF network element, and the UPF network element) to indicate the operation of the PCF network element, the SMF network element, and the UPF network element.
  • control plane network element and the user plane network element are included.
  • the 4.5G for the control plane and the user plane is similar to the 5G system, and the 4.5G system is taken as an example, and the control plane of the PGW network element is used. Separated from the user plane, divided into PGW-C and PGW-U. For example, PGW-C can initiate bearer modification with bearer QoS update flow using control plane signaling.
  • the control plane and user plane of the SGW network element are separated into SGW-C and SGW-U.
  • the SGW-C can initiate the bearer modification with bearer QoS update procedure using control plane signaling.
  • the PGW-C corresponds to a data control plane function network element in the 5G system, such as an SMF network element
  • the PGW-U corresponds to a data user plane function network element in the 5G system, such as a UPF network element.
  • the control plane and the user plane are not separated in the 4G system architecture, and thus the functions of the control plane and the user plane may be implemented in the same network element, such as a Packet Data Network Gateway (PGW); Or the Mobility Management Entity (MME) corresponds to the control plane network element, and the Service Gateway (SGW) corresponds to the user plane network element.
  • PGW Packet Data Network Gateway
  • MME Mobility Management Entity
  • SGW Service Gateway
  • the PGW network element sets the control plane and the user plane, and the PGW network element can be used to manage the Wi-Fi hotspot traffic of the terminal device.
  • the PGW network element may use the control plane signaling or the user plane signaling to send a traffic abnormality notification to the terminal device.
  • the control signaling may be a packet data network (PDN) connection modification process or a bearer modification process, for example, a PGW.
  • the NE initiates the bearer modification with bearer QoS update process.
  • PDN packet data network
  • the Wi-Fi hotspot is specifically used as an example, and the parameter mode is set for the terminal device (the Wi-Fi hotspot opener) to limit other user devices (Wi-Fi hotspot users) to the Wi-Fi.
  • the use of hotspots solves the problem that the traffic cannot be detected in time through the data service during the use of the Wi-Fi hotspot.
  • the current hotspot status is notified to the network, and the network monitors the data service in the current state in real time through big data analysis.
  • the determination and alarm of abnormal hot traffic of the hotspot of the terminal device are implemented.
  • the method of the embodiment of the present application mainly includes the following process: for one UE, the NWDAF network element acquires a service type that is allowed or not allowed to be used during the hotspot of the UE, for example, acquiring a list of one or more service types.
  • the service type may be a type identifier (such as a type A service or a type B service).
  • the business type can also be an application identifier.
  • the application identifier may include an APP id or a flow id.
  • the service type list may be a list of applications (Application, APP) that the UE only uses when the WLAN is enabled.
  • the business type list may include at least one business type.
  • the UE reports the hotspot status (on/off) of the UE to the network, for example, the UE reports the information to the SMF network element, and the SMF network element reports the information to the UPF network element and/or NWDAF through the PC network element or the serviced interface.
  • Network element the NWDAF network element collects the characteristics of the data packets flowing through the UPF network element during the hotspot of the terminal device, and obtains a list of service types allowed by each UE during the hotspot opening period.
  • the NWDAF network element monitors the data packet characteristics flowing through the UPF network element in real time and obtains the data service type.
  • determining the abnormal traffic has the following two different implementation manners:
  • the NWDAF network element determines the abnormal traffic, and sends an abnormal traffic indication to the SMF network element and/or the UPF network element.
  • the determining condition may be that the service type corresponding to the data feature is not in the allowed service type list.
  • the SMF network element and the UPF network element can be used for the abnormal traffic behavior of the Wi-Fi hotspot. The operation is as follows: the SMF network element or the UPF network element notifies the UE of the hot spot abnormal traffic behavior, and the UE determines the next operation, and the current service continues.
  • the UPF network element obtains the detection information of the data packet (for example, the IP quintuple, the UE ID/IP, and the like), suspends the delivery and buffers the data packet corresponding to the detection information, and no longer charges, and the SMF network element or the UPF The network element notifies the UE of the hot spot abnormal traffic behavior. If the UE confirms that the SMF network element and the UPF network element are hotspot abnormal traffic, the UE is notified to discard all the data packets corresponding to the detection information (for example, the IP quintuple). Otherwise, the UPF The network element continues to forward the corresponding data packet.
  • the detection information of the data packet for example, the IP quintuple, the UE ID/IP, and the like
  • the NWDAF network element sends the analyzed data service type to the SMF network element and/or the UPF network element, and the SMF network element and the UPF network element are allowed/disallowed according to the hotspot open condition obtained from the UE or the NWDAF network element.
  • the service type list determines whether to initiate an alarm to the UE. For example, it may be determined whether to initiate an alarm to the UE according to the service type list used only in the WLAN ON condition.
  • a flow processing method provided by an embodiment of the present application may include:
  • the user plane function network element receives the hot spot indication information sent by the terminal device, where the hot spot indication information includes the hotspot switch being turned on.
  • the terminal device is an open party of a hotspot, such as an open party of a Wi-Fi hotspot.
  • the terminal device When the user turns on the hotspot switch, the terminal device generates the hot spot indication information, and the terminal device can send the hot spot indication information to the user plane function network element through the RAN, and the user plane function network element obtains the hot spot indication information, and determines that the hotspot switch of the terminal device is turned on.
  • the terminal device may report the PDU Session Establishment/PDU Session Modification/Registration/Service Request (Service Request) process to report the hotspot switch status to the user plane function network. yuan. Further, the terminal device may also report the service type (list) that the terminal device allows or disallows during the hotspot opening to the user plane function network element by using the initial PDU Session Establishment/PDU Session Modification/Registration/Service Request procedure.
  • Service Request PDU Session Establishment/PDU Session Modification/Registration/Service Request
  • the user plane function network element acquires the feature parameter of the first data packet, and sends the feature parameter of the first data packet to the data analysis network element, where the first data packet is a user plane function network element during the hotspot switch of the terminal device. Get the data.
  • the user plane function network element acquires data during the hotspot switch of the terminal device, wherein the data transmission of the user plane function network element can be divided into uplink transmission and downlink transmission.
  • the uplink transmission may be that the hotspot user sends the uplink data packet to the user plane function network element by using the hotspot provided by the hotspot opener, and the user plane function network element sends the uplink data packet to the data network.
  • the downlink transmission may be that the user plane function network element receives the downlink data packet from the data network, and the user plane function network element sends the downlink data packet to the hotspot opener through the RAN, and the hotspot opener sends the downlink data packet to the hotspot user through the hotspot.
  • the user plane function network element obtains the data packet during the hotspot switch of the terminal device, for example, the first data packet acquired by the user plane function network element during the hotspot opening of the terminal device, and the first data packet may be the uplink data.
  • the packet can also be a downlink transmission packet.
  • the user plane function network element can also obtain the feature parameters of the data packet, for example, the feature parameters of the first data packet can be obtained.
  • the feature parameter may include a parameter for indicating a service type of the data packet, such as an IP quintuple, a UE ID/IP, a packet length, a filter, a flow identifier, etc., or some characteristic parameters obtained according to the data packet. Wait.
  • the feature parameters may include one or more parameters, for example, the feature parameters may be embodied in the form of feature vectors.
  • the user plane function network element may obtain the feature parameters of the first data packet by means of feature engineering.
  • the user plane function network element may also send the feature parameters of the first data packet to the data analysis network element.
  • the data analysis network element may specifically be the NWDAF network element in the foregoing embodiment.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to the abnormal traffic.
  • the user plane function network element may determine that the traffic corresponding to the first data packet belongs to abnormal traffic, and may be implemented in multiple manners.
  • abnormal traffic in the embodiment of the present application includes data traffic that is not allowed by the terminal device in the current state, and may be abnormal for each user.
  • the service type A is normal traffic for the UE1.
  • it may be abnormal traffic for UE2.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic, including:
  • the user plane function network element receives the traffic abnormality notification from the data analysis network element or the control plane network element.
  • the user plane function network element may receive the traffic abnormality notification from the data analysis network element or the control plane network element, and the user plane function network element obtains the traffic abnormality notification, and the traffic abnormality notification may determine that the traffic corresponding to the first data packet belongs to Abnormal traffic.
  • the data analysis network element may use the feature parameter of the first data packet to identify the service type of the first data packet, and determine, by using the service type of the first data packet, whether the traffic corresponding to the first data packet belongs to abnormal traffic, and A traffic abnormality notification is generated when the traffic of the first data packet belongs to abnormal traffic.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic, including:
  • the user plane function network element receives the type of service that the data analysis network element or the terminal device sends or is not allowed to use during the opening of the hotspot switch;
  • the user plane function network element receives the service type of the first data packet sent by the data analysis network element;
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic according to the service type that the terminal device allows or does not allow during the hotspot switch.
  • the user plane function network element may obtain a service type that the terminal device is allowed to use during the opening of the hotspot switch, or the user plane function network element may obtain a service type that the terminal device does not allow during the hotspot switch.
  • the service type that is allowed or not allowed to be used may be sent by the data analysis network element to the user plane function network element, or sent by the terminal device to the user plane function network element.
  • the data analysis network element may use the feature parameter of the first data packet to identify the service type of the first data packet, and then send the service type of the first data packet to the user plane function network element.
  • the user plane function network element may determine whether the traffic corresponding to the first data packet belongs to abnormal traffic by using the service type obtained in the foregoing step.
  • the traffic processing method provided by the embodiment of the present application may further include the following steps:
  • the user plane function network element sends a traffic abnormality notification to the terminal device, and the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the user plane function network element may also generate the traffic abnormality notification when the traffic of the first data packet belongs to the abnormal traffic, and the user plane function.
  • the network element sends a traffic abnormality notification to the terminal device, and the terminal device can obtain the traffic abnormality notification, and the traffic abnormality notification can determine that the traffic corresponding to the first data packet belongs to the abnormal traffic.
  • the user plane function network element sends a traffic abnormality notification to the terminal device, including:
  • the user plane function network element carries the traffic exception notification in the data packet.
  • the user plane function network element may send a traffic abnormality notification to the terminal device by using a data packet, and the frame format of the specific data packet is not limited.
  • the user plane function network element sends a traffic abnormality notification to the control plane function network element, so that the traffic plane function network element can send a traffic abnormality notification to the terminal device, which may specifically be a signaling message (for example, a PDU Session Modification initiated by the network side).
  • the traffic message in the process the Paging message in the Service Request process initiated by the network side, carries the traffic exception notification.
  • the traffic processing method further includes the following steps:
  • the user plane function network element stops sending packets corresponding to abnormal traffic and buffers packets corresponding to abnormal traffic.
  • the user plane function network element may cache the received data packet according to some detection information corresponding to the first data packet, for example, according to the first
  • the IP quintuple corresponding to a data packet (for example, source IP address/port, destination IP address/port, and transmission protocol) buffers the data packet, wherein the traffic corresponding to one IP quintuple may include multiple data packets.
  • the user plane function network element stops sending the data packet corresponding to the abnormal traffic, thereby reducing the traffic loss of the Wi-Fi hotspot opener.
  • the traffic processing method provided by the embodiment of the present application may further perform the following steps:
  • the user plane function network element receives the abnormal traffic response sent by the terminal device, and the abnormal traffic response includes: abnormal traffic or no traffic abnormality;
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to the abnormal traffic according to the traffic abnormality response, the user plane function network element discards the data packet corresponding to the abnormal traffic of the user plane function network element cache;
  • the user plane function network element determines that the traffic corresponding to the first data packet does not belong to the abnormal traffic according to the traffic abnormality response, the user plane function network element sends the data packet corresponding to the abnormal traffic buffered by the user plane function network element to the terminal device.
  • the terminal device receives the traffic abnormality notification sent by the user plane function network element, and the terminal device may display the traffic abnormality notification to the user, and the user may respond to the traffic abnormality notification. For example, the user can identify whether the traffic is abnormal.
  • the user can send a traffic abnormal response to the user plane function network element through the terminal device.
  • the user plane function network element determines that the traffic corresponding to the first data packet belongs to the abnormal traffic according to the traffic abnormality response, the user plane function network element discards the data packet corresponding to the cached abnormal traffic, thereby reducing the traffic of the Wi-Fi hotspot opener. loss.
  • the user plane function network element When the traffic abnormality response determines that the traffic corresponding to the first data packet does not belong to the abnormal traffic, the user plane function network element sends the data packet corresponding to the cached abnormal traffic, so that the Wi-Fi hotspot opener can be the Wi-Fi hotspot consumer. Provide traffic.
  • the traffic processing method provided by the embodiment of the present application may further perform the following steps:
  • the user plane function network element receives the abnormal traffic response sent by the terminal device, and the abnormal traffic response includes: abnormal traffic or no traffic abnormality;
  • the user plane function network element sends a traffic exception response to the data analysis network element.
  • the terminal device receives the traffic abnormality notification sent by the user plane function network element, and the terminal device may display the traffic abnormality notification to the user, and the user may respond to the traffic abnormality notification. For example, the user can identify whether the traffic is abnormal.
  • the user can send a traffic abnormal response to the user plane function network element through the terminal device.
  • the user plane function network element may also send a traffic abnormality response to the data analysis network element, and the data analysis network element may determine whether there is a traffic abnormality according to the traffic abnormality response.
  • the data analysis network element can update the service type information that the terminal device is allowed to use when the Wi-Fi hotspot is turned on according to the abnormal traffic response, so that the online packet can be more accurately identified whether the data packet belongs to abnormal traffic.
  • the foregoing embodiment describes the traffic processing method provided by the embodiment of the present application from the perspective of the user plane function network element, and then describes the traffic processing method provided by the embodiment of the present application from the terminal device side.
  • the implementation of the present application is implemented.
  • the flow processing method provided by the example may include:
  • the terminal device sends the hot spot indication information to the core network element, where the hot spot indication information includes the hotspot switch of the terminal device.
  • the terminal device is a hotspot opener.
  • the terminal device may be a Wi-Fi hotspot opener.
  • the terminal device When the user turns on the hotspot switch, the terminal device generates hotspot indication information, and the terminal device may perform the RAN to the user plane function.
  • the network element sends hotspot indication information.
  • the traffic processing method provided by the embodiment of the present application may further include the following steps:
  • the terminal device sends to the core network element a service type that the terminal device is not allowed to use or allowed to use during the opening of the hotspot switch.
  • the service type that is not allowed or allowed to be used during the Wi-Fi hotspot is also used as the content in the hotspot indication information, so that the hotspot indication information sent by the terminal device to the core network element includes not only the notification that the hotspot switch is turned on, but also The type of service type that is not allowed or allowed to be used during the Wi-Fi hotspot is turned on.
  • the core network element may include one of a control plane function network element, a user plane function network element, a policy network element, and a data analysis network element.
  • the 4G system is used as an example.
  • the control plane function network element and the user plane function network element may be a PGW network element.
  • the 5G system is used as an example.
  • the control plane function network element may be an SMF network element and a user plane function network element.
  • the data may be a UPF network element
  • the data analysis network element may be the foregoing NWDAF network element.
  • the terminal device acquires a traffic abnormality notification sent by the core network element according to the hot spot indication information.
  • the core network element may determine that the traffic corresponding to the first data packet belongs to abnormal traffic, and then the core network element may send a traffic abnormality notification to the terminal device, where the traffic abnormality notification is used to notify the first data packet.
  • the corresponding traffic belongs to abnormal traffic.
  • the traffic processing method provided by the embodiment of the present application may further include the following steps:
  • the terminal device sends a traffic abnormal response to the core network element.
  • the abnormal traffic response includes: abnormal traffic or no traffic abnormality.
  • the terminal device receives the traffic abnormality notification sent by the user plane function network element, and the terminal device may display the traffic abnormality notification to the user, and the user may respond to the traffic abnormality notification. For example, the user can identify whether the traffic is abnormal.
  • the user can send a traffic abnormal response to the core network element through the terminal device.
  • the network element of the core network can determine whether there is a traffic abnormality according to the abnormal traffic response, and the core network element can update the service type allowed by the terminal device when the Wi-Fi hotspot is enabled according to the abnormal traffic response, so that the online service can be detected during online detection. More accurately identify whether it is abnormal traffic.
  • the traffic processing method provided by the embodiment of the present application may further include the following steps:
  • the terminal device turns off the hotspot of the terminal device according to the traffic abnormality notification.
  • the terminal device closes the connection of the hotspot user that generates abnormal traffic; or,
  • the terminal device prohibits the service type that generates abnormal traffic from using the hotspot of the terminal device.
  • the processing after the terminal device receives the traffic abnormality information in the embodiment of the present application is not limited. For example, after the abnormal traffic is determined, the Wi-Fi hotspot is turned off, or a Wi-Fi hotspot user is determined to close the user's connection, or a certain service type is temporarily disabled.
  • the specific implementation manner is not limited herein.
  • the foregoing description of the traffic management method provided by the embodiment of the present application shows that the terminal device sends the hot spot indication information to the core network element, and the terminal device obtains the traffic abnormality notification sent by the core network element according to the hot spot indication information, so that the terminal device can The traffic abnormality notification determines which traffic corresponding to the data packet belongs to abnormal traffic.
  • the foregoing embodiment describes the traffic processing method provided by the embodiment of the present application from the perspective of the terminal device, and then describes the traffic processing method provided by the embodiment of the present application from the data analysis network element side.
  • the embodiment of the present application The provided traffic processing method may include:
  • the data analysis network element acquires a service type that the terminal device allows or does not allow to use during the hotspot switch is turned on.
  • the data analysis network element may be specifically the foregoing NWDAF network element, and the data analysis network element first obtains the service type that the terminal device is allowed to use during the opening of the hotspot switch, or the data analysis network element acquires the terminal device in the hotspot switch.
  • the type of business that is not allowed during opening can obtain the service type by means of big data analysis, and the data analysis network element can also obtain the service type through the terminal device.
  • the step 401 data analysis network element obtains a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch, including:
  • the data analysis network element determines, according to the training data, a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch; or
  • the data analysis network element receives the service type that the terminal device sends or is not allowed to use during the hotspot switch being turned on by the terminal device.
  • the data analysis network element obtains the service type that the terminal device allows or disallows during the hotspot switch to be opened, and may include the following two implementation manners: the UE sends the allowed or disallowed service type list to the data analysis network element, or the data.
  • the network element is analyzed for machine learning training to obtain a business type recognition model.
  • the training data used in machine learning may include two types of data, one is application data from an operator platform, or an OTT (Over The Top) server, or a vertical industry control center, including the size of the data packet, the start and end time.
  • IP quintuple, service type, and network data from the network side including UE identity, terminal type, access point name (APN), data network name (Data Network Name) , DNN), base station side radio channel quality, cell ID (Cell ID) and other information.
  • the data analysis network element can obtain the service type identification model based on the two types of information, and can classify the data packets of the UE flowing through the UPF network element, thereby obtaining the service type allowed by the UE during the Wi-Fi hotspot opening of the UE.
  • the data analysis network element receives the feature parameter of the first data packet sent by the user plane function network element, where the first data packet is a data packet acquired by the user plane function network element during the hotspot switch of the terminal device.
  • the feature parameter includes a parameter for indicating a service type of the data packet.
  • the feature parameter can be a feature vector.
  • the user plane function network element may obtain the feature parameters of the first data packet by means of feature engineering.
  • the user plane function network element may also send the feature parameter of the first data packet to the data analysis network element.
  • the user plane function network element sends the feature parameter of the first data packet to the SMF network element, and the SMF network element will be the first.
  • the characteristic parameters of the data packet are sent to the PCF network element, and the PCF network element sends the characteristic parameter of the first data packet to the NWDAF network element, and the NWDAF network element can receive the characteristic parameter of the first data packet sent by the user plane function network element.
  • the data analysis network element determines, according to the feature parameter of the first data packet, a service type of the first data packet.
  • the data analysis network element can determine the service type of the first data packet by using the service type identification model. For example, the data analysis network element can obtain the feature list of the service type identification model through feature learning, and then train the service. The model parameters of the type identification model are calculated by the feature parameters of the first data packet and the service recognition model, so that the service type of the first data packet can be determined.
  • the data analysis network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic according to the service type that the terminal device allows or does not allow during the hotspot switch.
  • the data analysis network element may determine, by using step 403, the service type of the first data packet, and the service type of the first data packet and the terminal device obtained in step 401 are allowed to be used during the opening of the hotspot switch or The types of services that are not allowed to be matched are matched, so that the traffic corresponding to the first data packet is determined to be abnormal traffic.
  • the data analysis network element obtains the service type that the terminal device is allowed to use during the opening of the hotspot switch. If the service type of the first data packet does not belong to the allowed service type, the corresponding data packet may be determined. Traffic is abnormal traffic.
  • the data analysis network element obtains the service type that the terminal device is not allowed to use during the opening of the hotspot switch. If the service type of the first data packet belongs to the service type that is not allowed to be used, the first data packet may be determined. The traffic is abnormal traffic.
  • the traffic processing method provided by the embodiment of the present application may further include the following steps:
  • the data analysis network element sends a traffic abnormality notification to the control plane function network element or the user plane function network element, and the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the data analysis network element may determine that the traffic corresponding to the first data packet belongs to abnormal traffic, and then the data analysis network element may send a traffic abnormality notification to the control plane function network element or the user plane function network element. After the control plane function network element or the user plane function network element receives the traffic abnormality notification, the control plane function network element or the user plane function network element sends the traffic abnormality notification, and may also forward the traffic abnormality notification to the terminal device, as described in the foregoing embodiment. An example of the terminal device side.
  • the traffic processing method provided by the embodiment of the present application may further include the following steps:
  • the data analysis network element receives the abnormal traffic response sent by the terminal device, and the abnormal traffic response includes: abnormal traffic or no traffic abnormality;
  • the data analysis network element updates the type of service that the terminal device is allowed to use or disallow during the hotspot switch being turned on according to the traffic abnormality response.
  • the terminal device receives the traffic abnormality notification sent by the user plane function network element, and the terminal device can display the traffic abnormality notification to the user, and the user can respond to the traffic abnormality notification, for example, the user can identify whether the traffic is abnormal, and the user can pass
  • the terminal device sends a traffic abnormal response to the user plane function network element, and the user plane function network element can also send a traffic abnormal response to the data analysis network element, and the data analysis network element can determine whether the traffic abnormality exists according to the traffic abnormality response, and the data analysis network element
  • the traffic type allowed during the hotspot switch is updated according to the traffic abnormality response, so that the data packet can be more accurately identified as abnormal traffic.
  • the description of the traffic management method provided by the embodiment of the present application is as follows.
  • the data analysis network element obtains the service type that the terminal device allows or does not allow to use during the hotspot switch, and the data analysis network element receives the user plane function network element to send.
  • the characteristic parameter of the first data packet, the first data packet is a data packet acquired by the user plane function network element during the hotspot switch of the terminal device, and the data analysis network element determines the first data packet according to the characteristic parameter of the first data packet.
