WO2023016298A1 - Service awareness method, communication apparatus, and communication system - Google Patents

Service awareness method, communication apparatus, and communication system Download PDF

Info

Publication number
WO2023016298A1
WO2023016298A1 PCT/CN2022/109737 CN2022109737W WO2023016298A1 WO 2023016298 A1 WO2023016298 A1 WO 2023016298A1 CN 2022109737 W CN2022109737 W CN 2022109737W WO 2023016298 A1 WO2023016298 A1 WO 2023016298A1
Authority
WO
WIPO (PCT)
Prior art keywords
event
network element
application
request message
service
Prior art date
Application number
PCT/CN2022/109737
Other languages
French (fr)
Chinese (zh)
Inventor
丁辉
周凯
韩文勇
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2023016298A1 publication Critical patent/WO2023016298A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/08Testing, supervising or monitoring using real traffic

Definitions

  • the present application relates to the technical field of wireless communication, and in particular to a service perception method, a communication device and a communication system.
  • the application detection for business flow mainly depends on the plaintext domain name information carried in the packet header corresponding to the application identification (such as IP triplet, domain name, fully qualified domain name (fully qualified domain name, FQDN), etc.)
  • the application identification such as IP triplet, domain name, fully qualified domain name (fully qualified domain name, FQDN), etc.
  • Perform pre-configuration perform application detection based on the plaintext domain name information carried in the packet header, and identify the service flow of which application the packet belongs to.
  • the application packets transmitted by the terminal equipment may be encrypted packets, or the same packet header may actually correspond to multiple different services.
  • the messages can be effectively distinguished.
  • the present application provides a service perception method, a communication device and a communication system, which are used to effectively distinguish messages of different application services.
  • the embodiment of the present application provides a service perception method, which can be executed by a session management function network element or a module (such as a chip) applied to the session management function network element.
  • the method includes: the session management function network element sends a first request message to the user plane function network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes an application service identifier and packet detection feature information, the The detection rule is used to detect the service flow of the application service in the session, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, and the first event identifier is used Instructing to report the event of the service flow of the application service, the event is an application start event or an application end event; the session management function network element receives the first event report from the user plane function network element, and the first event report is used to indicate An event of a service flow of the application service.
  • the session management functional network element may request the user plane functional network element to perform application detection by sending a request message, and provide packet detection characteristic information of the application service.
  • the user plane functional network element can perform application detection on the received packet according to the packet detection feature information. In this way, packets of different application services can be effectively distinguished, and the accuracy of application detection can be effectively improved.
  • the method further includes: the session management function network element receives a second request message from the policy control function network element, the second request message is used to subscribe to the event, and the second The request message includes the identification of the application service, the packet detection feature information and the second event identification, and the second event identification is used to indicate the reporting of the event; the session management function network element sends the second event report to the policy control function network element , the second event report is used to indicate the event.
  • the packet detection feature information includes statistical features and/or packet header features of packets in the service flow of the application service.
  • the above technical solution can solve the problem of being unable to determine the service flow to which the message belongs and the type of the application service unable to be accurately determined due to the capability limitation of the plaintext domain name information in the packet header of the message. For example, when encrypted messages or messages of different application services have the same packet header, the messages of different application services can be accurately identified.
  • the detection rule further includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection feature information is applicable; the flow description information is included in the second request message .
  • the packet detection feature information and flow description information are used together for application detection, which can effectively improve the accuracy of application detection.
  • the first event report includes the identifier of the application service and the first event identifier
  • the second event report includes the identifier of the application service and the second event identifier
  • the embodiment of the present application provides a service perception method, which can be executed by a user plane functional network element or a module (such as a chip) applied to the user plane functional network element.
  • the method includes: a user plane function network element receives a first request message from a session management function network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes an application service identifier and packet detection feature information, The detection rule is used to detect the service flow of the application service in the session, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, and the first event identifier An event used to indicate to report the service flow of the application service, the event is an application start event or an application end event; the user plane functional network element performs application detection on the received packet in the session according to the packet detection characteristic information; if detected For an event of the service flow of the application service, the user plane functional network element sends a first event report to the session management functional network element, where the first event report is used to indicate the event.
  • the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
  • the detection rule includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection characteristic information applies; Executing application detection on received packets includes: performing application detection on packets in the session that match the flow description information according to packet detection characteristic information.
  • the first event report includes the identifier of the application service and the identifier of the first event.
  • the embodiment of the present application provides a service perception method, which can be executed by a network element with a policy control function or a module (such as a chip) applied to a network element with a policy control function.
  • the method includes: the policy control function network element receives a third request message from the application function network element, the third request message includes the identifier of the application service, packet detection characteristic information and a third event identifier, and the packet detection characteristic information is used for Indicate the matching feature of the service flow of the application service, the third event identifier is used to indicate the event of reporting the service flow of the application service, the event is an application start event or an application end event; the policy control function network element sends a session management The functional network element sends a second request message, the second request message is used to request to subscribe to the event, the second request message includes the identification of the application service, packet detection feature information and a second event identification, the second event The identifier is used to indicate the reporting of the event; the policy control function network element receives the second event report from the session management function network element, and the second event report is used to indicate the event; the policy control function network element sends the application function network element A third event report, the second event report is used to indicate the event.
  • the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
  • the second request message and the third request message further include flow description information, where the flow description information is used to indicate a service flow to which the packet detection feature information applies.
  • the second event report includes the identifier of the application service and a second event identifier
  • the third event report includes the identifier of the application service and a third event identifier
  • the embodiment of the present application provides a service perception method, which can be executed by an application function network element or applied to a module (such as a chip) in the application function network element.
  • the method includes: the application function network element sends a third request message to the policy control function network element, the third request message includes the identifier of the application service, packet detection characteristic information and a third event identifier, and the packet detection characteristic information is used to indicate The matching feature of the service flow of the application service, the third event identifier is used to indicate the event of reporting the service flow of the application service, and the event is an application start event or an application end event; the application function network element receives the event from the policy control function A third event report of the network element, where the third event report is used to indicate the event.
  • the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
  • the third request message further includes flow description information, where the flow description information is used to indicate a service flow to which the packet detection characteristic information applies.
  • the third event report includes an identifier of the application service and a third event identifier.
  • the application start event is used to trigger a policy control function network element to initiate a configuration update process to the terminal device.
  • the embodiment of the present application provides a service perception method, which can be executed by a network element with a network data analysis function or a module (such as a chip) applied to a network element with a network data analysis function.
  • the method includes: the network data analysis function network element receives a fourth request message from the application function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event,
  • the fourth request message includes the identification of the application service and packet detection feature information, and the packet detection feature information is used to indicate the matching feature of the service flow of the application service;
  • the network data analysis function network element sends the session management function network element Sending the fifth request message, the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device;
  • the network data analysis function network element according to the packet detection feature information, the received from the session management function network element or the user plane
  • the mirror image of the functional network element performs application detection; if an event of the service flow of the application service is detected, the network data analysis functional network element sends an event report to the application functional network element, and the event report is used to indicate the event.
  • the network data analysis function network element can obtain the mirror image of the message in the session of the terminal device from the user plane function network element through the session management function network element, and analyze the received packets according to the packet detection feature information provided by the application function network element.
  • the mirror image of the message performs application detection, and returns a corresponding event report to the application function network element.
  • the packet detection feature information includes statistical features and/or packet header features of packets in the service flow of the application service.
  • the above technical solution can solve the problem of being unable to determine the service flow to which the message belongs and the type of the application service unable to be accurately determined due to the capability limitation of the plaintext domain name information in the packet header of the message. For example, when encrypted messages or messages of different application services have the same packet header, the messages of different application services can be accurately identified.
  • the fourth request message further includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection feature information is applicable; in the fifth request message It also includes flow description information, where the flow description information is used to indicate the mirroring of the packets matching the flow description information in the session of the forwarding terminal device.
  • the packet detection feature information and flow description information are used together for application detection, which can effectively improve the accuracy of application detection.
  • the network element with the network data analysis function can request to forward the mirror image of the message matching the flow description information in the session of the terminal device, without forwarding the mirror image of all messages, therefore, reducing the data volume of the message transmitted between network elements, Make full use of network resources.
  • the fifth request message further includes a mirroring destination address, where the mirroring destination address is an address of a network element with a network data analysis function that receives the mirroring.
  • the mirroring destination address is an address of a network element with a network data analysis function that receives the mirroring.
  • the fourth request message further includes an event identifier, and the event identifier is used to indicate reporting of the event; the event report includes the identifier of the application service and the event logo.
  • the embodiment of the present application provides a service perception method, which can be executed by a session management function network element or a module (such as a chip) applied to the session management function network element.
  • the method includes: the session management function network element receives the fifth request message from the network data analysis function network element, and the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device; the session management function network element sends the user interface
  • the functional network element sends a sixth request message, the sixth request message includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow of the session of the terminal device, the forwarding rule includes a mirror forwarding indication, and the mirroring forwarding indication uses Instruct to forward the image.
  • the fifth request message includes flow description information, and the flow description information is used to indicate forwarding the image of the message matching the flow description information in the session of the terminal device;
  • the flow description information is included in the above detection rules.
  • the detection rule includes wildcard indication information, and the wildcard indication information is used to forward images of all packets in the session of the terminal device.
  • the session management function network element can clearly inform the user plane function network element to indicate which packets in the session of the terminal device need to be forwarded, so that the user plane The functional network element performs corresponding processing.
  • the fifth request message further includes a mirroring destination address, where the mirroring destination address is an address of a network element with a network data analysis function that receives the mirroring.
  • the method further includes: the session management function network element receives the image from the user plane function network element, and sends the image to the network data analysis function network element according to the image destination address ;
  • the forwarding rule also includes a mirroring destination address.
  • the embodiment of the present application provides a service perception method, which can be executed by a user plane functional network element or a module (such as a chip) applied to the user plane functional network element.
  • the method includes: the user plane function network element receives a sixth request message from the session management function network element, the sixth request message includes a detection rule and a forwarding rule, and the detection rule is used to detect the service flow in the session of the terminal device,
  • the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate forwarding the mirroring of the message in the session of the terminal device;
  • the user plane functional network element detects the message in the session of the terminal device according to the detection rule;
  • the user plane The functional network element sends the image to the session management functional network element or the network data analysis functional network element according to the image forwarding instruction.
  • the detection rule includes flow description information; the method further includes: according to the flow description information, the user plane function network element sends a session management function network element or a network data analysis function network The mirror image of the message matching the flow description information in the session of the original sending terminal device.
  • the detection rule includes wildcard indication information; the method further includes: according to the wildcard indication information, the user plane function network element sends a session management function network element or network data analysis The functional network element sends the mirror image of all packets in the session of the terminal device.
  • the forwarding rule further includes the destination address of the image;
  • the sending of the image by the user plane functional network element to the network data analysis function network element includes: the user plane functional network element according to The destination address of the image is used to send the image to the network element with the network data analysis function.
  • the embodiment of the present application provides a service perception method, which can be executed by an application function network element or a module (such as a chip) applied to the application function network element.
  • the method includes: the application function network element sends a fourth request message to the network data analysis function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, the The fourth request message includes the identification of the application service and packet detection characteristic information, the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service; the application function network element receives the network data analysis function network element An event report indicating the event.
  • the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
  • the fourth request message further includes flow description information, where the flow description information is used to indicate a service flow to which the packet detection feature information applies.
  • the fourth request message further includes an event identifier, and the event identifier is used to indicate reporting of the event; the event report includes the identifier of the application service and the event logo.
  • the embodiment of the present application provides a service perception method, which can be executed by an application function network element or a module (such as a chip) applied to the application function network element.
  • the method includes: the application function network element sends a seventh request message to the policy control function network element, the seventh request message is used to obtain the mirror image of the message in the session of the terminal device, the seventh request message includes a mirror destination address, the The destination address of the image is the address of the application function network element receiving the image; the application function network element receives the image from the user plane function network element; the application function network element performs application detection according to the image.
  • the application function network element can send forwarding rules to the user plane function network element through the policy control function network element and the session management function network element to obtain the mirror image of the message in the session of the terminal device, and then according to the received message mirror image for application detection.
  • the application function network element can perceive the type of the application service actually initiated by the terminal device, and it is convenient for the AF to execute corresponding management decisions based on the application service currently initiated by the terminal device.
  • the seventh request message further includes flow description information, and the flow description information is used to indicate forwarding a mirror image of a packet matching the flow description information in a session of the terminal device.
  • the application function network element can request to forward the mirror image of the message matching the flow description information in the session of the terminal device, without forwarding the mirror image of all messages, Therefore, the data volume of messages transmitted between network elements is reduced, and network resources are fully utilized.
  • the embodiment of the present application provides a service awareness method, which can be executed by a network element with a policy control function or a module (such as a chip) applied to a network element with a policy control function.
  • the method includes: the policy control function network element receives a seventh request message from the application function network element, the seventh request message is used to obtain the mirror image of the message in the session of the terminal device, and the seventh request message includes a mirror destination address, The destination address of the image is the address receiving the image in the application function network element; the policy control function network element sends an eighth request message to the session management function network element, and the eighth request message is used to request forwarding of the image, the eighth The mirroring destination address is included in the request message.
  • the seventh request message further includes flow description information, where the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device;
  • the eighth request message also includes the stream description information.
  • the embodiment of the present application provides a service perception method, which can be executed by a session management function network element or a module (such as a chip) applied to the session management function network element.
  • the method includes: the session management function network element receives an eighth request message from the policy control function network element, the eighth request message is used to request forwarding the mirroring of the message in the session of the terminal device, and the eighth request message includes the mirroring purpose address, the mirroring destination address is the address of the application function network element receiving the mirroring; the session management function network element sends a ninth request message to the user plane function network element, the ninth request message includes detection rules and forwarding rules, the The detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used to mirror and forward the message in the session of the terminal device.
  • the forwarding rule includes a mirror forwarding indication and the mirror destination address, and the mirror forwarding The instruction is used to instruct to forward the image.
  • the detection rule includes flow description information, and the flow description information is used to indicate the mirror image of the packet that matches the flow description information in the session of the forwarding terminal device.
  • the detection rule includes wildcard indication information, and the wildcard indication information is used to forward images of all packets in the session of the terminal device.
  • the session management function network element can clearly inform the user plane function network element which mirror images of the packets in the session of the terminal device need to be forwarded, so as to facilitate the user plane
  • the functional network element performs corresponding processing.
  • the embodiment of the present application provides a service perception method, which can be executed by a user plane functional network element or a module (such as a chip) applied to the user plane functional network element.
  • the method includes: the user plane functional network element receives a detection rule and a forwarding rule from a session management functional network element, the detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used to detect the traffic flow in the session of the terminal device
  • the packet is mirrored and forwarded.
  • the forwarding rule includes a mirrored forwarding instruction and a mirrored destination address.
  • the mirrored destination address is the address received in the application function network element;
  • the user plane function network element detects the session of the terminal device according to the detection rule message: the user plane function network element sends the image to the application function network element according to the image forwarding instruction and the image destination address.
  • the detection rule includes flow description information; the method further includes: the user plane function network element sends the session information of the terminal device to the application function network element according to the flow description information Mirroring of packets matching the flow description information.
  • the detection rule includes wildcard indication information; the method further includes: the user plane functional network element sends the terminal device information to the application function network element according to the wildcard indication information Mirroring of all packets in the session.
  • the embodiment of the present application provides a communication device, which can have the function of implementing any of the above-mentioned aspects or any possible design application function network element, or can realize the above-mentioned aspects or aspects any possible design of the network element with the policy control function, or the function of the network element with the session management function in any of the above-mentioned aspects or aspects, or the function of the network element with the above-mentioned aspects or aspects
  • the function of the user plane function network element in any possible design, or the function of the network data analysis function network element in any of the above aspects or any possible design of the aspects.
  • the device may be a network device, or a chip included in the network device.
  • the above-mentioned functions of the communication device may be realized by hardware, or may be realized by executing corresponding software by hardware, and the hardware or software includes one or more modules or units or means corresponding to the above-mentioned functions.
  • the structure of the device includes a processing module and a transceiver module, wherein the processing module is configured to support the device to perform the corresponding functions of the application function network element in any design of the above aspects or aspects , or perform the corresponding functions of the policy control function network element in any design of the above aspects or aspects, or perform the corresponding functions of the session management function network element in any design of the above aspects or aspects, or perform the above
  • the corresponding functions of the user plane function network element in any design of the aspects or any aspects of the aspects, or the corresponding functions of the network data analysis function network element in the above aspects or any design of the aspects.
  • the transceiver module is used to support communication between the device and other communication devices.
  • the communication device may also include a storage module, which is coupled to the processing module and stores necessary program instructions and data of the device.
  • the processing module may be a processor
  • the communication module may be a transceiver
  • the storage module may be a memory
  • the memory may be integrated with the processor or configured separately from the processor.
  • the structure of the device includes a processor, and may also include a memory.
  • the processor is coupled with the memory, and can be used to execute the computer program instructions stored in the memory, so that the apparatus performs the method in any one possible design of the above-mentioned aspects or aspects.
  • the device further includes a communication interface, and the processor is coupled to the communication interface.
  • the communication interface may be a transceiver or an input/output interface; when the device is a chip included in the network device, the communication interface may be an input/output interface of the chip.
  • the transceiver may be a transceiver circuit, and the input/output interface may be an input/output circuit.
  • the embodiment of the present application provides a chip system, including: a processor, the processor is coupled with a memory, and the memory is used to store programs or instructions, when the programs or instructions are executed by the processor When, make the system-on-a-chip implement the above-mentioned aspects or any one possible design method of the aspects.
  • the chip system further includes an interface circuit, which is used for exchanging code instructions to the processor.
  • processors in the chip system, and the processors may be implemented by hardware or by software.
  • the processor may be a logic circuit, an integrated circuit, or the like.
  • the processor may be a general-purpose processor implemented by reading software codes stored in a memory.
  • the memory can be integrated with the processor, or can be set separately from the processor.
  • the memory may be a non-transitory processor, such as a read-only memory ROM, which may be integrated with the processor on the same chip, or may be respectively disposed on different chips.
  • the embodiment of the present application also provides a computer-readable storage medium, the computer-readable storage medium stores instructions, and when it is run on a communication device, any one of the above aspects or aspects A possible design approach is implemented.
  • the embodiment of the present application also provides a computer program product, the computer program product includes computer programs or instructions, and when the computer program or instructions are run by the communication device, any one of the above-mentioned aspects or aspects is possible The method in the design is executed.
  • the embodiment of the present application also provides a communication system, the communication system includes a session management function network element configured to execute the method in the third aspect or any possible design of the third aspect and a network element configured to A user plane function network element that executes the method in the fourth aspect or any possible design of the fourth aspect.
  • the communication system may further include an application function network element configured to implement the first aspect or any method in a possible design of the first aspect and an application function network element configured to implement the second aspect or any of the second aspects.
  • an application function network element configured to implement the first aspect or any method in a possible design of the first aspect
  • an application function network element configured to implement the second aspect or any of the second aspects.
  • the embodiment of the present application also provides a communication system, the communication system includes a network element with a network data analysis function and a user A network element with a session management function for performing the method in the seventh aspect or any possible design of the seventh aspect.
  • the communication system may further include an application function network element configured to implement the method in the fifth aspect or any possible design of the fifth aspect and an application function network element configured to implement the eighth aspect or any of the eighth aspects.
  • an application function network element configured to implement the method in the fifth aspect or any possible design of the fifth aspect
  • an application function network element configured to implement the eighth aspect or any of the eighth aspects.
  • the embodiment of the present application further provides a communication system, the communication system includes an application function network element for performing the method in any possible design of the ninth aspect or the ninth aspect, and a network element configured to perform the above-mentioned first aspect
  • the user plane functional network element of the method in the twelfth aspect or any possible design of the twelfth aspect is configured to perform the above-mentioned first aspect.
  • the communication system may further include a policy control function network element configured to implement the above tenth aspect or the method in any possible design of the tenth aspect, and a network element configured to implement the above eleventh aspect or the eleventh aspect Aspects of any one possible design of the method in the session management function network element.
  • Figure 1a, Figure 1b and Figure 1c are schematic diagrams of a communication system provided by an embodiment of the present application.
  • Figure 2a is a schematic diagram of a 5G network architecture based on a service architecture
  • Figure 2b is a schematic diagram of a 5G network architecture based on a point-to-point interface
  • FIG. 3 is a schematic diagram of a service perception method provided by an embodiment of the present application.
  • FIG. 4 is a schematic diagram of another service perception method provided by an embodiment of the present application.
  • FIG. 5 is a schematic diagram of another service perception method provided by the embodiment of the present application.
  • FIG. 6 and FIG. 7 are schematic structural diagrams of a communication device provided by an embodiment of the present application.
  • the present application provides a communication system.
  • the communication system may include a session management functional network element and a user plane functional network element.
  • the communication system may further include an application function network element and a policy control function network element.
  • the session management function network element is configured to send a first request message to the user plane function network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes the identification of the application service and packet detection feature information, the detection The rule is used to detect the service flow of the application service, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, and the first event identifier is used to indicate the reporting An event of the service flow of the application service, where the event is an application start event or an application end event; and used for receiving a first event report from a user plane functional network element, where the first event report is used to indicate the event.
  • the second request message is used to request to subscribe to the event, and the second request message includes the identification of the application service and the packet detection feature Information and a second event identifier, where the second event identifier is used to indicate reporting of the event; and, used to send a second event report to the policy control function network element, where the second event report is used to indicate the event.
  • the user plane functional network element is configured to receive the first request message from the session management functional network element; perform application detection on the received packets in the session according to the packet detection characteristic information; if the service of the application service is detected If there is an event of the flow, a first event report is sent to the network element with the session management function.
  • the policy control function network element is used to send the second request message to the session management function network element; and is used to receive the second event report from the session management function network element;
  • the third request message of the application function network element, the third request message includes the identification of the application service, the packet detection characteristic information and the third event identification, and the third event identification is used to indicate to report the event;
  • the application function network element sends a third event report, where the third event report is used to indicate the event.
  • the application function network element is configured to send a third request message to the policy control function network element; and is configured to receive a third event report from the policy control function network element.
  • the communication system may include a network element with a network data analysis function and a network element with a session management function.
  • the communication system may further include an application function network element and a user plane function network element.
  • the network data analysis function network element is used to receive the fourth request message from the application function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, the The fourth request message includes the identification of the application service and packet detection characteristic information, and the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service; it is used to send the fifth request message to the session management function network element , the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device; it is used to receive the mirror image from the session management function network element or the user plane function network element; The mirror image executes application detection; and, if the event is detected, send an event report to the application function network element, where the event report is used to indicate the event.
  • the session management function network element is used to receive the fifth request message from the network data analysis function network element; it is used to send the sixth request message to the user plane function network element, the sixth request message includes detection rules and forwarding rules, the The detection rule is used to detect the service flow of the session of the terminal device, and the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate forwarding of the mirroring.
  • the application function network element is configured to send a fourth request message to the network data analysis function network element; and receive an event report from the network data analysis function network element.
  • the user plane functional network element is used to receive the sixth request message from the session management functional network element; it is used to detect the service flow in the session of the terminal device according to the detection rule; the user plane functional network element forwards the instruction according to the image , sending the image to a network element with a session management function or a network element with a network data analysis function.
  • the communication system may include an application function network element and a user plane function network element.
  • the communication system may further include a network element with a policy control function and a network element with a session management function.
  • the application function network element is used to send a seventh request message to the policy control function network element, the seventh request message is used to obtain the image of the message in the session of the terminal device, the seventh request message includes the image destination address, and the image The destination address is the address of the application function network element receiving the image; it is used for receiving the image from the user plane function network element; and performing application detection according to the image.