  • the service type of the data analysis network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic according to the service type that the terminal device allows or does not allow during the hotspot switch.
  • the data analysis network element can obtain the service type of the first data packet from the user plane function network element, and the first data can be determined by the terminal device allowing the service type to be used or not allowed during the hotspot switch opening period.
  • the traffic corresponding to the packet belongs to abnormal traffic, which can accurately identify abnormal traffic and improve traffic management.
  • the foregoing embodiment describes a traffic processing method provided by the embodiment of the present application from the perspective of the data analysis network element.
  • another traffic processing method provided by the embodiment of the present application is described from the data analysis network element side, as shown in FIG. 5 .
  • the traffic processing method in the embodiment of the present application may include:
  • the data analysis network element obtains a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch.
  • the data analysis network element may be specifically the foregoing NWDAF network element, and the data analysis network element first obtains the service type that the terminal device is allowed to use during the opening of the hotspot switch, or the data analysis network element acquires the terminal device in the hotspot switch.
  • the type of business that is not allowed during opening can obtain the service type by means of feature engineering, and the data analysis network element can also obtain the service type through the terminal device.
  • the step 501 data analysis network element obtains a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch, including:
  • the data analysis network element determines, according to the training data, the type of service that the terminal device is allowed to use or not allowed to use during the opening of the hotspot switch.
  • the data analysis network element sends, to the user plane function network element or the control plane function network element, a service type that is allowed to be used by the terminal device during the opening of the hotspot switch.
  • the data analysis network element may send the service type that the terminal device allows during the hotspot switch to be sent to the user plane function network element or the control plane function network element, so that the user plane function network element or the control plane function network
  • the element can determine the type of service that the terminal device is allowed to use during the hotspot switch is turned on.
  • the data analysis network element receives the feature parameter of the first data packet sent by the user plane function network element, where the first data packet is data acquired by the user plane function network element during the hotspot switch of the terminal device.
  • the feature parameter is a parameter for indicating a service type of the data packet.
  • the feature parameter may be a feature vector
  • the user plane function network element may specifically calculate the first data packet by using feature engineering.
  • the feature parameter, the user plane function network element may also send the feature parameter of the first data packet to the data analysis network element, for example, the user plane function network element sends the feature parameter of the first data packet to the SMF network element, and the SMF network element will
  • the characteristic parameter of the first data packet is sent to the PCF network element, and the PCF network element sends the characteristic parameter of the first data packet to the NWDAF network element, and the NWDAF network element can receive the feature of the first data packet sent by the user plane function network element. parameter.
  • the data analysis network element determines a service type of the first data packet according to a feature parameter of the first data packet.
  • the data analysis network element can determine the service type of the first data packet by using the service type identification model. For example, the data analysis network element can obtain the feature list of the service type identification model through feature learning, and then train the service. The model parameters of the type identification model are calculated by the feature parameters of the first data packet and the service recognition model, so that the service type of the first data packet can be determined.
  • the data analysis network element sends the service type of the first data packet to the user plane function network element or the control plane function network element.
  • the data analysis network element after the data analysis network element determines the service type of the first data packet, the data analysis network element sends the service type of the first data packet to the user plane function network element or the control plane function network element, so that the user The function network element or the control plane function network element can be matched according to the service type of the first data packet and the service type allowed by the terminal device during the opening of the hotspot switch, so that the user plane function network element or the control plane function network element can Determine whether the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the data analysis network element in the embodiment of the present application can be used for determining the service type of the first data packet, but the data analysis network element does not judge the traffic abnormality, but the user plane function network element or the control plane function network element can Determine whether the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the foregoing embodiment describes a traffic processing method provided by the embodiment of the present application from the perspective of the data analysis network element.
  • a traffic processing method provided by the embodiment of the present application is described from the control plane function network element side.
  • the method for processing a traffic may include:
  • the control plane function network element receives the hot spot indication information sent by the terminal device, and the hot spot indication information includes the hotspot switch being turned on.
  • the control plane function network element may be an SMF network element in a 5G system.
  • the terminal device is the opener of the Wi-Fi hotspot.
  • the terminal device When the user turns on the hotspot switch, the terminal device generates the hot spot indication information, and the terminal device can send the hot spot indication information to the user plane function network element through the RAN, and the user plane function network element to the control plane function.
  • the network element forwards the hot spot indication information, and the control plane function network element parses the hot spot indication information to determine that the hotspot switch of the terminal device is turned on.
  • the control plane function network element receives the feature parameter of the first data packet sent by the user plane function network element, and sends the feature parameter of the first data packet to the data analysis network element, where the first data packet is a user plane function network element.
  • the data acquired during the hotspot switch of the terminal device is turned on.
  • the user plane function network element transmits data during the opening of the hotspot switch of the terminal device, wherein the data transmission of the user plane function network element can be divided into uplink transmission and downlink transmission.
  • the user plane function network element can also acquire the characteristic parameter of the data packet, for example, the feature parameter of the first data packet can be obtained.
  • the user plane function network element sends the feature parameter of the first data packet to the control plane function network element, and the control plane function network element can forward the feature parameter of the first data packet to the data analysis network element.
  • the control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the control plane function network element determines that the traffic corresponding to the first data packet belongs to the abnormal traffic.
  • the control plane function network element may determine that the traffic corresponding to the first data packet belongs to an abnormal traffic, and may be implemented in multiple manners.
  • the traffic processing method provided by the embodiment of the present application further includes:
  • the control plane function network element sends a traffic abnormality notification to the terminal device, and the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the control plane function network element may send a traffic abnormality notification to the terminal device, and the terminal device may parse the traffic abnormality notification, and the traffic abnormality notification may determine that the traffic corresponding to the first data packet belongs to the abnormal traffic.
  • control plane function network element sends a traffic abnormality notification to the terminal device, including:
  • the control plane function network element carries the traffic abnormality notification in the control signaling.
  • the control plane function network element may send a traffic abnormality notification to the terminal device by using a control signaling manner, and the specific message of the control signaling is not limited.
  • the step 603 controls the surface function network element to determine that the traffic corresponding to the first data packet belongs to abnormal traffic, including:
  • the control plane function network element receives the traffic abnormality notification from the data analysis network element or the user plane function network element.
  • the control plane function network element may receive the traffic abnormality notification from the data analysis network element or the user plane network element, and the control plane function network element parses the traffic abnormality notification, and the traffic abnormality notification may determine that the traffic corresponding to the first data packet belongs to Abnormal traffic.
  • the data analysis network element may use the feature parameter of the first data packet to identify the service type of the first data packet, and determine, by using the service type of the first data packet, whether the traffic corresponding to the first data packet belongs to abnormal traffic, and A traffic abnormality notification is generated when the traffic of the first data packet belongs to abnormal traffic.
  • the step 603 controls the surface function network element to determine that the traffic corresponding to the first data packet belongs to abnormal traffic, including:
  • the control plane function network element receives the type of service that the data analysis network element or the terminal device sends or is not allowed to use during the opening of the hotspot switch;
  • the control plane function network element receives the service type of the first data packet sent by the data analysis network element;
  • the control plane function network element determines that the traffic corresponding to the first data packet belongs to abnormal traffic according to the service type that the terminal device allows or does not allow during the hotspot switch opening period.
  • the control plane function network element can obtain the service type that the terminal device is allowed to use during the opening of the hotspot switch, or the control plane function network element can obtain the service that the terminal device is not allowed to use during the opening of the hotspot switch.
  • the service type may be sent by the data analysis network element to the control plane function network element, or sent by the terminal device to the control plane function network element.
  • the data analysis network element may use the feature parameter of the first data packet to identify the service type of the first data packet, and then send the service type of the first data packet to the control plane function network element.
  • the control plane function network element may determine whether the traffic corresponding to the first data packet belongs to abnormal traffic by using the service type obtained in the foregoing step.
  • the traffic processing method provided by the embodiment of the present application further includes:
  • the control plane function network element notifies the user plane function network element to stop sending the traffic corresponding to the first data packet, and buffers the traffic corresponding to the first data packet.
  • the control plane function network element After the control plane function network element determines that the traffic corresponding to the first data packet belongs to the abnormal traffic, the control plane function network element notifies the user that the surface function network element can be cached according to the data packet of the IP quintuple corresponding to the first data packet. Processing, wherein the traffic corresponding to one IP quintuple may include multiple data packets, and the user plane function network element stops sending the data packet corresponding to the abnormal traffic, thereby reducing the traffic loss of the Wi-Fi hotspot opener.
  • the traffic processing method provided by the embodiment of the present application further includes:
  • the control plane function network element receives the abnormal traffic response sent by the terminal device, and the abnormal traffic response includes: abnormal traffic or no traffic abnormality;
  • control plane function network element determines that the traffic corresponding to the first data packet belongs to the abnormal traffic according to the traffic abnormality response, the control plane function network element notifies the user plane function network element to discard the data packet corresponding to the cached abnormal traffic; or
  • the control plane function network element determines, according to the traffic abnormality response, that the traffic corresponding to the first data packet does not belong to the abnormal traffic, and the control plane function network element notifies the user function network element to forward the buffer corresponding to the abnormal traffic.
  • the terminal device receives the traffic abnormality notification sent by the user plane function network element, and the terminal device can display the traffic abnormality notification to the user, and the user can respond to the traffic abnormality notification, for example, the user can identify whether the traffic is abnormal, and the user can pass
  • the terminal device sends a traffic abnormality response to the control plane function network element, and the control plane function network element determines, according to the traffic abnormality response, that the traffic corresponding to the first data packet belongs to abnormal traffic, and the control plane function network element notifies the user plane function network element to discard the cached
  • the data packet corresponding to the abnormal traffic can reduce the traffic loss of the Wi-Fi hotspot opener.
  • the control plane function network element When the traffic abnormality response determines that the traffic corresponding to the first data packet does not belong to the abnormal traffic, the control plane function network element notifies the user function network element to send the data packet corresponding to the cached abnormal traffic, so that the Wi-Fi hotspot opener can be Wi-Fi hotspot consumers provide traffic.
  • the traffic processing method provided by the embodiment of the present application further includes:
  • the control plane function network element receives the abnormal traffic response sent by the terminal device, and the abnormal traffic response includes: abnormal traffic or no traffic abnormality;
  • the control plane function network element forwards the traffic anomaly response to the data analysis network element.
  • the terminal device receives the traffic abnormality notification sent by the control plane function network element, and the terminal device can display the traffic abnormality notification to the control, and the control can respond to the traffic abnormality notification, for example, the control can identify whether the traffic is abnormal, and the control can pass
  • the terminal device sends a traffic abnormal response to the control plane function network element, and the control plane function network element can also send a traffic abnormal response to the data analysis network element, and the data analysis network element can determine whether the traffic abnormality exists according to the traffic abnormality response, and the data analysis network element
  • the traffic type allowed during the hotspot switch is updated according to the traffic abnormality response, so that the service type to which the data packet belongs can be more accurately identified, and an accurate service type is provided for the analysis of the abnormal traffic.
  • the control plane function network element can obtain the service type of the first data packet from the user plane function network element, and the terminal device is in the hotspot.
  • the service type that is allowed or not allowed during the switch opening period it can be determined that the traffic corresponding to the first data packet belongs to abnormal traffic, thereby accurately identifying abnormal traffic and improving traffic management effects.
  • FIG. 7 it is a flow diagram of an interactive UE Hotspot Off on/off state between multiple network elements in a 5G system.
  • the interaction process is described by using a UE-initiated PDU Session Establishment/Modification process as an example.
  • the process may also be a service request/Registration process initiated by the UE, and is not described here. It mainly includes the following steps:
  • the UE sends a session management request message to the SMF network element.
  • the UE acts as a Wi-Fi hotspot opener, and the UE reports the UE Hotspot Off on/off state or other specific mode on/off status to the network.
  • the UE will also not be in the UE Hotspot Off during the period.
  • the service type that is allowed to be used is reported to the network.
  • the hotspot is enabled as an example.
  • the hotspot status information is notified to the SMF network element in the session establishment/modification process, and may be carried in the PDU session establishment/modification request by the RAN-AMF-SMF, and the message names of the segments are different. But all are to establish or modify the session.
  • the SMF network element sends a session management request message to the UPF network element.
  • the SMF notifies the UPF network element of the hotspot status information, and can be carried in the N4 session establishment/modification request.
  • both the SMF network element and the UPF network element obtain the current hot spot status information of the UE.
  • the UPF network element reports the data feature of the data packet of the UE in the hotspot enabling device to the NWDAF network element.
  • the NWDAF network element is used as the network element for abnormal data traffic determination.
  • the NWDAF network element collects data characteristics as training data for the service data packet in the Hotspot opening time, such as: UE ID/IP, time/cycle, packet size/ Quantity, extension field.
  • the NWDAF network element obtains a list of service types allowed or not allowed during the hotspot of the UE by using big data analysis.
  • the NWDAF network element performs big data analysis for each UE, assuming the behavior or model of the service type discrimination, learns the feature list of the service type discriminant model, and synchronizes the feature list corresponding to the model to the features of the NWDAF network element and the UPF network element.
  • a list of features in the feature vector can be understood as a parameter name.
  • the feature vector reported by the UPF network element to the NWDAF network element is a parameter value.
  • a list of service types allowed (or not allowed) by the UE in a specific state (hotspot on state) is obtained by training the NWDAF network element.
  • the UPF network element determines that the current hotspot of the UE is enabled, collects real-time data packets, and calculates a feature vector corresponding to the service type classification model.
  • the UPF network element receives a new data packet when the Hotspot is turned on, and calculates a feature vector according to the local feature engineering.
  • the UPF network element sends an abnormal traffic detection request to the NWDAF network element.
  • the UPF network element reports the calculated feature vector to the NWDAF network element through the SMF network element and the PCF network element, and requests the NWDAF network element to discriminate the data service type.
  • the NWDAF network element obtains a service type according to the feature vector, determines whether the service corresponding to the data packet is a service type list, and if not, determines the Wi-Fi hotspot abnormal traffic.
  • the NWDAF network element obtains the service type of the current data according to the feature vector, and compares with the service type list trained in the foregoing step, and determines whether the service data flow corresponding to the current data packet belongs to abnormal traffic.
  • the NWDAF network element sends a Wi-Fi hotspot abnormal traffic indication to the UPF network element.
  • the abnormal traffic indication is forwarded to the SMF network element and the UPF network element by the PCF network element.
  • the PCF network element may, according to the analysis result of the NWDAF network element, combine the UE status and the abnormal traffic indication of the NWDAF network element, and determine to send an indication to the SMF network element or the UPF network element to the UE, for example, the policy requirement in the PCF network element is for Wi.
  • the abnormal traffic indication information in the on state of the Fi hotspot is notified to the UE by means of control signaling, and then the PCF network element may instruct the SMF network element to perform according to the mode A; or execute according to the mode B.
  • the PCF network element may instruct the SMF network element to perform according to the mode A; or execute according to the mode B.
  • an achievable way A includes:
  • the SMF learns from the NWDAF that during the hotspot on, there is an abnormal traffic behavior of the Wi-Fi hotspot, and the UE is determined to be alerted.
  • the SMF network element After receiving the abnormal traffic indication sent by the NWDAF network element, the SMF network element determines that the current UE has a suspected data packet abnormality and alerts the UE. The SMF network element sends an alarm to the UE, carrying an abnormal traffic indication.
  • An achievable way B includes:
  • the SMF learns from the NWDAF that during the hotspot on, there is an abnormal traffic behavior of the Wi-Fi hotspot, and the UE is determined to be alerted.
  • the UPF network element After receiving the abnormal traffic indication sent by the NWDAF network element, the UPF network element learns that the current UE has a suspected data packet abnormality and alerts the UE. The UPF network element sends an alarm to the UE, carrying an abnormal traffic indication.
  • the UPF network element may send a specific abnormal traffic indication data packet, and the abnormality traffic indication information is carried in the data packet header, for example, the abnormal traffic indication field is included in the packet, or an exception is added to the extension field other than the standard field. Traffic indication information.
  • the UE can obtain abnormal traffic indication information from the packet header.
  • the packet can be a packet that is independent of the current service data, or a data packet that is in the current service.
  • the processing in the embodiment of the present application is not limited to the process after the UE receives the abnormal traffic indication information, and may determine that the Wi-Fi hotspot is abnormally closed, determine that a Wi-Fi hotspot user closes the connection of the user, and temporarily disable a service. Type, etc.
  • the NWDAF network element can monitor the service status of the Wi-Fi hotspot opener in real time, analyze the data feature to obtain the service type of the data, and obtain a list of allowed/disallowed service types according to the current state of the training. It is determined whether the current service is abnormal traffic, and the determination result of the NWDAF network element is sent to the data forwarding control network element and the data forwarding network element, and they decide to initiate an abnormal traffic indication to the UE, and the UE determines the subsequent operation.
  • the embodiment of the present application is free from the artificial setting method or the method of adding network analysis and indication based on the existing artificial setting.
  • the data analysis network element in the network obtains the service type by analyzing the data service, and gives a judgment, that is, the current status, with the list of allowed/disallowed service types in the state obtained by the training.
  • the data of the service type is abnormal traffic, and is sent to the network processing related network element (for example, the SMF network element and the UPF network element) in the network, and then the data processing related network element sends an abnormal traffic indication to the UE.
  • the network processing related network element for example, the SMF network element and the UPF network element
  • the following describes the interaction process between multiple network elements in another 5G system provided by the embodiment of the present application, which mainly includes the following processes:
  • the UE sends a session management request message to the SMF network element.
  • the SMF network element sends a session management request message to the UPF network element.
  • the UPF network element reports the data feature of the data packet of the UE in the hotspot open device to the NWDAF network element.
  • the NWDAF network element obtains a list of service types allowed or not allowed during the hotspot of the UE by using big data analysis. 805.
  • the UPF network element determines that the current hotspot of the UE is enabled, collects real-time data packets, and calculates a feature vector corresponding to the service type classification model.
  • the UPF network element sends an abnormal traffic detection request to the NWDAF network element.
  • the NWDAF network element obtains a service type according to the feature vector, determines whether the service corresponding to the service packet is a service type list, and if not, determines the Wi-Fi hotspot abnormal traffic.
  • the NWDAF network element sends a Wi-Fi hotspot abnormal traffic indication to the UPF network element.
  • the steps 801 to 808 are the same as the steps 701 to 708 in the NWDAF related processing flow in the embodiment shown in FIG. 7 .
  • step 808 there may be two implementation manners of the following manners A and B.
  • Mode A The manner of controlling signaling includes steps 809 to 814.
  • the UPF network element pauses to deliver and caches the data packet.
  • the UPF network element sends a Wi-Fi-hotspot abnormality indication to the SMF network element.
  • the SMF network element pauses to deliver and cache the data packet.
  • the SMF network element sends a Wi-Fi hotspot abnormal traffic indication to the UE.
  • the UE indicates, to the SMF network element, whether it is abnormal traffic.
  • the SMF network element sends a Wi-Fi hotspot abnormality confirmation message to the UPF network element.
  • the UPF network element After receiving the abnormal traffic indication information sent by the NWDAF network element, the UPF network element, in addition to determining to send an alarm to the UE, also includes suspending the delivery and buffering the current service data. In this embodiment, the UPF network element needs to perform certain control on the service data after receiving the abnormal traffic indication information sent by the NWDAF network element, and the UPF network element pauses and caches the service data. If the UPF network element determines whether to initiate an alarm, the UPF network element also needs to instruct the SMF network element to send abnormal traffic indication information to the UE.
  • the SMF network element sends an alarm to the UE after receiving the abnormal traffic indication information sent by the NWDAF network element, and the UPF network element pauses and caches the data after receiving the abnormal traffic indication information of the NWDAF network element.
  • the UE feeds back the abnormal traffic confirmation information through the signaling message, and the result is yes/no.
  • Mode B The manner of the data packet includes the following steps 815 to 818.
  • the UPF learns from the NWDAF that the hotspot is turned on, there is an abnormal traffic behavior of the Wi-Fi hotspot, the UPF pauses the delivery, and buffers the data packet of the service, and determines to alert the UE.
  • the UPF network element sends a Wi-Fi hotspot abnormal traffic indication to the UE.
  • the UE sends an abnormal traffic to the UPF network element.
  • the UPF network element sends abnormal traffic to the SMF network element.
  • the UPF network element After receiving the abnormal traffic indication information sent by the NWDAF network element, the UPF network element, in addition to determining to send an alarm to the UE, also includes suspending the delivery and buffering the current service data. The UE feeds back abnormal traffic confirmation information by means of data packets, and the result is yes/no. The UPF network element needs to report the acknowledgement information to the SMF network element.
  • the UPF network element determines that the current data packet is abnormal according to the feedback result of the UE, and sends the buffered data packet.
  • the UPF network element judges from the feedback result of the UE that the current data packet is abnormal, and discards all the data packets corresponding to the IP quintuple.
  • the UPF network element discards the cached service data.
  • the SMF network element sends an abnormal traffic to the NWDAF network element.
  • the NWDAF network element performs abnormal traffic discriminant correction and updates the allowed service list.
  • the UPF network element/SMF network element After the UPF network element/SMF network element receives the feedback from the UE, the UPF network element/SMF network element sends a feedback to the NWDAF network element through the reporting mode, that is, the current service type is not abnormal traffic for the current UE, and is used to correct the NWDAF.
  • the condition for determining the abnormal traffic of the network element the most direct way, adding the service type to the type list allowed during the hotspot opening period; or adding the feature and classification result of the service to the algorithm for determining the service type, as the training data update Feature list.
  • the embodiment adds the processing of the data packet after the abnormal traffic indication information of the NWDAF network element is received by the UPF network element, and can simultaneously check the abnormal traffic judgment of the NWDAF network element and The UE confirms the abnormal traffic indication to avoid the problem caused by the inaccurate judgment of the abnormal traffic of the NWDAF network element. And according to the feedback of the confirmation information of the UE, the NWDAF network element updates and corrects the service type discrimination model or the list of service types allowed/disallowed in the state.
  • the SMF network element/UPF network element not only determines the current data service abnormality according to the indication information of the NWDAF network element, but also sends the abnormal indication to the NWDAF network element.
  • the indication information is sent, and the confirmation message of the UE is used as the final result.
  • the UPF network element After the UPF network element receives the abnormality indication of the NWDAF network element and does not receive the acknowledgment information of the UE, the UPF network element pauses the processing and buffers the service data, and after receiving the acknowledgment information, decides to continue forwarding or Discard this business data.
  • the SMF/UPF reports the confirmation information of the UE to the NWDAF network element to correct the abnormal traffic determination and update the service list.
  • the interaction process between multiple network elements in another 5G system mainly includes the following steps:
  • the UE sends, to the SMF network element, a service type list that is supported under the condition that the Wi-Fi hotspot is enabled.
  • the SMF network element sends a list of service types running under the condition that the Wi-Fi hotspot is enabled to the UPF network element.
  • the UE sends the hotspot status, the list of service types that are allowed or not allowed to run in the state, for example, only the service type list that is running under the WLAN on condition, or the service type list that is not supported under the WLAN enable condition. Send to the network.
  • the list of allowed business types is optional. If the SMF network element determines whether the traffic is abnormal, the service type list information is not sent to the UPF network element. If the UPF network element determines whether it is abnormal traffic, the service type list needs to be sent to the UPF network element. Status and list are not required to be sent in the same message. The status and the list can be sent in the session modification process when the user opens the hotspot, but the allowed service list in the hotspot open state can be sent to the network as the capability of the UE in the session creation process.
  • the UPF network element determines that the current hotspot of the UE is enabled, collects real-time data packets, and calculates a feature vector corresponding to the service type classification model. The UPF network element reports the feature vector of the data to the NWDAF network element.
  • the UPF network element sends a service type request to the NWDAF network element.
  • the NWDAF network element obtains a service type according to the feature vector.
  • the NWDAF network element analyzes the service type of the data according to the feature vector reported by the UPF network element.
  • the NWDAF network element sends a service type response to the UPF network element.
  • the NWDAF network element sends the analysis result to the SMF network element or the UPF network element.
  • the UPF network element learns, from the NWDAF network element, the service type of the real-time data packet during the hotspot on-time, and determines that the service type is not in the service type list that is running under the condition that the Wi-Fi hotspot is enabled, and determines the alarm UE.
  • the UE is notified of the abnormal traffic flow by means of the control signaling, which is the same as the mode A in the embodiment shown in FIG.
  • the data packet is used to notify the UE that there is abnormal traffic, which is the same as that in the embodiment shown in FIG. 8.
  • the network element related to the data processing of the network side is configured to know the allowed/disallowed service type list in a specific state (the Wi-Fi hotspot open state, etc.), and implements the service for analyzing the current data through the NWDAF network element.
  • the type is fed back to the network element related to the data processing, so that the current service data can be determined as abnormal traffic, and an abnormal traffic indication is sent to the UE, and the UE can perform further processing.
  • the UE sends a list of service types allowed in the Wi-Fi hotspot open state to the network (for example, an SMF network element/UPF network element) in advance, and receives the NWDAF network. After the service type information of the current data obtained by the meta-analysis, it can be determined whether the current data service is abnormal traffic in the SMF or the UPF, and if yes, an alarm is sent to the UE.
  • the network for example, an SMF network element/UPF network element
  • a user plane device 1000 provided by an embodiment of the present application may include: a receiving module 1001, an obtaining module 1002, and a determining module 1003, where
  • the receiving module 1001 is configured to receive the hot spot indication information sent by the terminal device, where the hot spot indication information includes the hotspot switch being turned on;
  • the obtaining module 1002 is configured to obtain a feature parameter of the first data packet, and send the feature parameter of the first data packet to the data analysis network element, where the first data packet is acquired by the user plane device during the opening of the hotspot switch of the terminal device. data;
  • the determining module 1003 is configured to determine that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the user plane device 1000 further includes: a sending module 1004, where
  • the sending module 1004 is configured to: after determining that the traffic corresponding to the first data packet belongs to the abnormal traffic, the module 1003 sends a traffic abnormality notification to the terminal device, where the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to the abnormal traffic.
  • the sending module 1003 is specifically configured to carry a traffic abnormality notification in the data packet.
  • the determining module 1003 is specifically configured to receive a traffic abnormality notification from a data analysis network element or a control plane network element.
  • the determining module 1003 includes:
  • the receiving sub-module 10031 is configured to receive, by the data analysis network element or the terminal device, a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch; and receive a service type of the first data packet sent by the data analysis network element;
  • the abnormal traffic determining sub-module 10032 is configured to determine that the traffic corresponding to the first data packet belongs to abnormal traffic according to the service type that the terminal device allows or does not allow to use during the hotspot switch opening.
  • the user plane device 1000 further includes: a traffic buffer module 1005, configured to determine that the module 1003 stops sending after the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the packet corresponding to the abnormal traffic, and the packet corresponding to the abnormal traffic is cached.
  • the user plane device 1000 further includes: a traffic processing module 1006, where
  • the receiving module 1001 is further configured to receive a traffic abnormality response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality;
  • the traffic processing module 1006 is configured to: when determining that the traffic corresponding to the first data packet belongs to the abnormal traffic according to the traffic abnormality response, discard the data packet corresponding to the abnormal traffic buffered by the user plane device; or determine the first data packet according to the traffic abnormal response. When the corresponding traffic does not belong to abnormal traffic, the packet corresponding to the abnormal traffic buffered by the user plane device is transmitted.
  • the user plane device further includes: a sending module 1004, where
  • the receiving module 1001 is further configured to receive a traffic abnormality response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality;
  • the sending module 1003 is further configured to send a traffic abnormal response to the data analysis network element.
  • a terminal device 1100 includes: a sending module 1101, configured to send hotspot indication information to a core network element, where the hotspot indication information includes a hotspot switch being opened; and the obtaining module 1102 And configured to obtain a traffic abnormality notification sent by the core network element according to the hot spot indication information.
  • the sending module 1101 is further configured to send, to the core network element, a service type that the terminal device does not allow or allow to use during the opening of the hotspot switch. Specifically, when the terminal device reports to the core network element, the first time the Wi-Fi hotspot information is sent to the core network element, the portable terminal is not allowed to be used during the Wi-Fi hotspot opening period. Business type or type of business allowed.
  • the sending module 1101 is further configured to: after the acquiring module 1102 acquires the traffic abnormality notification sent by the core network element according to the hot spot indication information, to the core network element A traffic abnormal response is sent, and the traffic abnormal response includes: abnormal traffic or no traffic abnormality.
  • the terminal device 1100 further includes: an exception processing module 1103, configured to acquire, by the obtaining module 1102, the core network element according to a hot spot indication. After the traffic abnormality notification of the information is sent, the hotspot is turned off according to the traffic abnormality notification; or the connection of the hotspot user that generates the abnormal traffic is closed; or the service type using the hotspot is prohibited from using the hotspot.
  • an exception processing module 1103 configured to acquire, by the obtaining module 1102, the core network element according to a hot spot indication. After the traffic abnormality notification of the information is sent, the hotspot is turned off according to the traffic abnormality notification; or the connection of the hotspot user that generates the abnormal traffic is closed; or the service type using the hotspot is prohibited from using the hotspot.
  • the core network element includes at least one of a control plane function network element, a user plane function network element, a policy network element, and a data analysis network element.
  • the foregoing description of the traffic management method provided by the embodiment of the present application shows that the terminal device sends the hot spot indication information to the core network element, and the terminal device obtains the traffic abnormality notification sent by the core network element according to the hot spot indication information, so that the terminal device can The traffic abnormality notification determines which traffic corresponding to the data packet belongs to abnormal traffic.
  • the embodiment of the present application further provides a data analysis network element 1200, where the data analysis network element 1200 includes:
  • the obtaining module 1201 is configured to acquire a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch;
  • the receiving module 1202 is configured to receive a feature parameter of the first data packet sent by the user plane function network element, where the first data packet is data acquired by the user plane function network element during the hotspot switch of the terminal device package;
  • the service type determining module 1203 is configured to determine, according to the feature parameter of the first data packet, a service type of the first data packet;
  • the abnormal traffic determining module 1204 is configured to determine that the traffic corresponding to the first data packet belongs to an abnormal traffic according to a service type that is allowed or not allowed to be used by the terminal device during the opening of the hotspot switch.
  • the data analysis network element 1200 further includes: a sending module 1203, configured to determine, by the abnormal traffic determining module 1202, the first data packet. After the corresponding traffic belongs to the abnormal traffic, the traffic abnormality notification is sent to the control plane function network element or the user plane function network element, and the traffic abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the acquiring module 1201 is specifically configured to determine, according to the training data, a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch; or, receive the terminal device.
  • the receiving module 1202 is further configured to receive a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality;
  • the analyzing network element updates the service type that the terminal device allows or does not allow to use during the hotspot switch opening according to the traffic abnormality response.
  • the embodiment of the present application further provides a data analysis network element 1300, including:
  • the obtaining module 1301 is configured to acquire a service type that the terminal device allows or does not allow to use during the opening of the wireless fidelity hotspot switch;
  • the sending module 1302 is configured to send, to the user plane function network element or the control plane function network element, a service type that is allowed to be used by the terminal device during the opening of the hotspot switch;
  • the receiving module 1303 is configured to receive a feature parameter of the first data packet sent by the user plane function network element, where the first data packet is acquired by the user plane function network element during the hotspot switch of the terminal device The data;
  • a service type determining module 1304, configured to determine, according to a feature parameter of the first data packet, a service type of the first data packet;
  • the sending module 1302 is further configured to send the service type of the first data packet to the user plane function network element or the control plane function network element.
  • the obtaining module 1301 is specifically configured to determine, according to the training data, a service type that the terminal device allows or does not allow to use during the opening of the hotspot switch.
  • the data analysis network element in the embodiment of the present application can obtain the service type of the first data packet from the user plane function network element, and the terminal device is in the hot spot.
  • the service type that is allowed or not allowed during the switch opening period it can be determined that the traffic corresponding to the first data packet belongs to abnormal traffic, thereby accurately identifying abnormal traffic and improving traffic management effects.
  • control plane function network element 1400 including:
  • the receiving module 1401 is configured to receive the hot spot indication information sent by the terminal device, where the hot spot indication information includes the hotspot switch of the terminal device is turned on;
  • the receiving module 1401 is further configured to receive a feature parameter of the first data packet sent by the user plane function network element;
  • the sending module 1402 is configured to send the feature parameter of the first data packet to the data analysis network element, where the first data packet is acquired by the user plane function network element during the hotspot switch of the terminal device data;
  • the abnormal traffic determining module 1403 is configured to determine that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the sending module 1402 is further configured to: after the abnormal traffic determining module 1403 determines that the traffic corresponding to the first data packet belongs to abnormal traffic, send the traffic to the terminal device.
  • the abnormality notification is used to notify that the traffic corresponding to the first data packet belongs to abnormal traffic.
  • the sending module 1402 is specifically configured to carry the traffic abnormality notification in the control signaling.
  • the control signaling may use, but is not limited to, two kinds of process messages as exemplified below, one is a service request process initiated by the network side, and the Paging message carries a traffic abnormality notification to the UE, and the PDU Session initiated by the network side.
  • the Modification process sends a traffic exception notification to the UE through the PDU Session Modification Accept message.
  • the abnormal traffic determining module 1403 is specifically configured to receive a traffic abnormality notification from the data analysis network element or the user plane function network element.
  • the abnormal traffic determining module 1403 is specifically configured to receive the data analysis network element or the terminal device sent by the terminal device to allow or not allow the hotspot switch to be opened during the opening of the hotspot switch. a type of service used; receiving a service type of the first data packet sent by the data analysis network element or the terminal device; determining, according to a service type that the terminal device is allowed to use or not allowed during the opening of the hotspot switch, The traffic corresponding to the first data packet belongs to abnormal traffic.
  • the abnormal traffic determining module 1403 is specifically configured to receive a service type that is sent by the terminal device to be allowed or not allowed to be used during the opening of the hotspot switch; Receiving, by the data analysis network element or the service type of the first data packet sent by the terminal device, determining the first data according to a service type that the terminal device allows or does not allow to use during a hotspot switch opening period; The traffic corresponding to the packet belongs to abnormal traffic.
  • the sending module 1402 is further configured to notify the user plane function network element after the abnormal traffic notification module determines that the traffic corresponding to the first data packet belongs to abnormal traffic. Stop sending the traffic corresponding to the first data packet, and buffer the traffic corresponding to the first data packet.
  • the receiving module 1401 is further configured to receive a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality;
  • the module is further configured to notify the user plane function network element to discard the data packet corresponding to the cached abnormal traffic when determining that the traffic corresponding to the first data packet belongs to the abnormal traffic according to the traffic abnormality response; or
  • the traffic abnormality response determines that the traffic corresponding to the first data packet does not belong to the abnormal traffic, and notifies the user plane function network element to forward the data packet corresponding to the cached abnormal traffic.
  • the receiving module 1401 is further configured to receive a traffic abnormal response sent by the terminal device, where the traffic abnormal response includes: abnormal traffic or no traffic abnormality;
  • the surface function network element forwards the traffic abnormal response to the data analysis network element.
  • control plane function network element can obtain the service type of the first data packet from the user plane function network element, and the terminal device is obtained through the terminal device.
  • the type of service that is allowed or not allowed to be used during the opening of the hotspot switch, it can be determined that the traffic corresponding to the first data packet belongs to abnormal traffic, thereby accurately identifying the abnormal traffic and improving the traffic management effect.
  • the embodiment of the present application further provides a computer storage medium, wherein the computer storage medium stores a program, and the program executes some or all of the steps described in the foregoing method embodiments.
  • the user plane device 1500 includes:
  • the receiver 1501, the transmitter 1502, the processor 1503, and the memory 1504 (wherein the number of the processors 1503 in the user plane device 1500 may be one or more, and one processor in FIG. 15 is taken as an example).
  • the receiver 1501, the transmitter 1502, the processor 1503, and the memory 1504 may be connected by a bus or other manner, wherein the bus connection is taken as an example in FIG.
  • the memory 1504 can include read only memory and random access memory and provides instructions and data to the processor 1503. A portion of the memory 1504 may also include a non-volatile random access memory (English name: Non-Volatile Random Access Memory, English abbreviation: NVRAM).
  • the memory 1504 stores operating systems and operational instructions, executable modules or data structures, or a subset thereof, or an extended set thereof, wherein the operational instructions can include various operational instructions for implementing various operations.
  • the operating system can include a variety of system programs for implementing various basic services and handling hardware-based tasks.
  • the processor 1503 controls the operation of the user plane device.
  • the processor 1503 may also be referred to as a central processing unit (English name: Central Processing Unit, English abbreviation: CPU).
  • CPU Central Processing Unit
  • the components of the user plane device are coupled together by a bus system.
  • the bus system may include a power bus, a control bus, and a status signal bus in addition to the data bus.
  • various buses are referred to as bus systems in FIG.
  • the method disclosed in the foregoing embodiment of the present application may be applied to the processor 1503 or implemented by the processor 1503.
  • the processor 1503 can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the foregoing method may be completed by an integrated logic circuit of hardware in the processor 1503 or an instruction in a form of software.
  • the processor 1503 may be a general-purpose processor, a digital signal processor (English full name: digital signal processing, English abbreviation: DSP), an application specific integrated circuit (English name: Application Specific Integrated Circuit, English abbreviation: ASIC), field programmable Gate array (English name: Field-Programmable Gate Array, English abbreviation: FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
  • the methods, steps, and logical block diagrams disclosed in the embodiments of the present application can be implemented or executed.
  • the general purpose processor may be a microprocessor or the processor or any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present application may be directly implemented by the hardware decoding processor, or may be performed by a combination of hardware and software modules in the decoding processor.
  • the software module can be located in a conventional storage medium such as random access memory, flash memory, read only memory, programmable read only memory or electrically erasable programmable memory, registers, and the like.
  • the storage medium is located in the memory 1504, and the processor 1503 reads the information in the memory 1504 and performs the steps of the above method in combination with its hardware.
  • the receiver 1501 can be configured to receive input digital or character information, and generate signal inputs related to related settings and function control of the user plane device.
  • the transmitter 1502 can include a display device such as a display screen, and the transmitter 1502 can be used to output through an external interface. Number or character information.
  • the receiver 1501 and the transmitter 1502 are configured to implement data transmission and reception.
  • the processor 1503 is configured to implement data transmission and reception by the receiver 1501 and the transmitter 1502, and complete a data processing process performed by the foregoing user plane function network element.
  • the terminal device 1600 includes:
  • the receiver 1601, the transmitter 1602, the processor 1603, and the memory 1604 (wherein the number of the processors 1603 in the terminal device 1600 may be one or more, and one processor in FIG. 16 is taken as an example).
  • the receiver 1601, the transmitter 1602, the processor 1603, and the memory 1604 may be connected by a bus or other means, wherein the bus connection is taken as an example in FIG.
  • Memory 1604 can include read only memory and random access memory and provides instructions and data to processor 1603. A portion of the memory 1604 can also include an NVRAM.
  • the memory 1604 stores operating systems and operational instructions, executable modules or data structures, or a subset thereof, or an extended set thereof, wherein the operational instructions can include various operational instructions for implementing various operations.
  • the operating system can include a variety of system programs for implementing various basic services and handling hardware-based tasks.
  • the processor 1603 controls the operation of the terminal device, and the processor 1603 may also be referred to as a CPU.
  • the components of the terminal device are coupled together by a bus system.
  • the bus system may include a power bus, a control bus, a status signal bus, and the like in addition to the data bus.
  • the various buses are referred to as bus systems in the figures.
  • the method disclosed in the foregoing embodiments of the present invention may be applied to the processor 1603 or implemented by the processor 1603.
  • the processor 1603 can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the foregoing method may be completed by an integrated logic circuit of hardware in the processor 1603 or an instruction in a form of software.
  • the processor 1603 described above can be a general purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component.
  • the methods, steps, and logical block diagrams disclosed in the embodiments of the present invention may be implemented or carried out.
  • the general purpose processor may be a microprocessor or the processor or any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present invention may be directly implemented by the hardware decoding processor, or may be performed by a combination of hardware and software modules in the decoding processor.
  • the software module can be located in a conventional storage medium such as random access memory, flash memory, read only memory, programmable read only memory or electrically erasable programmable memory, registers, and the like.
  • the storage medium is located in memory 1604, and processor 1603 reads the information in memory 1604 and, in conjunction with its hardware, performs the steps of the above method.
  • Receiver 1601 and transmitter 1602 are used to implement data transceiving.
  • the processor 1603 is configured to implement data transmission and reception by the receiver 1601 and the transmitter 1602, and complete a data processing process performed by the foregoing terminal device.
  • the data analysis network element 1700 includes:
  • the receiver 1701, the transmitter 1702, the processor 1703, and the memory 1704 (wherein the number of processors 1703 in the data analysis network element 1700 may be one or more, and one processor in FIG. 17 is taken as an example).
  • the receiver 1701, the transmitter 1702, the processor 1703, and the memory 1704 may be connected by a bus or other means, wherein the bus connection is taken as an example in FIG.
  • Memory 1704 can include read only memory and random access memory and provides instructions and data to processor 1703. A portion of the memory 1704 can also include an NVRAM.
  • the memory 1704 stores operating systems and operational instructions, executable modules or data structures, or a subset thereof, or an extended set thereof, wherein the operational instructions can include various operational instructions for implementing various operations.
  • the operating system can include a variety of system programs for implementing various basic services and handling hardware-based tasks.
  • the processor 1703 controls the operation of the data analysis network element, and the processor 1703 may also be referred to as a CPU.
  • each component of the data analysis network element is coupled together by a bus system.
  • the bus system may include a power bus, a control bus, and a status signal bus in addition to the data bus.
  • the various buses are referred to as bus systems in the figures.
  • the method disclosed in the foregoing embodiment of the present invention may be applied to the processor 1703 or implemented by the processor 1703.
  • the processor 1703 can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method may be completed by an integrated logic circuit of hardware in the processor 1703 or an instruction in a form of software.
  • the processor 1703 described above may be a general purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component.
  • the methods, steps, and logical block diagrams disclosed in the embodiments of the present invention may be implemented or carried out.
  • the general purpose processor may be a microprocessor or the processor or any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present invention may be directly implemented by the hardware decoding processor, or may be performed by a combination of hardware and software modules in the decoding processor.
  • the software module can be located in a conventional storage medium such as random access memory, flash memory, read only memory, programmable read only memory or electrically erasable programmable memory, registers, and the like.
  • the storage medium is located in memory 1704, and processor 1703 reads the information in memory 1704 and, in conjunction with its hardware, performs the steps of the above method.
  • Receiver 1701 and transmitter 1702 are used to implement data transceiving.
  • the processor 1703 is configured to implement data transmission and reception by the receiver 1701 and the transmitter 1702, and complete the data processing process performed by the foregoing data plane analysis network element.
  • control plane function network element 1800 includes:
  • the receiver 1801, the transmitter 1802, the processor 1803, and the memory 1804 (wherein the number of the processors 1803 in the control plane function network element 1800 may be one or more, and one processor in FIG. 18 is taken as an example).
  • the receiver 1801, the transmitter 1802, the processor 1803, and the memory 1804 may be connected by a bus or other means, wherein the bus connection is taken as an example in FIG.
  • Memory 1804 can include read only memory and random access memory and provides instructions and data to processor 1803. A portion of the memory 1804 can also include an NVRAM.
  • the memory 1804 stores operating systems and operational instructions, executable modules or data structures, or a subset thereof, or an extended set thereof, wherein the operational instructions can include various operational instructions for performing various operations.
  • the operating system can include a variety of system programs for implementing various basic services and handling hardware-based tasks.
  • the processor 1803 controls the operation of the control plane function network element, and the processor 1803 may also be referred to as a CPU.
  • the components of the control plane function network element are coupled together by a bus system.
  • the bus system may include a power bus, a control bus, and a status signal bus in addition to the data bus.
  • the various buses are referred to as bus systems in the figures.
  • the method disclosed in the foregoing embodiments of the present invention may be applied to the processor 1803 or implemented by the processor 1803.
  • the processor 1803 can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the foregoing method may be completed by an integrated logic circuit of hardware in the processor 1803 or an instruction in a form of software.
  • the processor 1803 described above may be a general purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component.
  • the methods, steps, and logical block diagrams disclosed in the embodiments of the present invention may be implemented or carried out.
  • the general purpose processor may be a microprocessor or the processor or any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present invention may be directly implemented by the hardware decoding processor, or may be performed by a combination of hardware and software modules in the decoding processor.
  • the software module can be located in a conventional storage medium such as random access memory, flash memory, read only memory, programmable read only memory or electrically erasable programmable memory, registers, and the like.
  • the storage medium is located in memory 1804, and processor 1803 reads the information in memory 1804 and, in conjunction with its hardware, performs the steps of the above method.
  • Receiver 1801 and transmitter 1802 are used to implement data transceiving.
  • the processor 1803 is configured to implement data transmission and reception by the receiver 1801 and the transmitter 1802, and complete a data processing process performed by the foregoing control plane function network element.
  • the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be Physical units can be located in one place or distributed to multiple network elements. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • the connection relationship between the modules indicates that there is a communication connection between them, and may be implemented as one or more communication buses or signal lines.
  • the method described in the various embodiments of the embodiments of the present application may be a personal computer, a server, or a network device.
  • the computer program product includes one or more computer instructions.
  • the computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable device.
  • the computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be from a website site, computer, server or data center Transfer to another website site, computer, server, or data center by wire (eg, coaxial cable, fiber optic, digital subscriber line (DSL), or wireless (eg, infrared, wireless, microwave, etc.).
  • wire eg, coaxial cable, fiber optic, digital subscriber line (DSL), or wireless (eg, infrared, wireless, microwave, etc.).
  • the computer readable storage medium can be any available media that can be stored by a computer or a data storage device such as a server, data center, or the like that includes one or more available media.
  • the usable medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (such as a solid state disk (SSD)).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • Cardiology (AREA)
  • General Health & Medical Sciences (AREA)
  • Environmental & Geological Engineering (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请实施例公开了一种流量处理方法和用户面装置以及终端设备,用于对异常流量进行精确识别,提高流量管理效果。本申请实施例提供一种流量处理方法,包括:用户面功能网元接收终端设备发送的热点指示信息,所述热点指示信息包括热点开关打开;所述用户面功能网元获取第一数据包的特征参数,并将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量。