  • the policy control function network element is used to receive the seventh request message from the application function network element; it is used to send the eighth request message to the session management function network element, and the eighth request message is used to request forwarding the image, the eighth The mirroring destination address is included in the request message.
  • the session management functional network element is configured to receive an eighth request message from the policy control functional network element; and is configured to send a ninth request message to the user plane functional network element, where the ninth request message includes detection rules and forwarding A rule, the detection rule is used to detect the service flow in the session of the terminal device, the forwarding rule is used to mirror forward the message in the session of the terminal device, and the forwarding rule includes a mirroring forwarding indication and the mirroring destination address, The image forwarding indication is used to instruct to forward the image.
  • the user plane function network element is used to receive the detection rule and the forwarding rule from the session management function network element; according to the detection rule, detect the message in the session of the terminal device; according to the mirroring forwarding instruction and the mirroring destination address, and send the image to the application function network element.
  • the system shown in Figure 1a, Figure 1b or Figure 1c can be used in the 5G network architecture shown in Figure 2a or Figure 2b, and can also be used in future network architectures, such as the sixth generation (6th generation, 6G) network architecture etc., this application does not make a limitation.
  • 6G sixth generation
  • FIG 2a is a schematic diagram of a 5G network architecture based on a service-based architecture.
  • the 5G network architecture shown in Figure 2a may include a data network (data network, DN) and an operator network.
  • DN data network
  • Operator network operator network
  • the operator network may include one or more of the following network elements: authentication server function (authentication server function, AUSF) network element, network exposure function (network exposure function, NEF) network element, policy control function (policy control function (PCF) network element, unified data management (unified data management, UDM) network element, unified database (unified data repository, UDR) network element, network storage function (network repository function, NRF) network element, application function (application function) , AF) network elements, access and mobility management function (access and mobility management function, AMF) network elements, session management function (session management function, SMF) network elements, radio access network (radio access network, RAN) equipment And user plane function (UPF) network elements, network data analysis function (network data analysis function, NWDAF) network elements, network slice selection function (Network Slice Selection Function, NSSF) network elements, etc.
  • network elements or devices other than radio access network devices may be referred to as core network elements or core network devices.
  • the wireless access network equipment can be a base station (base station), an evolved base station (evolved NodeB, eNodeB), a transmission reception point (transmission reception point, TRP), and a next generation base station (next generation NodeB, gNB) in a 5G mobile communication system , a next-generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a wireless fidelity (Wireless Fidelity, WiFi) system, etc.; it can also be a module or unit that completes some functions of the base station, for example, It can be a centralized unit (central unit, CU) or a distributed unit (distributed unit, DU).
  • the radio access network equipment may be a macro base station, a micro base station or an indoor station, or a relay node or a donor node. The embodiment of the present application does not limit the specific technology and specific equipment form adopted by the radio access network equipment.
  • the terminal communicating with the RAN may also be referred to as terminal equipment, user equipment (user equipment, UE), mobile station, mobile terminal, and so on.
  • Terminals can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things ( internet of things, IOT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearables, smart transportation, smart city, etc.
  • Terminals can be mobile phones, tablet computers, computers with wireless transceiver functions, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc.
  • the embodiment of the present application does not limit the specific technology and specific device form adopted by the terminal.
  • Base stations and terminals can be fixed or mobile. Base stations and terminals can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed on aircraft, balloons and artificial satellites in the air. The embodiments of the present application do not limit the application scenarios of the base station and the terminal.
  • the AMF network element performs functions such as mobility management and access authentication/authorization. In addition, it is also responsible for transferring user policies between the terminal and the PCF.
  • the SMF network element performs functions such as session management, execution of control policies issued by the PCF, selection of UPF, and allocation of Internet Protocol (IP) addresses for terminals.
  • functions such as session management, execution of control policies issued by the PCF, selection of UPF, and allocation of Internet Protocol (IP) addresses for terminals.
  • IP Internet Protocol
  • the UPF network element as an interface with the data network, completes functions such as user plane data forwarding, session/flow-based charging statistics, and bandwidth limitation.
  • the UDM network element performs functions such as managing subscription data and user access authorization.
  • UDR implements the access function of contract data, policy data, application data and other types of data.
  • NEF network elements are used to support the opening of capabilities and events.
  • the AF network element transmits the requirements from the application side to the network side, such as quality of service (quality of service, QoS) requirements or user status event subscription.
  • the AF may be a third-party functional entity, or an application service deployed by an operator, such as an IP Multimedia Subsystem (IP Multimedia Subsystem, IMS) voice call service.
  • IP Multimedia Subsystem IP Multimedia Subsystem
  • the PCF network element is responsible for policy control functions such as charging for sessions and service flow levels, QoS bandwidth guarantee, mobility management, and terminal policy decision-making.
  • the NRF network element is used to provide a network element discovery function, and provide network element information corresponding to a network element type based on requests from other network elements.
  • NRF also provides network element management services, such as network element registration, update, de-registration, network element status subscription and push, etc.
  • the AUSF network element is responsible for authenticating users to determine whether users or devices are allowed to access the network.
  • the NSSF network element is used to select a network slice and count users in the network slice.
  • the NWDAF network element is responsible for performing analysis functions based on the input information collected from each node, and outputting corresponding analysis results for scenarios such as network operation and maintenance, policy decision-making, and user experience evaluation.
  • DN is a network outside the operator's network.
  • the operator's network can access multiple DNs, and various services can be deployed on the DN, which can provide data and/or voice services for terminals.
  • DN is a private network of a smart factory.
  • the sensors installed in the workshop of the smart factory can be terminals, and the control server of the sensors is deployed in the DN, and the control server can provide services for the sensors.
  • the sensor can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions.
  • DN is a company's internal office network.
  • the mobile phone or computer of the company's employees can be a terminal, and the employee's mobile phone or computer can access information and data resources on the company's internal office network.
  • Nausf, Nnef, Npcf, Nudm, Naf, Namf, and Nsmf are the service interfaces provided by the above-mentioned AUSF, NEF, PCF, UDM, AF, AMF, and SMF, respectively, and are used to call corresponding service operations.
  • N1, N2, N3, N4, and N6 are interface serial numbers. The meanings of these interface serial numbers may refer to the meanings defined in the 3rd generation partnership project (3rd generation partnership project, 3GPP) standard agreement, and there is no limitation here.
  • FIG. 2b is a schematic diagram of a 5G network architecture based on a point-to-point interface.
  • the introduction of the functions of the network elements can refer to the introduction of the functions of the corresponding network elements in FIG.
  • the main difference between Fig. 2b and Fig. 2a is that: the interface between each control plane network element in Fig. 2a is a service interface, and the interface between each control plane network element in Fig. 2b is a point-to-point interface.
  • N1 the interface between the AMF and the terminal, which can be used to transmit QoS control rules and the like to the terminal.
  • N2 the interface between the AMF and the RAN, which can be used to transfer radio bearer control information from the core network side to the RAN.
  • N3 the interface between the RAN and the UPF, mainly used to transfer the uplink and downlink user plane data between the RAN and the UPF.
  • N4 The interface between SMF and UPF, which can be used to transfer information between the control plane and the user plane, including controlling the distribution of forwarding rules, QoS control rules, traffic statistics rules, etc. Information reporting.
  • N5 the interface between the AF and the PCF, which can be used for sending application service requests and reporting network events.
  • N6 the interface between UPF and DN, used to transfer the uplink and downlink user data flow between UPF and DN.
  • N7 the interface between PCF and SMF, which can be used to deliver protocol data unit (protocol data unit, PDU) session granularity and service data flow granularity control policy.
  • protocol data unit protocol data unit
  • PDU protocol data unit
  • N8 The interface between AMF and UDM, which can be used for AMF to obtain subscription data and authentication data related to access and mobility management from UDM, and for AMF to register terminal current mobility management related information with UDM.
  • N9 a user plane interface between UPF and UPF, used to transmit uplink and downlink user data flows between UPFs.
  • N10 the interface between SMF and UDM, which can be used for SMF to obtain session management-related subscription data from UDM, and for SMF to register terminal current session-related information with UDM.
  • N11 the interface between SMF and AMF, which can be used to transfer PDU session tunnel information between RAN and UPF, transfer control messages sent to terminals, transfer radio resource control information sent to RAN, etc.
  • N12 the interface between AMF and AUSF, which can be used for AMF to initiate an authentication process to AUSF, which can carry SUCI as a subscription identifier;
  • N13 the interface between UDM and AUSF, which can be used for AUSF to obtain user authentication vector from UDM to execute the authentication process.
  • N15 the interface between the PCF and the AMF, which can be used to issue terminal policies and access control-related policies.
  • N35 the interface between UDM and UDR, which can be used for UDM to obtain user subscription data information from UDR.
  • N36 the interface between the PCF and the UDR, which can be used for the PCF to obtain policy-related subscription data and application data-related information from the UDR.
  • the above-mentioned network element or function may be a network element in a hardware device, or a software function running on dedicated hardware, or a virtualization function instantiated on a platform (for example, a cloud platform).
  • a platform for example, a cloud platform.
  • the foregoing network element or function may be implemented by one device, or jointly implemented by multiple devices, or may be a functional module in one device, which is not specifically limited in this embodiment of the present application.
  • the application function network element, policy control function network element, session management function network element, user plane function network element, and network data analysis function network element in this application can be AF, PCF, SMF, UPF in Figure 2a or Figure 2b respectively , NWDAF, or a network element having the above-mentioned functions of AF, PCF, SMF, UPF, and NWDAF in future communications such as 6G networks, which is not limited in this application.
  • AF, PCF, SMF, UPF, and NWDAF will be used as application function network elements, policy control function network elements, session management function network elements, user plane function network elements, and network data network elements respectively.
  • An example of an analysis function network element is used to introduce the technical solution provided by this application.
  • Figure 3 is a service perception method provided by this application, which includes:
  • step 301 the AF sends a request message 1 to the PCF, and the request message 1 includes application service ID, packet detection feature information and event ID 1.
  • the PCF receives the request message 1 from the AF.
  • the request message 1 is used to request to create or update the policy of the service flow of the application service.
  • the request message 1 may be a policy authorization creation/update request message, or other messages, which are not limited in this application.
  • the packet detection feature information of the application service is used to indicate the matching feature of the service flow of the application service.
  • the packet detection feature information can be understood as the matching feature provided by the AF to the core network (such as 5GC) for application detection.
  • the packet detection feature information may include statistical features and/or packet header features of packets in the service flow of the application service. Among them, the statistical characteristics of the message may include message period, message size, etc., the message period can be used by UPF to judge whether there is a service flow of the application service based on the period characteristic of the received message, and the message size can be used by UPF Based on the interval distribution to which the size of the received packet belongs, it is judged whether there is a service flow of the application service.
  • the description form of the packet header characteristics of the message can be a combination of other packet headers other than the conventional packet headers such as the original address, destination address, and protocol type defined in the current IP packet or Ethernet packet, for example, in the Profinet protocol header.
  • the frame identifier Frame ID and the function code in the Modbus protocol header can be the target field and its corresponding value, or the matching feature composed of offset + field length + field value. This application does not limit this.
  • Event ID 1 is used to indicate the event of reporting the service flow of the application service.
  • the event can be an application start event (app start event) or an application end event (app stop event).
  • the event ID 1 can be all The identifier of the application start event or the identifier of the application end event of the service flow of the above-mentioned application service.
  • the application start event may trigger the PCF to initiate a configuration update process to the terminal device
  • the application end event may trigger the PCF to cancel the previous configuration information of the terminal device.
  • the request message 1 may also include flow description information, where the flow description information is used to indicate the service flow to which the packet detection feature information is applicable, and may also be understood as used to identify the service flow to be matched.
  • the flow description information may be in the form of an IP quintuple. If the request message 1 does not include the flow description information, it can be considered that all the service flows in the session of the terminal device corresponding to the request message 1 are the service flows to which the above-mentioned packet detection feature information applies (that is, the service flows to be matched).
  • the session of the terminal device there may be one or more service flows in the session of the terminal device, and different service flows may correspond to different application services, and each service flow may consist of one or more messages.
  • the detection of a packet of a certain application service is the detection of the service flow of the application service, which may also be referred to as an application start event in which the service flow of the application service is detected. After a packet of an application service is detected, no packet of the application service is detected within a period of time, that is, the service flow of the application service is no longer detected, which can also be called detection of the application service
  • the application end event of the business flow may be a protocol data unit (protocol data unit, PDU) session, and correspondingly, the session establishment process may be a PDU session establishment process, which will not be described in detail below.
  • PDU protocol data unit
  • the request message 1 may also include terminal device information
  • the terminal device information may include the terminal device's IP address, terminal device identifier, data network name (data network name, DNN), single network slice selection assistance Information (single-network slice selection assistance information, S-NSSAI) and other information, such as the IP address of the terminal device, or the identification and DNN of the terminal device, or the identification of the terminal device and S-NSSAI wait.
  • the above terminal device information can be used by the PCF to determine the session of the terminal device corresponding to the request message 1, or the session of the terminal device where the service flow of the application service is located, or the session of the terminal device to be detected.
  • the AF may only carry the above terminal device information in the policy authorization creation request message.
  • the terminal device may initiate a session establishment procedure to establish a session of the above-mentioned terminal device.
  • the AF may directly or indirectly send the request message 1 to the PCF.
  • the AF directly sends the request message 1 to the PCF means: the AF directly sends the request message 1 to the PCF without being forwarded by other network elements.
  • AF sends request message 1 to PCF indirectly means: AF sends request message 1 to PCF through the forwarding of other network elements (such as NEF), for example, AF sends request message 1 to NEF, and NEF sends the request message 1 to PCF .
  • NEF network elements
  • the AF indirectly sends the request message 1 to the PCF through the NEF
  • the request message 1 includes the information of the terminal device
  • the information of the terminal device can also be used by the NEF to find the PCF that provides services for the session of the terminal device .
  • Step 302 the PCF sends a request message 2 to the SMF, the request message 2 is used to request to subscribe to the event of the service flow of the application service, and the request message 2 includes the identification of the application service, packet detection feature information and event identification 2 .
  • the SMF receives the request message 2 from the PCF.
  • the request message 2 may be an event subscription request message, or a policy association/control update notification message, or other messages, which are not limited in this application.
  • the request message 2 may also include flow description information, where the flow description information is used to indicate the service flow to which the packet detection characteristic information applies.
  • the request message 2 may also include a policy association identifier corresponding to the session of the terminal device, and the policy association identifier is used by the SMF to determine the session of the terminal device corresponding to the request message 2 and to search for the context of the session.
  • the event identifier 2 and the above event identifier 1 are used to indicate the same event, but the event identifier 2 and the event identifier 1 may be the same or different, which is not specifically limited in this application.
  • the difference between the event identifier 2 and the event identifier 1 may mean that the description forms of the event identifiers are different, and the description forms may include APP_START/STOP character strings or indication information. If the event identifier 2 is the same as the event identifier 1, the event identifier 2 may be directly obtained by the PCF from the AF.
  • the event identifier 2 may be determined by the PCF according to the event identifier 1 obtained from the AF, and there is a corresponding relationship between the event identifier 2 and the event identifier 1 .
  • One or more pieces of information such as the identification of the above application service, packet detection feature information or flow description information may be obtained by the PCF from the AF. For example, if the request message 1 includes the above one or multiple items of information, the PCF can obtain the above one or multiple items of information from the request message 1, and then include the above one or multiple items of information in the request message 2 and send it to SMF.
  • the PCF when the PCF receives the request message 1, the PCF can execute a policy decision according to the request message 1, generate a corresponding policy and charging control (policy and charging control, PCC) rule, and pass the request message 2 to the PCC Rules are sent to SMF.
  • the PCC rule may include the identifier of the application service, packet detection characteristic information and event identifier.
  • the PCC rule may also include flow description information.
  • Step 303 the SMF sends a request message 3 to the UPF, the request message 3 includes a detection rule and a usage reporting rule (usage reporting rule, URR), the detection rule is used to detect the service flow of the application service, and the detection rule includes the The above-mentioned identification of the application service and packet detection feature information, the URR includes event identification 3.
  • usage reporting rule URR
  • the UPF receives the request message 3 from the SMF.
  • the request message 3 may be an event subscription request message, or an N4 session modification request message, or other messages, which are not limited in this application. It should be noted that the request message 3 has an N4 session granularity, and the request message 3 corresponds to a session of the terminal device one by one.
  • the detection rule may be a packet detection rule (packet detection rule, PDR).
  • PDR packet detection rule
  • the PDR is used to detect the service flow of the application service in the session, that is, to detect the service flow of the application service in the session of the terminal device, or to detect the message of the application service in the session of the terminal device.
  • the URR is configured to report the usage statistics of the service flow of the application service after the event of the service flow of the application service is detected.
  • the PDR may also include flow description information, where the flow description information is used to indicate the service flow to which the packet detection feature information applies.
  • the flow description information may be obtained by the SMF from the PCF.
  • the URR may also include an event reporting indication, which is used to instruct the UPF to report a corresponding event report after detecting the event of the service flow of the application service.
  • the event reporting indication can be understood as a special indication for reporting Instructions for app events.
  • the event identifier 3 and the above event identifier 2 are used to indicate the same event, but the event identifier 3 and the event identifier 2 may be the same or different, which is not specifically limited in this application. In this application, the difference between the event identifier 3 and the event identifier 2 may mean that the description forms of the event identifiers are different. If the event identifier 3 is the same as the event identifier 2, the event identifier 3 may be directly obtained by the SMF from the PCF. If the event identifier 3 is different from the event identifier 2, the event identifier 3 may be determined by the SMF according to the event identifier 2 obtained from the PCF, and there is a corresponding relationship between the event identifier 3 and the event identifier 2 .
  • One or more items of information such as the identification of the above application service, packet detection feature information, flow description information or event reporting indication may be obtained by the SMF from the PCF. For example, if the request message 2 includes one or more items of information above, the SMF can obtain the above one or more items of information from the request message, and then include the identification of the application service, packet detection feature information or flow description information in the PDR , include the event reporting indication in the URR, and then send the PDR and URR to the UPF through request message 3.
  • the SMF can generate the N4 rule according to the PCC rule, and then send the above N4 rule to the UPF through the request message 3 for execution.
  • the N4 rule includes PDR and URR.
  • the PDR may include application service identification and packet detection feature information, and optionally, the PDR may also include flow description information.
  • the URR may also include an event identifier 3, and optionally, the URR may also include an event reporting indication and the like.
  • step 304 the UPF performs application detection on the received packets in the session according to the packet detection feature information.
  • the UPF when the UPF receives the PDR from the SMF, the UPF can perform application detection on the message in the session of the terminal device according to the PDR, which can also be understood as executing the application on the service flow in the session of the terminal device according to the PDR detection.
  • the packet in the session of the terminal device refers to the packet of the terminal device transmitted by the user plane.
  • Executing application detection may refer to determining whether a packet of a certain application service is received or judging which application service the received packet belongs to (that is, judging the service flow of which application service the received packet belongs to).
  • the UPF may perform application detection on packets in the session of the terminal device according to the packet detection characteristic information.
  • the UPF can directly perform application detection on the packets in the session of the terminal device according to the packet detection characteristic information. Since UPF usually performs service flow matching according to the priority order of each PDR in the session of the terminal device, the packets of other service flows after the service flow matching the PDR with higher priority are removed in the session of the terminal device The application detection will be performed on the original packet as the characteristic information of the packet detection. In this case, the packets in the session of the terminal device that match the packet detection feature information can be considered as packets in the service flow that match the PDR.
  • the UPF may perform application detection on packets matching the flow description information in the session of the terminal device according to the packet detection characteristic information.
  • the flow description information is included in the PDR
  • UPF can first perform application detection on the packets in the session of the terminal device according to the flow description information, and then perform application detection on the packets that match the flow description information in the previous step according to the packet detection characteristic information.
  • Application detection In the session of the terminal device, the packets of other service flows except the service flows matching the higher priority PDR will be executed as the original packets of the packet detection characteristic information Application detection.
  • the packets in the session of the terminal device that match both the flow description information and the packet detection characteristic information can be regarded as packets in the service flow that match the PDR.
  • Step 305 if an event of the service flow of the application service is detected, the UPF sends an event report 3 to the SMF, where the event report 3 is used to indicate the event.
  • the SMF receives the event report 3 from the UPF.
  • the UPF detecting the application start event of the service flow of the application service may refer to: the UPF detects that the above-mentioned packet detection characteristic information (or packet detection characteristic information and flow description information) is related to the session of the terminal device. matching message.
  • the UPF detects the application end event of the service flow of the application service may refer to: after the UPF detects a message that matches the above packet detection characteristic information (or packet detection characteristic information and flow description information) in the session of the terminal device, No more packets matching the above packet detection characteristic information (or packet detection characteristic information and flow description information) are detected within a period of time.
  • the event report 3 is used to report the event of the service flow of the application service, and the event report 3 may include the identifier of the application service and the event identifier 3 .
  • the UPF may send the above event report 3 to the SMF according to the event reporting instruction.
  • step 306 the SMF sends event report 2 to the PCF.
  • the PCF receives the event report 2 from the SMF.
  • the event report 2 is used to report the event of the service flow of the application service, and the event report 2 may include the identifier of the application service and the event identifier 2 .
  • step 307 the PCF sends event report 1 to the AF.
  • the AF receives event report 1 from the PCF.
  • the event report 1 is used to report the event of the service flow of the application service, and the event report 1 may include the identifier of the application service and the event identifier 1 .
  • the PCF may also indirectly send the event report 1 to the AF.
  • the PCF may send the event report 1 to the NEF, and the NEF may send the event report 1 to the AF.
  • the AF After the AF receives the event report 1 above, it can perform corresponding management actions on the terminal device based on the event report, such as notifying the adjustment of the encoding method, service packet sending cycle, and scheduled power-off.
  • the event report 1 and the event report 2 may also be the same.
  • the event report 2 and the event report 3 may also be the same.
  • the AF may subscribe to the PCF for application events, and provide packet detection feature information for application detection.
  • the PCF can subscribe to the application event to the SMF, and the SMF instructs the UPF to perform application detection.
  • UPF can perform application detection on the packets received in the session of the terminal device according to the packet detection characteristic information, and return corresponding event reports to AF through SMF and PCF.
  • the UPF can perform service detection on the packets in the session of the terminal device according to the packet detection feature information, the above technical solution can effectively distinguish the packets of different application services, and accurately determine the service flow of the application service to which the packets belong. judge. Furthermore, since the packet detection characteristic information can indicate the statistical characteristics and packet header characteristics of the packets in the service flow of the application service, compared with the technical solution in the prior art that only performs detection based on the plaintext domain name information in the packet header, the above-mentioned Technical solution In the scenario where packets of different application services have the same packet header (for example, encrypted packets or packets of different application services in industrial applications have the same packet header), it is also possible to Effectively differentiate, so as to accurately determine the type of application business.
  • the packet detection characteristic information can indicate the statistical characteristics and packet header characteristics of the packets in the service flow of the application service, compared with the technical solution in the prior art that only performs detection based on the plaintext domain name information in the packet header.
  • Figure 4 is another service perception method provided by this application, which includes:
  • Step 401 the AF sends a request message 4 to the NWDAF, the request message 4 is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, and the fourth request message includes the application service Identification and packet detection characteristic information, where the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service.
  • NWDAF receives request message 4 from AF.
  • the request message 4 may be an analysis subscription request message or other messages, which is not limited in this application.