Description

一种流量处理方法和用户面装置以及终端设备
本申请要求于2017年10月23日提交中国专利局、申请号为201710993953.6、发明名称为“一种流量处理方法和用户面装置以及终端设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请实施例涉及通信技术领域,尤其涉及一种流量处理方法和用户面装置以及终端设备。
背景技术
在移动终端上提供流量和使用流量的场景中,例如某个手机开启了无线保真(Wireless-Fidelity,Wi-Fi)热点,其他的用户设备(例如手机、平板等)可以通过该Wi-Fi热点接入。这个过程中,这些使用者并不能感知自己访问的业务是通过第三代合作伙伴计划(3rd Generation Partnership Project,3GPP)网络还是非3GPP网络实现的,对于他们来说,Wi-Fi热点与普通的无线局域网络(Wireless Local Area Networks,WLAN)(即非3GPP接入方式之一)是一致的,这些使用者有可能开启大流量业务,比如在线视频、虚拟现实(Virtual Reality,VR)、增强现实(Augmented Reality,AR)等等业务。另外,即使使用者能够感知Wi-Fi热点接入,使用者的行为对于开启Wi-Fi热点的用户来说仍然是不可控的。
基于前述的现有技术场景,如果使用者开启了大流量业务,可能导致Wi-Fi热点开启方造成经济损失。现有技术为解决Wi-Fi热点不可控的问题,提供了在开启Wi-Fi热点的时候在终端侧提供一些参数设置的解决方案。比如,现有技术提供了如下几种解决方案:
1)、设置密码:限定只有获得密码的用户设备才被允许接入。
2)、设置最大连接人数:超过人数之后其他用户设备无法接入。
3)、设置流量阈值:单次Wi-Fi热点开启状态下允许消耗的流量的最大值,达到阈值则开启方自动关闭Wi-Fi热点。
4)、设置Wi-Fi热点保持时间:一段时间内无连接则自动关闭。
热点开启方通过上述的方案可以对Wi-Fi热点设置参数,从而以直观的方式控制流量的消耗,防止流量异常消耗而带来经济损失。
然而,这种基于终端参数设置的方式并不能真正解决异常流量问题,比如,虽然设置密码的方式杜绝了不可信的用户设备接入,设置最大连接人数也阻止了更多的用户设备接入,但是已接入的用户仍然可以使用大流量业务而不提示热点开启方;流量阈值的方式可以防止流量超过门限,但是只有大流量已经被消耗之后才发出告警,仍然会造成开启方的经济损失。
发明内容
本申请实施例提供了一种流量处理方法和用户面装置以及终端设备,用于对异常流量 进行精确识别,提高流量管理效果。
为解决上述技术问题,本申请实施例提供以下技术方案:
第一方面,本申请实施例提供一种流量处理方法,包括:用户面功能网元接收终端设备发送的热点指示信息,所述热点指示信息包括热点开关打开;所述用户面功能网元获取第一数据包的特征参数,并将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量。
在本申请实施例中,用户面功能网元通过终端设备发送的热点指示信息确定该终端设备的热点开关打开,用户面功能网元在终端设备的热点开关打开期间获取到第一数据包,并将该第一数据包的特征参数发送给数据分析网元。用户面功能网元确定第一数据包所对应的流量属于异常流量。本申请实施例中不依赖于热点开启方的用户端设置,用户面功能网元可以确定在终端设备的热点开关打开期间获取到的第一数据包所对应的流量是否属于异常流量,从而可以对异常流量进行精确识别,提高流量管理效果。
在本申请第一方面的一个可能设计中,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量之后,所述方法还包括:所述用户面功能网元向所述终端设备发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。因此,终端设备可以获得该流量异常通知,通过该流量异常通知可以确定第一数据包所对应的流量属于异常流量,使得终端设备能够识别出哪些数据包对应的流量属于异常流量。
在本申请第一方面的一个可能设计中,所述用户面功能网元向所述终端设备发送流量异常通知,包括:所述用户面功能网元在数据报文中携带所述流量异常通知。用户面功能网元可以采用数据报文的方式向终端设备发送流量异常通知,具体数据报文的帧格式不做限定。
在本申请第一方面的一个可能设计中,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量,包括:所述用户面功能网元从所述数据分析网元或控制面网元接收流量异常通知。因此用户面功能网元通过解析该流量异常通知就可以确定出哪些数据包对应的流量属于异常流量。
在本申请第一方面的一个可能设计中,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量,包括:所述用户面功能网元接收所述数据分析网元或所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;所述用户面功能网元接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;所述用户面功能网元根据所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。因此,用户面功能网元可以使用终端设备在热点开关打开期间允许使用或不允许使用的业务类型,对第一数据包的业务类别进行匹配,能够通过自行识别出第一数据包所对应的流量是否属于异常流量。
在本申请第一方面的一个可能设计中,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量之后,所述方法还包括:所述用户面功能网元停止发送所述异常流量所对应的数据包,并缓存所述异常流量所对应的数据包。用户面功能网元停止发送异常流量所对应的数据包,从而可以减少热点开启方的流量损失。
在本申请第一方面的一个可能设计中,所述方法还包括:所述用户面功能网元接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述用户面功能网元根据所述流量异常应答确定所述第一数据包所对应的流量属于异常流量时,丢弃所述用户面功能网元缓存的异常流量所对应的数据包;或者,所述用户面功能网元根据所述流量异常应答确定所述第一数据包所对应的流量不属于异常流量时,向所述终端设备发送所述用户面功能网元缓存的异常流量所对应的数据包。在流量异常应答确定第一数据包所对应的流量不属于异常流量时,用户面功能网元发送缓存的异常流量所对应的数据包,从而热点开启方可以为热点使用方提供流量。
在本申请第一方面的一个可能设计中,所述方法还包括:所述用户面功能网元接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述用户面功能网元向所述数据分析网元发送所述流量异常应答。数据分析网元可以根据该流量异常应答更新终端设备在Wi-Fi热点开启情况下允许使用的业务类型信息,从而可以在在线检测时,更精确的识别出数据包是否属于异常流量。
第二方面,本申请实施例还提供一种用户面装置,包括:接收模块,用于接收终端设备发送的热点指示信息,所述热点指示信息包括热点开关打开;获取模块,用于获取第一数据包的特征参数,并将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面装置在所述终端设备的热点开关打开期间获取到的数据;确定模块,用于确定所述第一数据包所对应的流量属于异常流量。
在本申请第二方面的一个可能设计中,所述用户面装置还包括:发送模块,其中,所述发送模块,用于所述确定模块确定所述第一数据包所对应的流量属于异常流量之后,向所述终端设备发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
在本申请第二方面的一个可能设计中,所述发送模块,具体用于在数据报文中携带所述流量异常通知。
在本申请第二方面的一个可能设计中,所述确定模块,具体用于从所述数据分析网元或控制面网元接收流量异常通知。
在本申请第二方面的一个可能设计中,所述确定模块,包括:接收子模块,用于接收所述数据分析网元或所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;异常流量确定子模块,用于根据所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在本申请第二方面的一个可能设计中,所述用户面装置还包括:流量缓存模块,用于所述确定模块确定所述第一数据包所对应的流量属于异常流量之后,停止发送所述异常流量所对应的数据包,并缓存所述异常流量所对应的数据包。
在本申请第二方面的一个可能设计中,所述用户面装置还包括:流量处理模块,其中,所述接收模块,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述流量处理模块,用于根据所述流量异常应答确定所述第一数据包所对应的流量属于异常流量时,丢弃所述用户面装置缓存的异常流量所对 应的数据包;或者,根据所述流量异常应答确定所述第一数据包所对应的流量不属于异常流量时,发送所述用户面装置缓存的异常流量所对应的数据包。
在本申请第二方面的一个可能设计中,所述用户面装置还包括:发送模块,其中,所述接收模块,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述发送模块,用于向所述数据分析网元发送所述流量异常应答。
在本申请实施例的第二方面中,用户面装置的组成模块还可以执行前述第一方面以及各种可能的实现方式中所描述的步骤,详见前述对第一方面以及各种可能的实现方式中的说明。
第三方面,本申请实施例一种流量处理方法,包括:终端设备向核心网网元发送热点指示信息,所述热点指示信息包括所述终端设备的热点开关打开;所述终端设备获取所述核心网网元根据所述热点指示信息发送的流量异常通知。本申请实施例中终端设备需要向核心网网元发送热点指示信息,就可以从核心网网元接收到流量异常通知,使得终端设备可以确定哪些数据包对应的流量属于异常流量。
在第三方面的一个可能设计中,所述方法还包括:所述终端设备向所述核心网网元发送所述终端设备在所述热点开关打开期间不允许使用或者允许使用的业务类型。具体的,终端设备向核心网网元上报的时候,可以在其向核心网网元发送第一次Wi-Fi热点(hotspot)信息的时候,携带终端在Wi-Fi hotspot开启期间不允许使用的业务类型或者允许使用的业务类型。
在第三方面的一个可能设计中,所述终端设备获取所述核心网网元根据热点指示信息发送的流量异常通知之后,所述方法还包括:所述终端设备向所述核心网网元发送流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常。用户可以使用终端设备向核心网网元确定是否存在流量异常,从而核心网网元可以使用该流量异常应答进行后续的流量管理。
在第三方面的一个可能设计中,所述终端设备获取所述核心网网元根据热点指示信息发送的流量异常通知之后,所述方法还包括:所述终端设备根据所述流量异常通知关闭所述终端设备的热点;或者,所述终端设备关闭产生异常流量的热点使用者的连接;或者,所述终端设备禁止产生异常流量的业务类型使用所述终端设备的热点。
在第三方面的一个可能设计中,所述核心网网元包括:控制面功能网元、用户面功能网元、策略网元和数据分析网元中的至少一种。
第四方面,本申请实施例还提供一种流量处理方法,所述方法包括:数据分析网元获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型;所述数据分析网元接收用户面功能网元发送的第一数据包的特征参数,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据包;所述数据分析网元根据所述第一数据包的特征参数确定所述第一数据包的业务类型;所述数据分析网元根据所述终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。本申请实施例中不依赖于热点开启方的用户端设置,数据分析网元可以确定在终端设备的热点开关打开期间获取到的第一数据包所对应的流量是否属于 异常流量,从而可以对异常流量进行精确识别,提高流量管理效果。
在第四方面的一个可能设计中,所述确定所述第一数据包所对应的流量属于异常流量之后,所述方法还包括:所述数据分析网元向控制面功能网元或所述用户面功能网元发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
在第四方面的一个可能设计中,所述数据分析网元获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型,包括:所述数据分析网元根据训练数据确定所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;或者,所述数据分析网元接收所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
在第四方面的一个可能设计中,所述方法还包括:所述数据分析网元接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述数据分析网元根据所述流量异常应答更新所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
第五方面,本申请实施例还提供一种流量处理方法,所述方法包括:数据分析网元获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型;所述数据分析网元向用户面功能网元或控制面功能网元发送所述终端设备在热点开关打开期间允许使用的业务类型;所述数据分析网元接收所述用户面功能网元发送的第一数据包的特征参数,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;所述数据分析网元根据所述第一数据包的特征参数确定所述第一数据包的业务类型;所述数据分析网元向所述用户面功能网元或所述控制面功能网元发送所述第一数据包的业务类型。
在第五方面的一个可能设计中,所述数据分析网元获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型,包括:所述数据分析网元根据训练数据确定所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
第六方面,本申请实施例提供一种流量处理方法,所述方法包括:控制面功能网元接收终端设备发送的热点指示信息,所述热点指示信息包括热点开关打开;所述控制面功能网元接收用户面功能网元发送的第一数据包的特征参数,并将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;所述控制面功能网元确定所述第一数据包所对应的流量属于异常流量。本申请实施例中不依赖于热点开启方的用户端设置,控制面功能网元可以确定在终端设备的热点开关打开期间获取到的第一数据包所对应的流量是否属于异常流量,从而可以对异常流量进行精确识别,提高流量管理效果。
在第六方面的一个可能设计中,所述控制面功能网元确定所述第一数据包所对应的流量属于异常流量之后,所述方法还包括:所述控制面功能网元向所述终端设备发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
在第六方面的一个可能设计中,所述控制面功能网元向所述终端设备发送流量异常通知,包括:所述控制面功能网元在控制信令中携带所述流量异常通知。具体的,该控制信令可以使用但不限于如下举例的两种流程消息,一种是网络侧发起的Service Request流 程,通过Paging消息携带流量异常通知发给UE,另外是网络侧发起的PDU Session Modification流程,通过PDU Session Modification Accept消息携带流量异常通知发给UE。
在第六方面的一个可能设计中,所述控制面功能网元确定所述第一数据包所对应的流量属于异常流量,包括:所述控制面功能网元从所述数据分析网元或所述用户面功能网元接收流量异常通知。
在第六方面的一个可能设计中,所述控制面功能网元确定所述第一数据包所对应的流量属于异常流量,包括:所述控制面功能网元接收所述数据分析网元或所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;所述控制面功能网元接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;所述控制面功能网元根据所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在第六方面的一个可能设计中,所述控制面功能网元确定所述第一数据包所对应的流量属于异常流量,包括:所述控制面功能网元接收所述终端设备发送的所述终端设备在所述热点开关打开期间允许使用或者不允许使用的业务类型;所述控制面功能网元接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;所述控制面功能网元根据所述终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在第六方面的一个可能设计中,所述控制面功能网元确定所述第一数据包所对应的流量属于异常流量之后,所述方法还包括:所述控制面功能网元通知所述用户面功能网元停止发送所述第一数据包所对应的流量,并缓存所述第一数据包所对应的流量。
在第六方面的一个可能设计中,所述方法还包括:所述控制面功能网元接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述控制面功能网元根据所述流量异常应答确定所述第一数据包所对应的流量属于异常流量时,所述控制面功能网元通知所述用户面功能网元丢弃缓存的异常流量所对应的数据包;或者,所述控制面功能网元根据所述流量异常应答确定所述第一数据包所对应的流量不属于异常流量时,所述控制面功能网元通知所述用户面功能网元转发缓存的异常流量所对应的数据包。
在第六方面的一个可能设计中,所述方法还包括:所述控制面功能网元接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述控制面功能网元向所述数据分析网元转发所述流量异常应答。
第七方面,本申请实施例提供一种通信装置,该通信装置可以包括芯片等实体,所述通信装置包括:处理器、存储器;所述存储器用于存储指令;所述处理器用于执行所述存储器中的所述指令,使得所述通信装置执行如前述第一方面到第六方面中任一项所述的方法。
第八方面,本申请实施例一种终端设备,包括:发送模块,用于向核心网网元发送热点指示信息,所述热点指示信息包括热点开关打开;获取模块,用于获取所述核心网网元根据所述热点指示信息发送的流量异常通知。
在第八方面的一个可能设计中,所述发送模块,还用于向所述核心网网元发送所述终端设备在所述热点开关打开期间不允许使用或者允许使用的业务类型。具体的,终端设备向核心网网元上报的时候,可以在其向核心网网元发送第一次Wi-Fi热点(hotspot)信息的时候,携带终端在Wi-Fi hotspot开启期间不允许使用的业务类型或者允许使用的业务类型。
在第八方面的一个可能设计中,所述发送模块,还用于所述获取模块获取所述核心网网元根据热点指示信息发送的流量异常通知之后,向所述核心网网元发送流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常。
在第八方面的一个可能设计中,所述终端设备,还包括:异常处理模块,用于所述获取模块获取所述核心网网元根据热点指示信息发送的流量异常通知之后,根据所述流量异常通知关闭热点;或者,关闭产生异常流量的热点使用者的连接;或者,禁止产生异常流量的业务类型使用热点。
在第八方面的一个可能设计中,所述核心网网元包括:控制面功能网元、用户面功能网元、策略网元和数据分析网元中的至少一种。
第九方面,本申请实施例还提供一种数据分析网元,所述数据分析网元包括:获取模块,用于获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型;接收模块,用于接收用户面功能网元发送的第一数据包的特征参数,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据包;业务类型确定模块,用于根据所述第一数据包的特征参数确定所述第一数据包的业务类型;异常流量确定模块,用于根据所述终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在第九方面的一个可能设计中,所述数据分析网元,还包括:发送模块,用于所述异常流量确定模块确定所述第一数据包所对应的流量属于异常流量之后,向控制面功能网元或所述用户面功能网元发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
在第九方面的一个可能设计中,所述获取模块,具体用于根据训练数据确定所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;或者,接收所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
在第九方面的一个可能设计中,所述接收模块,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述数据分析网元根据所述流量异常应答更新所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
第十方面,本申请实施例还提供一种数据分析网元,包括:获取模块,用于获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型;发送模块,用于向用户面功能网元或控制面功能网元发送所述终端设备在热点开关打开期间允许使用的业务类型;接收模块,用于接收所述用户面功能网元发送的第一数据包的特征参数,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;业务类型确定模块,用于根据所述第一数据包的特征参数确定所述第一数据包的业务类型;所述 发送模块,还用于向所述用户面功能网元或所述控制面功能网元发送所述第一数据包的业务类型。
在第十方面的一个可能设计中,所述获取模块,具体用于根据训练数据确定所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
第十一方面,本申请实施例提供一种控制面功能网元,包括:接收模块,用于接收终端设备发送的热点指示信息,所述热点指示信息包括热点开关打开;所述接收模块,还用于接收用户面功能网元发送的第一数据包的特征参数;发送模块,用于将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;异常流量确定模块,用于确定所述第一数据包所对应的流量属于异常流量。
在第十一方面的一个可能设计中,所述发送模块,还用于所述异常流量确定模块确定所述第一数据包所对应的流量属于异常流量之后,向所述终端设备发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
在第十一方面的一个可能设计中,所述发送模块,具体用于在控制信令中携带所述流量异常通知。具体的,该控制信令可以使用但不限于如下举例的两种流程消息,一种是网络侧发起的Service Request流程,通过Paging消息携带流量异常通知发给UE,另外是网络侧发起的PDU Session Modification流程,通过PDU Session Modification Accept消息携带流量异常通知发给UE。
在第十一方面的一个可能设计中,所述异常流量确定模块,具体用于从所述数据分析网元或所述用户面功能网元接收流量异常通知。
在第十一方面的一个可能设计中,所述异常流量确定模块,具体用于接收所述数据分析网元或所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;根据所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在第十一方面的一个可能设计中,所述异常流量确定模块,具体用于接收所述终端设备发送的所述终端设备在所述热点开关打开期间允许使用或者不允许使用的业务类型;接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;根据所述终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在第十一方面的一个可能设计中,所述发送模块,还用于所述异常流量通知模块确定所述第一数据包所对应的流量属于异常流量之后,通知所述用户面功能网元停止发送所述第一数据包所对应的流量,并缓存所述第一数据包所对应的流量。
在第十一方面的一个可能设计中,所述接收模块,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述发送模块还用于根据所述流量异常应答确定所述第一数据包所对应的流量属于异常流量时,通知所述用户面功能网元丢弃缓存的异常流量所对应的数据包;或者,根据所述流量异常应答确定所述第一数据包所对应的流量不属于异常流量时,通知所述用户面功能网元转发缓存的 异常流量所对应的数据包。
在第十一方面的一个可能设计中,所述接收模块,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述控制面功能网元向所述数据分析网元转发所述流量异常应答。
第十二方面,本申请实施例提供一种终端设备,该终端设备可以包括终芯片等实体,所述终端设备包括:处理器、存储器;所述存储器用于存储指令;所述处理器用于执行所述存储器中的所述指令,使得所述终端设备执行如前述第三方面中任一项所述的方法。
第十三方面,本申请实施例提供了一种芯片系统,该芯片系统包括处理器,用于支持网络设备实现上述方面中所涉及的功能,例如,例如发送或处理上述方法中所涉及的数据和/或信息。在一种可能的设计中,所述芯片系统还包括存储器,所述存储器,用于保存网络设备必要的程序指令和数据。该芯片系统,可以由芯片构成,也可以包括芯片和其他分立器件。
本申请实施例的第十四方面提供了一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行上述各方面所述的方法。
本申请实施例的第十五方面提供了一种包含指令的计算机程序产品,当其在计算机上运行时,使得计算机执行上述各方面所述的方法。
附图说明
图1为本申请实施例提供的一种5G系统的架构示意图;
图2为本申请实施例提供的一种流量处理方法的流程方框示意图;
图3为本申请实施例提供的另一种流量处理方法的流程方框示意图;
图4为本申请实施例提供的另一种流量处理方法的流程方框示意图;
图5为本申请实施例提供的另一种流量处理方法的流程方框示意图;
图6为本申请实施例提供的另一种流量处理方法的流程方框示意图;
图7为本申请实施例提供的流量处理方法所应用的一种场景下多网元之间的交互流程示意图;
图8为本申请实施例提供的流量处理方法所应用的一种场景下多网元之间的交互流程示意图;
图9为本申请实施例提供的流量处理方法所应用的一种场景下多网元之间的交互流程示意图;
图10-a为本申请实施例提供的一种用户面装置的结构示意图;
图10-b为本申请实施例提供的另一种用户面装置的结构示意图;
图10-c为本申请实施例提供的另一种用户面装置的结构示意图;
图10-d为本申请实施例提供的另一种用户面装置的结构示意图;
图11-a为本申请实施例提供的一种终端设备的结构示意图;
图11-b为本申请实施例提供的另一种终端设备的结构示意图;
图12-a为本申请实施例提供的一种数据面分析网元的结构示意图;
图12-b为本申请实施例提供的另一种数据面分析网元的结构示意图;
图13为本申请实施例提供的另一种数据面分析网元的结构示意图;
图14为本申请实施例提供的一种控制面功能网元的结构示意图;
图15为本申请实施例提供的一种用户面装置的结构示意图;
图16为本申请实施例提供的另一种终端设备的结构示意图;
图17为本申请实施例提供的另一种数据面分析网元的结构示意图;
图18为本申请实施例提供的另一种控制面功能网元的结构示意图。
具体实施方式
下面结合附图,对本申请实施例的实施例进行描述。
本申请实施例的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,这仅仅是描述本申请实施例的实施例中对相同属性的对象在描述时所采用的区分方式。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,以便包含一系列单元的过程、方法、系统、产品或设备不必限于那些单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它单元。
在本申请的实施例中,“和/或”仅仅是一种描述关联对象的关联关系,表示可以存在三种关系。例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,在本申请的描述中,“多个”是指两个或多于两个。另外本申请实施例中,“/”可以指的是和/或的关系。
以下分别进行详细说明。
本申请实施例提供的流量处理方法可应用于第三代移动通信(3-Generation,3G)系统、第四代移动通信(4-Generation,4G)系统、第五代移动通信(5th Generation,5G)系统或者后续演进的通信系统。
请参阅图1所示,为本申请实施例提供的一种流量处理方法所应用的5G系统的系统架构示意图。5G系统架构分为接入网和核心网两部分。接入网用于实现无线接入有关的功能,接入网包括有无线接入网(Radio Accessing Network,RAN)。核心网可分为用户面和控制面,其中,核心网用户面包括用户面功能(User Plane Function,UPF)网元;核心网控制面包括核心网接入和移动性管理功能(Access and Mobility Management Function,AMF)网元、会话管理功能(Session Management Function,SMF)网元、策略控制功能(Policy Control Function,PCF)网元、网络数据分析功能(NetWork Data Analytics Function,NWDAF)网元。在5G系统中还可以包括:用户设备(User Equipment,UE)和数据网络(Data Network,DN)。在图1中,UPF网元简写为UPF,NWDAF网元简写为NWDAF等等,不再逐一示意说明。
其中,AMF网元主要负责移动网络中的移动性管理,如用户位置更新、用户注册网络、用户切换等。
SMF网元主要负责移动网络中的会话管理,举例说明,SMF网元具体功能可包括:为用户分配互联网协议(Internet Protocol,IP)地址、选择提供报文转发功能的UPF网元等。本申请实施例中,SMF管理UPF的数据传输,负责NWDAF和UPF之间的特征向量、流量异 常结果、数据类型等信息的发送,并且可以完成与UE的信令交互,获得热点状态,例如获取到无线保真Wi-Fi热点状态,告警UE流量异常。
RAN指的是基站,UE通过基站接入到网络。
UPF网元主要负责对用户报文进行流量处理,如转发、计费等。用于传输网络中的数据,包括热点使用者通过热点开启方接入网络并传输的业务数据。
PCF网元负责向AMF网元、SMF网元提供策略,如服务质量(Quality of Service,QoS)策略、切片选择策略等。PCF网元直接与AMF、SMF、NWDAF相连,PCF可根据NWDAF的分析结果决定业务处理策略,比如PCF决定由SMF还是UPF发起告警、告警通过3GPP网络信令还是数据报文的方式实现。
该终端设备包括但不限于:用户设备(user equipment,UE)、用户单元、用户站、移动站、移动台、远方站、远程终端设备、移动终端设备、用户终端设备、终端设备、无线通信设备、用户代理、用户装置、蜂窝电话、无绳电话、会话启动协议(session initiation protocol,SIP)电话、无线本地环路(wireless local loop,WLL)站、个人数字处理(personal digital assistant,PDA)、具有无线通信功能的手持设备、计算设备、连接到无线调制解调器的处理设备、车载设备、可穿戴设备、物联网中的终端设备设备、家用电器、虚拟现实设备、未来5G网络中的终端设备设备或者未来演进的公共陆地移动网络(public land mobile network,PLMN)中的终端设备设备等。在本申请的各实施例中,以终端设备为UE进行举例说明。
UE通过建立UE到RAN、RAN到UPF网元、UPF网元到DN之间的分组数据单元(Packet Data Unit,PDU)会话(session)访问数据网络。UE1指的是用户设备1,作为热点开启方,例如UE1作为Wi-Fi热点的开启者,通过无线接口与基站连接。后续实施例中以UE1为Wi-Fi热点开启方进行示例说明,UE2/3/4/5作为热点的使用者,通过WLAN方式接入UE1的热点,网络对其所使用的流量所产生的流量计费都计入UE1的账单中。
NWDAF网元用于负责接收网络中的数据特征进行训练,得到数据模型;接收网络中实时上报的数据特征,根据数据模型得到当前数据的业务类型;获得热点开启下的允许使用或者不允许使用的数据业务类型集;在得到热点开启下的允许使用或者不允许使用的数据业务类型基础上还可结合实时数据包的业务类型给出判定,即可以判断出当前数据是否属于异常流量。NWDAF网元还可以将分析获得的信息下发给其他网元(如PCF网元、SMF网元、UPF网元),指示PCF网元、SMF网元、UPF网元的操作。
在前述实施例提供的5G系统中包括了控制面网元和用户面网元,对于控制面、用户面分离的4.5G与该5G系统类似,以4.5G系统为例,PGW网元的控制面和用户面分离,分成PGW-C以及PGW-U。例如:PGW-C可以使用控制面信令发起bearer modification with bearer QoS update流程。在4.5G网络中,SGW网元的控制面和用户面分离,分为SGW-C以及SGW-U。例如:SGW-C可以使用控制面信令发起bearer modification with bearer QoS update流程。在4.5G系统中,PGW-C对应于5G系统中的数据控制面功能网元,例如SMF网元,PGW-U对应于5G系统中的数据用户面功能网元,例如UPF网元。
在本申请的一些实施例中,4G系统架构中控制面、用户面不分离,因此可能在同一个网元如分组数据网关(Packet Data Network Gateway,PGW)中实现控制面和用户面的功 能;或者移动管理实体(Mobility Management Entity,MME)对应控制面网元,服务网关(Service Gateway,SGW)对应用户面网元。例如,在4G系统中,PGW网元集控制面和用户面一身,PGW网元可用于对终端设备的Wi-Fi热点流量进行管理。例如PGW网元可以使用控制面信令或者用户面信令向终端设备发送流量异常通知,控制信令可以是分组数据网络(Packet Data Network,PDN)连接修改流程或承载修改流程等,例如:PGW网元发起bearer modification with bearer QoS update流程。
本申请实施例中,接下来以热点具体为Wi-Fi热点为例,针对终端设备(Wi-Fi热点开启方)设置参数方式限定其他用户设备(Wi-Fi热点使用者)对该Wi-Fi热点的使用的方式,解决Wi-Fi热点使用过程中不能及时通过数据业务判定流量异常情况的问题,将当前热点状态通知网络,网络通过大数据分析的方式对当前状态下的数据业务实时监控,实现终端设备的热点异常流量的判定和告警。本申请实施例的方法主要包括如下过程:针对一个UE,NWDAF网元获取在该UE开启热点期间允许使用或不允许使用的业务类型,例如:获取一个或多个业务类型组成的列表。其中,业务类型可以是类型标识(如A类业务、B类业务)。业务类型也可以是应用标识。例如:该应用标识可以包括APP id或者流标识(flow id)等。可选的,业务类型列表可以是UE仅允许WLAN开启情况下使用的应用程序(Application,APP)列表。业务类型列表可以包括至少一个业务类型。
UE上报UE的热点状态(开启/关闭)给网络,例如UE上报给SMF网元,SMF网元再上报(可通过PC网元间接上报或者服务化接口直接上报)给UPF网元和/或NWDAF网元。离线大数据分析时,NWDAF网元在终端设备的热点开启期间,可以收集流经UPF网元的数据包的特征,得到每个UE在热点开启期间允许的业务类型列表。在线实时数据包监测时,在终端设备的热点开启期间,NWDAF网元实时监测流经UPF网元的数据包特征,并得到数据业务类型。
在本申请的实施例中,判定异常流量有如下两种不同的实现方式:
1)、NWDAF网元判定异常流量,并向SMF网元和/或UPF网元发送异常流量指示,判定条件具体可以是该数据特征对应的业务类型不在允许的业务类型列表内。SMF网元、UPF网元可针对Wi-Fi热点异常流量行为,操作如下:SMF网元或UPF网元通知UE存在热点异常流量行为,由UE决定下一步操作,当前业务继续进行。或者,UPF网元获取数据包的检测信息(例如IP五元组、UE ID/IP等),暂停下发并缓存该检测信息对应的数据包,不再计费,并且,SMF网元或UPF网元通知UE的热点异常流量行为,若UE向SMF网元和UPF网元确认是热点异常流量,则通知UPF网元丢弃检测信息(例如IP五元组)对应的所有数据包,否则,UPF网元继续转发相应数据包。
2)、NWDAF网元将分析得到的数据业务类型发送给SMF网元和/或UPF网元,SMF网元、UPF网元根据从UE或者NWDAF网元获得的热点开启情况下允许/不允许的业务类型列表决定是否向UE发起告警,例如可以根据仅WLAN开启条件下使用的业务类型列表决定是否向UE发起告警。
接下来以不同网元执行的流量处理方法为例进行详细说明,首先从用户面功能网元的角度进行示例说明,该用户面功能网元也可以称为用户面装置。请参阅图2所示,本申请实施例一个实施例提供的流量处理方法,可以包括:
201、用户面功能网元接收终端设备发送的热点指示信息,热点指示信息包括热点开关打开。
在本申请实施例中,终端设备是热点的开启方,例如Wi-Fi热点的开启方。当用户打开热点开关时,终端设备生成热点指示信息,终端设备可以通过RAN向用户面功能网元发送热点指示信息,用户面功能网元获得该热点指示信息,并确定终端设备的热点开关打开。
举例说明,终端设备可以通过PDU会话建立(PDU Session Establishment)/PDU会话建立修改(PDU Session Modification)/注册(Registration)/业务请求(Service Request)流程,把热点的开关状态上报给用户面功能网元。进一步的,终端设备还可以通过initiated PDU Session Establishment/PDU Session Modification/Registration/Service Request流程将终端设备在热点开启期间允许或者不允许使用的业务类型(list)上报给用户面功能网元。
202、用户面功能网元获取第一数据包的特征参数,并将第一数据包的特征参数发送给数据分析网元,第一数据包是用户面功能网元在终端设备的热点开关打开期间获取到的数据。
在本申请实施例中,用户面功能网元在终端设备的热点开关打开期间获取到数据,其中,用户面功能网元的数据传输可以分为上行传输以及下行传输。上行传输可以是热点使用方使用热点开启方提供的热点向用户面功能网元发送上行数据包,用户面功能网元将该上行数据包发送给数据网络。下行传输可以是用户面功能网元从数据网络接收到下行数据包,用户面功能网元通过RAN将下行数据包发送给热点开启方,热点开启方再通过热点将下行数据包发送给热点使用方。用户面功能网元在终端设备的热点开关打开期间获取到数据包,例如用户面功能网元在终端设备的热点打开期间获取到的第一数据包,该第一数据包可以是上行传输的数据包,也可以是下行传输的数据包。用户面功能网元还可以获取数据包的特征参数,例如可以获取第一数据包的特征参数。其中,特征参数可以包括用于表示数据包的业务类型的参数,例如:IP五元组、UE ID/IP、报文长度、滤波器、流标识等,或者根据数据报文获取的一些特征参数等。特征参数可以包括一个或多个参数,例如:特征参数可以以特征向量的形式体现。用户面功能网元具体可以通过特征工程的方式获取第一数据包的特征参数。用户面功能网元还可以将第一数据包的特征参数发送给数据分析网元。该数据分析网元具体可以是前述实施例中的NWDAF网元。
203、用户面功能网元确定第一数据包所对应的流量属于异常流量。
在本申请实施例中,用户面功能网元将第一数据包的特征参数发送给数据分析网元之后,用户面功能网元确定第一数据包所对应的流量属于异常流量。其中,用户面功能网元确定第一数据包所对应的流量属于异常流量可以有多种实现方式,接下来进行举例说明。
本申请实施例中的“异常流量”包括终端设备在当前状态下不被允许的数据流量,对于每个用户来说是否为异常流量都可能不同,例如:业务类型A对于UE1来说是正常流量,但是对于UE2来说可能是异常流量。
在本申请的一些实施例中,步骤203用户面功能网元确定第一数据包所对应的流量属于异常流量,包括:
用户面功能网元从数据分析网元或控制面网元接收流量异常通知。
其中,用户面功能网元可以从数据分析网元或控制面网元接收流量异常通知,用户面功能网元获得该流量异常通知,通过该流量异常通知可以确定第一数据包所对应的流量属于异常流量。其中,数据分析网元可以使用第一数据包的特征参数识别该第一数据包的业务类型,再通过第一数据包的业务类型确定该第一数据包所对应的流量是否属于异常流量,并在第一数据包所应的流量属于异常流量时生成流量异常通知。
在本申请的一些实施例中,步骤203用户面功能网元确定第一数据包所对应的流量属于异常流量,包括:
用户面功能网元接收数据分析网元或终端设备发送的终端设备在热点开关打开期间允许使用或不允许使用的业务类型;
用户面功能网元接收数据分析网元发送的第一数据包的业务类型;
用户面功能网元根据终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定第一数据包所对应的流量属于异常流量。
其中,在前述实现场景下,用户面功能网元可以获取终端设备在热点开关打开期间允许使用的业务类型,或者用户面功能网元可以获取终端设备在热点开关打开期间不允许使用的业务类型。该允许或不允许使用的业务类型可以由数据分析网元发送给用户面功能网元,或者由终端设备发送给用户面功能网元。数据分析网元可以使用第一数据包的特征参数识别该第一数据包的业务类型,再将第一数据包的业务类型发送给用户面功能网元。用户面功能网元可以使用前述步骤中获取到的业务类型确定该第一数据包所对应的流量是否属于异常流量。
在本申请的一些实施例中,步骤203用户面功能网元确定第一数据包所对应的流量属于异常流量之后,本申请实施例提供的流量处理方法还可以包括如下步骤:
用户面功能网元向终端设备发送流量异常通知,流量异常通知用于通知第一数据包所对应的流量属于异常流量。
其中,用户面功能网元在确定第一数据包所对应的流量属于异常流量之后,用户面功能网元还可以在第一数据包所应的流量属于异常流量时生成流量异常通知,用户面功能网元向终端设备发送流量异常通知,终端设备可以获得该流量异常通知,通过该流量异常通知可以确定第一数据包所对应的流量属于异常流量。
在本申请的一些实施例中,用户面功能网元向终端设备发送流量异常通知,包括:
用户面功能网元在数据报文中携带流量异常通知。
其中,用户面功能网元可以采用数据报文的方式向终端设备发送流量异常通知,具体数据报文的帧格式不做限定。
用户面功能网元向控制面功能网元发送流量异常通知,从而可以通过控制面功能网元向终端设备发送流量异常通知,具体地可以是在信令消息(比如,网络侧发起的PDU Session Modification流程中消息,网络侧发起的Service Request流程中的Paging消息)中携带流量异常通知。
在本申请的一些实施例中,步骤203用户面功能网元确定第一数据包所对应的流量属于异常流量之后,本申请实施例提供的流量处理方法还包括如下步骤:
用户面功能网元停止发送异常流量所对应的数据包,并缓存异常流量所对应的数据包。
其中,用户面功能网元确定第一数据包所对应的流量属于异常流量之后,用户面功能网元可以按照第一数据包对应的某些检测信息对接收到的数据包进行缓存,比如按照第一数据包对应的IP五元组(例如源IP地址/端口,目的IP地址/端口,传输协议)对数据包进行缓存处理,其中,一个IP五元组对应的流量中可以包括多个数据包,用户面功能网元停止发送异常流量所对应的数据包,从而可以减少Wi-Fi热点开启方的流量损失。
进一步的,在本申请的一些实施例中,在执行前述步骤的实现场景下,本申请实施例提供的流量处理方法还可以执行如下步骤:
用户面功能网元接收终端设备发送的流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常;
用户面功能网元根据流量异常应答确定第一数据包所对应的流量属于异常流量时,用户面功能网元丢弃用户面功能网元缓存的异常流量所对应的数据包;或者,
用户面功能网元根据流量异常应答确定第一数据包所对应的流量不属于异常流量时,用户面功能网元向终端设备发送用户面功能网元缓存的异常流量所对应的数据包。
其中,终端设备接收到用户面功能网元发送的流量异常通知,终端设备可以显示该流量异常通知给用户,用户可以针对该流量异常通知作出响应。例如:用户可以识别流量是否存在异常,用户可以通过终端设备向用户面功能网元发送流量异常应答。用户面功能网元根据流量异常应答确定第一数据包所对应的流量属于异常流量时,用户面功能网元丢弃缓存的异常流量所对应的数据包,从而可以减少Wi-Fi热点开启方的流量损失。在流量异常应答确定第一数据包所对应的流量不属于异常流量时,用户面功能网元发送缓存的异常流量所对应的数据包,从而Wi-Fi热点开启方可以为Wi-Fi热点使用方提供流量。
在本申请的一些实施例中,除了执行前述的方法步骤之外,本申请实施例提供的流量处理方法还可以执行如下步骤:
用户面功能网元接收终端设备发送的流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常;
用户面功能网元向数据分析网元发送流量异常应答。
其中,终端设备接收到用户面功能网元发送的流量异常通知,终端设备可以显示该流量异常通知给用户,用户可以针对该流量异常通知作出响应。例如:用户可以识别流量是否存在异常,用户可以通过终端设备向用户面功能网元发送流量异常应答。用户面功能网元还可以向数据分析网元发送流量异常应答,数据分析网元可以根据该流量异常应答确定是否存在流量异常。数据分析网元可以根据该流量异常应答更新终端设备在Wi-Fi热点开启情况下允许使用的业务类型信息,从而可以在在线检测时,更精确的识别出数据包是否属于异常流量。
前述实施例从用户面功能网元的角度描述了本申请实施例提供的流量处理方法,接下来从终端设备侧描述本申请实施例提供的流量处理方法,请参阅图3所示,本申请实施例提供的流量处理方法,可以包括:
301、终端设备向核心网网元发送热点指示信息,热点指示信息包括终端设备的热点开关打开。
在本申请实施例中,终端设备是热点开启方,例如终端设备可以是Wi-Fi热点的开启 方,当用户打开热点开关时,终端设备生成热点指示信息,终端设备可以通过RAN向用户面功能网元发送热点指示信息。
在本申请实施例的一个可能设计中,本申请实施例提供的流量处理方法除了执行前述方法步骤之外,本申请实施例提供的流量处理方法还可以包括如下步骤:
终端设备向核心网网元发送终端设备在热点开关打开期间不允许使用或者允许使用的业务类型。
其中,Wi-Fi热点打开期间不允许使用或允许使用的业务类型也可以作为热点指示信息中的内容,从而终端设备发送给核心网网元的热点指示信息除了包括热点开关打开的通知,还包括Wi-Fi热点打开期间不允许使用或允许使用的业务类型信息。
在本申请实施例的一个可能设计中,该核心网网元可以包括:控制面功能网元、用户面功能网元、策略网元和数据分析网元中的一种。其中,以4G系统为例,该控制面功能网元和用户面功能网元具体可以为PGW网元,以5G系统为例,控制面功能网元具体可以是SMF网元,用户面功能网元具体可以UPF网元,数据分析网元具体可以为前述的NWDAF网元。
302、终端设备获取核心网网元根据热点指示信息发送的流量异常通知。
在本申请实施例中,核心网网元可以确定第一数据包所对应的流量属于异常流量,然后核心网网元可以向终端设备发送流量异常通知,流量异常通知用于通知第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,步骤302终端设备获取核心网网元根据热点指示信息发送的流量异常通知之后,本申请实施例提供的流量处理方法还可以包括如下步骤:
终端设备向核心网网元发送流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常。
其中,终端设备接收到用户面功能网元发送的流量异常通知,终端设备可以显示该流量异常通知给用户,用户可以针对该流量异常通知作出响应。例如:用户可以识别流量是否存在异常,用户可以通过终端设备向核心网网元发送流量异常应答。核心网网元可以根据该流量异常应答确定是否存在流量异常,核心网网元可以根据该流量异常应答更新终端设备在Wi-Fi热点开启情况下允许使用的业务类型,从而可以在在线检测时,更精确的识别出是否属于异常流量。
在本申请实施例的一个可能设计中,步骤302终端设备获取核心网网元根据热点指示信息发送的流量异常通知之后,本申请实施例提供的流量处理方法还可以包括如下步骤:
终端设备根据流量异常通知关闭终端设备的热点;或者,
终端设备关闭产生异常流量的热点使用者的连接;或者,
终端设备禁止产生异常流量的业务类型使用终端设备的热点。
其中,本申请实施例中对终端设备接收到流量异常信息之后的处理并不限定。例如,可以是确定异常流量之后,关闭Wi-Fi热点,或者确定某个Wi-Fi热点使用者关闭该使用者的连接,或者暂时禁用某个业务类型等,具体实现方式此处不做限定。
通过前述实施例对本申请实施例提供的流量管理方法的说明可知,终端设备向核心网网元发送热点指示信息,终端设备获取核心网网元根据热点指示信息发送的流量异常通知, 使得终端设备可以通过该流量异常通知确定出哪些数据包对应的流量属于异常流量。
前述实施例从终端设备的角度描述了本申请实施例提供的流量处理方法,接下来从数据分析网元侧描述本申请实施例提供的流量处理方法,请参阅图4所示,本申请实施例提供的流量处理方法,可以包括:
401、数据分析网元获取终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
在本申请实施例中,数据分析网元具体可以是前述的NWDAF网元,数据分析网元首先获取终端设备在热点开关打开期间允许使用的业务类型,或者数据分析网元获取终端设备在热点开关打开期间不允许使用的业务类型。例如数据分析网元可以通过大数据分析的方式获取到该业务类型,数据分析网元也可以通过终端设备获取到该业务类型。
在本申请实施例的一个可能设计中,步骤401数据分析网元获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型,包括:
数据分析网元根据训练数据确定终端设备在热点开关打开期间允许使用或不允许使用的业务类型;或者,
数据分析网元接收终端设备发送的终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