  • the packet detection feature information of the application service may include statistical features and/or packet header features of packets in the service flow of the application service. Regarding the specific implementation manner of the packet detection feature information, reference may be made to the relevant description above, and details are not repeated here.
  • the request message 4 may include flow description information, which is used to indicate the service flow to which the packet detection feature information is applicable, and can also be understood as used to identify the service flow to be matched.
  • flow description information is used to indicate the service flow to which the packet detection feature information is applicable, and can also be understood as used to identify the service flow to be matched.
  • the request message 4 may include an event identifier, which is used to indicate the reporting of the event of the service flow of the application service, and the event identifier may be the identifier of the application start event of the service flow of the application service or the application The ID of the end event.
  • the request message 1 may include terminal device information, and the terminal device information may be used by NWDAF to determine the session of the terminal device corresponding to the request message 4, or the session of the terminal device where the service flow of the application service is located, Or the session of the terminal device to be detected.
  • NWDAF NWDAF
  • the request message 1 may include terminal device information, and the terminal device information may be used by NWDAF to determine the session of the terminal device corresponding to the request message 4, or the session of the terminal device where the service flow of the application service is located, Or the session of the terminal device to be detected.
  • NWDAF After NWDAF receives the request message 4 from the AF, NWDAF can determine the session of the terminal device corresponding to the request message 4 and the SMF that provides services for the session of the terminal device according to the information of the above-mentioned terminal device, so as to request the SMF to obtain Mirroring of packets in the session of this end device.
  • step 400 the terminal device initiates a session establishment procedure to establish a session of the above-mentioned terminal device.
  • the AF may directly or indirectly send the request message 4 to the NWDAF.
  • the AF directly sending the request message 4 to the NWDAF refers to: the AF directly sends the request message 4 to the NWDAF without being forwarded by other network elements.
  • AF sends request message 4 to NWDAF indirectly means: AF sends request message 4 to NWDAF through the forwarding of other network elements (such as NEF), for example, AF sends request message 4 to NEF, and NEF sends the request message 4 to NWDAF .
  • NEF network elements
  • the AF indirectly sends the request message 4 to the NWDAF through the NEF
  • the request message 4 includes the information of the terminal device
  • the information of the terminal device can also be used by the NWDAF to find the NWDAF that provides services for the session of the terminal device .
  • step 402 the NWDAF sends a request message 5 to the SMF, where the request message 5 is used to request forwarding the mirror image of the message in the session of the terminal device.
  • the SMF receives the request message 5 from the NWDAF.
  • the request message 5 may be a message subscription request message, or an event subscription request message, or an event exposure message, or other messages, which are not limited in this application.
  • the request message 5 may include flow description information, where the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device.
  • the flow description information may be obtained by the NWDAF from the AF. For example, if the request message 4 includes the flow description information, the NWDAF obtains the flow description information from the request message 4, and may carry the flow description information in the request message 5 and send it to the SMF. If the request message 5 does not include the flow description information, it means that the mirror image of all packets in the session of the terminal device needs to be forwarded.
  • the request message 5 may also include a mirroring destination address, which is the mirroring address of the message in the session receiving the terminal device in the NWDAF, and is used to instruct the SMF or UPF to forward the required message to the address
  • the mirror image of (for example, the mirror image of the message matching the above-mentioned flow description information in the session of the terminal device), the mirror destination address can also be called the mirror report address or event notification address or event report address, etc., which is not limited in this application.
  • the request message 5 may also include a mirroring forwarding indication, which may be used to indicate forwarding the mirroring of the packets in the session of the terminal device.
  • the mirror forwarding indication can also be understood as indication information for instructing to forward the mirroring of the message in the session of the terminal device.
  • Step 403 the SMF sends a request message 6 to the UPF, which includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, the forwarding rule includes a mirror forwarding indication, and the mirror forwarding Indicates the mirror image used to instruct forwarding the packets in the session of the terminal device.
  • the detection rule is used to detect the service flow in the session of the terminal device
  • the forwarding rule includes a mirror forwarding indication
  • the mirror forwarding Indicates the mirror image used to instruct forwarding the packets in the session of the terminal device.
  • the UPF receives the request message 6 from the SMF.
  • the request message 6 may be an event subscription request message, or an N4 session modification request message, or other messages, which are not limited in this application. It should be noted that the request message 6 has an N4 session granularity, and the request message 6 corresponds to a session of the terminal device one by one.
  • the detection rule may be a packet detection rule (packet detection rule, PDR), and the forwarding rule may be a forwarding action rule (forwarding action rule, FAR), and the FAR may include the above mirroring forwarding indication.
  • PDR packet detection rule
  • FAR forwarding action rule
  • the PDR may include flow description information or wildcard indication information.
  • the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device
  • the wildcard indication information is used to forward the image of all packets in the session of the terminal device. If the SMF obtains the flow description information from NWDAF, for example, the request message 5 contains the flow description information, then the SMF can include the flow description information in the PDR, indicating that the UPF needs to report the mirror image of the packet matching the flow description information in the session of the terminal device . If SMF does not obtain flow description information from NWDAF, SMF can include wildcard indication information in PDR.
  • This wildcard indication information can also be called match-all indication, indicating that UPF needs to report the mirror image of all packets in the session of the terminal device .
  • the SMF can clearly inform the UPF which mirror image of the message needs to be forwarded, so that the UPF can perform corresponding processing.
  • the FAR may also include a mirroring destination address, and the mirroring destination address is used by the UPF to directly forward the mirroring of the required packets to the NWDAF.
  • the mirroring destination address may be obtained by the SMF from the NWDAF.
  • the SMF may include the mirroring destination address in the FAR. It should be noted that the mirror destination address may not be included in the FAR. If the FAR does not include the mirror destination address, it means that the UPF needs to forward the mirror image of the above message to NWDAF through the SMF, that is, the UPF can send the mirror image of the above message to the SMF, and the SMF will forward the mirror image of the above message according to the mirror destination address. The image is sent to SMF.
  • the image forwarding instruction sent by the SMF to the UPF may be the same as or different from the image forwarding instruction sent by the NWDAF to the SMF, which is not limited in this application.
  • the different mirroring forwarding indications may mean that the description forms of the two are different.
  • the SMF may generate the N4 rule according to the request message 5, and then send the N4 rule to the UPF through the request message 6 for execution.
  • the N4 rule may include a PDR and a FAR, where the PDR may include flow description information or wildcard indication information, and the FAR may include a mirror forwarding indication.
  • the mirroring destination address may also be included in the FAR.
  • step 404 the UPF detects the packets in the session of the terminal device according to the detection rule.
  • Step 405 the UPF sends the mirror image of the message in the session of the terminal device to the SMF or NWDAF according to the mirror forwarding instruction.
  • the NWDAF receives the mirror image of the message in the session from the terminal device of the SMF or UPF.
  • the UPF after the UPF receives the request message 6 from the SMF, it can perform packet matching according to the PDR in it, and then perform packet mirroring according to the mirror forwarding instruction in the FAR corresponding to the PDR, and report the session in the terminal device to The image of the file is sent directly or indirectly to NWDAF.
  • the UPF may directly or indirectly send the image of the packet matching the flow description information in the session of the terminal device to the NWDAF. If the PDR includes wildcard indication information, the UPF may directly or indirectly send the images of all packets in the session of the terminal device to the NWDAF.
  • the UPF directly sends the mirror image of the session message of the terminal device to the NWDAF may refer to: the FAR includes the mirroring destination address, and the mirroring destination address is the address of the mirror image receiving the session message of the terminal device in the NWDAF, and the UPF may according to The mirroring destination address directly sends the mirroring of the message in the session of the terminal device to NWDAF, without forwarding by SMF in the middle.
  • UPF indirectly sending the packet in the session of the terminal device to NWDAF can refer to: FAR does not include the mirroring destination address, and UPF can send the mirror image of the packet in the session of the terminal device to NWDAF through SMF forwarding, that is, UPF first sends the packet of the terminal device to NWDAF. The mirror image of the message in the session is sent to the SMF, and then the SMF forwards it to the NWDAF.
  • the mirroring of the foregoing packet may also be referred to as a mirroring packet.
  • the mirroring of multiple packets can form the mirroring of a service flow, which can also be called a mirroring service flow.
  • the mirror forwarding process of the above message does not affect the forwarding of the original message by the UPF, that is, the UPF can still send the message in the session of the terminal device to the terminal device via the access network device as usual.
  • step 406 the NWDAF performs application detection on the image of the received packet according to the packet detection characteristic information.
  • step 406 For the specific implementation manner of this step 406, please refer to the related description about the UPF performing application detection on the received packet according to the packet detection characteristic information in the above step 304, and details are not repeated here.
  • Step 407 If an event of the service flow of the application service is detected, the NWDAF sends an event report to the AF, where the event report is used to indicate the event.
  • the AF receives the event report from the NWDAF.
  • the event report may include the identifier of the application service and an event identifier, the event identifier is used to indicate an event of the service flow of the application service, and the event identifier may be an application start event of the service flow of the application service The ID or ID of the application end event.
  • the AF can perform corresponding management actions on the terminal device based on the event report, such as notifying the adjustment of encoding mode, service message sending cycle, and scheduled power-off.
  • the AF may request the NWDAF to analyze the application event, and provide the NWDAF with packet detection feature information for application detection.
  • NWDAF can obtain the image of the message in the session of the terminal device from the UPF through SMF, perform application detection on the image of the received message according to the packet detection characteristic information, and return the corresponding event report to AF.
  • the above technical solution can effectively distinguish the messages of different application services, and perform the service flow of the application service to which the message belongs. judge accurately.
  • the packet detection characteristic information can indicate the statistical characteristics and packet header characteristics of the packets in the service flow of the application service, compared with the technical solution in the prior art that only performs detection based on the plaintext domain name information in the packet header, the above-mentioned Technical solution
  • packets of different application services have the same packet header (for example, encrypted packets or packets of different application services in industrial applications have the same packet header)
  • Figure 5 is another service perception method provided by this application, which includes:
  • Step 501 the AF sends a request message 7 to the PCF, the request message 7 is used to obtain the mirror image of the message in the session of the terminal device, the request message 7 includes the mirror destination address, and the mirror destination address is the AF receiving the mirror image address.
  • the PCF receives the request message 7 from the AF.
  • the request message 7 may be a policy authorization creation/update request message, or other messages, which are not limited in this application.
  • the request message 7 may include flow description information, and the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device. If the request message 7 does not include the flow description information, it means that the mirror image of all packets in the session of the terminal device needs to be forwarded. Regarding the specific implementation manner of the flow description information, reference may be made to the relevant description above, and details are not repeated here.
  • the request message 7 may include terminal device information, and the terminal device information is used by the PCF to determine the session of the terminal device corresponding to the request message 7, or the session of the terminal device to be detected.
  • the terminal device information is used by the PCF to determine the session of the terminal device corresponding to the request message 7, or the session of the terminal device to be detected.
  • the terminal device may initiate a session establishment process to establish a session of the above-mentioned terminal device.
  • the AF may directly or indirectly send the request message 7 to the PCF, which is similar to the sending of the request message 1 above and will not be repeated here.
  • step 502 the PCF sends a request message 8 to the SMF, the request message 8 is used to request forwarding the mirroring of the message in the session of the terminal device, and the request message 8 includes the mirroring destination address.
  • the SMF receives the request message 8 from the PCF.
  • the request message 8 may be a message subscription request message, or an event subscription request message, or a policy association/control update notification message, or other messages, which are not limited in this application.
  • the request message 8 may include flow description information, and the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device.
  • the flow description information may be obtained by the PCF from the AF, for example, if the request message 7 includes the flow description information, the PCF may obtain the flow description information from the request message 7, and then include the flow description information in the request message 8 Send to SMF.
  • the PCF when the PCF receives the request message 7 from the AF, the PCF can execute policy decisions according to the request message 7, generate corresponding PCC rules, and send the PCC rules to the SMF through the request message 8.
  • the PCC rule may include a mirroring destination address, and optionally flow description information, and is used to instruct the SMF to send a mirror image of a packet matching the flow description information in the session of the terminal device to the mirroring destination address.
  • Step 503 the SMF sends a request message 9 to the UPF, the request message 9 includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used for the traffic
  • the message is mirrored and forwarded, and the forwarding rule includes a mirroring forwarding indication and a mirroring destination address, and the mirroring forwarding indication is used to indicate forwarding the mirroring of the message in the session of the terminal device.
  • the UPF receives the request message 9 from the SMF.
  • the request message 9 may be a message subscription request message, an event subscription request message, an N4 session modification request message, or other messages, which are not limited in this application. It should be noted that the request message 9 has an N4 session granularity, and the request message 9 corresponds to a session of the terminal device one by one.
  • the detection rule can be a PDR
  • the forwarding rule can be a FAR or a packet mirror rule (packet mirror rule, PMR).
  • the forwarding rule can also be called a mirroring rule, or a mirroring forwarding rule, etc.
  • the PDR may include flow description information or wildcard indication information, wherein the flow description information is used to indicate the mirror image of the message matching the flow description information in the session of the forwarding terminal device, and the wildcard indication information is used to indicate the forwarding terminal device Mirroring of all packets in the session.
  • the SMF obtains the flow description information from the PCF, for example, the request message 8 includes the flow description information
  • the SMF may include the flow description information in the PDR, indicating that the UPF needs to report the image of the packet matching the flow description information in the session of the terminal device.
  • SMF does not obtain flow description information from NWDAF, SMF can include wildcard indication information in PDR.
  • This wildcard indication information can also be called match-all indication, indicating that UPF needs to report the mirror image of all packets in the session of the terminal device .
  • the SMF can clearly inform the UPF which mirror image of the message needs to be forwarded, so that the UPF can perform corresponding processing.
  • the SMF can generate the N4 rule according to the PCC rule, and then send the N4 rule to the UPF through the request message 9 for execution.
  • the N4 rule includes PDR and FAR, or includes PDR and PMR.
  • the PDR includes flow description information or wildcard indication information
  • the FAR or PMR includes a mirroring forwarding indication and a mirroring destination address.
  • step 504 the UPF detects the packets in the session of the terminal device according to the detection rule.
  • step 505 the UPF sends the mirror image of the message in the session of the terminal device to the AF according to the mirror forwarding instruction and the mirror destination address.
  • the AF receives the mirror image of the message in the session from the terminal device of the UPF.
  • the UPF after the UPF receives the request message 9 from the SMF, it can perform message matching according to the PDR therein, and then perform message mirroring according to the mirroring forwarding indication and the mirroring destination address in the FAR corresponding to the PDR, and the terminal
  • the mirror image of the packet in the session of the device is sent to the AF.
  • the mirroring of the message may also be called a mirroring message, and the mirroring of multiple messages may constitute a mirroring of a service flow, which may also be called a mirroring service flow.
  • UPF can send the mirror image of the message matching the flow description information in the session of the terminal device to AF; if the PDR includes wildcard indication information, UPF can send all A mirror image of the message is sent to the AF. It should be noted that the above message mirroring forwarding process does not affect the forwarding of the original message by the UPF.
  • step 506 the AF performs application detection according to the image of the received message.
  • the AF can determine the type of the application service according to the received image of the message in the session of the terminal device, and send a corresponding management command to the terminal device.
  • the AF can send the forwarding rules of the message to the UPF through the PCF and SMF, obtain the image of the message in the session of the terminal device, and then perform application detection according to the image of the received message, and perform subsequent management decisions.
  • the above technical solution opens the application detection capability to the AF, so that the AF can perceive the type of the application service actually initiated by the terminal device, so as to facilitate the AF to execute corresponding management decisions based on the application service currently initiated by the terminal device.
  • the AF may directly communicate with the terminal device, or may only serve as a management device for the terminal device without directly communicating with the terminal device.
  • FIG. 6 and FIG. 7 are schematic structural diagrams of possible communication devices provided by the embodiments of the present application. These communication devices can be used to implement the functions of the application function network element, the policy control function network element, the session management function network element, the user plane function network element or the network data analysis function network element in the above method embodiment, so the above method can also be implemented Beneficial effects possessed by the embodiment.
  • the communication device may be an application function network element, a policy control function network element, a session management function network element, a user plane function network element, or a network data analysis function network element, or it may be an application function network element Modules (such as chips) of network elements, policy control function network elements, session management function network elements, user plane function network elements, or network data analysis function network elements.
  • an application function network element Modules such as chips
  • a communication device 600 includes a processing unit 610 and a transceiver unit 620 .
  • the communication device 600 is used to implement the application function network element, the policy control function network element, the session management function network element, the user plane function network element or the network data analysis in any of the method embodiments shown in Fig. 3, Fig. 4 to Fig. 5 above.
  • Functional network element function As shown in FIG. 6 , a communication device 600 includes a processing unit 610 and a transceiver unit 620 .
  • the communication device 600 is used to implement the application function network element, the policy control function network element, the session management function network element, the user plane function network element or the network data analysis in any of the method embodiments shown in Fig. 3, Fig. 4 to Fig. 5 above.
  • Functional network element function function.
  • the transceiver unit 620 is configured to send a first request message to the user plane function network element, and the first request message includes A detection rule and a usage reporting rule, the detection rule includes the identification of the application service and packet detection feature information, the detection rule is used to detect the service flow of the application service in the session, and the packet detection feature information is used to indicate the application service
  • the usage reporting rule includes a first event identifier, the first event identifier is used to indicate the event of reporting the service flow of the application service, and the event is an application start event or an application end event;
  • the transceiver unit 620 It is further used for receiving a first event report from a user plane functional network element, where the first event report is used to indicate an event of the service flow of the application service.
  • the transceiver unit 620 is configured to receive a first request message from the session management function network element, in which Including a detection rule and a usage reporting rule, the detection rule includes the identification of the application service and packet detection feature information, the detection rule is used to detect the service flow of the application service in the session, and the packet detection feature information is used to indicate that the application service
  • the processing unit 610 configured to perform application detection on the received packets in the session according to the packet detection feature information; if an event of the service flow of the application service is detected, the transceiver unit 620 is used to send the session management function network element A first event report is sent, the first event report indicating the event.
  • the transceiver unit 620 is configured to receive a third request message from the application function network element, the third request message includes An application service identifier, packet detection feature information, and a third event identifier, where the packet detection feature information is used to indicate the matching feature of the service flow of the application service, and the third event identifier is used to indicate reporting of the service flow of the application service event, the event is an application start event or an application end event; the transceiver unit 620 is further configured to send a second request message to the session management function network element, where the second request message is used to request to subscribe to the event, and the second request The message includes the identifier of the application service, packet detection feature information, and a second event identifier, and the second event identifier is used to indicate reporting of the event; the transceiver unit 620 is also configured to receive the second event identifier from the session management function network element An event report, where the second
  • the transceiver unit 620 is configured to send a third request message to the policy control function network element, the third request message includes A service identifier, packet detection characteristic information, and a third event identifier, where the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service, and the third event identifier is used to indicate the reporting of the service flow of the application service An event, where the event is an application start event or an application end event; the transceiver unit 620 is further configured to receive a third event report from a network element with a policy control function, where the third event report is used to indicate the event.
  • the communication device 600 When the communication device 600 is used to realize the function of the network element with the network data analysis function in the method embodiment shown in FIG.
  • An event that requests to analyze the service flow of the application service the event is an application start event or an application end event, the fourth request message includes the identification of the application service and packet detection characteristic information, and the packet detection characteristic information is used to indicate the The matching feature of the service flow of the application service; the transceiver unit 620 is also configured to send a fifth request message to the session management function network element, and the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device; the processing unit 610, configured to perform application detection on the image received from the session management function network element or the user plane function network element according to the packet detection characteristic information; if the event of the service flow of the application service is detected, the transceiver unit 620 It is also used to send an event report to the application function network element, where the event report is used to indicate the event.
  • the transceiver unit 620 is configured to receive the fifth request message from the network data analysis function network element, the fifth request message It is used to request forwarding of the mirror image of the message in the session of the terminal device; the transceiver unit 620 is also used to send a sixth request message to the user plane functional network element, the sixth request message includes a detection rule and a forwarding rule, and the detection rule uses For detecting the service flow of the session of the terminal device, the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate the mirroring.
  • the transceiver unit 620 is configured to receive a sixth request message from the session management function network element, in which Including a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate forwarding the mirroring of the message in the session of the terminal device; processing The unit 610 is configured to detect the message in the session of the terminal device according to the detection rule; the transceiver unit 620 is also configured to send the image to the session management function network element or the network data analysis function network element according to the image forwarding instruction .
  • the transceiver unit 620 is configured to send a fourth request message to the network data analysis function network element, the fourth request message is used for An event requesting to analyze the service flow of the application service, the event is an application start event or an application end event, the fourth request message includes the identification of the application service and packet detection characteristic information, and the packet detection characteristic information is used to indicate the The matching feature of the service flow of the application service; the transceiver unit 620 is further configured to receive an event report from a network element with a network data analysis function, where the event report is used to indicate the event.
  • the seventh request message includes the mirroring destination address, and the mirroring destination address is the address receiving the mirroring in the application function network element; the transceiver unit 620 is also used to receive the The image of the network element; a processing unit 610, configured to perform application detection according to the image.
  • the transceiver unit 620 is configured to receive the seventh request message from the application function network element, the seventh request message is used Obtain the mirror image of the message in the session of the terminal device, the seventh request message includes the mirror image destination address, and the mirror image destination address is the address receiving the mirror image in the application function network element; the transceiver unit 620 is also used to report to the session management function The network element sends an eighth request message, where the eighth request message is used to request forwarding of the image, and the eighth request message includes the image destination address.
  • the eighth request message includes the mirroring destination address, and the mirroring destination address is the address receiving the mirroring in the application function network element; the transceiver unit 620 is also used to send the user
  • the surface function network element sends a ninth request message, the ninth request message includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used for the traffic flow in the session of the terminal device
  • the message is mirrored and forwarded, and the forwarding rule includes a mirroring forwarding indication and the mirroring destination address, and the mirroring forwarding indication is used to instruct forwarding of the mirroring.
  • the transceiver unit 620 is used to receive the detection rule and the forwarding rule from the session management function network element. Detect the service flow in the session of the terminal device.
  • the forwarding rule is used to mirror and forward the packets in the session of the terminal device.
  • the forwarding rule includes a mirror forwarding instruction and a mirror destination address.
  • the mirror destination address is the application function network element Receive the address of the mirror image;
  • the processing unit 610 is used to detect the message in the session of the terminal device according to the detection rule;
  • the transceiver unit 620 is used to send the mirror image to the application function network element according to the mirror forwarding instruction and the mirror destination address.
  • the processing unit 610 involved in the communication device may be realized by at least one processor or processor-related circuit components, and the transceiver unit 620 may be realized by at least one transceiver or transceiver-related circuit components or a communication interface.
  • the communication device may further include a storage unit, which may be used to store data and/or instructions, and the transceiver unit 620 and/or the processing unit 610 may read the data and/or instructions in the storage unit, thereby The communication device is made to implement a corresponding method.
  • the storage unit can be realized, for example, by at least one memory.
  • the above-mentioned storage unit, processing unit and transceiver unit may exist separately, or may be integrated in whole or in part, for example, the storage unit is integrated with the processing unit, or the processing unit is integrated with the transceiver unit.
  • each unit in the communication device is to implement the corresponding processes of the methods shown in FIG. 3 to FIG. 5 , and for the sake of brevity, details are not repeated here.
  • a communication device 700 includes a processor 710 and an interface circuit 720 .
  • the processor 710 and the interface circuit 720 are coupled to each other.
  • the interface circuit 720 may be a transceiver or an input-output interface.
  • the communication device 700 may further include a memory 730 for storing instructions executed by the processor 710, or storing input data required by the processor 710 to execute the instructions, or storing data generated by the processor 710 after executing the instructions.
  • the processor 710 is used to implement the functions of the processing unit 610
  • the interface circuit 720 is used to implement the functions of the transceiver unit 620 .
  • the processor in the embodiments of the present application can be a central processing unit (central processing unit, CPU), and can also be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application-specific integrated circuits (application specific integrated circuit, ASIC), field programmable gate array (field programmable gate array, FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof.
  • a general-purpose processor can be a microprocessor, or any conventional processor.
  • the method steps in the embodiments of the present application may be implemented by means of hardware, or may be implemented by means of a processor executing software instructions.
  • Software instructions can be composed of corresponding software modules, and software modules can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only Memory, registers, hard disk, removable hard disk, CD-ROM or any other form of storage medium known in the art.
  • An exemplary storage medium is coupled to the processor such the processor can read information from, and write information to, the storage medium.
  • the storage medium may also be a component of the processor.
  • the processor and storage medium can be located in the ASIC.
  • the ASIC can be located in the base station or the terminal.
  • the processor and the storage medium may also exist in the base station or the terminal as discrete components.
  • all or part of them may be implemented by software, hardware, firmware or any combination thereof.
  • software When implemented using software, it may be implemented in whole or in part in the form of a computer program product.
  • the computer program product comprises one or more computer programs or instructions. When the computer program or instructions are loaded and executed on the computer, the processes or functions described in the embodiments of the present application are executed in whole or in part.
  • the computer may be a general purpose computer, a special purpose computer, a computer network, a base station, user equipment or other programmable devices.
  • the computer program or instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instructions may be downloaded from a website, computer, A server or data center transmits to another website site, computer, server or data center by wired or wireless means.
  • the computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center integrating one or more available media.
  • the available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disk; and it may also be a semiconductor medium, such as a solid state disk.
  • the computer readable storage medium may be a volatile or a nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
  • “at least one” means one or more, and “multiple” means two or more.
  • “And/or” describes the association relationship of associated objects, indicating that there may be three types of relationships, for example, A and/or B, which can mean: A exists alone, A and B exist simultaneously, and B exists alone, where A, B can be singular or plural.
  • the character “/” generally indicates that the contextual objects are an “or” relationship; in the formulas of this application, the character “/” indicates that the contextual objects are a "division” Relationship.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The present application provides a service awareness method, a communication apparatus, and a communication system. The method comprises: a session management function network element sends a first request message to a user plane function network element, the first request message comprising a detection rule and a usage reporting rule, the detection rule comprising an identifier of an application service and packet detection feature information, the detection rule being used for detecting a service flow of the application service, the packet detection feature information being used for indicating a matching feature of the service flow of the application service, the usage reporting rule comprising an event identifier, the event identifier being used for indicating an event of reporting the service flow of the application service, and the event being an application start event or an application end event; and the session management function network element receives a first event report from the user plane function network element, the first event report being used for indicating the event. The technical solution can be used for effectively distinguishing packets of different application services.

Description

一种业务感知方法、通信装置及通信系统A service perception method, communication device and communication system
相关申请的交叉引用Cross References to Related Applications
本申请要求在2021年08月13日提交中国国家知识产权局、申请号为202110929598.2、申请名称为“一种业务感知方法、通信装置及通信系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims the priority of the Chinese patent application submitted to the State Intellectual Property Office of China on August 13, 2021, with the application number 202110929598.2 and the application title "A Service Perception Method, Communication Device, and Communication System". References are incorporated in this application.
技术领域technical field
本申请涉及无线通信技术领域,尤其涉及一种业务感知方法、通信装置及通信系统。The present application relates to the technical field of wireless communication, and in particular to a service perception method, a communication device and a communication system.
背景技术Background technique
现有技术中,针对业务流的应用检测主要依赖于对应用标识对应的报文包头中携带的明文域名信息(如IP三元组、域名、全限定域名(fully qualified domain name,FQDN)等)进行预先配置,根据报文包头中携带的明文域名信息执行应用检测,识别出报文属于哪个应用的业务流。In the prior art, the application detection for business flow mainly depends on the plaintext domain name information carried in the packet header corresponding to the application identification (such as IP triplet, domain name, fully qualified domain name (fully qualified domain name, FQDN), etc.) Perform pre-configuration, perform application detection based on the plaintext domain name information carried in the packet header, and identify the service flow of which application the packet belongs to.
然而,在实际场景中,终端设备传输的应用报文可能是加密报文,或者相同的报文包头可能实际对应多个不同的业务,这种情况下,采用现有技术,无法对不同应用业务的报文进行有效区分。However, in actual scenarios, the application packets transmitted by the terminal equipment may be encrypted packets, or the same packet header may actually correspond to multiple different services. The messages can be effectively distinguished.
发明内容Contents of the invention
本申请提供一种业务感知方法、通信装置及通信系统,用于对不同应用业务的报文进行有效区分。The present application provides a service perception method, a communication device and a communication system, which are used to effectively distinguish messages of different application services.
第一方面,本申请实施例提供一种业务感知方法,该方法可由会话管理功能网元或应用于会话管理功能网元中的模块(如芯片)来执行。In the first aspect, the embodiment of the present application provides a service perception method, which can be executed by a session management function network element or a module (such as a chip) applied to the session management function network element.
该方法包括:会话管理功能网元向用户面功能网元发送第一请求消息,该第一请求消息中包括检测规则和用量上报规则,该检测规则包括应用业务的标识和包检测特征信息,该检测规则用于检测会话中所述应用业务的业务流,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该用量上报规则包括第一事件标识,该第一事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;会话管理功能网元接收来自用户面功能网元的第一事件报告,该第一事件报告用于指示所述应用业务的业务流的事件。The method includes: the session management function network element sends a first request message to the user plane function network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes an application service identifier and packet detection feature information, the The detection rule is used to detect the service flow of the application service in the session, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, and the first event identifier is used Instructing to report the event of the service flow of the application service, the event is an application start event or an application end event; the session management function network element receives the first event report from the user plane function network element, and the first event report is used to indicate An event of a service flow of the application service.
上述技术方案,会话管理功能网元可通过发送请求消息的方式请求用户面功能网元执行应用检测,并提供应用业务的包检测特征信息。用户面功能网元可根据该包检测特征信息对接收到报文执行应用检测。从而实现对不同应用业务的报文进行有效区分,有效提高应用检测的准确性。In the above technical solution, the session management functional network element may request the user plane functional network element to perform application detection by sending a request message, and provide packet detection characteristic information of the application service. The user plane functional network element can perform application detection on the received packet according to the packet detection feature information. In this way, packets of different application services can be effectively distinguished, and the accuracy of application detection can be effectively improved.
在第一方面的一种可能的设计中,该方法还包括:会话管理功能网元接收来自策略控制功能网元的第二请求消息,该第二请求消息用于订阅所述事件,该第二请求消息中包括所述应用业务的标识、包检测特征信息和第二事件标识,该第二事件标识用于指示上报所 述事件;会话管理功能网元向策略控制功能网元发送第二事件报告,该第二事件报告用于指示所述事件。In a possible design of the first aspect, the method further includes: the session management function network element receives a second request message from the policy control function network element, the second request message is used to subscribe to the event, and the second The request message includes the identification of the application service, the packet detection feature information and the second event identification, and the second event identification is used to indicate the reporting of the event; the session management function network element sends the second event report to the policy control function network element , the second event report is used to indicate the event.
在第一方面的一种可能的设计中,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。In a possible design of the first aspect, the packet detection feature information includes statistical features and/or packet header features of packets in the service flow of the application service.
上述技术方案,可解决由于报文的包头中明文域名信息的能力限制导致无法判断报文归属的业务流,无法准确确定应用业务的类型的问题。例如,可以在加密报文或不同应用业务的报文具有相同的包头的情况下,准确识别不同应用业务的报文。The above technical solution can solve the problem of being unable to determine the service flow to which the message belongs and the type of the application service unable to be accurately determined due to the capability limitation of the plaintext domain name information in the packet header of the message. For example, when encrypted messages or messages of different application services have the same packet header, the messages of different application services can be accurately identified.
在第一方面的一种可能的设计中,所述检测规则还包括流描述信息,该流描述信息用于指示包检测特征信息适用的业务流;所述第二请求消息中包括该流描述信息。In a possible design of the first aspect, the detection rule further includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection feature information is applicable; the flow description information is included in the second request message .
上述技术方案,将包检测特征信息与流描述信息共同用于应用检测,可有效提高应用检测的准确性。In the above technical solution, the packet detection feature information and flow description information are used together for application detection, which can effectively improve the accuracy of application detection.
在第一方面的一种可能的设计中,所述第一事件报告包括所述应用业务的标识和第一事件标识,所述第二事件报告包括所述应用业务的标识和第二事件标识。In a possible design of the first aspect, the first event report includes the identifier of the application service and the first event identifier, and the second event report includes the identifier of the application service and the second event identifier.
第二方面,本申请实施例提供一种业务感知方法,该方法可由用户面功能网元或应用于用户面功能网元中的模块(如芯片)来执行。In the second aspect, the embodiment of the present application provides a service perception method, which can be executed by a user plane functional network element or a module (such as a chip) applied to the user plane functional network element.
该方法包括:用户面功能网元接收来自会话管理功能网元的第一请求消息,该第一请求消息中包括检测规则和用量上报规则,该检测规则包括应用业务的标识和包检测特征信息,该检测规则用于检测会话中所述应用业务的业务流,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该用量上报规则包括第一事件标识,该第一事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;用户面功能网元根据包检测特征信息对接收到的会话中的报文执行应用检测;若检测到所述应用业务的业务流的事件,用户面功能网元向会话管理功能网元发送第一事件报告,该第一事件报告用于指示所述事件。The method includes: a user plane function network element receives a first request message from a session management function network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes an application service identifier and packet detection feature information, The detection rule is used to detect the service flow of the application service in the session, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, and the first event identifier An event used to indicate to report the service flow of the application service, the event is an application start event or an application end event; the user plane functional network element performs application detection on the received packet in the session according to the packet detection characteristic information; if detected For an event of the service flow of the application service, the user plane functional network element sends a first event report to the session management functional network element, where the first event report is used to indicate the event.
在第二方面的一种可能的设计中,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。In a possible design of the second aspect, the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
在第二方面的一种可能的设计中,所述检测规则包括流描述信息,该流描述信息用于指示包检测特征信息适用的业务流;所述用户面功能网元根据包检测特征信息对接收到的报文执行应用检测,包括:用户面功能网元根据包检测特征信息,对所述会话中与该流描述信息匹配的报文执行应用检测。In a possible design of the second aspect, the detection rule includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection characteristic information applies; Executing application detection on received packets includes: performing application detection on packets in the session that match the flow description information according to packet detection characteristic information.
在第二方面的一种可能的设计中,所述第一事件报告包括所述应用业务的标识和第一事件标识。In a possible design of the second aspect, the first event report includes the identifier of the application service and the identifier of the first event.
第三方面,本申请实施例提供一种业务感知方法,该方法可由策略控制功能网元或应用于由策略控制功能网元中的模块(如芯片)来执行。In the third aspect, the embodiment of the present application provides a service perception method, which can be executed by a network element with a policy control function or a module (such as a chip) applied to a network element with a policy control function.
该方法包括:策略控制功能网元接收来自应用功能网元的第三请求消息,该第三请求消息中包括应用业务的标识、包检测特征信息和第三事件标识,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该第三事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;策略控制功能网元向会话管理功能网元发送第二请求消息,该第二请求消息用于请求订阅所述事件,该第二请求消息中包括所述应用业务的标识、包检测特征信息和第二事件标识,该第二事件标识用于指示上报所述事件;策略控制功能网元接收来自会话管理功能网元的第二事件报告,该第二事件报告用 于指示所述事件;策略控制功能网元向应用功能网元发送第三事件报告,该第二事件报告用于指示所述事件。The method includes: the policy control function network element receives a third request message from the application function network element, the third request message includes the identifier of the application service, packet detection characteristic information and a third event identifier, and the packet detection characteristic information is used for Indicate the matching feature of the service flow of the application service, the third event identifier is used to indicate the event of reporting the service flow of the application service, the event is an application start event or an application end event; the policy control function network element sends a session management The functional network element sends a second request message, the second request message is used to request to subscribe to the event, the second request message includes the identification of the application service, packet detection feature information and a second event identification, the second event The identifier is used to indicate the reporting of the event; the policy control function network element receives the second event report from the session management function network element, and the second event report is used to indicate the event; the policy control function network element sends the application function network element A third event report, the second event report is used to indicate the event.
在第三方面的一种可能的设计中,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。In a possible design of the third aspect, the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
在第三方面的一种可能的设计中,所述第二请求消息和所述第三请求消息中还包括流描述信息,该流描述信息用于指示包检测特征信息适用的业务流。In a possible design of the third aspect, the second request message and the third request message further include flow description information, where the flow description information is used to indicate a service flow to which the packet detection feature information applies.
在第三方面的一种可能的设计中,所述第二事件报告包括所述应用业务的标识和第二事件标识,所述第三事件报告包括所述应用业务的标识和第三事件标识。In a possible design of the third aspect, the second event report includes the identifier of the application service and a second event identifier, and the third event report includes the identifier of the application service and a third event identifier.
第四方面,本申请实施例提供一种业务感知方法,该方法可由应用功能网元执行或应用于应用功能网元中的模块(如芯片)来执行。In a fourth aspect, the embodiment of the present application provides a service perception method, which can be executed by an application function network element or applied to a module (such as a chip) in the application function network element.
该方法包括:应用功能网元向策略控制功能网元发送第三请求消息,该第三请求消息中包括应用业务的标识、包检测特征信息和第三事件标识,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该第三事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;应用功能网元接收来自策略控制功能网元的第三事件报告,该第三事件报告用于指示所述事件。The method includes: the application function network element sends a third request message to the policy control function network element, the third request message includes the identifier of the application service, packet detection characteristic information and a third event identifier, and the packet detection characteristic information is used to indicate The matching feature of the service flow of the application service, the third event identifier is used to indicate the event of reporting the service flow of the application service, and the event is an application start event or an application end event; the application function network element receives the event from the policy control function A third event report of the network element, where the third event report is used to indicate the event.
在第四方面的一种可能的设计中,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。In a possible design of the fourth aspect, the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
在第四方面的一种可能的设计中,所述第三请求消息中还包括流描述信息,该流描述信息用于指示所述包检测特征信息适用的业务流。In a possible design of the fourth aspect, the third request message further includes flow description information, where the flow description information is used to indicate a service flow to which the packet detection characteristic information applies.
在第四方面的一种可能的设计中,所述第三事件报告包括所述应用业务的标识和第三事件标识。In a possible design of the fourth aspect, the third event report includes an identifier of the application service and a third event identifier.
在第四方面的一种可能的设计中,所述应用开始事件用于触发策略控制功能网元向终端设备发起配置更新流程。In a possible design of the fourth aspect, the application start event is used to trigger a policy control function network element to initiate a configuration update process to the terminal device.
上述第二方面至第四方面的任一种可能的设计中的有益效果,可参考第一方面中的对应描述,重复之处不再赘述。For the beneficial effect of any possible design of the above-mentioned second aspect to the fourth aspect, reference may be made to the corresponding description in the first aspect, and repeated descriptions will not be repeated.
第五方面,本申请实施例提供一种业务感知方法,该方法可由网络数据分析功能网元或应用于网络数据分析功能网元中的模块(如芯片)来执行。In the fifth aspect, the embodiment of the present application provides a service perception method, which can be executed by a network element with a network data analysis function or a module (such as a chip) applied to a network element with a network data analysis function.
该方法包括:网络数据分析功能网元接收来自应用功能网元的第四请求消息,该第四请求消息用于请求分析应用业务的业务流的事件,该事件为应用开始事件或应用结束事件,该第四请求消息中包括所述应用业务的标识和包检测特征信息,该包检测特征信息用于指示所述应用业务的业务流的匹配特征;网络数据分析功能网元向会话管理功能网元发送第五请求消息,该第五请求消息用于请求转发终端设备的会话中报文的镜像;网络数据分析功能网元根据包检测特征信息,对接收到的来自会话管理功能网元或用户面功能网元的所述镜像执行应用检测;若检测到所述应用业务的业务流的事件,网络数据分析功能网元向应用功能网元发送事件报告,该事件报告用于指示所述事件。The method includes: the network data analysis function network element receives a fourth request message from the application function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, The fourth request message includes the identification of the application service and packet detection feature information, and the packet detection feature information is used to indicate the matching feature of the service flow of the application service; the network data analysis function network element sends the session management function network element Sending the fifth request message, the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device; the network data analysis function network element according to the packet detection feature information, the received from the session management function network element or the user plane The mirror image of the functional network element performs application detection; if an event of the service flow of the application service is detected, the network data analysis functional network element sends an event report to the application functional network element, and the event report is used to indicate the event.
上述技术方案中,网络数据分析功能网元可通过会话管理功能网元从用户面功能网元获取终端设备的会话中报文的镜像,根据应用功能网元提供的包检测特征信息对接收到的报文的镜像执行应用检测,并向应用功能网元返回相应的事件报告。从而实现对不同应用业务的报文进行有效区分,有效提高应用检测的准确性。In the above technical solution, the network data analysis function network element can obtain the mirror image of the message in the session of the terminal device from the user plane function network element through the session management function network element, and analyze the received packets according to the packet detection feature information provided by the application function network element. The mirror image of the message performs application detection, and returns a corresponding event report to the application function network element. In this way, packets of different application services can be effectively distinguished, and the accuracy of application detection can be effectively improved.
在第五方面的一种可能的设计中,所述包检测特征信息包括所述应用业务的业务流中 报文的统计特征和/或包头特征。In a possible design of the fifth aspect, the packet detection feature information includes statistical features and/or packet header features of packets in the service flow of the application service.
上述技术方案,可解决由于报文的包头中明文域名信息的能力限制导致无法判断报文归属的业务流,无法准确确定应用业务的类型的问题。例如,可以在加密报文或不同应用业务的报文具有相同的包头的情况下,准确识别不同应用业务的报文。The above technical solution can solve the problem of being unable to determine the service flow to which the message belongs and the type of the application service unable to be accurately determined due to the capability limitation of the plaintext domain name information in the packet header of the message. For example, when encrypted messages or messages of different application services have the same packet header, the messages of different application services can be accurately identified.
在第五方面的一种可能的设计中,所述第四请求消息中还包括流描述信息,该流描述信息用于指示所述包检测特征信息适用的业务流;所述第五请求消息中还包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像。In a possible design of the fifth aspect, the fourth request message further includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection feature information is applicable; in the fifth request message It also includes flow description information, where the flow description information is used to indicate the mirroring of the packets matching the flow description information in the session of the forwarding terminal device.
上述技术方案,将包检测特征信息与流描述信息共同用于应用检测,可有效提高应用检测的准确性。而且,网络数据分析功能网元可请求转发终端设备的会话中与流描述信息匹配的报文的镜像,无需转发所有报文的镜像,因此,减少网元之间传输的报文的数据量,充分利用网络资源。In the above technical solution, the packet detection feature information and flow description information are used together for application detection, which can effectively improve the accuracy of application detection. Moreover, the network element with the network data analysis function can request to forward the mirror image of the message matching the flow description information in the session of the terminal device, without forwarding the mirror image of all messages, therefore, reducing the data volume of the message transmitted between network elements, Make full use of network resources.
在第五方面的一种可能的设计中,所述第五请求消息中还包括镜像目的地址,该镜像目的地址为网络数据分析功能网元中接收所述镜像的地址。如此,可便于会话管理功能网元或用户面功能网元向网络数据分析功能网元转发终端设备的会话中业务流的镜像。In a possible design of the fifth aspect, the fifth request message further includes a mirroring destination address, where the mirroring destination address is an address of a network element with a network data analysis function that receives the mirroring. In this way, it is convenient for the session management function network element or the user plane function network element to forward the mirror image of the service flow in the session of the terminal device to the network data analysis function network element.
在第五方面的一种可能的设计中,所述第四请求消息中还包括事件标识,该事件标识用于指示上报所述事件;所述事件报告中包括所述应用业务的标识和该事件标识。In a possible design of the fifth aspect, the fourth request message further includes an event identifier, and the event identifier is used to indicate reporting of the event; the event report includes the identifier of the application service and the event logo.
第六方面,本申请实施例提供一种业务感知方法,该方法可由会话管理功能网元或应用于会话管理功能网元中的模块(如芯片)来执行。In a sixth aspect, the embodiment of the present application provides a service perception method, which can be executed by a session management function network element or a module (such as a chip) applied to the session management function network element.
该方法包括:会话管理功能网元接收来自网络数据分析功能网元的第五请求消息,该第五请求消息用于请求转发终端设备的会话中报文的镜像;会话管理功能网元向用户面功能网元发送第六请求消息,该第六请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话的业务流,该转发规则中包括镜像转发指示,该镜像转发指示用于指示转发所述镜像。The method includes: the session management function network element receives the fifth request message from the network data analysis function network element, and the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device; the session management function network element sends the user interface The functional network element sends a sixth request message, the sixth request message includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow of the session of the terminal device, the forwarding rule includes a mirror forwarding indication, and the mirroring forwarding indication uses Instruct to forward the image.
在第六方面的一种可能的设计中,所述第五请求消息中包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像;所述检测规则中包括该流描述信息。In a possible design of the sixth aspect, the fifth request message includes flow description information, and the flow description information is used to indicate forwarding the image of the message matching the flow description information in the session of the terminal device; The flow description information is included in the above detection rules.
在第六方面的一种可能的设计中,所述检测规则中包括通配指示信息,该通配指示信息用于转发终端设备的会话中所有报文的镜像。In a possible design of the sixth aspect, the detection rule includes wildcard indication information, and the wildcard indication information is used to forward images of all packets in the session of the terminal device.
上述技术方案,通过在检测规则中包含流描述信息或通配指示信息,会话管理功能网元可明确告知用户面功能网元指示需要转发终端设备的会话中哪些报文的镜像,从而便于用户面功能网元执行相应的处理。In the above technical solution, by including the flow description information or wildcard indication information in the detection rule, the session management function network element can clearly inform the user plane function network element to indicate which packets in the session of the terminal device need to be forwarded, so that the user plane The functional network element performs corresponding processing.
在第六方面的一种可能的设计中,所述第五请求消息中还包括镜像目的地址,该镜像目的地址为网络数据分析功能网元中接收所述镜像的地址。In a possible design of the sixth aspect, the fifth request message further includes a mirroring destination address, where the mirroring destination address is an address of a network element with a network data analysis function that receives the mirroring.
在第六方面的一种可能的设计中,该方法还包括:会话管理功能网元接收来自用户面功能网元的所述镜像,并根据镜像目的地址向网络数据分析功能网元发送所述镜像;或者,所述转发规则中还包括镜像目的地址。In a possible design of the sixth aspect, the method further includes: the session management function network element receives the image from the user plane function network element, and sends the image to the network data analysis function network element according to the image destination address ; Or, the forwarding rule also includes a mirroring destination address.
第七方面,本申请实施例提供一种业务感知方法,该方法可由用户面功能网元或应用于用户面功能网元中的模块(如芯片)来执行。In a seventh aspect, the embodiment of the present application provides a service perception method, which can be executed by a user plane functional network element or a module (such as a chip) applied to the user plane functional network element.