其中,数据分析网元获取终端设备在热点开关打开期间允许使用或不允许使用的业务类型可以包括如下两种实现方式:UE将允许或不允许的业务类型列表发送给数据分析网元,或者数据分析网元进行机器学习训练,得到业务类型识别模型。其中机器学习所使用的训练数据,可以包括两种数据,一种是来自运营商平台、或OTT(Over The Top)服务器、或垂直行业管控中心等的应用数据,包括数据包的大小、起止时间、IP五元组、业务类型,另一种是来自网络侧的网络数据,包括UE标识、终端类型(Terminal Type)、接入点名称(Access Point Name,APN)、数据网络名称(Data Network Name,DNN)、基站侧无线信道质量、小区标识(Cell ID)等信息。数据分析网元可以基于这两种信息得到业务类型识别模型,能够对在流经UPF网元的UE的数据包进行分类,从而得到UE的Wi-Fi热点开启期间UE允许使用的业务类型。
402、数据分析网元接收用户面功能网元发送的第一数据包的特征参数,第一数据包是用户面功能网元在终端设备的热点开关打开期间获取到的数据包。
在本申请实施例中,特征参数包括用于表示数据包的业务类型的参数。例如:该特征参数可以是特征向量。用户面功能网元具体可以通过特征工程的方式获取第一数据包的特征参数。用户面功能网元还可以将第一数据包的特征参数发送给数据分析网元,例如:用户面功能网元将第一数据包的特征参数发送给SMF网元,SMF网元再将第一数据包的特征参数发送给PCF网元,PCF网元再将该第一数据包的特征参数发送给NWDAF网元,NWDAF网元可以接收用户面功能网元发送的第一数据包的特征参数。
403、数据分析网元根据第一数据包的特征参数确定第一数据包的业务类型。
在本申请实施例中,数据分析网元可以通过业务类型识别模型来判断第一数据包的业务类型,例如:数据分析网元可以通过特征学习得到业务类型识别模型的特征列表,进而训练得到业务类型识别模型的模型参数,通过第一数据包的特征参数以及业务识别模型计 算,从而可以确定出第一数据包的业务类型。
404、数据分析网元根据终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定第一数据包所对应的流量属于异常流量。
在本申请实施例中,数据分析网元可以通过步骤403确定出第一数据包的业务类型,将该第一数据包的业务类型和步骤401中获取到终端设备在热点开关打开期间允许使用或者不允许使用的业务类型进行匹配,从而可以确定出第一数据包所对应的流量属于异常流量。例如:数据分析网元获取到的是终端设备在热点开关打开期间允许使用的业务类型,如果第一数据包的业务类型不属于允许使用的业务类型,则可以确定该第一数据包所对应的流量属于异常流量。又如数据分析网元获取到的是终端设备在热点开关打开期间不允许使用的业务类型,如果第一数据包的业务类型属于不允许使用的业务类型,则可以确定该第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,步骤404确定第一数据包所对应的流量属于异常流量之后,本申请实施例提供的流量处理方法还可以包括如下步骤:
数据分析网元向控制面功能网元或用户面功能网元发送流量异常通知,流量异常通知用于通知第一数据包所对应的流量属于异常流量。
其中,在本申请实施例中,数据分析网元可以确定第一数据包所对应的流量属于异常流量,然后数据分析网元可以向控制面功能网元或用户面功能网元发送流量异常通知,控制面功能网元或用户面功能网元接收到该流量异常通知之后,控制面功能网元或用户面功能网元发送流量异常通知还可以向终端设备转发该流量异常通知,详见前述实施例中对终端设备侧的举例说明。
在本申请实施例的一个可能设计中,除了执行前述的方法步骤之外,本申请实施例提供的流量处理方法还可以包括如下步骤:
数据分析网元接收终端设备发送的流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常;
数据分析网元根据流量异常应答更新终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
其中,终端设备接收到用户面功能网元发送的流量异常通知,终端设备可以显示该流量异常通知给用户,用户可以针对该流量异常通知作出响应,例如用户可以识别流量是否存在异常,用户可以通过终端设备向用户面功能网元发送流量异常应答,用户面功能网元还可以向数据分析网元发送流量异常应答,数据分析网元可以根据该流量异常应答确定是否存在流量异常,数据分析网元可以根据该流量异常应答更新热点开关打开期间允许使用的业务类型,从而可以更精确的识别出数据包是否属于异常流量。
通过前述实施例对本申请实施例提供的流量管理方法的说明可知,数据分析网元获取终端设备在热点开关打开期间允许使用或不允许使用的业务类型,数据分析网元接收用户面功能网元发送的第一数据包的特征参数,第一数据包是用户面功能网元在终端设备的热点开关打开期间获取到的数据包,数据分析网元根据第一数据包的特征参数确定第一数据包的业务类型,数据分析网元根据终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定第一数据包所对应的流量属于异常流量。本申请实施例中数据分析网元 可以从用户面功能网元获取到第一数据包的业务类型,通过终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,就可以确定第一数据包所对应的流量属于异常流量,从而可对异常流量进行精确识别,提高流量管理效果。
前述实施例从数据分析网元的角度描述了本申请实施例提供的一种流量处理方法,接下来从数据分析网元侧描述本申请实施例提供的另一种流量处理方法,请参阅图5所示,本申请实施例的流量处理方法,可以包括:
501、数据分析网元获取终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
在本申请实施例中,数据分析网元具体可以是前述的NWDAF网元,数据分析网元首先获取终端设备在热点开关打开期间允许使用的业务类型,或者数据分析网元获取终端设备在热点开关打开期间不允许使用的业务类型。例如:数据分析网元可以通过特征工程的方式获取到该业务类型,数据分析网元也可以通过终端设备获取到该业务类型。
在本申请实施例的一个可能设计中,步骤501数据分析网元获取终端设备在热点开关打开期间允许使用或不允许使用的业务类型,包括:
数据分析网元根据训练数据确定终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
502、数据分析网元向用户面功能网元或控制面功能网元发送终端设备在热点开关打开期间允许使用的业务类型。
在本发明实施例中,数据分析网元可以将终端设备在热点开关打开期间允许使用的业务类型发送给用户面功能网元或者控制面功能网元,使得用户面功能网元或者控制面功能网元可以确定出终端设备在热点开关打开期间允许使用的业务类型。
503、数据分析网元接收用户面功能网元发送的第一数据包的特征参数,第一数据包是用户面功能网元在终端设备的热点开关打开期间获取到的数据。
在本申请实施例中,特征参数是用于表示数据包的业务类型的参数,例如:该特征参数可以是特征向量,用户面功能网元具体可以通过特征工程的方式计算出第一数据包的特征参数,用户面功能网元还可以将第一数据包的特征参数发送给数据分析网元,例如用户面功能网元将第一数据包的特征参数发送给SMF网元,SMF网元再将第一数据包的特征参数发送给PCF网元,PCF网元再将该第一数据包的特征参数发送给NWDAF网元,NWDAF网元可以接收用户面功能网元发送的第一数据包的特征参数。
504、数据分析网元根据第一数据包的特征参数确定第一数据包的业务类型。
在本申请实施例中,数据分析网元可以通过业务类型识别模型来判断第一数据包的业务类型,例如:数据分析网元可以通过特征学习得到业务类型识别模型的特征列表,进而训练得到业务类型识别模型的模型参数,通过第一数据包的特征参数以及业务识别模型计算,从而可以确定出第一数据包的业务类型。
505、数据分析网元向用户面功能网元或控制面功能网元发送第一数据包的业务类型。
在本申请实施例中,数据分析网元在确定出第一数据包的业务类型之后,数据分析网元向用户面功能网元或控制面功能网元发送第一数据包的业务类型,从而用户面功能网元或控制面功能网元可以根据该第一数据包的业务类型和终端设备在热点开关打开期间允许 使用的业务类型进行匹配,从而用户面功能网元或控制面功能网元可以自行确定第一数据包所对应的流量是否属于异常流量。本申请实施例中数据分析网元可用于第一数据包的业务类型的判断,但是数据分析网元并不对流量异常情况进行判断,而是由用户面功能网元或控制面功能网元可以自行确定第一数据包所对应的流量是否属于异常流量。
前述实施例从数据分析网元的角度描述了本申请实施例提供的一种流量处理方法,接下来从控制面功能网元侧描述本申请实施例提供的一种流量处理方法,请参阅图6所示,本申请实施例提供的流量处理方法,可以包括:
601、控制面功能网元接收终端设备发送的热点指示信息,热点指示信息包括热点开关打开。
在本申请实施例中,控制面功能网元可以是5G系统中的SMF网元。终端设备是Wi-Fi热点的开启方,当用户打开热点开关时,终端设备生成热点指示信息,终端设备可以通过RAN向用户面功能网元发送热点指示信息,用户面功能网元向控制面功能网元转发该热点指示信息,控制面功能网元解析该热点指示信息确定终端设备的热点开关打开。
602、控制面功能网元接收用户面功能网元发送的第一数据包的特征参数,并将第一数据包的特征参数发送给数据分析网元,第一数据包是用户面功能网元在终端设备的热点开关打开期间获取到的数据。
在本申请实施例中,用户面功能网元在终端设备的热点开关打开期间传输数据,其中,用户面功能网元的数据传输可以分为上行传输以及下行传输。用户面功能网元在终端设备的热点开关打开期间获取到数据包之后,用户面功能网元还可以获取数据包的特征参数,例如可以获取第一数据包的特征参数。用户面功能网元将该第一数据包的特征参数发送给控制面功能网元,控制面功能网元可以再将第一数据包的特征参数转发给数据分析网元。
603、控制面功能网元确定第一数据包所对应的流量属于异常流量。
在本申请实施例中,控制面功能网元将第一数据包的特征参数发送给数据分析网元之后,控制面功能网元确定第一数据包所对应的流量属于异常流量。其中,控制面功能网元确定第一数据包所对应的流量属于异常流量可以有多种实现方式,接下来进行举例说明。
在本申请实施例的一个可能设计中,步骤603控制面功能网元确定第一数据包所对应的流量属于异常流量之后,本申请实施例提供的流量处理方法还包括:
控制面功能网元向终端设备发送流量异常通知,流量异常通知用于通知第一数据包所对应的流量属于异常流量。
其中,控制面功能网元可以向终端设备发送流量异常通知,终端设备可以解析该流量异常通知,通过该流量异常通知可以确定第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,控制面功能网元向终端设备发送流量异常通知,包括:
控制面功能网元在控制信令中携带流量异常通知。
其中,控制面功能网元可以采用控制信令的方式向终端设备发送流量异常通知,控制信令的具体消息不做限定。
在本申请实施例的一个可能设计中,步骤603控制面功能网元确定第一数据包所对应的流量属于异常流量,包括:
控制面功能网元从数据分析网元或用户面功能网元接收流量异常通知。
其中,控制面功能网元可以从数据分析网元或用户面网元接收流量异常通知,控制面功能网元解析该流量异常通知,通过该流量异常通知可以确定第一数据包所对应的流量属于异常流量。其中,数据分析网元可以使用第一数据包的特征参数识别该第一数据包的业务类型,再通过第一数据包的业务类型确定该第一数据包所对应的流量是否属于异常流量,并在第一数据包所应的流量属于异常流量时生成流量异常通知。
在本申请实施例的一个可能设计中,步骤603控制面功能网元确定第一数据包所对应的流量属于异常流量,包括:
控制面功能网元接收数据分析网元或终端设备发送的终端设备在热点开关打开期间允许使用或不允许使用的业务类型;
控制面功能网元接收数据分析网元发送的第一数据包的业务类型;
控制面功能网元根据终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定第一数据包所对应的流量属于异常流量。
其中,在前述步骤的实现场景下,控制面功能网元可以获取终端设备在热点开关打开期间允许使用的业务类型,或者控制面功能网元可以获取终端设备在热点开关打开期间不允许使用的业务类型。该业务类型可以由数据分析网元发送给控制面功能网元,或者由终端设备发送给控制面功能网元。数据分析网元可以使用第一数据包的特征参数识别该第一数据包的业务类型,再将第一数据包的业务类型发送给控制面功能网元。控制面功能网元可以使用前述步骤中获取到的业务类型确定该第一数据包所对应的流量是否属于异常流量。
在本申请实施例的一个可能设计中,步骤603控制面功能网元确定第一数据包所对应的流量属于异常流量之后,本申请实施例提供的流量处理方法还包括:
控制面功能网元通知用户面功能网元停止发送第一数据包所对应的流量,并缓存第一数据包所对应的流量。
其中,控制面功能网元确定第一数据包所对应的流量属于异常流量之后,控制面功能网元通知用户面功能网元可以按照第一数据包对应的IP五元组下的数据包进行缓存处理,其中,一个IP五元组对应的流量中可以包括多个数据包,用户面功能网元停止发送异常流量所对应的数据包,从而可以减少Wi-Fi热点开启方的流量损失。
在本申请实施例的一个可能设计中,本申请实施例提供的流量处理方法还包括:
控制面功能网元接收终端设备发送的流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常;
控制面功能网元根据流量异常应答确定第一数据包所对应的流量属于异常流量时,控制面功能网元通知用户面功能网元丢弃缓存的异常流量所对应的数据包;或者,
控制面功能网元根据流量异常应答确定第一数据包所对应的流量不属于异常流量时,控制面功能网元通知用户面功能网元转发缓存的异常流量所对应的数据包。
其中,终端设备接收到用户面功能网元发送的流量异常通知,终端设备可以显示该流量异常通知给用户,用户可以针对该流量异常通知作出响应,例如用户可以识别流量是否存在异常,用户可以通过终端设备向控制面功能网元发送流量异常应答,控制面功能网元 根据流量异常应答确定第一数据包所对应的流量属于异常流量时,控制面功能网元通知用户面功能网元丢弃缓存的异常流量所对应的数据包,从而可以减少Wi-Fi热点开启方的流量损失。在流量异常应答确定第一数据包所对应的流量不属于异常流量时,控制面功能网元通知用户面功能网元发送缓存的异常流量所对应的数据包,从而Wi-Fi热点开启方可以为Wi-Fi热点使用方提供流量。
在本申请实施例的一个可能设计中,本申请实施例提供的流量处理方法还包括:
控制面功能网元接收终端设备发送的流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常;
控制面功能网元向数据分析网元转发流量异常应答。
其中,终端设备接收到控制面功能网元发送的流量异常通知,终端设备可以显示该流量异常通知给控制,控制可以针对该流量异常通知作出响应,例如控制可以识别流量是否存在异常,控制可以通过终端设备向控制面功能网元发送流量异常应答,控制面功能网元还可以向数据分析网元发送流量异常应答,数据分析网元可以根据该流量异常应答确定是否存在流量异常,数据分析网元可以根据该流量异常应答更新热点开关打开期间允许使用的业务类型,从而可以更精确的识别出数据包所属的业务类型,为异常流量的分析提供准确的业务类型。
通过前述实施例对本申请实施例提供的流量管理方法的举例说明可知,本申请实施例中控制面功能网元可以从用户面功能网元获取到第一数据包的业务类型,通过终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,就可以确定第一数据包所对应的流量属于异常流量,从而可对异常流量进行精确识别,提高流量管理效果。
为便于更好的理解和实施本申请实施例的上述方案,下面举例相应的应用场景来进行具体说明。
如图7所示,为5G系统中多个网元之间的一种交互UE Hotspot Off开启/关闭状态流程示意图,这里交互流程以UE发起的PDU Session Establishment/Modification流程为例进行说明,另外该流程也可以是UE发起的Service Request/Registration流程,此处不再赘述。主要包括如下步骤:
701、UE发送会话管理请求消息给SMF网元。
例如,UE作为Wi-Fi热点开启方,UE将UE Hotspot Off开启/关闭状态或其他特定模式开启/关闭状态上报给网络,可选地,与此同时UE也会将在UE Hotspot Off开启期间不允许使用的业务类型上报给网络,后续描述中均以热点开启状态为例描述。例如,在会话建立/修改流程中将热点状态信息通知给SMF网元,可以通过RAN-AMF-SMF在会话管理请求消息(PDU session establishment/modification request)中携带,各段的消息名称有差别,但都是为了建立或修改会话。
702、SMF网元将会话管理请求消息发送给UPF网元。
举例说明,SMF将热点状态信息通知给UPF网元,可以通过会话管理请求消息(N4session establishment/modification request)中携带。
通过前述步骤701和702,SMF网元和UPF网元均获得UE当前的热点状态信息。
703、UPF网元将UE在热点开启器件的数据包的数据特征上报给NWDAF网元。
其中,NWDAF网元作为数据流量异常判定的网元,NWDAF网元会针对Hotspot开启时间内的业务数据包,收集数据特征作为训练数据,比如:UE ID/IP、时间/周期、数据包大小/数量、扩展字段。
704、NWDAF网元通过大数据分析,得到UE开启热点期间允许或不允许的业务类型列表。
NWDAF网元针对每个UE进行大数据分析,假设业务类型判别的行为或模型,学习得到业务类型判别模型的特征列表,并将模型对应的特征列表同步到NWDAF网元与UPF网元上的特征工程中。该特征向量中的特征列表,可以理解为参数名。而UPF网元上报给NWDAF网元的特征向量则是参数值。通过训练NWDAF网元得到UE处于特定状态(hotspot开启状态)下允许(或不允许)的业务类型列表。
705、UPF网元判定UE当前热点开启,收集实时数据包,计算得到业务类型分类模型对应的特征向量。
UPF网元在Hotspot开启情况下,接收新的数据包,根据本地特征工程计算特征向量。
706、UPF网元向NWDAF网元发送异常流量检测请求。
UPF网元通过SMF网元以及PCF网元将计算得到的特征向量上报给NWDAF网元,请求NWDAF网元对数据业务类型进行判别。
707、NWDAF网元根据特征向量得到业务类型,判断该数据包对应的业务是否允许的业务类型列表,如果不在则判定为Wi-Fi热点异常流量。
NWDAF网元根据特征向量得到当前数据的业务类型,与前述步骤中训练得到的业务类型列表比对,判定当前数据包对应的业务数据流是否属于异常流量。
708、NWDAF网元向UPF网元发送Wi-Fi热点异常流量指示。
NWDAF网元判定当前数据业务为异常流量之后,经PCF网元转发异常流量指示给SMF网元和UPF网元。
其中,PCF网元可以根据NWDAF网元的分析结果,结合UE状态以及NWDAF网元的异常流量指示,决定向SMF网元或者UPF网元向UE发出指示,比如PCF网元中的策略要求对Wi-Fi热点开启状态下的异常流量指示信息通过控制信令的方式通知UE,那么PCF网元会指示SMF网元按照方式A执行;或者按照方式B执行。当然如果本来就只有一种策略,则没有策略选择的问题,但是也需要从PCF网元获知用什么策略。
其中,一种可实现的方式A包括:
709、SMF从NWDAF得知热点开启期间,存在Wi-Fi热点异常流量行为,决定告警UE。
710、Wi-Fi热点异常流量指示。
SMF网元接收到NWDAF网元下发的异常流量指示之后,判定当前UE存在疑似数据包异常,告警UE。SMF网元向UE发起告警,携带异常流量指示。
一种可实现的方式B包括:
711、SMF从NWDAF得知热点开启期间,存在Wi-Fi热点异常流量行为,决定告警UE。
712、Wi-Fi热点异常流量指示。
UPF网元接收到NWDAF网元下发的异常流量指示之后,得知当前UE存在疑似数据包异常,告警UE。UPF网元向UE发起告警,携带异常流量指示。
具体地,UPF网元可以发送一个特定的异常流量指示的数据包,通过数据包头中携带异 常流量指示信息,比如报文中包括异常流量指示字段,或者在标准字段之外的扩展字段中添加异常流量指示信息。UE收到报文之后能够从包头中获得异常流量指示信息。报文可以是与当前业务数据独立的报文,也可以是在当前业务的数据报文。
本申请实施例对UE接收到异常流量指示信息之后的处理并不限定,可以是确定异常关闭Wi-Fi热点、确定某个Wi-Fi热点使用者关闭该使用者的连接、暂时禁用某个业务类型等。
通过本实施例的方案,NWDAF网元能够实时监测Wi-Fi热点开启方的业务状况,对数据特征分析得到该数据的业务类型,并且根据训练所得的当前状态下允许/不允许的业务类型列表判定当前业务是否可能为异常流量,并将NWDAF网元的判定结果发送给数据转发控制网元和数据转发网元,由它们决定向UE发起异常流量指示,并由UE决定后续操作。
与现有技术相比,本申请实施例摆脱了人为设置的方式或者是在现有人为设置的基础上增加了网络分析并指示的方式。对处于特定状态下的用户,网络中的数据分析网元通过对数据业务的分析,获得业务类型,与训练所得的该状态下允许/不允许的业务类型列表比对给出判定,即当前状态下该业务类型的数据是否为异常流量,并发送给网络中数据处理相关的网元(例如SMF网元、UPF网元),再由数据处理相关的网元向UE发出异常流量指示。
如图8所示,接下来介绍本申请实施例提供的另一种5G系统中的多个网元之间的交互流程,主要包括如下过程:
801、UE发送会话管理请求消息给SMF网元。
802、SMF网元将会话管理请求消息发送给UPF网元。
803、UPF网元将UE在热点开启器件的数据包的数据特征上报给NWDAF网元。
804、NWDAF网元通过大数据分析,得到UE开启热点期间允许或不允许的业务类型列表。805、UPF网元判定UE当前热点开启,收集实时数据包,计算得到业务类型分类模型对应的特征向量。
806、UPF网元向NWDAF网元发送异常流量检测请求。
807、NWDAF网元根据特征向量得到业务类型,判断该数据包对应的业务是否允许的业务类型列表,如果不在则判定为Wi-Fi热点异常流量。
808、NWDAF网元向UPF网元发送Wi-Fi热点异常流量指示。
其中,步骤801至步骤808与图7所示的实施例在NWDAF相关的处理流程中步骤701至步骤708相同。
步骤808执行之后,可以有如下方式A和方式B两种实现方式。
方式A:控制信令的方式,包括步骤809至步骤814。
809、UPF网元暂停下发并缓存数据包。
810、UPF网元向SMF网元发送Wi-Fi-热点异常指示。
811、SMF网元暂停下发并缓存数据包。
812、SMF网元向UE发送Wi-Fi热点异常流量指示。
813、UE向SMF网元指示是否为异常流量。
814、SMF网元向UPF网元发送Wi-Fi热点异常确认信息。
其中,UPF网元在收到NWDAF网元下发的异常流量指示信息之后,除了决定向UE发起告警外,还包括暂停下发并缓存当前业务数据。由于本实施例涉及到UPF网元收到NWDAF网元 发送的异常流量指示信息之后需要对业务数据作一定的控制,UPF网元对该业务数据暂停下发并缓存。如果是UPF网元决定是否发起告警,那么UPF网元还需要指示SMF网元向UE发送异常流量指示信息。另一种情况是,SMF网元收到了NWDAF网元发送的异常流量指示信息后向UE发出告警,而UPF网元收到NWDAF网元的异常流量指示信息后对数据暂停下发并缓存。UE通过信令消息反馈异常流量确认信息,结果为是/否。
方式B:数据报文的方式,包括如下步骤815至步骤818。
815、UPF从NWDAF得知热点开启期间,存在Wi-Fi热点异常流量行为,UPF暂停下发,并缓存该业务的数据包,决定告警UE。
816、UPF网元向UE发送Wi-Fi热点异常流量指示。
817、UE向UPF网元发送是否为异常流量。
818、UPF网元向SMF网元发送是否为异常流量。
其中,UPF网元在收到NWDAF网元下发的异常流量指示信息之后,除了决定向UE发起告警外,还包括暂停下发并缓存当前业务数据。UE通过数据报文的方式反馈异常流量确认信息,结果为是/否。UPF网元需要将确认信息上报给SMF网元。
819、若不是,UPF网元从UE反馈结果判定当前数据包非异常,将缓存的数据包下发。
如果UE反馈当前告警的业务并未异常流量,那么将缓存的数据下发。
820、若是,UPF网元从UE反馈结果判当前数据包确实异常,丢弃IP五元组对应的所有的数据包。
如果UE反馈当前告警的业务确实是异常流量,那么UPF网元丢弃缓存的该业务数据。
821、SMF网元向NWDAF网元发送是否为异常流量。
822、NWDAF网元进行异常流量判别矫正,更新允许业务列表。
其中,UPF网元/SMF网元收到UE反馈后,UPF网元/SMF网元通过上报方式给NWDAF网元一个反馈,即当前业务类型对当前UE来说并不是异常流量,用于矫正NWDAF网元对异常流量的判定条件,最直接的方式,将该业务类型添加到热点开启期间允许的类型列表中;或者在判定业务类型的算法中添加该业务的特征及分类结果,作为训练数据更新特征列表。
本实施例在图7所示实施例的基础上,增加了UPF网元在接收到NWDAF网元的异常流量指示信息之后对数据报文的处理,并且能够同时考察NWDAF网元的异常流量判断以及UE对异常流量指示的确认,避免NWDAF网元异常流量判断不准确带来的问题。并且能够根据UE的确认信息的反馈,NWDAF网元更新和修正业务类型判别模型或该状态下允许/不允许的业务类型列表。