该方法包括:用户面功能网元接收来自会话管理功能网元的第六请求消息,该第六请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该 转发规则中包括镜像转发指示,该镜像转发指示用于指示转发终端设备的会话中报文的镜像;用户面功能网元根据所述检测规则,检测终端设备的会话中的报文;用户面功能网元根据镜像转发指示,向会话管理功能网元或网络数据分析功能网元发送所述镜像。The method includes: the user plane function network element receives a sixth request message from the session management function network element, the sixth request message includes a detection rule and a forwarding rule, and the detection rule is used to detect the service flow in the session of the terminal device, The forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate forwarding the mirroring of the message in the session of the terminal device; the user plane functional network element detects the message in the session of the terminal device according to the detection rule; the user plane The functional network element sends the image to the session management functional network element or the network data analysis functional network element according to the image forwarding instruction.
在第七方面的一种可能的设计中,所述检测规则中包括流描述信息;该方法还包括:用户面功能网元根据该流描述信息,向会话管理功能网元或网络数据分析功能网元发送终端设备的会话中与该流描述信息匹配的报文的镜像。In a possible design of the seventh aspect, the detection rule includes flow description information; the method further includes: according to the flow description information, the user plane function network element sends a session management function network element or a network data analysis function network The mirror image of the message matching the flow description information in the session of the original sending terminal device.
在第七方面的一种可能的设计中,所述检测规则中包括通配指示信息;该方法还包括:用户面功能网元根据该通配指示信息,向会话管理功能网元或网络数据分析功能网元发送终端设备的会话中所有报文的镜像。In a possible design of the seventh aspect, the detection rule includes wildcard indication information; the method further includes: according to the wildcard indication information, the user plane function network element sends a session management function network element or network data analysis The functional network element sends the mirror image of all packets in the session of the terminal device.
在第七方面的一种可能的设计中,所述转发规则中还包括镜像目的地址;所述用户面功能网元向网络数据分析功能网元发送所述镜像,包括:用户面功能网元根据该镜像目的地址,向网络数据分析功能网元发送所述镜像。In a possible design of the seventh aspect, the forwarding rule further includes the destination address of the image; the sending of the image by the user plane functional network element to the network data analysis function network element includes: the user plane functional network element according to The destination address of the image is used to send the image to the network element with the network data analysis function.
第八方面,本申请实施例提供一种业务感知方法,该方法可由应用功能网元或应用于应用功能网元中的模块(如芯片)来执行。In an eighth aspect, the embodiment of the present application provides a service perception method, which can be executed by an application function network element or a module (such as a chip) applied to the application function network element.
该方法包括:应用功能网元向网络数据分析功能网元发送第四请求消息,该第四请求消息用于请求分析应用业务的业务流的事件,该事件为应用开始事件或应用结束事件,该第四请求消息中包括所述应用业务的标识和包检测特征信息,该包检测特征信息用于指示所述应用业务的业务流的匹配特征;应用功能网元接收来自网络数据分析功能网元的事件报告,该事件报告用于指示所述事件。The method includes: the application function network element sends a fourth request message to the network data analysis function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, the The fourth request message includes the identification of the application service and packet detection characteristic information, the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service; the application function network element receives the network data analysis function network element An event report indicating the event.
在第八方面的一种可能的设计中,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。In a possible design of the eighth aspect, the packet detection characteristic information includes statistical characteristics and/or packet header characteristics of packets in the service flow of the application service.
在第八方面的一种可能的设计中,所述第四请求消息中还包括流描述信息,该流描述信息用于指示包检测特征信息适用的业务流。In a possible design of the eighth aspect, the fourth request message further includes flow description information, where the flow description information is used to indicate a service flow to which the packet detection feature information applies.
在第八方面的一种可能的设计中,所述第四请求消息中还包括事件标识,该事件标识用于指示上报所述事件;所述事件报告中包括所述应用业务的标识和该事件标识。In a possible design of the eighth aspect, the fourth request message further includes an event identifier, and the event identifier is used to indicate reporting of the event; the event report includes the identifier of the application service and the event logo.
上述第六方面至第八方面的任一种可能的设计中的有益效果,可参考第五方面中的对应描述,重复之处不再赘述。For the beneficial effects of any possible design of the sixth aspect to the eighth aspect, reference may be made to the corresponding description in the fifth aspect, and repeated descriptions will not be repeated.
第九方面,本申请实施例提供一种业务感知方法,该方法可由应用功能网元或应用于应用功能网元中的模块(如芯片)来执行。In a ninth aspect, the embodiment of the present application provides a service perception method, which can be executed by an application function network element or a module (such as a chip) applied to the application function network element.
该方法包括:应用功能网元向策略控制功能网元发送第七请求消息,该第七请求消息用于获取终端设备的会话中报文的镜像,该第七请求消息中包括镜像目的地址,该镜像目的地址为应用功能网元中接收所述镜像的地址;应用功能网元接收来自用户面功能网元的所述镜像;应用功能网元根据所述镜像执行应用检测。The method includes: the application function network element sends a seventh request message to the policy control function network element, the seventh request message is used to obtain the mirror image of the message in the session of the terminal device, the seventh request message includes a mirror destination address, the The destination address of the image is the address of the application function network element receiving the image; the application function network element receives the image from the user plane function network element; the application function network element performs application detection according to the image.
上述技术方案中,应用功能网元可通过策略控制功能网元、会话管理功能网元向用户面功能网元发送转发规则,获取终端设备的会话中报文的镜像,进而根据接收到的报文的镜像进行应用检测。从而使得应用功能网元能够感知终端设备实际所发起的应用业务的类型,便于AF基于终端设备当前发起的应用业务执行相应的管理决策。In the above technical solution, the application function network element can send forwarding rules to the user plane function network element through the policy control function network element and the session management function network element to obtain the mirror image of the message in the session of the terminal device, and then according to the received message mirror image for application detection. In this way, the application function network element can perceive the type of the application service actually initiated by the terminal device, and it is convenient for the AF to execute corresponding management decisions based on the application service currently initiated by the terminal device.
在第九方面的一种可能的设计中,所述第七请求消息中还包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像。In a possible design of the ninth aspect, the seventh request message further includes flow description information, and the flow description information is used to indicate forwarding a mirror image of a packet matching the flow description information in a session of the terminal device.
上述技术方案中,通过在第七请求消息中携带流描述信息,应用功能网元可请求转发 终端设备的会话中与该流描述信息匹配的报文的镜像,而无需转发所有报文的镜像,从而、减少网元之间传输的报文的数据量,充分利用网络资源。In the above technical solution, by carrying the flow description information in the seventh request message, the application function network element can request to forward the mirror image of the message matching the flow description information in the session of the terminal device, without forwarding the mirror image of all messages, Therefore, the data volume of messages transmitted between network elements is reduced, and network resources are fully utilized.
第十方面,本申请实施例提供一种业务感知方法,该方法可由策略控制功能网元或应用于策略控制功能网元中的模块(如芯片)来执行。In a tenth aspect, the embodiment of the present application provides a service awareness method, which can be executed by a network element with a policy control function or a module (such as a chip) applied to a network element with a policy control function.
该方法包括:策略控制功能网元接收来自应用功能网元的第七请求消息,该第七请求消息用于获取终端设备的会话中报文的镜像,该第七请求消息中包括镜像目的地址,该镜像目的地址为应用功能网元中接收所述镜像的地址;策略控制功能网元向会话管理功能网元发送第八请求消息,该第八请求消息用于请求转发所述镜像,该第八请求消息中包括所述镜像目的地址。The method includes: the policy control function network element receives a seventh request message from the application function network element, the seventh request message is used to obtain the mirror image of the message in the session of the terminal device, and the seventh request message includes a mirror destination address, The destination address of the image is the address receiving the image in the application function network element; the policy control function network element sends an eighth request message to the session management function network element, and the eighth request message is used to request forwarding of the image, the eighth The mirroring destination address is included in the request message.
在第十方面的一种可能的设计中,所述第七请求消息中还包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像;所述第八请求消息中还包括该流描述信息。In a possible design of the tenth aspect, the seventh request message further includes flow description information, where the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device; The eighth request message also includes the stream description information.
第十一方面,本申请实施例提供一种业务感知方法,该方法可由会话管理功能网元或应用于会话管理功能网元中的模块(如芯片)来执行。In an eleventh aspect, the embodiment of the present application provides a service perception method, which can be executed by a session management function network element or a module (such as a chip) applied to the session management function network element.
该方法包括:会话管理功能网元接收来自策略控制功能网元的第八请求消息,该第八请求消息用于请求转发终端设备的会话中报文的镜像,该第八请求消息中包括镜像目的地址,该镜像目的地址为应用功能网元中接收所述镜像的地址;会话管理功能网元向用户面功能网元发送第九请求消息,该第九请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则用于对终端设备的会话中的报文进行镜像转发,该转发规则中包括镜像转发指示和所述镜像目的地址,该镜像转发指示用于指示转发所述镜像。The method includes: the session management function network element receives an eighth request message from the policy control function network element, the eighth request message is used to request forwarding the mirroring of the message in the session of the terminal device, and the eighth request message includes the mirroring purpose address, the mirroring destination address is the address of the application function network element receiving the mirroring; the session management function network element sends a ninth request message to the user plane function network element, the ninth request message includes detection rules and forwarding rules, the The detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used to mirror and forward the message in the session of the terminal device. The forwarding rule includes a mirror forwarding indication and the mirror destination address, and the mirror forwarding The instruction is used to instruct to forward the image.
在第十一方面的一种可能的设计中,所述检测规则中包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像。In a possible design of the eleventh aspect, the detection rule includes flow description information, and the flow description information is used to indicate the mirror image of the packet that matches the flow description information in the session of the forwarding terminal device.
在第十一方面的一种可能的设计中,所述检测规则中包括通配指示信息,该通配指示信息用于转发终端设备的会话中所有报文的镜像。In a possible design of the eleventh aspect, the detection rule includes wildcard indication information, and the wildcard indication information is used to forward images of all packets in the session of the terminal device.
上述技术方案中,通过在检测规则中包含流描述信息或通配指示信息,会话管理功能网元可明确告知用户面功能网元需要转发终端设备的会话中哪些报文的镜像,从而便于用户面功能网元执行相应的处理。In the above technical solution, by including flow description information or wildcard indication information in the detection rule, the session management function network element can clearly inform the user plane function network element which mirror images of the packets in the session of the terminal device need to be forwarded, so as to facilitate the user plane The functional network element performs corresponding processing.
第十二方面,本申请实施例提供一种业务感知方法,该方法可由用户面功能网元或应用于用户面功能网元中的模块(如芯片)来执行。In a twelfth aspect, the embodiment of the present application provides a service perception method, which can be executed by a user plane functional network element or a module (such as a chip) applied to the user plane functional network element.
该方法包括:用户面功能网元接收来自会话管理功能网元的检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则用于对终端设备的会话中的报文进行镜像转发,该转发规则中包括镜像转发指示和镜像目的地址,该镜像目的地址为应用功能网元中接收镜像的地址;用户面功能网元根据检测规则,检测终端设备的会话中的报文;用户面功能网元根据镜像转发指示和镜像目的地址,向应用功能网元发送所述镜像。The method includes: the user plane functional network element receives a detection rule and a forwarding rule from a session management functional network element, the detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used to detect the traffic flow in the session of the terminal device The packet is mirrored and forwarded. The forwarding rule includes a mirrored forwarding instruction and a mirrored destination address. The mirrored destination address is the address received in the application function network element; the user plane function network element detects the session of the terminal device according to the detection rule message: the user plane function network element sends the image to the application function network element according to the image forwarding instruction and the image destination address.
在第十二方面的一种可能的设计中,所述检测规则中包括流描述信息;该方法还包括:用户面功能网元根据该流描述信息,向应用功能网元发送终端设备的会话中与该流描述信息匹配的报文的镜像。In a possible design of the twelfth aspect, the detection rule includes flow description information; the method further includes: the user plane function network element sends the session information of the terminal device to the application function network element according to the flow description information Mirroring of packets matching the flow description information.
在第十二方面的一种可能的设计中,所述检测规则中包括通配指示信息;该方法还包括:用户面功能网元根据该通配指示信息,向应用功能网元发送终端设备的会话中所有报 文的镜像。In a possible design of the twelfth aspect, the detection rule includes wildcard indication information; the method further includes: the user plane functional network element sends the terminal device information to the application function network element according to the wildcard indication information Mirroring of all packets in the session.
上述第十方面至第十二方面的任一种可能的设计中的有益效果,可参考第九方面中的对应描述,重复之处不再赘述。For the beneficial effect of any possible design of the above tenth to twelfth aspects, reference may be made to the corresponding description in the ninth aspect, and repeated descriptions will not be repeated.
第十三方面,本申请实施例提供一种通信装置,该装置可以具有实现上述各方面或各方面的任一种可能的设计中应用功能网元的功能,或者具有实现上述各方面或各方面的任一种可能的设计中策略控制功能网元的功能,或者具有实现上述各方面或各方面的任一种可能的设计中会话管理功能网元的功能,或者具有实现上述各方面或各方面的任一种可能的设计中用户面功能网元的功能,或者具有实现上述各方面或各方面的任一种可能的设计中网络数据分析功能网元的功能。该装置可以为网络设备,也可以为网络设备中包括的芯片。In the thirteenth aspect, the embodiment of the present application provides a communication device, which can have the function of implementing any of the above-mentioned aspects or any possible design application function network element, or can realize the above-mentioned aspects or aspects any possible design of the network element with the policy control function, or the function of the network element with the session management function in any of the above-mentioned aspects or aspects, or the function of the network element with the above-mentioned aspects or aspects The function of the user plane function network element in any possible design, or the function of the network data analysis function network element in any of the above aspects or any possible design of the aspects. The device may be a network device, or a chip included in the network device.
上述通信装置的功能可以通过硬件实现,也可以通过硬件执行相应的软件实现,所述硬件或软件包括一个或多个与上述功能相对应的模块或单元或手段(means)。The above-mentioned functions of the communication device may be realized by hardware, or may be realized by executing corresponding software by hardware, and the hardware or software includes one or more modules or units or means corresponding to the above-mentioned functions.
在一种可能的设计中,该装置的结构中包括处理模块和收发模块,其中,处理模块被配置为支持该装置执行上述各方面或各方面的任一种设计中应用功能网元相应的功能,或者执行上述各方面或各方面的任一种设计中策略控制功能网元相应的功能,或者执行上述各方面或各方面的任一种设计中会话管理功能网元相应的功能,或者执行上述各方面或各方面的任一种设计中用户面功能网元相应的功能,或者执行上述各方面或各方面的任一种设计中网络数据分析功能网元相应的功能。收发模块用于支持该装置与其他通信设备之间的通信,例如该装置为会话管理功能网元时,可向用户面功能网元发送第一请求消息。该通信装置还可以包括存储模块,存储模块与处理模块耦合,其保存有装置必要的程序指令和数据。作为一种示例,处理模块可以为处理器,通信模块可以为收发器,存储模块可以为存储器,存储器可以和处理器集成在一起,也可以和处理器分离设置。In a possible design, the structure of the device includes a processing module and a transceiver module, wherein the processing module is configured to support the device to perform the corresponding functions of the application function network element in any design of the above aspects or aspects , or perform the corresponding functions of the policy control function network element in any design of the above aspects or aspects, or perform the corresponding functions of the session management function network element in any design of the above aspects or aspects, or perform the above The corresponding functions of the user plane function network element in any design of the aspects or any aspects of the aspects, or the corresponding functions of the network data analysis function network element in the above aspects or any design of the aspects. The transceiver module is used to support communication between the device and other communication devices. For example, when the device is a network element with a session management function, it can send a first request message to a network element with a user plane function. The communication device may also include a storage module, which is coupled to the processing module and stores necessary program instructions and data of the device. As an example, the processing module may be a processor, the communication module may be a transceiver, and the storage module may be a memory, and the memory may be integrated with the processor or configured separately from the processor.
在另一种可能的设计中,该装置的结构中包括处理器,还可以包括存储器。处理器与存储器耦合,可用于执行存储器中存储的计算机程序指令,以使装置执行上述各方面或各方面的任一种可能的设计中的方法。可选地,该装置还包括通信接口,处理器与通信接口耦合。当装置为网络设备时,该通信接口可以是收发器或输入/输出接口;当该装置为网络设备中包含的芯片时,该通信接口可以是芯片的输入/输出接口。可选地,收发器可以为收发电路,输入/输出接口可以是输入/输出电路。In another possible design, the structure of the device includes a processor, and may also include a memory. The processor is coupled with the memory, and can be used to execute the computer program instructions stored in the memory, so that the apparatus performs the method in any one possible design of the above-mentioned aspects or aspects. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface. When the device is a network device, the communication interface may be a transceiver or an input/output interface; when the device is a chip included in the network device, the communication interface may be an input/output interface of the chip. Optionally, the transceiver may be a transceiver circuit, and the input/output interface may be an input/output circuit.
第十四方面,本申请实施例提供一种芯片系统,包括:处理器,所述处理器与存储器耦合,所述存储器用于存储程序或指令,当所述程序或指令被所述处理器执行时,使得该芯片系统实现上述各方面或各方面的任一种可能的设计中的方法。In a fourteenth aspect, the embodiment of the present application provides a chip system, including: a processor, the processor is coupled with a memory, and the memory is used to store programs or instructions, when the programs or instructions are executed by the processor When, make the system-on-a-chip implement the above-mentioned aspects or any one possible design method of the aspects.
可选地,该芯片系统还包括接口电路,该接口电路用于交互代码指令至所述处理器。Optionally, the chip system further includes an interface circuit, which is used for exchanging code instructions to the processor.
可选地,该芯片系统中的处理器可以为一个或多个,该处理器可以通过硬件实现也可以通过软件实现。当通过硬件实现时,该处理器可以是逻辑电路、集成电路等。当通过软件实现时,该处理器可以是一个通用处理器,通过读取存储器中存储的软件代码来实现。Optionally, there may be one or more processors in the chip system, and the processors may be implemented by hardware or by software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like. When implemented by software, the processor may be a general-purpose processor implemented by reading software codes stored in a memory.
可选地,该芯片系统中的存储器也可以为一个或多个。该存储器可以与处理器集成在一起,也可以和处理器分离设置。示例性的,存储器可以是非瞬时性处理器,例如只读存储器ROM,其可以与处理器集成在同一块芯片上,也可以分别设置在不同的芯片上。Optionally, there may be one or more memories in the chip system. The memory can be integrated with the processor, or can be set separately from the processor. Exemplarily, the memory may be a non-transitory processor, such as a read-only memory ROM, which may be integrated with the processor on the same chip, or may be respectively disposed on different chips.
第十五方面,本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当其在通信装置上运行时,使得上述各方面或各方面的任一种可能的设 计中的方法被执行。In the fifteenth aspect, the embodiment of the present application also provides a computer-readable storage medium, the computer-readable storage medium stores instructions, and when it is run on a communication device, any one of the above aspects or aspects A possible design approach is implemented.
第十六方面,本申请实施例还提供一种计算机程序产品,该计算机程序产品包括计算机程序或指令,当计算机程序或指令被通信装置运行时,使得上述各方面或各方面的任一种可能的设计中的方法被执行。In the sixteenth aspect, the embodiment of the present application also provides a computer program product, the computer program product includes computer programs or instructions, and when the computer program or instructions are run by the communication device, any one of the above-mentioned aspects or aspects is possible The method in the design is executed.
第十七方面,本申请实施例还提供一种通信系统,该通信系统包括用于执行上述第三方面或第三方面的任一种可能的设计中的方法的会话管理功能网元和用于执行上述第四方面或第四方面的任一种可能的设计中的方法的用户面功能网元。In the seventeenth aspect, the embodiment of the present application also provides a communication system, the communication system includes a session management function network element configured to execute the method in the third aspect or any possible design of the third aspect and a network element configured to A user plane function network element that executes the method in the fourth aspect or any possible design of the fourth aspect.
可选的,该通信系统还可包括用于执行上述第一方面或第一方面的任一种可能的设计中的方法的应用功能网元和用于执行上述第二方面或第二方面的任一种可能的设计中的方法的策略控制功能网元。Optionally, the communication system may further include an application function network element configured to implement the first aspect or any method in a possible design of the first aspect and an application function network element configured to implement the second aspect or any of the second aspects. A possible design approach for policy control of functional network elements.
第十八方面,本申请实施例还提供一种通信系统,该通信系统包括用于执行上述第六方面或第六方面的任一种可能的设计中的方法的网络数据分析功能网元和用于执行上述第七方面或第七方面的任一种可能的设计中的方法的会话管理功能网元。In the eighteenth aspect, the embodiment of the present application also provides a communication system, the communication system includes a network element with a network data analysis function and a user A network element with a session management function for performing the method in the seventh aspect or any possible design of the seventh aspect.
可选的,该通信系统还可包括用于执行上述第五方面或第五方面的任一种可能的设计中的方法的应用功能网元和用于执行上述第八方面或第八方面的任一种可能的设计中的方法的用户面功能网元。Optionally, the communication system may further include an application function network element configured to implement the method in the fifth aspect or any possible design of the fifth aspect and an application function network element configured to implement the eighth aspect or any of the eighth aspects. A possible design approach for user plane functional network elements.
第十九方面,本申请实施例还提供一种通信系统,该通信系统包括执行上述第九方面或第九方面的任一种可能的设计中的方法的应用功能网元和用于执行上述第十二方面或第十二方面的任一种可能的设计中的方法的用户面功能网元。In a nineteenth aspect, the embodiment of the present application further provides a communication system, the communication system includes an application function network element for performing the method in any possible design of the ninth aspect or the ninth aspect, and a network element configured to perform the above-mentioned first aspect The user plane functional network element of the method in the twelfth aspect or any possible design of the twelfth aspect.
可选的,该通信系统还可包括用于执行上述第十方面或第十方面的任一种可能的设计中的方法的策略控制功能网元和用于执行上述第十一方面或第十一方面的任一种可能的设计中的方法的会话管理功能网元。Optionally, the communication system may further include a policy control function network element configured to implement the above tenth aspect or the method in any possible design of the tenth aspect, and a network element configured to implement the above eleventh aspect or the eleventh aspect Aspects of any one possible design of the method in the session management function network element.
附图说明Description of drawings
图1a、图1b和图1c为本申请实施例提供的一种通信系统的示意图;Figure 1a, Figure 1b and Figure 1c are schematic diagrams of a communication system provided by an embodiment of the present application;
图2a为基于服务化架构的5G网络架构示意图;Figure 2a is a schematic diagram of a 5G network architecture based on a service architecture;
图2b为基于点对点接口的5G网络架构示意图;Figure 2b is a schematic diagram of a 5G network architecture based on a point-to-point interface;
图3为本申请实施例提供的一种业务感知方法的示意图;FIG. 3 is a schematic diagram of a service perception method provided by an embodiment of the present application;
图4为本申请实施例提供的另一种业务感知方法的示意图;FIG. 4 is a schematic diagram of another service perception method provided by an embodiment of the present application;
图5为本申请实施例提供的又一种业务感知方法的示意图;FIG. 5 is a schematic diagram of another service perception method provided by the embodiment of the present application;
图6和图7为本申请实施例提供的一种通信装置的结构示意图。FIG. 6 and FIG. 7 are schematic structural diagrams of a communication device provided by an embodiment of the present application.
具体实施方式Detailed ways
为了使本申请的目的、技术方案和优点更加清楚,下面将结合附图对本申请作进一步地详细描述。方法实施例中的具体操作方法也可以应用于装置实施例或系统实施例中。In order to make the purpose, technical solution and advantages of the application clearer, the application will be further described in detail below in conjunction with the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments.
为了准确地进行业务感知,实现对不同应用业务的报文的有效区分,本申请提供一种通信系统。In order to perform service perception accurately and effectively distinguish packets of different application services, the present application provides a communication system.