本实施例与图7所示实施例的区别在于,SMF网元/UPF网元不只是依据NWDAF网元的指示信息判定当前数据业务异常,在NWDAF网元下发异常指示的情况下,向UE发送指示信息,并以UE的确认消息作为最终结果。在UPF网元收到NWDAF网元的异常指示并未收到UE的确认信息的这段时间,UPF网元对该业务数据作出暂停下发并缓存的处理,收到确认信息之后决定继续转发或者丢弃该业务数据。SMF/UPF将UE的确认信息上报给NWDAF网元,使其对异常流量判定作出矫正,更新业务列表。
如图9所示,为本申请实施例提供的另一种5G系统中的多个网元之间的交互流程,主要包括如下步骤:
901、UE向SMF网元发送支持Wi-Fi热点开启条件下运行的业务类型列表。
902、SMF网元向UPF网元发送支持Wi-Fi热点开启条件下运行的业务类型列表。
其中,UE将热点状态、该状态下的允许或者不允许运行的业务类型列表,例如:仅支持WLAN开启条件下运行的业务类型列表等发送给网络,或者WLAN开启条件下不支持的业务类型列表发送给网络。
其中,允许的业务类型列表可选。如果是SMF网元决定是否为异常流量那么就不用将业务类型列表信息发送给UPF网元;如果是UPF网元决定是否为异常流量那么就需要将业务类型列表发送给UPF网元。状态和列表不要求必须在同一条消息中发送。状态和列表都可以是用户开启热点的时候在会话修改流程中发送,但是热点开启状态下允许的业务列表却可以作为UE的能力在会话创建流程发送给网络。
903、UPF网元判定UE当前热点开启,收集实时数据包,计算得到业务类型分类模型对应的特征向量。UPF网元将数据的特征向量上报给NWDAF网元。
904、UPF网元向NWDAF网元发送业务类型请求。
905、NWDAF网元根据特征向量得到业务类型。
NWDAF网元根据UPF网元上报的特征向量分析得到数据的业务类型。
906、NWDAF网元向UPF网元发送业务类型响应。
NWDAF网元将分析结果发送到SMF网元或UPF网元。
907、UPF网元从NWDAF网元得知热点开启期间,实时数据包的业务类型,判定业务类型不在支持Wi-Fi热点开启条件下运行的业务类型列表中,决定告警UE。
例如,通过控制信令的方式通知UE目前存在异常流量,同图8所示实施例中方式A。又如,通过数据报文的方式通知UE目前存在异常流量,同图8所示实施例中方式B。
本实施例通过UE上报的方式让网络侧数据处理相关的网元知道特定状态(Wi-Fi热点开启状态等)下允许/不允许的业务类型列表,并且通过NWDAF网元实施分析当前数据的业务类型并反馈给数据处理相关的网元,从而可以判定当前业务数据是否为异常流量,并向UE发出异常流量指示,UE可以做进一步的处理。
本实施例与图7所示实施例的区别在于,UE预先将支持Wi-Fi热点开启状态下允许的业务类型列表发送给网络(例如,SMF网元/UPF网元),当接收到NWDAF网元分析得到的当前数据的业务类型信息后,能够在SMF或UPF判定当前数据业务是否为异常流量,如果是则向UE发出告警。
为便于更好的实施本申请实施例的上述方案,下面还提供用于实施上述方案的相关装置。
请参阅图10-a所示,本申请实施例提供的一种用户面装置1000,可以包括:接收模块1001、获取模块1002、确定模块1003,其中,
接收模块1001,用于接收终端设备发送的热点指示信息,热点指示信息包括热点开关打开;
获取模块1002,用于获取第一数据包的特征参数,并将第一数据包的特征参数发送给数据分析网元,第一数据包是用户面装置在终端设备的热点开关打开期间获取到的数据;
确定模块1003,用于确定第一数据包所对应的流量属于异常流量。
在本申请的一些实施例中,如图10-b所示,用户面装置1000还包括:发送模块1004,其中,
发送模块1004,用于确定模块1003确定第一数据包所对应的流量属于异常流量之后,向终端设备发送流量异常通知,流量异常通知用于通知第一数据包所对应的流量属于异常流量。
在本申请的一些实施例中,发送模块1003,具体用于在数据报文中携带流量异常通知。
在本申请的一些实施例中,确定模块1003,具体用于从数据分析网元或控制面网元接收流量异常通知。
在本申请的一些实施例中,确定模块1003,包括:
接收子模块10031,用于接收数据分析网元或终端设备发送的终端设备在热点开关打开期间允许使用或不允许使用的业务类型;接收数据分析网元发送的第一数据包的业务类型;
异常流量确定子模块10032,用于根据终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定第一数据包所对应的流量属于异常流量。
在本申请的一些实施例中,如图10-c所示,用户面装置1000还包括:流量缓存模块1005,用于确定模块1003确定第一数据包所对应的流量属于异常流量之后,停止发送异常流量所对应的数据包,并缓存异常流量所对应的数据包。
在本申请的一些实施例中,如图10-d所示,用户面装置1000还包括:流量处理模块1006,其中,
接收模块1001,还用于接收终端设备发送的流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常;
流量处理模块1006,用于根据流量异常应答确定第一数据包所对应的流量属于异常流量时,丢弃用户面装置缓存的异常流量所对应的数据包;或者,根据流量异常应答确定第一数据包所对应的流量不属于异常流量时,发送用户面装置缓存的异常流量所对应的数据包。
在本申请的一些实施例中,如图10-b所示,用户面装置还包括:发送模块1004,其中,
接收模块1001,还用于接收终端设备发送的流量异常应答,流量异常应答包括:存在流量异常或者不存在流量异常;
发送模块1003,还用于向数据分析网元发送流量异常应答。
请参阅图11-a所示,本申请实施例一种终端设备1100,包括:发送模块1101,用于向核心网网元发送热点指示信息,所述热点指示信息包括热点开关打开;获取模块1102,用于获取所述核心网网元根据所述热点指示信息发送的流量异常通知。
在本申请实施例的一个可能设计中,所述发送模块1101,还用于向所述核心网网元发送所述终端设备在所述热点开关打开期间不允许使用或者允许使用的业务类型。具体的,终端设备向核心网网元上报的时候,可以在其向核心网网元发送第一次Wi-Fi热点(hotspot)信息的时候,携带终端在Wi-Fi hotspot开启期间不允许使用的业务类型或者允许使用的业务类型。
在本申请实施例的一个可能设计中,所述发送模块1101,还用于所述获取模块1102获取所述核心网网元根据热点指示信息发送的流量异常通知之后,向所述核心网网元发送流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常。
在本申请实施例的一个可能设计中,如图11-b所示,所述终端设备1100,还包括:异常处理模块1103,用于所述获取模块1102获取所述核心网网元根据热点指示信息发送的流量异常通知之后,根据所述流量异常通知关闭热点;或者,关闭产生异常流量的热点使用者的连接;或者,禁止产生异常流量的业务类型使用热点。
在本申请实施例的一个可能设计中,所述核心网网元包括:控制面功能网元、用户面功能网元、策略网元和数据分析网元中的至少一种。
通过前述实施例对本申请实施例提供的流量管理方法的说明可知,终端设备向核心网网元发送热点指示信息,终端设备获取核心网网元根据热点指示信息发送的流量异常通知,使得终端设备可以通过该流量异常通知确定出哪些数据包对应的流量属于异常流量。
如图12-a所示,本申请实施例还提供一种数据分析网元1200,所述数据分析网元1200包括:
获取模块1201,用于获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型;
接收模块1202,用于接收用户面功能网元发送的第一数据包的特征参数,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据包;
业务类型确定模块1203,用于根据所述第一数据包的特征参数确定所述第一数据包的业务类型;
异常流量确定模块1204,用于根据所述终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,如图12-b所示,所述数据分析网元1200,还包括:发送模块1203,用于所述异常流量确定模块1202确定所述第一数据包所对应的流量属于异常流量之后,向控制面功能网元或所述用户面功能网元发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,所述获取模块1201,具体用于根据训练数据确定所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;或者,接收所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
在本申请实施例的一个可能设计中,所述接收模块1202,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述数据分析网元根据所述流量异常应答更新所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
如图13所示,本申请实施例还提供一种数据分析网元1300,包括:
获取模块1301,用于获取终端设备在无线保真热点开关打开期间允许使用或不允许使用的业务类型;
发送模块1302,用于向用户面功能网元或控制面功能网元发送所述终端设备在热点开关打开期间允许使用的业务类型;
接收模块1303,用于接收所述用户面功能网元发送的第一数据包的特征参数,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;
业务类型确定模块1304,用于根据所述第一数据包的特征参数确定所述第一数据包的业务类型;
所述发送模块1302,还用于向所述用户面功能网元或所述控制面功能网元发送所述第一数据包的业务类型。
在本申请实施例的一个可能设计中,所述获取模块1301,具体用于根据训练数据确定所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型。
通过前述实施例对本申请实施例提供的数据分析网元的举例说明可知,本申请实施例中数据分析网元可以从用户面功能网元获取到第一数据包的业务类型,通过终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,就可以确定第一数据包所对应的流量属于异常流量,从而可对异常流量进行精确识别,提高流量管理效果。
请参阅图14所示,本申请实施例提供一种控制面功能网元1400,包括:
接收模块1401,用于接收终端设备发送的热点指示信息,所述热点指示信息包括终端设备的热点开关打开;
所述接收模块1401,还用于接收用户面功能网元发送的第一数据包的特征参数;
发送模块1402,用于将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;
异常流量确定模块1403,用于确定所述第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,所述发送模块1402,还用于所述异常流量确定模块1403确定所述第一数据包所对应的流量属于异常流量之后,向所述终端设备发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,所述发送模块1402,具体用于在控制信令中携带所述流量异常通知。具体的,该控制信令可以使用但不限于如下举例的两种流程消息,一种是网络侧发起的Service Request流程,通过Paging消息携带流量异常通知发给UE,另外是网络侧发起的PDU Session Modification流程,通过PDU Session Modification Accept消息携带流量异常通知发给UE。
在本申请实施例的一个可能设计中,所述异常流量确定模块1403,具体用于从所述数据分析网元或所述用户面功能网元接收流量异常通知。
在本申请实施例的一个可能设计中,所述异常流量确定模块1403,具体用于接收所述数据分析网元或所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;根据所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,所述异常流量确定模块1403,具体用于接收所述终端设备发送的所述终端设备在所述热点开关打开期间允许使用或者不允许使用的业务类型;接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;根据所述终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,确定所述第一数据包 所对应的流量属于异常流量。
在本申请实施例的一个可能设计中,所述发送模块1402,还用于所述异常流量通知模块确定所述第一数据包所对应的流量属于异常流量之后,通知所述用户面功能网元停止发送所述第一数据包所对应的流量,并缓存所述第一数据包所对应的流量。
在本申请实施例的一个可能设计中,所述接收模块1401,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述发送模块还用于根据所述流量异常应答确定所述第一数据包所对应的流量属于异常流量时,通知所述用户面功能网元丢弃缓存的异常流量所对应的数据包;或者,根据所述流量异常应答确定所述第一数据包所对应的流量不属于异常流量时,通知所述用户面功能网元转发缓存的异常流量所对应的数据包。
在本申请实施例的一个可能设计中,所述接收模块1401,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;所述控制面功能网元向所述数据分析网元转发所述流量异常应答。
通过前述实施例对本申请实施例提供的控制面功能网元的举例说明可知,本申请实施例中控制面功能网元可以从用户面功能网元获取到第一数据包的业务类型,通过终端设备在热点开关打开期间允许使用或者不允许使用的业务类型,就可以确定第一数据包所对应的流量属于异常流量,从而可对异常流量进行精确识别,提高流量管理效果。
需要说明的是,上述装置各模块/单元之间的信息交互、执行过程等内容,由于与本申请实施例方法实施例基于同一构思,其带来的技术效果与本申请实施例方法实施例相同,具体内容可参见本申请实施例前述所示的方法实施例中的叙述,此处不再赘述。
本申请实施例还提供一种计算机存储介质,其中,该计算机存储介质存储有程序,该程序执行包括上述方法实施例中记载的部分或全部步骤。
接下来介绍本申请实施例提供的另一种用户面装置,请参阅图15所示,用户面装置1500包括:
接收器1501、发射器1502、处理器1503和存储器1504(其中用户面装置1500中的处理器1503的数量可以一个或多个,图15中以一个处理器为例)。在本申请实施例的一些实施例中,接收器1501、发射器1502、处理器1503和存储器1504可通过总线或其它方式连接,其中,图15中以通过总线连接为例。
存储器1504可以包括只读存储器和随机存取存储器,并向处理器1503提供指令和数据。存储器1504的一部分还可以包括非易失性随机存取存储器(英文全称:Non-Volatile Random Access Memory,英文缩写:NVRAM)。存储器1504存储有操作系统和操作指令、可执行模块或者数据结构,或者它们的子集,或者它们的扩展集,其中,操作指令可包括各种操作指令,用于实现各种操作。操作系统可包括各种系统程序,用于实现各种基础业务以及处理基于硬件的任务。
处理器1503控制用户面装置的操作,处理器1503还可以称为中央处理单元(英文全称:Central Processing Unit,英文简称:CPU)。具体的应用中,用户面装置的各个组件通过总线系统耦合在一起,其中总线系统除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图15中将各种总线都称为总线系统。
上述本申请实施例揭示的方法可以应用于处理器1503中,或者由处理器1503实现。处理器1503可以是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器1503中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器1503可以是通用处理器、数字信号处理器(英文全称:digital signal processing,英文缩写:DSP)、专用集成电路(英文全称:Application Specific Integrated Circuit,英文缩写:ASIC)、现场可编程门阵列(英文全称:Field-Programmable Gate Array,英文缩写:FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器1504,处理器1503读取存储器1504中的信息,结合其硬件完成上述方法的步骤。
接收器1501可用于接收输入的数字或字符信息,以及产生与用户面装置的相关设置以及功能控制有关的信号输入,发射器1502可包括显示屏等显示设备,发射器1502可用于通过外接接口输出数字或字符信息。
本申请实施例中,接收器1501和发射器1502用于实现数据收发。处理器1503,用于通过接收器1501和发射器1502实现数据收发,完成前述用户面功能网元所执行的数据处理过程。
接下来介绍本发明实施例提供的另一种终端设备,请参阅图16所示,终端设备1600包括:
接收器1601、发射器1602、处理器1603和存储器1604(其中终端设备1600中的处理器1603的数量可以一个或多个,图16中以一个处理器为例)。在本发明的一些实施例中,接收器1601、发射器1602、处理器1603和存储器1604可通过总线或其它方式连接,其中,图16中以通过总线连接为例。
存储器1604可以包括只读存储器和随机存取存储器,并向处理器1603提供指令和数据。存储器1604的一部分还可以包括NVRAM。存储器1604存储有操作系统和操作指令、可执行模块或者数据结构,或者它们的子集,或者它们的扩展集,其中,操作指令可包括各种操作指令,用于实现各种操作。操作系统可包括各种系统程序,用于实现各种基础业务以及处理基于硬件的任务。
处理器1603控制终端设备的操作,处理器1603还可以称为CPU。具体的应用中,终端设备的各个组件通过总线系统耦合在一起,其中总线系统除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都称为总线系统。
上述本发明实施例揭示的方法可以应用于处理器1603中,或者由处理器1603实现。处理器1603可以是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器1603中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器1603可以是通用处理器、DSP、ASIC、FPGA或者其他可编程逻辑器件、分立门或者晶 体管逻辑器件、分立硬件组件。可以实现或者执行本发明实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本发明实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器1604,处理器1603读取存储器1604中的信息,结合其硬件完成上述方法的步骤。
接收器1601和发射器1602用于实现数据收发。处理器1603,用于通过接收器1601和发射器1602实现数据收发,完成前述终端设备所执行的数据处理过程。
接下来介绍本发明实施例提供的另一种数据分析网元,请参阅图17所示,数据分析网元1700包括:
接收器1701、发射器1702、处理器1703和存储器1704(其中数据分析网元1700中的处理器1703的数量可以一个或多个,图17中以一个处理器为例)。在本发明的一些实施例中,接收器1701、发射器1702、处理器1703和存储器1704可通过总线或其它方式连接,其中,图17中以通过总线连接为例。
存储器1704可以包括只读存储器和随机存取存储器,并向处理器1703提供指令和数据。存储器1704的一部分还可以包括NVRAM。存储器1704存储有操作系统和操作指令、可执行模块或者数据结构,或者它们的子集,或者它们的扩展集,其中,操作指令可包括各种操作指令,用于实现各种操作。操作系统可包括各种系统程序,用于实现各种基础业务以及处理基于硬件的任务。
处理器1703控制数据分析网元的操作,处理器1703还可以称为CPU。具体的应用中,数据分析网元的各个组件通过总线系统耦合在一起,其中总线系统除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都称为总线系统。
上述本发明实施例揭示的方法可以应用于处理器1703中,或者由处理器1703实现。处理器1703可以是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器1703中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器1703可以是通用处理器、DSP、ASIC、FPGA或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本发明实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本发明实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器1704,处理器1703读取存储器1704中的信息,结合其硬件完成上述方法的步骤。
接收器1701和发射器1702用于实现数据收发。处理器1703,用于通过接收器1701和发射器1702实现数据收发,完成前述数据面分析网元所执行的数据处理过程。
接下来介绍本发明实施例提供的另一种控制面功能网元,请参阅图18所示,控制面功 能网元1800包括:
接收器1801、发射器1802、处理器1803和存储器1804(其中控制面功能网元1800中的处理器1803的数量可以一个或多个,图18中以一个处理器为例)。在本发明的一些实施例中,接收器1801、发射器1802、处理器1803和存储器1804可通过总线或其它方式连接,其中,图18中以通过总线连接为例。
存储器1804可以包括只读存储器和随机存取存储器,并向处理器1803提供指令和数据。存储器1804的一部分还可以包括NVRAM。存储器1804存储有操作系统和操作指令、可执行模块或者数据结构,或者它们的子集,或者它们的扩展集,其中,操作指令可包括各种操作指令,用于实现各种操作。操作系统可包括各种系统程序,用于实现各种基础业务以及处理基于硬件的任务。
处理器1803控制控制面功能网元的操作,处理器1803还可以称为CPU。具体的应用中,控制面功能网元的各个组件通过总线系统耦合在一起,其中总线系统除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都称为总线系统。
上述本发明实施例揭示的方法可以应用于处理器1803中,或者由处理器1803实现。处理器1803可以是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器1803中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器1803可以是通用处理器、DSP、ASIC、FPGA或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本发明实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本发明实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器1804,处理器1803读取存储器1804中的信息,结合其硬件完成上述方法的步骤。
接收器1801和发射器1802用于实现数据收发。处理器1803,用于通过接收器1801和发射器1802实现数据收发,完成前述控制面功能网元所执行的数据处理过程。
另外需说明的是,以上所描述的装置实施例仅仅是示意性的,其中所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。另外,本申请实施例提供的装置实施例附图中,模块之间的连接关系表示它们之间具有通信连接,具体可以实现为一条或多条通信总线或信号线。
通过以上的实施方式的描述,所属领域的技术人员可以清楚地了解到本申请实施例可借助软件加必需的通用硬件的方式来实现,当然也可以通过专用硬件包括专用集成电路、专用CPU、专用存储器、专用元器件等来实现。一般情况下,凡由计算机程序完成的功能都可以很容易地用相应的硬件来实现,而且,用来实现同一功能的具体硬件结构也可以是多种多样的,例如模拟电路、数字电路或专用电路等。但是,对本申请实施例而言更多情 况下软件程序实现是更佳的实施方式。基于这样的理解,本申请实施例的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在可读取的存储介质中,如计算机的软盘、U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请实施例各个实施例所述的方法。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。
所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存储的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,DVD)、或者半导体介质(例如固态硬盘Solid State Disk(SSD))等。