在第一种实现方式中,如图1a所示,该通信系统可包括会话管理功能网元和用户面功能网元。可选的,该通信系统还可包括应用功能网元和策略控制功能网元。其中,In a first implementation manner, as shown in FIG. 1a, the communication system may include a session management functional network element and a user plane functional network element. Optionally, the communication system may further include an application function network element and a policy control function network element. in,
会话管理功能网元,用于向用户面功能网元发送第一请求消息,该第一请求消息中包括检测规则和用量上报规则,该检测规则包括应用业务的标识和包检测特征信息,该检测规则用于检测所述应用业务的业务流,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该用量上报规则包括第一事件标识,该第一事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;以及,用于接收来自用户面功能网元的第一事件报告,该第一事件报告用于指示所述事件。可选的,还用于接收来自策略控制功能网元的第二请求消息,该第二请求消息用于请求订阅所述事件,该第二请求消息中包括所述应用业务的标识、包检测特征信息和第二事件标识,该第二事件标识用于指示上报所述事件;以及,用于向策略控制功能网元发送第二事件报告,该第二事件报告用于指示所述事件。用户面功能网元,用于接收来自会话管理功能网元的第一请求消息;根据包检测特征信息对接收到的所述会话中的报文执行应用检测;若检测到所述应用业务的业务流的事件,则向会话管理功能网元发送第一事件报告。The session management function network element is configured to send a first request message to the user plane function network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes the identification of the application service and packet detection feature information, the detection The rule is used to detect the service flow of the application service, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, and the first event identifier is used to indicate the reporting An event of the service flow of the application service, where the event is an application start event or an application end event; and used for receiving a first event report from a user plane functional network element, where the first event report is used to indicate the event. Optionally, it is also used to receive a second request message from a policy control function network element, the second request message is used to request to subscribe to the event, and the second request message includes the identification of the application service and the packet detection feature Information and a second event identifier, where the second event identifier is used to indicate reporting of the event; and, used to send a second event report to the policy control function network element, where the second event report is used to indicate the event. The user plane functional network element is configured to receive the first request message from the session management functional network element; perform application detection on the received packets in the session according to the packet detection characteristic information; if the service of the application service is detected If there is an event of the flow, a first event report is sent to the network element with the session management function.
可选的,策略控制功能网元,用于向会话管理功能网元发送第二请求消息;以及,用于接收来自会话管理功能网元的第二事件报告;可选的,还用于接收来自应用功能网元的第三请求消息,该第三请求消息中包括应用业务的标识、包检测特征信息和第三事件标识,该第三事件标识用于指示上报所述事件;以及,用于向应用功能网元发送第三事件报告,该第三事件报告用于指示所述事件。Optionally, the policy control function network element is used to send the second request message to the session management function network element; and is used to receive the second event report from the session management function network element; The third request message of the application function network element, the third request message includes the identification of the application service, the packet detection characteristic information and the third event identification, and the third event identification is used to indicate to report the event; The application function network element sends a third event report, where the third event report is used to indicate the event.
可选的,应用功能网元,用于向策略控制功能网元发送第三请求消息;以及,用于接收来自策略控制功能网元的第三事件报告。Optionally, the application function network element is configured to send a third request message to the policy control function network element; and is configured to receive a third event report from the policy control function network element.
在第二种实现方式中,如图1b所示,该通信系统可包括网络数据分析功能网元和会话管理功能网元。可选的,该通信系统还可包括应用功能网元和用户面功能网元。其中,In a second implementation manner, as shown in FIG. 1b, the communication system may include a network element with a network data analysis function and a network element with a session management function. Optionally, the communication system may further include an application function network element and a user plane function network element. in,
网络数据分析功能网元,用于接收来自应用功能网元的第四请求消息,该第四请求消息用于请求分析应用业务的业务流的事件,该事件为应用开始事件或应用结束事件,该第四请求消息中包括所述应用业务的标识和包检测特征信息,该包检测特征信息用于指示所述应用业务的业务流的匹配特征;用于向会话管理功能网元发送第五请求消息,该第五请求消息用于请求转发终端设备的会话中报文的镜像;用于接收来自会话管理功能网元或用户面功能网元的所述镜像;用于根据包检测特征信息,对所述镜像执行应用检测;以及,用于若检测到所述事件,向应用功能网元发送事件报告,该事件报告用于指示所述事件。会话管理功能网元,用于接收来自网络数据分析功能网元的第五请求消息;用于向用户面功能网元发送第六请求消息,该第六请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话的业务流,该转发规则中包括镜像转发指示,该镜像转发指示用于指示转发所述镜像。The network data analysis function network element is used to receive the fourth request message from the application function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, the The fourth request message includes the identification of the application service and packet detection characteristic information, and the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service; it is used to send the fifth request message to the session management function network element , the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device; it is used to receive the mirror image from the session management function network element or the user plane function network element; The mirror image executes application detection; and, if the event is detected, send an event report to the application function network element, where the event report is used to indicate the event. The session management function network element is used to receive the fifth request message from the network data analysis function network element; it is used to send the sixth request message to the user plane function network element, the sixth request message includes detection rules and forwarding rules, the The detection rule is used to detect the service flow of the session of the terminal device, and the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate forwarding of the mirroring.
可选的,应用功能网元,用于向网络数据分析功能网元发送第四请求消息;接收来自网络数据分析功能网元的事件报告。Optionally, the application function network element is configured to send a fourth request message to the network data analysis function network element; and receive an event report from the network data analysis function network element.
可选的,用户面功能网元,用于接收来自会话管理功能网元的第六请求消息;用于根据检测规则,检测终端设备的会话中的业务流;用户面功能网元根据镜像转发指示,向会话管理功能网元或网络数据分析功能网元发送所述镜像。Optionally, the user plane functional network element is used to receive the sixth request message from the session management functional network element; it is used to detect the service flow in the session of the terminal device according to the detection rule; the user plane functional network element forwards the instruction according to the image , sending the image to a network element with a session management function or a network element with a network data analysis function.
在第三种实现方式中,如图1c所示,该通信系统可包括应用功能网元和用户面功能网元。可选的,该通信系统还可包括策略控制功能网元和会话管理功能网元。其中,In a third implementation manner, as shown in FIG. 1c, the communication system may include an application function network element and a user plane function network element. Optionally, the communication system may further include a network element with a policy control function and a network element with a session management function. in,
应用功能网元,用于向策略控制功能网元发送第七请求消息,该第七请求消息用于获 取终端设备的会话中报文的镜像,该第七请求消息中包括镜像目的地址,该镜像目的地址为应用功能网元中接收所述镜像的地址;用于接收来自用户面功能网元的所述镜像;根据所述镜像执行应用检测。策略控制功能网元,用于接收来自应用功能网元的第七请求消息;用于向会话管理功能网元发送第八请求消息,该第八请求消息用于请求转发所述镜像,该第八请求消息中包括所述镜像目的地址。The application function network element is used to send a seventh request message to the policy control function network element, the seventh request message is used to obtain the image of the message in the session of the terminal device, the seventh request message includes the image destination address, and the image The destination address is the address of the application function network element receiving the image; it is used for receiving the image from the user plane function network element; and performing application detection according to the image. The policy control function network element is used to receive the seventh request message from the application function network element; it is used to send the eighth request message to the session management function network element, and the eighth request message is used to request forwarding the image, the eighth The mirroring destination address is included in the request message.
可选的,会话管理功能网元,用于接收来自策略控制功能网元的第八请求消息;用于向用户面功能网元发送第九请求消息,该第九请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则用于对终端设备的会话中的报文进行镜像转发,该转发规则中包括镜像转发指示和所述镜像目的地址,该镜像转发指示用于指示转发所述镜像。Optionally, the session management functional network element is configured to receive an eighth request message from the policy control functional network element; and is configured to send a ninth request message to the user plane functional network element, where the ninth request message includes detection rules and forwarding A rule, the detection rule is used to detect the service flow in the session of the terminal device, the forwarding rule is used to mirror forward the message in the session of the terminal device, and the forwarding rule includes a mirroring forwarding indication and the mirroring destination address, The image forwarding indication is used to instruct to forward the image.
可选的,用户面功能网元,用于接收来自会话管理功能网元的检测规则和转发规则;根据所述检测规则,检测终端设备的会话中的报文;根据所述镜像转发指示和镜像目的地址,向应用功能网元发送所述镜像。Optionally, the user plane function network element is used to receive the detection rule and the forwarding rule from the session management function network element; according to the detection rule, detect the message in the session of the terminal device; according to the mirroring forwarding instruction and the mirroring destination address, and send the image to the application function network element.
图1a、图1b或图1c所示的系统可以用在图2a或图2b所示的5G网络架构中,也可以用在未来的网络架构中,比如第六代(6th generation,6G)网络架构等,本申请不做限定。The system shown in Figure 1a, Figure 1b or Figure 1c can be used in the 5G network architecture shown in Figure 2a or Figure 2b, and can also be used in future network architectures, such as the sixth generation (6th generation, 6G) network architecture etc., this application does not make a limitation.
图2a为基于服务化架构的5G网络架构示意图。图2a所示的5G网络架构中可包括数据网络(data network,DN)和运营商网络。下面对其中的部分网元的功能进行简单介绍说明。Figure 2a is a schematic diagram of a 5G network architecture based on a service-based architecture. The 5G network architecture shown in Figure 2a may include a data network (data network, DN) and an operator network. The functions of some of the network elements are briefly introduced and described below.
其中,运营商网络可包括以下网元中的一个或多个:鉴权服务器功能(authentication server function,AUSF)网元、网络开放功能(network exposure function,NEF)网元、策略控制功能(policy control function,PCF)网元、统一数据管理(unified data management,UDM)网元、统一数据库(unified data repository,UDR)网元、网络存储功能(network repository function,NRF)网元、应用功能(application function,AF)网元、接入与移动性管理功能(access and mobility management function,AMF)网元、会话管理功能(session management function,SMF)网元、无线接入网(radio access network,RAN)设备以及用户面功能(user plane function,UPF)网元、网络数据分析功能(network data analysis function,NWDAF)网元、网络切片选择功能(Network Slice Selection Function,NSSF)网元等。上述运营商网络中,除无线接入网设备之外的网元或设备可以称为核心网网元或核心网设备。Wherein, the operator network may include one or more of the following network elements: authentication server function (authentication server function, AUSF) network element, network exposure function (network exposure function, NEF) network element, policy control function (policy control function (PCF) network element, unified data management (unified data management, UDM) network element, unified database (unified data repository, UDR) network element, network storage function (network repository function, NRF) network element, application function (application function) , AF) network elements, access and mobility management function (access and mobility management function, AMF) network elements, session management function (session management function, SMF) network elements, radio access network (radio access network, RAN) equipment And user plane function (UPF) network elements, network data analysis function (network data analysis function, NWDAF) network elements, network slice selection function (Network Slice Selection Function, NSSF) network elements, etc. In the above operator network, network elements or devices other than radio access network devices may be referred to as core network elements or core network devices.
无线接入网设备可以是基站(base station)、演进型基站(evolved NodeB,eNodeB)、发送接收点(transmission reception point,TRP)、5G移动通信系统中的下一代基站(next generation NodeB,gNB)、6G移动通信系统中的下一代基站、未来移动通信系统中的基站或无线保真(wireless fidelity,WiFi)系统中的接入节点等;也可以是完成基站部分功能的模块或单元,例如,可以是集中式单元(central unit,CU),也可以是分布式单元(distributed unit,DU)。无线接入网设备可以是宏基站,也可以是微基站或室内站,还可以是中继节点或施主节点等。本申请的实施例对无线接入网设备所采用的具体技术和具体设备形态不做限定。The wireless access network equipment can be a base station (base station), an evolved base station (evolved NodeB, eNodeB), a transmission reception point (transmission reception point, TRP), and a next generation base station (next generation NodeB, gNB) in a 5G mobile communication system , a next-generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a wireless fidelity (Wireless Fidelity, WiFi) system, etc.; it can also be a module or unit that completes some functions of the base station, for example, It can be a centralized unit (central unit, CU) or a distributed unit (distributed unit, DU). The radio access network equipment may be a macro base station, a micro base station or an indoor station, or a relay node or a donor node. The embodiment of the present application does not limit the specific technology and specific equipment form adopted by the radio access network equipment.
与RAN通信的终端也可以称为终端设备、用户设备(user equipment,UE)、移动台、 移动终端等。终端可以广泛应用于各种场景,例如,设备到设备(device-to-device,D2D)、车物(vehicle to everything,V2X)通信、机器类通信(machine-type communication,MTC)、物联网(internet of things,IOT)、虚拟现实、增强现实、工业控制、自动驾驶、远程医疗、智能电网、智能家具、智能办公、智能穿戴、智能交通、智慧城市等。终端可以是手机、平板电脑、带无线收发功能的电脑、可穿戴设备、车辆、无人机、直升机、飞机、轮船、机器人、机械臂、智能家居设备等。本申请的实施例对终端所采用的具体技术和具体设备形态不做限定。The terminal communicating with the RAN may also be referred to as terminal equipment, user equipment (user equipment, UE), mobile station, mobile terminal, and so on. Terminals can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things ( internet of things, IOT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearables, smart transportation, smart city, etc. Terminals can be mobile phones, tablet computers, computers with wireless transceiver functions, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc. The embodiment of the present application does not limit the specific technology and specific device form adopted by the terminal.
基站和终端可以是固定位置的,也可以是可移动的。基站和终端可以部署在陆地上,包括室内或室外、手持或车载;也可以部署在水面上;还可以部署在空中的飞机、气球和人造卫星上。本申请的实施例对基站和终端的应用场景不做限定。Base stations and terminals can be fixed or mobile. Base stations and terminals can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed on aircraft, balloons and artificial satellites in the air. The embodiments of the present application do not limit the application scenarios of the base station and the terminal.
AMF网元,执行移动性管理、接入鉴权/授权等功能。此外,还负责在终端与PCF间传递用户策略。The AMF network element performs functions such as mobility management and access authentication/authorization. In addition, it is also responsible for transferring user policies between the terminal and the PCF.
SMF网元,执行会话管理、PCF下发控制策略的执行、UPF的选择、终端的互联网协议(internet protocol,IP)地址分配等功能。The SMF network element performs functions such as session management, execution of control policies issued by the PCF, selection of UPF, and allocation of Internet Protocol (IP) addresses for terminals.
UPF网元,作为和数据网络的接口,完成用户面数据转发、基于会话/流级的计费统计,带宽限制等功能。The UPF network element, as an interface with the data network, completes functions such as user plane data forwarding, session/flow-based charging statistics, and bandwidth limitation.
UDM网元,执行管理签约数据、用户接入授权等功能。The UDM network element performs functions such as managing subscription data and user access authorization.
UDR,执行签约数据、策略数据、应用数据等类型数据的存取功能。UDR implements the access function of contract data, policy data, application data and other types of data.
NEF网元,用于支持能力和事件的开放。NEF network elements are used to support the opening of capabilities and events.
AF网元,传递应用侧对网络侧的需求,例如,服务质量(quality of service,QoS)需求或用户状态事件订阅等。AF可以是第三方功能实体,也可以是运营商部署的应用服务,如IP多媒体子系统(IP Multimedia Subsystem,IMS)语音呼叫业务。The AF network element transmits the requirements from the application side to the network side, such as quality of service (quality of service, QoS) requirements or user status event subscription. The AF may be a third-party functional entity, or an application service deployed by an operator, such as an IP Multimedia Subsystem (IP Multimedia Subsystem, IMS) voice call service.
PCF网元,负责针对会话、业务流级别进行计费、QoS带宽保障及移动性管理、终端策略决策等策略控制功能。The PCF network element is responsible for policy control functions such as charging for sessions and service flow levels, QoS bandwidth guarantee, mobility management, and terminal policy decision-making.
NRF网元,用于提供网元发现功能,基于其他网元的请求,提供网元类型对应的网元信息。NRF还提供网元管理服务,如网元注册、更新、去注册以及网元状态订阅和推送等。The NRF network element is used to provide a network element discovery function, and provide network element information corresponding to a network element type based on requests from other network elements. NRF also provides network element management services, such as network element registration, update, de-registration, network element status subscription and push, etc.
AUSF网元,负责对用户进行鉴权,以确定是否允许用户或设备接入网络。The AUSF network element is responsible for authenticating users to determine whether users or devices are allowed to access the network.
NSSF网元,用于选择网络切片,对网络切片内的用户进行计数等。The NSSF network element is used to select a network slice and count users in the network slice.
NWDAF网元,负责基于从各节点所收集到的输入信息执行分析功能,并输出相应分析结果用于网络运维、策略决策、用户体验评估等场景。The NWDAF network element is responsible for performing analysis functions based on the input information collected from each node, and outputting corresponding analysis results for scenarios such as network operation and maintenance, policy decision-making, and user experience evaluation.
DN,是位于运营商网络之外的网络,运营商网络可以接入多个DN,DN上可部署多种业务,可为终端提供数据和/或语音等服务。例如,DN是某智能工厂的私有网络,智能工厂安装在车间的传感器可为终端,DN中部署了传感器的控制服务器,控制服务器可为传感器提供服务。传感器可与控制服务器通信,获取控制服务器的指令,根据指令将采集的传感器数据传送给控制服务器等。又例如,DN是某公司的内部办公网络,该公司员工的手机或者电脑可为终端,员工的手机或者电脑可以访问公司内部办公网络上的信息、数据资源等。DN is a network outside the operator's network. The operator's network can access multiple DNs, and various services can be deployed on the DN, which can provide data and/or voice services for terminals. For example, DN is a private network of a smart factory. The sensors installed in the workshop of the smart factory can be terminals, and the control server of the sensors is deployed in the DN, and the control server can provide services for the sensors. The sensor can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions. For another example, DN is a company's internal office network. The mobile phone or computer of the company's employees can be a terminal, and the employee's mobile phone or computer can access information and data resources on the company's internal office network.
图2a中Nausf、Nnef、Npcf、Nudm、Naf、Namf、Nsmf分别为上述AUSF、NEF、PCF、UDM、AF、AMF和SMF提供的服务化接口,用于调用相应的服务化操作。N1、N2、N3、N4,以及N6为接口序列号。这些接口序列号的含义可参见第三代合作伙伴计划 (3rd generation partnership project,3GPP)标准协议中定义的含义,在此不做限制。In Figure 2a, Nausf, Nnef, Npcf, Nudm, Naf, Namf, and Nsmf are the service interfaces provided by the above-mentioned AUSF, NEF, PCF, UDM, AF, AMF, and SMF, respectively, and are used to call corresponding service operations. N1, N2, N3, N4, and N6 are interface serial numbers. The meanings of these interface serial numbers may refer to the meanings defined in the 3rd generation partnership project (3rd generation partnership project, 3GPP) standard agreement, and there is no limitation here.
图2b为基于点对点接口的5G网络架构示意图,其中的网元的功能的介绍可以参考图2a中对应的网元的功能的介绍,不再赘述。图2b与图2a的主要区别在于:图2a中的各个控制面网元之间的接口是服务化的接口,图2b中的各个控制面网元之间的接口是点对点的接口。FIG. 2b is a schematic diagram of a 5G network architecture based on a point-to-point interface. The introduction of the functions of the network elements can refer to the introduction of the functions of the corresponding network elements in FIG. The main difference between Fig. 2b and Fig. 2a is that: the interface between each control plane network element in Fig. 2a is a service interface, and the interface between each control plane network element in Fig. 2b is a point-to-point interface.
在图2b所示的架构中,各个网元之间的接口名称及功能如下:In the architecture shown in Figure 2b, the interface names and functions between each network element are as follows:
1)、N1:AMF与终端之间的接口,可以用于向终端传递QoS控制规则等。1), N1: the interface between the AMF and the terminal, which can be used to transmit QoS control rules and the like to the terminal.
2)、N2:AMF与RAN之间的接口,可以用于传递核心网侧至RAN的无线承载控制信息等。2), N2: the interface between the AMF and the RAN, which can be used to transfer radio bearer control information from the core network side to the RAN.
3)、N3:RAN与UPF之间的接口,主要用于传递RAN与UPF间的上下行用户面数据。3), N3: the interface between the RAN and the UPF, mainly used to transfer the uplink and downlink user plane data between the RAN and the UPF.
4)、N4:SMF与UPF之间的接口,可以用于控制面与用户面之间传递信息,包括控制面向用户面的转发规则、QoS控制规则、流量统计规则等的下发以及用户面的信息上报。4), N4: The interface between SMF and UPF, which can be used to transfer information between the control plane and the user plane, including controlling the distribution of forwarding rules, QoS control rules, traffic statistics rules, etc. Information reporting.
5)、N5:AF与PCF之间的接口,可以用于应用业务请求下发以及网络事件上报。5), N5: the interface between the AF and the PCF, which can be used for sending application service requests and reporting network events.
6)、N6:UPF与DN的接口,用于传递UPF与DN之间的上下行用户数据流。6), N6: the interface between UPF and DN, used to transfer the uplink and downlink user data flow between UPF and DN.
7)、N7:PCF与SMF之间的接口,可以用于下发协议数据单元(protocol data unit,PDU)会话粒度以及业务数据流粒度控制策略。7), N7: the interface between PCF and SMF, which can be used to deliver protocol data unit (protocol data unit, PDU) session granularity and service data flow granularity control policy.
8)、N8:AMF与UDM间的接口,可以用于AMF向UDM获取接入与移动性管理相关签约数据与鉴权数据,以及AMF向UDM注册终端当前移动性管理相关信息等。8), N8: The interface between AMF and UDM, which can be used for AMF to obtain subscription data and authentication data related to access and mobility management from UDM, and for AMF to register terminal current mobility management related information with UDM.
9)、N9:UPF和UPF之间的用户面接口,用于传递UPF间的上下行用户数据流。9), N9: a user plane interface between UPF and UPF, used to transmit uplink and downlink user data flows between UPFs.
10)、N10:SMF与UDM间的接口,可以用于SMF向UDM获取会话管理相关签约数据,以及SMF向UDM注册终端当前会话相关信息等。10), N10: the interface between SMF and UDM, which can be used for SMF to obtain session management-related subscription data from UDM, and for SMF to register terminal current session-related information with UDM.
11)、N11:SMF与AMF之间的接口,可以用于传递RAN和UPF之间的PDU会话隧道信息、传递发送给终端的控制消息、传递发送给RAN的无线资源控制信息等。11), N11: the interface between SMF and AMF, which can be used to transfer PDU session tunnel information between RAN and UPF, transfer control messages sent to terminals, transfer radio resource control information sent to RAN, etc.
12)、N12:AMF和AUSF间的接口,可以用于AMF向AUSF发起鉴权流程,其中可携带SUCI作为签约标识;12), N12: the interface between AMF and AUSF, which can be used for AMF to initiate an authentication process to AUSF, which can carry SUCI as a subscription identifier;
13)、N13:UDM与AUSF间的接口,可以用于AUSF向UDM获取用户鉴权向量,以执行鉴权流程。13), N13: the interface between UDM and AUSF, which can be used for AUSF to obtain user authentication vector from UDM to execute the authentication process.
14)、N15:PCF与AMF之间的接口,可以用于下发终端策略及接入控制相关策略。14), N15: the interface between the PCF and the AMF, which can be used to issue terminal policies and access control-related policies.
15)、N35:UDM与UDR间的接口,可以用于UDM从UDR中获取用户签约数据信息。15), N35: the interface between UDM and UDR, which can be used for UDM to obtain user subscription data information from UDR.
16)、N36:PCF与UDR间的接口,可以用于PCF从UDR中获取策略相关签约数据以及应用数据相关信息。16), N36: the interface between the PCF and the UDR, which can be used for the PCF to obtain policy-related subscription data and application data-related information from the UDR.