Claims (30)

  1. 一种流量处理方法,其特征在于,所述方法包括:
    用户面功能网元接收终端设备发送的热点指示信息,所述热点指示信息包括热点开关打开;
    所述用户面功能网元获取第一数据包的特征参数,并将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面功能网元在所述终端设备的热点开关打开期间获取到的数据;
    所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量。
  2. 根据权利要求1所述的方法,其特征在于,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量之后,所述方法还包括:
    所述用户面功能网元向所述终端设备发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
  3. 根据权利要求2所述的方法,其特征在于,所述用户面功能网元向所述终端设备发送流量异常通知,包括:
    所述用户面功能网元在数据报文中携带所述流量异常通知。
  4. 根据权利要求1所述的方法,其特征在于,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量,包括:
    所述用户面功能网元从所述数据分析网元或控制面网元接收流量异常通知。
  5. 根据权利要求1所述的方法,其特征在于,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量,包括:
    所述用户面功能网元接收所述数据分析网元或所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;
    所述用户面功能网元接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;
    所述用户面功能网元根据所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
  6. 根据权利要求1所述的方法,其特征在于,所述用户面功能网元确定所述第一数据包所对应的流量属于异常流量之后,所述方法还包括:
    所述用户面功能网元停止发送所述异常流量所对应的数据包,并缓存所述异常流量所对应的数据包。
  7. 根据权利要求6所述的方法,其特征在于,所述方法还包括:
    所述用户面功能网元接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;
    所述用户面功能网元根据所述流量异常应答确定所述第一数据包所对应的流量属于异常流量时,丢弃所述用户面功能网元缓存的异常流量所对应的数据包;或者,
    所述用户面功能网元根据所述流量异常应答确定所述第一数据包所对应的流量不属于异常流量时,发送所述用户面功能网元缓存的异常流量所对应的数据包。
  8. 根据权利要求1至7中任一项所述的方法,其特征在于,所述方法还包括:
    所述用户面功能网元接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;
    所述用户面功能网元向所述数据分析网元发送所述流量异常应答。
  9. 一种流量处理方法,其特征在于,所述方法包括:
    终端设备向核心网网元发送热点指示信息,所述热点指示信息包括终端设备的热点开关打开;
    所述终端设备获取所述核心网网元根据所述热点指示信息发送的流量异常通知。
  10. 根据权利要求9所述的方法,其特征在于,所述方法还包括:
    所述终端设备向所述核心网网元发送所述终端设备在所述热点开关打开期间不允许使用或者允许使用的业务类型。
  11. 根据权利要求9所述的方法,其特征在于,所述终端设备获取所述核心网网元根据热点指示信息发送的流量异常通知之后,所述方法还包括:
    所述终端设备向所述核心网网元发送流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常。
  12. 根据权利要求9所述的方法,其特征在于,所述终端设备获取所述核心网网元根据热点指示信息发送的流量异常通知之后,所述方法还包括:
    所述终端设备根据所述流量异常通知所述终端设备的热点;或者,
    所述终端设备关闭产生异常流量的热点使用者的连接;或者,
    所述终端设备禁止产生异常流量的业务类型使用所述终端设备的热点。
  13. 根据权利要求9所述的方法,其特征在于,所述核心网网元包括:控制面功能网元、用户面功能网元、策略网元和数据分析网元中的至少一种。
  14. 一种用户面装置,其特征在于,所述用户面装置包括:
    接收模块,用于接收终端设备发送的热点指示信息,所述热点指示信息包括热点开关打开;
    获取模块,用于获取第一数据包的特征参数,并将所述第一数据包的特征参数发送给数据分析网元,所述第一数据包是所述用户面装置在所述终端设备的热点开关打开期间获取到的数据;
    确定模块,用于确定所述第一数据包所对应的流量属于异常流量。
  15. 根据权利要求14所述的用户面装置,其特征在于,所述用户面装置还包括:发送模块,其中,
    所述发送模块,用于所述确定模块确定所述第一数据包所对应的流量属于异常流量之后,向所述终端设备发送流量异常通知,所述流量异常通知用于通知所述第一数据包所对应的流量属于异常流量。
  16. 根据权利要求15所述的用户面装置,其特征在于,所述发送模块,具体用于在数据报文中携带所述流量异常通知。
  17. 根据权利要求14所述的用户面装置,其特征在于,所述确定模块,具体用于从所述数据分析网元或控制面网元接收流量异常通知。
  18. 根据权利要求14所述的用户面装置,其特征在于,所述确定模块,包括:
    接收子模块,用于接收所述数据分析网元或所述终端设备发送的所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型;接收所述数据分析网元或所述终端设备发送的所述第一数据包的业务类型;
    异常流量确定子模块,用于根据所述终端设备在热点开关打开期间允许使用或不允许使用的业务类型,确定所述第一数据包所对应的流量属于异常流量。
  19. 根据权利要求14所述的用户面装置,其特征在于,所述用户面装置还包括:流量缓存模块,用于所述确定模块确定所述第一数据包所对应的流量属于异常流量之后,停止发送所述异常流量所对应的数据包,并缓存所述异常流量所对应的数据包。
  20. 根据权利要求19所述的用户面装置,其特征在于,所述用户面装置还包括:流量处理模块,其中,
    所述接收模块,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;
    所述流量处理模块,用于根据所述流量异常应答确定所述第一数据包所对应的流量属于异常流量时,丢弃所述用户面装置缓存的异常流量所对应的数据包;或者,根据所述流量异常应答确定所述第一数据包所对应的流量不属于异常流量时,发送所述用户面装置缓存的异常流量所对应的数据包。
  21. 根据权利要求14至20中任一项所述的用户面装置,其特征在于,所述用户面装置还包括:发送模块,其中,
    所述接收模块,还用于接收所述终端设备发送的流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常;
    所述发送模块,用于向所述数据分析网元发送所述流量异常应答。
  22. 一种终端设备,其特征在于,所述终端设备包括:
    发送模块,用于向核心网网元发送热点指示信息,所述热点指示信息包括所述终端设备的热点开关打开;
    获取模块,用于获取所述核心网网元根据所述热点指示信息发送的流量异常通知。
  23. 根据权利要求22所述的终端设备,其特征在于,所述发送模块,还用于向所述核心网网元发送所述终端设备在所述热点开关打开期间不允许使用或者允许使用的业务类型。
  24. 根据权利要求22所述的终端设备,其特征在于,所述发送模块,还用于所述获取模块获取所述核心网网元根据热点指示信息发送的流量异常通知之后,向所述核心网网元发送流量异常应答,所述流量异常应答包括:存在流量异常或者不存在流量异常。
  25. 根据权利要求22所述的终端设备,其特征在于,所述终端设备,还包括:异常处理模块,用于所述获取模块获取所述核心网网元根据热点指示信息发送的流量异常通知之后,根据所述流量异常通知关闭所述终端设备的热点;或者,关闭产生异常流量的热点使用者的连接;或者,禁止产生异常流量的业务类型使用所述终端设备的热点。
  26. 根据权利要求22所述的终端设备,其特征在于,所述核心网网元包括:控制面功能网元、用户面功能网元、策略网元和数据分析网元中的至少一种。
  27. 一种用户面装置,其特征在于,所述用户面装置包括:处理器和存储器;
    所述存储器,用于存储指令;
    所述处理器,用于执行所述存储器中的所述指令,执行如权利要求1至8中任一项所述的方法。
  28. 一种终端设备,其特征在于,所述终端设备包括:处理器和存储器;
    所述存储器,用于存储指令;
    所述处理器,用于执行所述存储器中的所述指令,执行如权利要求9至13中任一项所述的方法。
  29. 一种计算机可读存储介质,包括指令,当其在计算机上运行时,使得计算机执行如权利要求1-8、或权利要求9-13任意一项所述的方法。
  30. 一种包含指令的计算机程序产品,当其在计算机上运行时,使得计算机执行如权利要求1-8、或权利要求9-13任意一项所述的方法。
PCT/CN2018/111222 2017-10-23 2018-10-22 一种流量处理方法和用户面装置以及终端设备 WO2019080799A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP18869735.3A EP3691209B1 (en) 2017-10-23 2018-10-22 Traffic processing method and user plane apparatus
US16/851,251 US20200244557A1 (en) 2017-10-23 2020-04-17 Traffic processing method, user plane apparatus, and terminal device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710993953.6A CN109698760B (zh) 2017-10-23 2017-10-23 一种流量处理方法和用户面装置以及终端设备
CN201710993953.6 2017-10-23

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US16/851,251 Continuation US20200244557A1 (en) 2017-10-23 2020-04-17 Traffic processing method, user plane apparatus, and terminal device

Publications (1)

Publication Number Publication Date
WO2019080799A1 true WO2019080799A1 (zh) 2019-05-02

Family

ID=66225897

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/111222 WO2019080799A1 (zh) 2017-10-23 2018-10-22 一种流量处理方法和用户面装置以及终端设备

Country Status (4)

Country Link
US (1) US20200244557A1 (zh)
EP (1) EP3691209B1 (zh)
CN (1) CN109698760B (zh)
WO (1) WO2019080799A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112291276A (zh) * 2020-12-28 2021-01-29 金锐同创(北京)科技股份有限公司 流量报警方法、装置及电子设备
WO2021160921A1 (en) * 2020-02-10 2021-08-19 Nokia Technologies Oy Propagating ue misbehavior information
WO2022141295A1 (zh) * 2020-12-30 2022-07-07 华为技术有限公司 一种通信方法和装置
CN115004653A (zh) * 2020-02-07 2022-09-02 华为技术有限公司 一种数据分析方法、装置及系统

Families Citing this family (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109982391B (zh) 2017-12-28 2023-04-11 华为技术有限公司 数据的处理方法及装置
WO2019225929A1 (en) * 2018-05-21 2019-11-28 Samsung Electronics Co., Ltd. Method and apparatus for utilizing data collection and analysis function in wireless communication system
CN111918280B (zh) * 2019-05-07 2022-07-22 华为技术有限公司 一种终端信息的处理方法、装置及系统
CN112104469B (zh) * 2019-06-17 2022-07-29 华为技术有限公司 数据处理方法及装置
US11470017B2 (en) * 2019-07-30 2022-10-11 At&T Intellectual Property I, L.P. Immersive reality component management via a reduced competition core network component
CN114503625B (zh) * 2019-09-30 2023-08-25 华为技术有限公司 一种通信方法、装置以及系统
CN113206814B (zh) * 2020-01-31 2022-11-18 华为技术有限公司 一种网络事件处理方法、装置及可读存储介质
CN111314347A (zh) * 2020-02-19 2020-06-19 联想(北京)有限公司 一种非法流量的处理方法、装置、系统和存储介质
WO2022027572A1 (en) * 2020-08-07 2022-02-10 Nokia Shanghai Bell Co., Ltd. Security management service in management plane
WO2022033660A1 (en) * 2020-08-11 2022-02-17 Nokia Technologies Oy Apparatuses, methods, and computer programs for exchanging analytics data
WO2022061784A1 (zh) * 2020-09-25 2022-03-31 华为技术有限公司 通信方法、装置及系统
CN114531681A (zh) * 2020-10-30 2022-05-24 华为技术有限公司 一种异常终端控制方法及装置
CN112969199B (zh) * 2021-02-24 2023-05-26 中国联合网络通信集团有限公司 一种数据采集方法和设备
CN114268957B (zh) * 2021-11-30 2023-07-04 中国联合网络通信集团有限公司 异常业务数据处理方法、装置、服务器及存储介质
CN116643954A (zh) * 2022-02-14 2023-08-25 大唐移动通信设备有限公司 模型监控方法、监控端、装置及存储介质
CN117014922A (zh) * 2022-04-27 2023-11-07 维沃移动通信有限公司 行为处理方法、装置、终端、网络侧设备及介质
CN115412308A (zh) * 2022-08-09 2022-11-29 北京天融信网络安全技术有限公司 报文处理方法、装置及电子设备

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101951551A (zh) * 2010-09-30 2011-01-19 上海顶竹通讯技术有限公司 一种带有无线局域网的网络以及终端接入无线局域网方法
CN105978826A (zh) * 2016-05-12 2016-09-28 中国联合网络通信集团有限公司 个人热点的流量控制方法和装置
US20170034860A1 (en) * 2015-07-30 2017-02-02 Sony Mobile Communications Inc. Mobile hotspot
US20170034857A1 (en) * 2015-07-30 2017-02-02 Sony Mobile Communications Inc. Mobile Hotspot

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150249910A1 (en) * 2014-02-28 2015-09-03 Carlos V. Roman Wireless network promotions
CN105451269A (zh) * 2014-07-04 2016-03-30 阿里巴巴集团控股有限公司 一种无线上网流量控制的方法和装置
US9078137B1 (en) * 2014-09-26 2015-07-07 Fortinet, Inc. Mobile hotspot managed by access controller
CN105577573B (zh) * 2015-12-31 2020-03-24 联想(北京)有限公司 一种信息处理方法及电子设备
CN105933928A (zh) * 2016-04-20 2016-09-07 努比亚技术有限公司 移动终端及其无线热点通信控制方法
CN107070669A (zh) * 2017-03-28 2017-08-18 新华三技术有限公司 一种终端的接入控制方法和装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101951551A (zh) * 2010-09-30 2011-01-19 上海顶竹通讯技术有限公司 一种带有无线局域网的网络以及终端接入无线局域网方法
US20170034860A1 (en) * 2015-07-30 2017-02-02 Sony Mobile Communications Inc. Mobile hotspot
US20170034857A1 (en) * 2015-07-30 2017-02-02 Sony Mobile Communications Inc. Mobile Hotspot
CN105978826A (zh) * 2016-05-12 2016-09-28 中国联合网络通信集团有限公司 个人热点的流量控制方法和装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3691209A4 *

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115004653A (zh) * 2020-02-07 2022-09-02 华为技术有限公司 一种数据分析方法、装置及系统
EP4087193A4 (en) * 2020-02-07 2023-01-18 Huawei Technologies Co., Ltd. DATA ANALYSIS METHOD, DEVICE AND SYSTEM
WO2021160921A1 (en) * 2020-02-10 2021-08-19 Nokia Technologies Oy Propagating ue misbehavior information
CN112291276A (zh) * 2020-12-28 2021-01-29 金锐同创(北京)科技股份有限公司 流量报警方法、装置及电子设备
CN112291276B (zh) * 2020-12-28 2021-03-23 金锐同创(北京)科技股份有限公司 流量报警方法、装置及电子设备
WO2022141295A1 (zh) * 2020-12-30 2022-07-07 华为技术有限公司 一种通信方法和装置

Also Published As

Publication number Publication date
CN109698760B (zh) 2021-05-04
CN109698760A (zh) 2019-04-30
US20200244557A1 (en) 2020-07-30
EP3691209B1 (en) 2021-12-08
EP3691209A1 (en) 2020-08-05
EP3691209A4 (en) 2020-10-21

Similar Documents

Publication Publication Date Title
WO2019080799A1 (zh) 一种流量处理方法和用户面装置以及终端设备
US11277324B2 (en) Determining an execution policy of a service
US10645007B2 (en) Quality of service (QOS) management in wireless networks
KR102069141B1 (ko) 서비스 계층 사우스바운드 인터페이스 및 서비스 품질
KR101597013B1 (ko) 모바일 송수신기, 기지국 송수신기, 데이터 서버, 그리고 관련 장치, 방법 및 컴퓨터 프로그램
US8805382B2 (en) System and method for quality of service in a wireless network environment
WO2020108003A1 (zh) 一种用户接入控制方法、信息发送方法及装置
JP5746427B2 (ja) Wlanとwwanとの間で対話するための方法、ユーザ装置、および基地局
US11012323B2 (en) Feature parameter obtaining method and apparatus
KR101452283B1 (ko) 서비스 제어 방법 및 시스템, 진화 기지국 및 패킷 데이터 네트워크 게이트웨이
US11617092B2 (en) Data analytics method and apparatus
US20110116469A1 (en) Local internet protocol access/selected internet protocol traffic offload packet encapsulation to support seamless mobility
WO2017166221A1 (zh) 无线接入控制方法、装置及系统
WO2017215215A1 (zh) 一种切换下载方式的方法、及其控制方法与控制系统
US20230070712A1 (en) Communication method, apparatus, and system
WO2015158285A1 (zh) 一种ip流路由规则的确定方法和设备
CN111919501B (zh) 专用承载管理
US8775596B2 (en) On-demand contextually aware steering rules
US20190394763A1 (en) Method and apparatus for controlling downlink or uplink transmission
CN107113247B (zh) 一种策略的确定方法及装置
EP3925307B1 (en) Technique for initiating a voice call in a mobile communication network
WO2017133059A1 (zh) 业务数据的传输方法和装置
JP2013038494A (ja) 無線基地局、無線lanシステム、データの送受信方法及びプログラム
US20230209505A1 (en) Device contexts, operational modes, and policy driven enhancements for paging in advanced networks
CN115767630A (zh) 传输链路选择方法及装置、计算机可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18869735

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2018869735

Country of ref document: EP

Effective date: 20200427