可以理解的是,上述网元或者功能既可以是硬件设备中的网络元件,也可以是在专用硬件上运行软件功能,或者是平台(例如,云平台)上实例化的虚拟化功能。可选的,上述网元或者功能可以由一个设备实现,也可以由多个设备共同实现,还可以是一个设备内的一个功能模块,本申请实施例对此不作具体限定。It can be understood that the above-mentioned network element or function may be a network element in a hardware device, or a software function running on dedicated hardware, or a virtualization function instantiated on a platform (for example, a cloud platform). Optionally, the foregoing network element or function may be implemented by one device, or jointly implemented by multiple devices, or may be a functional module in one device, which is not specifically limited in this embodiment of the present application.
本申请中的应用功能网元、策略控制功能网元、会话管理功能网元、用户面功能网元、网络数据分析功能网元可以分别是图2a或图2b中的AF、PCF、SMF、UPF、NWDAF, 也可以是未来通信如6G网络中具有上述AF、PCF、SMF、UPF、NWDAF的功能的网元,本申请对此不限定。为了便于描述,在本申请的实施例中,将以AF、PCF、SMF、UPF、NWDAF分别作为应用功能网元、策略控制功能网元、会话管理功能网元、用户面功能网元、网络数据分析功能网元的一个举例来介绍本申请提供的技术方案。The application function network element, policy control function network element, session management function network element, user plane function network element, and network data analysis function network element in this application can be AF, PCF, SMF, UPF in Figure 2a or Figure 2b respectively , NWDAF, or a network element having the above-mentioned functions of AF, PCF, SMF, UPF, and NWDAF in future communications such as 6G networks, which is not limited in this application. For ease of description, in the embodiments of this application, AF, PCF, SMF, UPF, and NWDAF will be used as application function network elements, policy control function network elements, session management function network elements, user plane function network elements, and network data network elements respectively. An example of an analysis function network element is used to introduce the technical solution provided by this application.
实施例一Embodiment one
请参考图3,为本申请提供的一种业务感知方法,该方法包括:Please refer to Figure 3, which is a service perception method provided by this application, which includes:
步骤301,AF向PCF发送请求消息1,该请求消息1中包括应用业务的标识(application service ID)、包检测特征信息和事件标识1。In step 301, the AF sends a request message 1 to the PCF, and the request message 1 includes application service ID, packet detection feature information and event ID 1.
相应的,PCF接收来自AF的请求消息1。Correspondingly, the PCF receives the request message 1 from the AF.
本申请实施例中,请求消息1用于请求创建或更新所述应用业务的业务流的策略。该请求消息1可以是策略授权创建/更新请求消息,或者其他消息,本申请并不限定。In the embodiment of the present application, the request message 1 is used to request to create or update the policy of the service flow of the application service. The request message 1 may be a policy authorization creation/update request message, or other messages, which are not limited in this application.
应用业务的包检测特征信息用于指示所述应用业务的业务流的匹配特征,该包检测特征信息可以理解为是AF向核心网(如5GC)提供的用于应用检测的匹配特征。该包检测特征信息可以包括所述应用业务的业务流中报文的统计特征和/或包头特征。其中,报文的统计特征可包括报文周期、报文大小等,报文周期可用于UPF基于接收到的报文的周期特征判断是否存在所述应用业务的业务流,报文大小可用于UPF基于接收到的报文的大小所属的区间分布判断是否存在所述应用业务的业务流。报文的包头特征的描述形式可以是当前IP报文或以太报文所定义的原地址、目的地址、协议类型等常规报文包头之外的其他报文包头的组合,例如Profinet协议包头中的帧标识Frame ID、Modbus协议包头中的功能码Function Code,在具体表征形式上可以是目标字段及其对应的取值,也可以是偏移量+字段长度+字段取值所组成的匹配特征,本申请对此不做限定。The packet detection feature information of the application service is used to indicate the matching feature of the service flow of the application service. The packet detection feature information can be understood as the matching feature provided by the AF to the core network (such as 5GC) for application detection. The packet detection feature information may include statistical features and/or packet header features of packets in the service flow of the application service. Among them, the statistical characteristics of the message may include message period, message size, etc., the message period can be used by UPF to judge whether there is a service flow of the application service based on the period characteristic of the received message, and the message size can be used by UPF Based on the interval distribution to which the size of the received packet belongs, it is judged whether there is a service flow of the application service. The description form of the packet header characteristics of the message can be a combination of other packet headers other than the conventional packet headers such as the original address, destination address, and protocol type defined in the current IP packet or Ethernet packet, for example, in the Profinet protocol header. The frame identifier Frame ID and the function code in the Modbus protocol header can be the target field and its corresponding value, or the matching feature composed of offset + field length + field value. This application does not limit this.
事件标识1(event ID)用于指示上报所述应用业务的业务流的事件,该事件可以为应用开始事件(app start event)或应用结束事件(app stop event),该事件标识1可以是所述应用业务的业务流的应用开始事件的标识或应用结束事件的标识。其中,应用开始事件可触发PCF向终端设备发起配置更新流程,应用结束事件可触发PCF取消终端设备之前的配置信息。Event ID 1 (event ID) is used to indicate the event of reporting the service flow of the application service. The event can be an application start event (app start event) or an application end event (app stop event). The event ID 1 can be all The identifier of the application start event or the identifier of the application end event of the service flow of the above-mentioned application service. Wherein, the application start event may trigger the PCF to initiate a configuration update process to the terminal device, and the application end event may trigger the PCF to cancel the previous configuration information of the terminal device.
可选的,请求消息1中还可包括流描述信息,该流描述信息用于指示上述包检测特征信息适用的业务流,也可以理解为用于标识待匹配的业务流。该流描述信息可以是IP五元组的形式。如果请求消息1中未包括流描述信息,则可认为该请求消息1对应的终端设备的会话中的所有业务流均是上述包检测特征信息适用的业务流(即待匹配的业务流)。Optionally, the request message 1 may also include flow description information, where the flow description information is used to indicate the service flow to which the packet detection feature information is applicable, and may also be understood as used to identify the service flow to be matched. The flow description information may be in the form of an IP quintuple. If the request message 1 does not include the flow description information, it can be considered that all the service flows in the session of the terminal device corresponding to the request message 1 are the service flows to which the above-mentioned packet detection feature information applies (that is, the service flows to be matched).
本申请中,终端设备的会话中可存在一个或多个业务流,不同的业务流可对应不同的应用业务,每个业务流可由一个或多个报文组成。检测到某一应用业务的报文,即为检测到该应用业务的业务流,也可以称之为检测到该应用业务的业务流的应用开始事件。在检测到某一应用业务的报文之后,在一段时间内未再检测到该应用业务的报文,即为不再检测到该应用业务的业务流,也可以称之为检测到该应用业务的业务流的应用结束事件。此外,终端设备的会话可以是协议数据单元(protocol data unit,PDU)会话,相应的,会话建立流程可以是PDU会话建立流程,下文不再赘述。In this application, there may be one or more service flows in the session of the terminal device, and different service flows may correspond to different application services, and each service flow may consist of one or more messages. The detection of a packet of a certain application service is the detection of the service flow of the application service, which may also be referred to as an application start event in which the service flow of the application service is detected. After a packet of an application service is detected, no packet of the application service is detected within a period of time, that is, the service flow of the application service is no longer detected, which can also be called detection of the application service The application end event of the business flow. In addition, the session of the terminal device may be a protocol data unit (protocol data unit, PDU) session, and correspondingly, the session establishment process may be a PDU session establishment process, which will not be described in detail below.
可选的,请求消息1中还可包括终端设备的信息,该终端设备的信息可包括终端设备的IP地址、终端设备的标识、数据网络名称(data network name,DNN)、单网络切片选 择辅助信息(single-network slice selection assistance information,S-NSSAI)等一项或多项信息,例如可以是终端设备的IP地址,或者是终端设备的标识和DNN,或者是终端设备的标识和S-NSSAI等。上述终端设备的信息可用于PCF确定请求消息1对应的终端设备的会话,或者说所述应用业务的业务流所在的终端设备的会话,或者说待检测的终端设备的会话。可选的,AF可以仅在策略授权创建请求消息中携带上述终端设备的信息。Optionally, the request message 1 may also include terminal device information, and the terminal device information may include the terminal device's IP address, terminal device identifier, data network name (data network name, DNN), single network slice selection assistance Information (single-network slice selection assistance information, S-NSSAI) and other information, such as the IP address of the terminal device, or the identification and DNN of the terminal device, or the identification of the terminal device and S-NSSAI wait. The above terminal device information can be used by the PCF to determine the session of the terminal device corresponding to the request message 1, or the session of the terminal device where the service flow of the application service is located, or the session of the terminal device to be detected. Optionally, the AF may only carry the above terminal device information in the policy authorization creation request message.
可选的,在执行步骤301之前,如步骤300所示,终端设备可发起会话建立流程,以建立上述终端设备的会话。Optionally, before step 301 is performed, as shown in step 300, the terminal device may initiate a session establishment procedure to establish a session of the above-mentioned terminal device.
需要说明的是,AF可以直接或间接地向PCF发送请求消息1。其中,AF直接向PCF发送请求消息1是指:AF直接向PCF发送请求消息1,中间不经过其它网元的转发。AF间接地向PCF发送请求消息1是指:AF通过其他网元(如NEF)的转发向PCF发送请求消息1,例如AF向NEF发送请求消息1,由NEF再将该请求消息1发送至PCF。可选的,当AF通过NEF间接地向PCF发送请求消息1时,若该请求消息1中包括终端设备的信息,则该终端设备的信息还可用于NEF查找为终端设备的会话提供服务的PCF。It should be noted that the AF may directly or indirectly send the request message 1 to the PCF. Wherein, the AF directly sends the request message 1 to the PCF means: the AF directly sends the request message 1 to the PCF without being forwarded by other network elements. AF sends request message 1 to PCF indirectly means: AF sends request message 1 to PCF through the forwarding of other network elements (such as NEF), for example, AF sends request message 1 to NEF, and NEF sends the request message 1 to PCF . Optionally, when the AF indirectly sends the request message 1 to the PCF through the NEF, if the request message 1 includes the information of the terminal device, the information of the terminal device can also be used by the NEF to find the PCF that provides services for the session of the terminal device .
步骤302,PCF向SMF发送请求消息2,该请求消息2用于请求订阅所述应用业务的业务流的事件,该请求消息2中包括所述应用业务的标识、包检测特征信息和事件标识2。Step 302, the PCF sends a request message 2 to the SMF, the request message 2 is used to request to subscribe to the event of the service flow of the application service, and the request message 2 includes the identification of the application service, packet detection feature information and event identification 2 .
相应的,SMF接收来自PCF的请求消息2。Correspondingly, the SMF receives the request message 2 from the PCF.
本申请实施例中,请求消息2可以是事件订阅请求消息,或策略关联/控制更新通知消息,或者其他消息,本申请并不限定。In this embodiment of the application, the request message 2 may be an event subscription request message, or a policy association/control update notification message, or other messages, which are not limited in this application.
可选的,请求消息2中还可包括流描述信息,该流描述信息用于指示包检测特征信息适用的业务流。Optionally, the request message 2 may also include flow description information, where the flow description information is used to indicate the service flow to which the packet detection characteristic information applies.
可选的,请求消息2中还可包括终端设备的会话所对应的策略关联标识,该策略关联标识用于SMF确定请求消息2对应的终端设备的会话,以及查找该会话的上下文。Optionally, the request message 2 may also include a policy association identifier corresponding to the session of the terminal device, and the policy association identifier is used by the SMF to determine the session of the terminal device corresponding to the request message 2 and to search for the context of the session.
事件标识2与上文中的事件标识1用于指示同一事件,但该事件标识2与事件标识1可以相同,也可以不同,本申请不作具体限定。本申请中,事件标识2与事件标识1不同可以是指事件标识的描述形式不同,所述描述形式可包括APP_START/STOP字符串形式或者指示信息的形式等。若事件标识2与事件标识1相同,则该事件标识2可以是PCF从AF直接获得的。若事件标识2与事件标识1不同,则该事件标识2可以是PCF根据从AF获得的事件标识1确定的,该事件标识2与事件标识1之间存在对应关系。The event identifier 2 and the above event identifier 1 are used to indicate the same event, but the event identifier 2 and the event identifier 1 may be the same or different, which is not specifically limited in this application. In this application, the difference between the event identifier 2 and the event identifier 1 may mean that the description forms of the event identifiers are different, and the description forms may include APP_START/STOP character strings or indication information. If the event identifier 2 is the same as the event identifier 1, the event identifier 2 may be directly obtained by the PCF from the AF. If the event identifier 2 is different from the event identifier 1, the event identifier 2 may be determined by the PCF according to the event identifier 1 obtained from the AF, and there is a corresponding relationship between the event identifier 2 and the event identifier 1 .
上述应用业务的标识、包检测特征信息或流描述信息等一项或多项信息可以是PCF从AF获得的。例如,若请求消息1中包括上述一项或多项信息,则PCF可从请求消息1中获取上述一项或多项信息,然后将上述一项或多项信息包含在请求消息2中发送给SMF。One or more pieces of information such as the identification of the above application service, packet detection feature information or flow description information may be obtained by the PCF from the AF. For example, if the request message 1 includes the above one or multiple items of information, the PCF can obtain the above one or multiple items of information from the request message 1, and then include the above one or multiple items of information in the request message 2 and send it to SMF.
示例性地,当PCF接收到请求消息1后,PCF可以根据该请求消息1执行策略决策,生成相应的策略与计费控制(policy and charging control,PCC)规则,并通过请求消息2将该PCC规则发送给SMF。该PCC规则可包括所述应用业务的标识、包检测特征信息和事件标识。可选的,该PCC规则中还可包括流描述信息。Exemplarily, when the PCF receives the request message 1, the PCF can execute a policy decision according to the request message 1, generate a corresponding policy and charging control (policy and charging control, PCC) rule, and pass the request message 2 to the PCC Rules are sent to SMF. The PCC rule may include the identifier of the application service, packet detection characteristic information and event identifier. Optionally, the PCC rule may also include flow description information.
步骤303,SMF向UPF发送请求消息3,该请求消息3中包括检测规则和用量上报规则(usage reporting rule,URR),该检测规则用于检测所述应用业务的业务流,该检测规则包括所述应用业务的标识和包检测特征信息,该URR包括事件标识3。Step 303, the SMF sends a request message 3 to the UPF, the request message 3 includes a detection rule and a usage reporting rule (usage reporting rule, URR), the detection rule is used to detect the service flow of the application service, and the detection rule includes the The above-mentioned identification of the application service and packet detection feature information, the URR includes event identification 3.
相应的,UPF接收来自SMF的请求消息3。Correspondingly, the UPF receives the request message 3 from the SMF.
本申请实施例中,请求消息3可以是事件订阅请求消息,或N4会话修改请求消息, 或者其他消息,本申请并不限定。应注意,该请求消息3为N4会话粒度,该请求消息3与终端设备的会话一一对应。In this embodiment of the application, the request message 3 may be an event subscription request message, or an N4 session modification request message, or other messages, which are not limited in this application. It should be noted that the request message 3 has an N4 session granularity, and the request message 3 corresponds to a session of the terminal device one by one.
检测规则可以是包检测规则(packet detection rule,PDR)。该PDR用于检测会话中所述应用业务的业务流,即用于检测终端设备的会话中所述应用业务的业务流,或者用于检测终端设备的会话中所述应用业务的报文。URR用于在检测到所述应用业务的业务流的事件后,对该应用业务的业务流执行用量统计上报。The detection rule may be a packet detection rule (packet detection rule, PDR). The PDR is used to detect the service flow of the application service in the session, that is, to detect the service flow of the application service in the session of the terminal device, or to detect the message of the application service in the session of the terminal device. The URR is configured to report the usage statistics of the service flow of the application service after the event of the service flow of the application service is detected.
可选的,PDR中还可包括流描述信息,该流描述信息用于指示包检测特征信息适用的业务流。该流描述信息可以是SMF从PCF获得的。Optionally, the PDR may also include flow description information, where the flow description information is used to indicate the service flow to which the packet detection feature information applies. The flow description information may be obtained by the SMF from the PCF.
可选的,URR中还可包括事件上报指示,该用于指示UPF在检测到所述应用业务的业务流的事件后上报相应的事件报告,该事件上报指示可以理解为一个专门用于指示上报应用事件的指示信息。Optionally, the URR may also include an event reporting indication, which is used to instruct the UPF to report a corresponding event report after detecting the event of the service flow of the application service. The event reporting indication can be understood as a special indication for reporting Instructions for app events.
事件标识3与上文中的事件标识2用于指示同一事件,但该事件标识3与事件标识2可以相同,也可以不同,本申请不作具体限定。本申请中,事件标识3与事件标识2不同可以是指事件标识的描述形式不同。若事件标识3与事件标识2相同,则该事件标识3可以是SMF从PCF直接获得的。若事件标识3与事件标识2不同,则该事件标识3可以是SMF根据从PCF获得的事件标识2确定的,该事件标识3与事件标识2之间存在对应关系。The event identifier 3 and the above event identifier 2 are used to indicate the same event, but the event identifier 3 and the event identifier 2 may be the same or different, which is not specifically limited in this application. In this application, the difference between the event identifier 3 and the event identifier 2 may mean that the description forms of the event identifiers are different. If the event identifier 3 is the same as the event identifier 2, the event identifier 3 may be directly obtained by the SMF from the PCF. If the event identifier 3 is different from the event identifier 2, the event identifier 3 may be determined by the SMF according to the event identifier 2 obtained from the PCF, and there is a corresponding relationship between the event identifier 3 and the event identifier 2 .
上述应用业务的标识、包检测特征信息、流描述信息或事件上报指示等一项或多项信息可以是SMF从PCF获得的。例如,若请求消息2中包括上述一项或多项信息,SMF可从请求消息中获取上述一项或多项信息,然后将应用业务的标识、包检测特征信息或流描述信息包含在PDR中,将该事件上报指示包含在URR中,然后通过请求消息3将PDR和URR发送给UPF。One or more items of information such as the identification of the above application service, packet detection feature information, flow description information or event reporting indication may be obtained by the SMF from the PCF. For example, if the request message 2 includes one or more items of information above, the SMF can obtain the above one or more items of information from the request message, and then include the identification of the application service, packet detection feature information or flow description information in the PDR , include the event reporting indication in the URR, and then send the PDR and URR to the UPF through request message 3.
示例性地,当SMF接收到来自PCF的PCC规则后,SMF可以根据该PCC规则,生成N4规则,然后通过请求消息3将上述N4规则发送给UPF执行。该N4规则包括PDR和URR。其中,PDR中可包括应用业务的标识和包检测特征信息,可选的,该PDR中还可包括流描述信息。URR中还可包括事件标识3,可选的,该URR中还可包括事件上报指示等。Exemplarily, after the SMF receives the PCC rule from the PCF, the SMF can generate the N4 rule according to the PCC rule, and then send the above N4 rule to the UPF through the request message 3 for execution. The N4 rule includes PDR and URR. Wherein, the PDR may include application service identification and packet detection feature information, and optionally, the PDR may also include flow description information. The URR may also include an event identifier 3, and optionally, the URR may also include an event reporting indication and the like.
步骤304,UPF根据包检测特征信息对接收到的所述会话中的报文执行应用检测。In step 304, the UPF performs application detection on the received packets in the session according to the packet detection feature information.
本申请实施例中,当UPF接收到来自SMF的PDR后,UPF可根据PDR对终端设备的会话中的报文执行应用检测,也可以理解为根据PDR对终端设备的会话中的业务流执行应用检测。所述终端设备的会话中的报文是指用户面传递的该终端设备的报文。In this embodiment of the application, when the UPF receives the PDR from the SMF, the UPF can perform application detection on the message in the session of the terminal device according to the PDR, which can also be understood as executing the application on the service flow in the session of the terminal device according to the PDR detection. The packet in the session of the terminal device refers to the packet of the terminal device transmitted by the user plane.
应理解,在本申请中,对报文执行应用检测与对业务流执行检测具有类似的含义,本文不再赘述。执行应用检测可以是指确定是否接收到某一应用业务的报文或者判断接收到的报文是哪个应用业务的报文(即判断接收到的报文归属于哪个应用业务的业务流)。It should be understood that in this application, performing application detection on packets has a similar meaning to performing detection on service flows, and details are not described herein again. Executing application detection may refer to determining whether a packet of a certain application service is received or judging which application service the received packet belongs to (that is, judging the service flow of which application service the received packet belongs to).
示例性地,若PDR中包括包检测特征信息,但不包括流描述信息,则UPF可根据包检测特征信息,对终端设备的会话中的报文执行应用检测。换言之,当PDR中不包括流描述信息时,UPF可直接根据包检测特征信息对终端设备的会话中的报文进行应用检测。由于通常UPF会按照终端设备的会话中各个PDR的优先级的顺序进行业务流匹配,因此,该终端设备的会话中除去匹配至更高优先级的PDR的业务流之后的其他业务流的报文均将作为包检测特征信息的原始报文执行应用检测。在该情形下,终端设备的会话中与包检 测特征信息相符的报文可被认为是与所述PDR匹配的业务流中的报文。Exemplarily, if the PDR includes packet detection characteristic information but does not include flow description information, the UPF may perform application detection on packets in the session of the terminal device according to the packet detection characteristic information. In other words, when the flow description information is not included in the PDR, the UPF can directly perform application detection on the packets in the session of the terminal device according to the packet detection characteristic information. Since UPF usually performs service flow matching according to the priority order of each PDR in the session of the terminal device, the packets of other service flows after the service flow matching the PDR with higher priority are removed in the session of the terminal device The application detection will be performed on the original packet as the characteristic information of the packet detection. In this case, the packets in the session of the terminal device that match the packet detection feature information can be considered as packets in the service flow that match the PDR.
若PDR中包括包检测特征信息和流描述信息,则UPF可根据该包检测特征信息,对终端设备的会话中与该流描述信息匹配的报文执行应用检测。换言之,当PDR中包括流描述信息时,UPF可先根据流描述信息对终端设备的会话中的报文进行应用检测,然后根据包检测特征信息对上一步中与流描述信息相符的报文进行应用检测。该终端设备的会话中除去匹配至更高优先级的PDR的业务流之外的其他业务流的报文中进一步与上述流描述信息相符的报文将被作为包检测特征信息的原始报文执行应用检测。在该情形下,终端设备的会话中与流描述信息和包检测特征信息均相符的报文可被认为是与所述PDR匹配的业务流中的报文。If the PDR includes packet detection characteristic information and flow description information, the UPF may perform application detection on packets matching the flow description information in the session of the terminal device according to the packet detection characteristic information. In other words, when the flow description information is included in the PDR, UPF can first perform application detection on the packets in the session of the terminal device according to the flow description information, and then perform application detection on the packets that match the flow description information in the previous step according to the packet detection characteristic information. Application detection. In the session of the terminal device, the packets of other service flows except the service flows matching the higher priority PDR will be executed as the original packets of the packet detection characteristic information Application detection. In this case, the packets in the session of the terminal device that match both the flow description information and the packet detection characteristic information can be regarded as packets in the service flow that match the PDR.
步骤305,若检测到所述应用业务的业务流的事件,UPF向SMF发送事件报告3,该事件报告3用于指示所述事件。Step 305, if an event of the service flow of the application service is detected, the UPF sends an event report 3 to the SMF, where the event report 3 is used to indicate the event.
相应的,SMF接收来自UPF的事件报告3。Correspondingly, the SMF receives the event report 3 from the UPF.
本申请实施例中,UPF检测到所述应用业务的业务流的应用开始事件可以是指:UPF在终端设备的会话中检测到与上述包检测特征信息(或者包检测特征信息和流描述信息)相符的报文。In this embodiment of the present application, the UPF detecting the application start event of the service flow of the application service may refer to: the UPF detects that the above-mentioned packet detection characteristic information (or packet detection characteristic information and flow description information) is related to the session of the terminal device. matching message.
UPF检测到所述应用业务的业务流的应用结束事件可以是指:UPF在终端设备的会话中检测到与上述包检测特征信息(或者包检测特征信息和流描述信息)相符的报文之后,在一段时间内没有再检测到与上述包检测特征信息(或者包检测特征信息和流描述信息)相符的报文。The UPF detects the application end event of the service flow of the application service may refer to: after the UPF detects a message that matches the above packet detection characteristic information (or packet detection characteristic information and flow description information) in the session of the terminal device, No more packets matching the above packet detection characteristic information (or packet detection characteristic information and flow description information) are detected within a period of time.
所述事件报告3用于上报所述应用业务的业务流的事件,该事件报告3可包括所述应用业务的标识和事件标识3。The event report 3 is used to report the event of the service flow of the application service, and the event report 3 may include the identifier of the application service and the event identifier 3 .
可选的,若SMF发送至UPF的URR中包括事件上报指示,UPF可根据该事件上报指示向SMF发送上述事件报告3。Optionally, if the URR sent by the SMF to the UPF includes an event reporting instruction, the UPF may send the above event report 3 to the SMF according to the event reporting instruction.
步骤306,SMF向PCF发送事件报告2。In step 306, the SMF sends event report 2 to the PCF.
相应的,PCF接收来自SMF的事件报告2。Correspondingly, the PCF receives the event report 2 from the SMF.
所述事件报告2用于上报所述应用业务的业务流的事件,该事件报告2可包括所述应用业务的标识和事件标识2。The event report 2 is used to report the event of the service flow of the application service, and the event report 2 may include the identifier of the application service and the event identifier 2 .
步骤307,PCF向AF发送事件报告1。In step 307, the PCF sends event report 1 to the AF.
相应的,AF接收来自PCF的事件报告1。Correspondingly, the AF receives event report 1 from the PCF.
所述事件报告1用于上报所述应用业务的业务流的事件,该事件报告1可包括所述应用业务的标识和事件标识1。The event report 1 is used to report the event of the service flow of the application service, and the event report 1 may include the identifier of the application service and the event identifier 1 .
可选的,若AF间接地向PCF发送请求消息1,PCF也可以间接地向AF发送事件报告1。例如,PCF可将该事件报告1发送给NEF,由NEF将该事件报告1发送至AF。Optionally, if the AF indirectly sends the request message 1 to the PCF, the PCF may also indirectly send the event report 1 to the AF. For example, the PCF may send the event report 1 to the NEF, and the NEF may send the event report 1 to the AF.
AF接收到上述事件报告1之后,可基于该事件报告对终端设备执行相应的管理动作,例如通知调整编码方式、业务报文发送周期、定时下电等。After the AF receives the event report 1 above, it can perform corresponding management actions on the terminal device based on the event report, such as notifying the adjustment of the encoding method, service packet sending cycle, and scheduled power-off.
可以理解的是,若事件标识1与事件标识2相同,则上述事件报告1与事件报告2也可以相同。类似的,若事件标识2与事件标识3相同,则上述事件报告2与事件报告3也可以相同。It can be understood that, if the event ID 1 and the event ID 2 are the same, the event report 1 and the event report 2 may also be the same. Similarly, if the event ID 2 is the same as the event ID 3, the event report 2 and the event report 3 may also be the same.
本申请的实施例一中,AF可向PCF订阅应用事件,并提供用于应用检测的包检测特征信息。PCF可向SMF订阅应用事件,由SMF指示UPF执行应用检测。UPF可以根据包 检测特征信息对接收到终端设备的会话中的报文执行应用检测,并通过SMF、PCF向AF返回相应的事件报告。In Embodiment 1 of the present application, the AF may subscribe to the PCF for application events, and provide packet detection feature information for application detection. The PCF can subscribe to the application event to the SMF, and the SMF instructs the UPF to perform application detection. UPF can perform application detection on the packets received in the session of the terminal device according to the packet detection characteristic information, and return corresponding event reports to AF through SMF and PCF.
由于UPF可根据包检测特征信息对终端设备的会话中的报文执行业务检测,因而上述技术方案可以对不同应用业务的报文进行有效区分,对报文所属的应用业务的业务流进行准确地判断。进一步地,由于包检测特征信息可指示应用业务的业务流中报文的统计特征、包头特征等,相比于现有技术中仅根据报文包头中的明文域名信息执行检测的技术方案,上述技术方案在不同应用业务的报文的包头相同的场景下(例如加密报文或工业应用中不同应用业务的报文具有相同的报文包头等场景),也可以对不同应用业务的报文进行有效区分,从而准确判断应用业务的类型。Since the UPF can perform service detection on the packets in the session of the terminal device according to the packet detection feature information, the above technical solution can effectively distinguish the packets of different application services, and accurately determine the service flow of the application service to which the packets belong. judge. Furthermore, since the packet detection characteristic information can indicate the statistical characteristics and packet header characteristics of the packets in the service flow of the application service, compared with the technical solution in the prior art that only performs detection based on the plaintext domain name information in the packet header, the above-mentioned Technical solution In the scenario where packets of different application services have the same packet header (for example, encrypted packets or packets of different application services in industrial applications have the same packet header), it is also possible to Effectively differentiate, so as to accurately determine the type of application business.
实施例二Embodiment two
请参考图4,为本申请提供的另一种业务感知方法,该方法包括:Please refer to Figure 4, which is another service perception method provided by this application, which includes:
步骤401,AF向NWDAF发送请求消息4,该请求消息4用于请求分析应用业务的业务流的事件,该事件为应用开始事件或应用结束事件,该第四请求消息中包括所述应用业务的标识和包检测特征信息,该包检测特征信息用于指示所述应用业务的业务流的匹配特征。Step 401, the AF sends a request message 4 to the NWDAF, the request message 4 is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, and the fourth request message includes the application service Identification and packet detection characteristic information, where the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service.
相应的,NWDAF接收来自AF的请求消息4。Correspondingly, NWDAF receives request message 4 from AF.
本申请实施例中,请求消息4可以是分析订阅请求消息,或者其他消息,本申请并不限定。In this embodiment of the application, the request message 4 may be an analysis subscription request message or other messages, which is not limited in this application.
应用业务的包检测特征信息可包括所述应用业务的业务流中报文的统计特征和/或包头特征。关于包检测特征信息的具体实施方式可参考上文中的相关描述,不再赘述。The packet detection feature information of the application service may include statistical features and/or packet header features of packets in the service flow of the application service. Regarding the specific implementation manner of the packet detection feature information, reference may be made to the relevant description above, and details are not repeated here.
可选的,请求消息4中可包括流描述信息,该流描述信息用于指示上述包检测特征信息适用的业务流,也可以理解为用于标识待匹配的业务流。关于流描述信息的具体实施方式可参考上文中的相关描述,不再赘述。Optionally, the request message 4 may include flow description information, which is used to indicate the service flow to which the packet detection feature information is applicable, and can also be understood as used to identify the service flow to be matched. For the specific implementation manner of the stream description information, reference may be made to the relevant description above, and details are not repeated here.
可选的,请求消息4中可包括事件标识,该事件标识用于指示上报所述应用业务的业务流的事件,该事件标识可以是所述应用业务的业务流的应用开始事件的标识或应用结束事件的标识。Optionally, the request message 4 may include an event identifier, which is used to indicate the reporting of the event of the service flow of the application service, and the event identifier may be the identifier of the application start event of the service flow of the application service or the application The ID of the end event.
可选的,请求消息1中可包括终端设备的信息,该终端设备的信息可用于NWDAF确定请求消息4对应的终端设备的会话,或者说所述应用业务的业务流所在的终端设备的会话,或者说待检测的终端设备的会话。该终端设备的信息的具体实施方式可参考上文中的相关描述,不再赘述。Optionally, the request message 1 may include terminal device information, and the terminal device information may be used by NWDAF to determine the session of the terminal device corresponding to the request message 4, or the session of the terminal device where the service flow of the application service is located, Or the session of the terminal device to be detected. For the specific implementation manner of the information of the terminal device, reference may be made to the relevant description above, and details are not repeated here.
在NWDAF接收到来自AF的请求消息4之后,NWDAF可根据上述终端设备的信息确定该请求消息4对应的终端设备的会话,以及为该终端设备的会话提供服务的SMF,以便后续向SMF请求获取该终端设备的会话中报文的镜像。After NWDAF receives the request message 4 from the AF, NWDAF can determine the session of the terminal device corresponding to the request message 4 and the SMF that provides services for the session of the terminal device according to the information of the above-mentioned terminal device, so as to request the SMF to obtain Mirroring of packets in the session of this end device.
可选的,在执行步骤401之前,如步骤400所示,终端设备发起会话建立流程,以建立上述终端设备的会话。Optionally, before step 401 is performed, as shown in step 400, the terminal device initiates a session establishment procedure to establish a session of the above-mentioned terminal device.
需要说明的是,AF可以直接或间接地向NWDAF发送请求消息4。其中,AF直接向NWDAF发送请求消息4是指:AF直接向NWDAF发送请求消息4,中间不经过其它网元的转发。AF间接地向NWDAF发送请求消息4是指:AF通过其他网元(如NEF)的转发向NWDAF发送请求消息4,例如AF向NEF发送请求消息4,由NEF再将该请求消息4 发送至NWDAF。可选的,当AF通过NEF间接地向NWDAF发送请求消息4时,若该请求消息4中包括终端设备的信息,则该终端设备的信息还可用于NWDAF查找为终端设备的会话提供服务的NWDAF。It should be noted that the AF may directly or indirectly send the request message 4 to the NWDAF. Wherein, the AF directly sending the request message 4 to the NWDAF refers to: the AF directly sends the request message 4 to the NWDAF without being forwarded by other network elements. AF sends request message 4 to NWDAF indirectly means: AF sends request message 4 to NWDAF through the forwarding of other network elements (such as NEF), for example, AF sends request message 4 to NEF, and NEF sends the request message 4 to NWDAF . Optionally, when the AF indirectly sends the request message 4 to the NWDAF through the NEF, if the request message 4 includes the information of the terminal device, the information of the terminal device can also be used by the NWDAF to find the NWDAF that provides services for the session of the terminal device .
步骤402,NWDAF向SMF发送请求消息5,该请求消息5用于请求转发终端设备的会话中报文的镜像。In step 402, the NWDAF sends a request message 5 to the SMF, where the request message 5 is used to request forwarding the mirror image of the message in the session of the terminal device.
相应的,SMF接收来自NWDAF的请求消息5。Correspondingly, the SMF receives the request message 5 from the NWDAF.
本申请实施例中,请求消息5可以是报文订阅请求消息,或者事件订阅请求消息,或者事件暴露消息,或者其他消息,本申请并不限定。In this embodiment of the application, the request message 5 may be a message subscription request message, or an event subscription request message, or an event exposure message, or other messages, which are not limited in this application.
可选的,请求消息5中可包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像。该流描述信息可以是NWDAF从AF获得的。例如,若请求消息4中包括流描述信息,NWDAF从请求消息4中获取该流描述信息,并可将该流描述信息携带在请求消息5中发送给SMF。若请求消息5中未包括流描述信息,则表示需要转发终端设备的会话中所有报文的镜像。Optionally, the request message 5 may include flow description information, where the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device. The flow description information may be obtained by the NWDAF from the AF. For example, if the request message 4 includes the flow description information, the NWDAF obtains the flow description information from the request message 4, and may carry the flow description information in the request message 5 and send it to the SMF. If the request message 5 does not include the flow description information, it means that the mirror image of all packets in the session of the terminal device needs to be forwarded.
可选的,请求消息5中还可包括镜像目的地址,该镜像目的地址为NWDAF中接收终端设备的会话中报文的镜像的地址,用于指示SMF或UPF向该地址转发符合要求的报文的镜像(例如终端设备的会话中与上述流描述信息匹配的报文的镜像),该镜像目的地址也可称为镜像上报地址或事件通知地址或事件上报地址等,本申请并不限定。Optionally, the request message 5 may also include a mirroring destination address, which is the mirroring address of the message in the session receiving the terminal device in the NWDAF, and is used to instruct the SMF or UPF to forward the required message to the address The mirror image of (for example, the mirror image of the message matching the above-mentioned flow description information in the session of the terminal device), the mirror destination address can also be called the mirror report address or event notification address or event report address, etc., which is not limited in this application.
可选的,请求消息5中还可包括镜像转发指示,该镜像转发指示可用于指示转发终端设备的会话中报文的镜像。该镜像转发指示也可以理解为用于指示转发终端设备的会话中报文的镜像的指示信息。Optionally, the request message 5 may also include a mirroring forwarding indication, which may be used to indicate forwarding the mirroring of the packets in the session of the terminal device. The mirror forwarding indication can also be understood as indication information for instructing to forward the mirroring of the message in the session of the terminal device.
步骤403,SMF向UPF发送请求消息6,该请求消息6中包括检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则中包括镜像转发指示,该镜像转发指示用于指示转发终端设备的会话中报文的镜像。Step 403, the SMF sends a request message 6 to the UPF, which includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, the forwarding rule includes a mirror forwarding indication, and the mirror forwarding Indicates the mirror image used to instruct forwarding the packets in the session of the terminal device.
相应的,UPF接收来自SMF的请求消息6。Correspondingly, the UPF receives the request message 6 from the SMF.
本申请实施例中,请求消息6可以是事件订阅请求消息,或N4会话修改请求消息,或者其他消息,本申请并不限定。应注意,该请求消息6为N4会话粒度,该请求消息6与终端设备的会话一一对应。In this embodiment of the application, the request message 6 may be an event subscription request message, or an N4 session modification request message, or other messages, which are not limited in this application. It should be noted that the request message 6 has an N4 session granularity, and the request message 6 corresponds to a session of the terminal device one by one.
检测规则可以是包检测规则(packet detection rule,PDR),转发规则可以是转发动作规则(forwarding action rule,FAR),该FAR中可包括上述镜像转发指示。The detection rule may be a packet detection rule (packet detection rule, PDR), and the forwarding rule may be a forwarding action rule (forwarding action rule, FAR), and the FAR may include the above mirroring forwarding indication.
PDR中可包括流描述信息或通配指示信息。其中,流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像,通配指示信息用于转发终端设备的会话中所有报文的镜像。若SMF从NWDAF获得流描述信息,例如请求消息5中包含流描述信息,则SMF可在PDR中包含该流描述信息,表示UPF需要上报终端设备的会话中与流描述信息匹配的报文的镜像。若SMF未从NWDAF获得流描述信息,则SMF可在PDR中包含通配指示信息,该通配指示信息也可称为match-all指示,表示UPF需要上报终端设备的会话中所有报文的镜像。通过上述方式,SMF可明确告知UPF需要转发哪些报文的镜像,从而便于UPF执行相应处理。The PDR may include flow description information or wildcard indication information. Wherein, the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device, and the wildcard indication information is used to forward the image of all packets in the session of the terminal device. If the SMF obtains the flow description information from NWDAF, for example, the request message 5 contains the flow description information, then the SMF can include the flow description information in the PDR, indicating that the UPF needs to report the mirror image of the packet matching the flow description information in the session of the terminal device . If SMF does not obtain flow description information from NWDAF, SMF can include wildcard indication information in PDR. This wildcard indication information can also be called match-all indication, indicating that UPF needs to report the mirror image of all packets in the session of the terminal device . Through the above method, the SMF can clearly inform the UPF which mirror image of the message needs to be forwarded, so that the UPF can perform corresponding processing.
可选的,FAR中还可包括镜像目的地址,该镜像目的地址用于UPF直接向NWDAF转发符合要求的报文的镜像。该镜像目的地址可以是SMF从NWDAF获得的。例如,当请求消息5中包括镜像目的地址时,SMF可在FAR中包含该镜像目的地址。应注意,FAR 中也可以不包括镜像目的地址。若FAR中不包括镜像目的地址,则表示UPF需要通过SMF向NWDAF转发上述报文的镜像,即UPF可将上述报文的镜像发送给SMF,由SMF根据镜像目的地址,再将上述报文的镜像发送给SMF。Optionally, the FAR may also include a mirroring destination address, and the mirroring destination address is used by the UPF to directly forward the mirroring of the required packets to the NWDAF. The mirroring destination address may be obtained by the SMF from the NWDAF. For example, when the request message 5 includes the mirroring destination address, the SMF may include the mirroring destination address in the FAR. It should be noted that the mirror destination address may not be included in the FAR. If the FAR does not include the mirror destination address, it means that the UPF needs to forward the mirror image of the above message to NWDAF through the SMF, that is, the UPF can send the mirror image of the above message to the SMF, and the SMF will forward the mirror image of the above message according to the mirror destination address. The image is sent to SMF.
SMF发送给UPF的镜像转发指示与NWDAF发送给SMF的镜像转发指示可以相同或不同,本申请并不限定。其中,镜像转发指示不同可以是指,二者的描述形式不同。The image forwarding instruction sent by the SMF to the UPF may be the same as or different from the image forwarding instruction sent by the NWDAF to the SMF, which is not limited in this application. Wherein, the different mirroring forwarding indications may mean that the description forms of the two are different.
示例性地,当SMF接收到请求消息5后,SMF可以根据该请求消息5生成N4规则,然后通过请求消息6将上述N4规则发送给UPF执行。该N4规则可包括PDR和FAR,其中,PDR中可包括流描述信息或通配指示信息,FAR中可包括镜像转发指示。可选的,FAR中还可包括镜像目的地址。Exemplarily, after the SMF receives the request message 5, the SMF may generate the N4 rule according to the request message 5, and then send the N4 rule to the UPF through the request message 6 for execution. The N4 rule may include a PDR and a FAR, where the PDR may include flow description information or wildcard indication information, and the FAR may include a mirror forwarding indication. Optionally, the mirroring destination address may also be included in the FAR.
步骤404,UPF根据检测规则,检测终端设备的会话中的报文。In step 404, the UPF detects the packets in the session of the terminal device according to the detection rule.
步骤405,UPF根据镜像转发指示,向SMF或NWDAF发送终端设备的会话中报文的镜像。Step 405, the UPF sends the mirror image of the message in the session of the terminal device to the SMF or NWDAF according to the mirror forwarding instruction.
相应的,NWDAF接收来自SMF或UPF的终端设备的会话中报文的镜像。Correspondingly, the NWDAF receives the mirror image of the message in the session from the terminal device of the SMF or UPF.
示例性地,UPF接收到来自SMF的请求消息6之后,可根据其中的PDR进行报文匹配,然后根据与该PDR对应的FAR中的镜像转发指示执行报文镜像,将终端设备的会话中报文的镜像直接或间接地发送至NWDAF。Exemplarily, after the UPF receives the request message 6 from the SMF, it can perform packet matching according to the PDR in it, and then perform packet mirroring according to the mirror forwarding instruction in the FAR corresponding to the PDR, and report the session in the terminal device to The image of the file is sent directly or indirectly to NWDAF.
若PDR中包括流描述信息时,UPF可将终端设备的会话中与该流描述信息匹配的报文的镜像直接或间接地发送至NWDAF。若PDR中包括通配指示信息,UPF可将终端设备的会话中的所有报文的镜像直接或间接地发送至NWDAF。If the PDR includes the flow description information, the UPF may directly or indirectly send the image of the packet matching the flow description information in the session of the terminal device to the NWDAF. If the PDR includes wildcard indication information, the UPF may directly or indirectly send the images of all packets in the session of the terminal device to the NWDAF.
其中,UPF直接向NWDAF发送终端设备的会话中报文的镜像可以是指:FAR中包括镜像目的地址,该镜像目的地址为NWDAF中接收终端设备的会话中报文的镜像的地址,UPF可根据该镜像目的地址直接向NWDAF发送终端设备的会话中报文的镜像,并且中间不经过SMF的转发。Wherein, the UPF directly sends the mirror image of the session message of the terminal device to the NWDAF may refer to: the FAR includes the mirroring destination address, and the mirroring destination address is the address of the mirror image receiving the session message of the terminal device in the NWDAF, and the UPF may according to The mirroring destination address directly sends the mirroring of the message in the session of the terminal device to NWDAF, without forwarding by SMF in the middle.
UPF间接向NWDAF发送终端设备的会话中的报文可以是指:FAR中不包括镜像目的地址,UPF可通过SMF的转发向NWDAF发送终端设备的会话中报文的镜像,即UPF先将终端设备的会话中报文的镜像发送至SMF,由SMF再转发给NWDAF。UPF indirectly sending the packet in the session of the terminal device to NWDAF can refer to: FAR does not include the mirroring destination address, and UPF can send the mirror image of the packet in the session of the terminal device to NWDAF through SMF forwarding, that is, UPF first sends the packet of the terminal device to NWDAF. The mirror image of the message in the session is sent to the SMF, and then the SMF forwards it to the NWDAF.
可以理解地,上述报文的镜像也可称为镜像报文。多个报文的镜像可组成业务流的镜像,也可称为镜像业务流。还应注意,上述报文的镜像转发过程,并不影响UPF对原始报文的转发,即UPF仍可照常将终端设备的会话中的报文经接入网设备发送至终端设备。It can be understood that the mirroring of the foregoing packet may also be referred to as a mirroring packet. The mirroring of multiple packets can form the mirroring of a service flow, which can also be called a mirroring service flow. It should also be noted that the mirror forwarding process of the above message does not affect the forwarding of the original message by the UPF, that is, the UPF can still send the message in the session of the terminal device to the terminal device via the access network device as usual.
步骤406,NWDAF根据包检测特征信息,对接收到的报文的镜像执行应用检测。In step 406, the NWDAF performs application detection on the image of the received packet according to the packet detection characteristic information.
该步骤406的具体实施方式可参考上文步骤304中关于UPF根据包检测特征信息对接收到的报文执行应用检测的相关描述,不再赘述。For the specific implementation manner of this step 406, please refer to the related description about the UPF performing application detection on the received packet according to the packet detection characteristic information in the above step 304, and details are not repeated here.
步骤407,若检测到所述应用业务的业务流的事件,NWDAF向AF发送事件报告,该事件报告用于指示所述事件。Step 407: If an event of the service flow of the application service is detected, the NWDAF sends an event report to the AF, where the event report is used to indicate the event.
相应的,AF接收来自NWDAF的事件报告。Correspondingly, the AF receives the event report from the NWDAF.
所述事件报告中可包括所述应用业务的标识和事件标识,该事件标识用于指示所述应用业务的业务流的事件,该事件标识可以是所述应用业务的业务流的应用开始事件的标识或应用结束事件的标识。The event report may include the identifier of the application service and an event identifier, the event identifier is used to indicate an event of the service flow of the application service, and the event identifier may be an application start event of the service flow of the application service The ID or ID of the application end event.
AF在接收到该事件报告后,可基于该事件报告对终端设备执行相应的管理动作,例如通知调整编码方式、业务报文发送周期、定时下电等。After receiving the event report, the AF can perform corresponding management actions on the terminal device based on the event report, such as notifying the adjustment of encoding mode, service message sending cycle, and scheduled power-off.
本申请的实施例二中,AF可请求NWDAF分析应用事件,并向NWDAF提供用于应用检测的包检测特征信息。NWDAF可通过SMF从UPF获取终端设备的会话中报文的镜像,根据该包检测特征信息对接收到的报文的镜像执行应用检测,并向AF返回相应的事件报告。In Embodiment 2 of the present application, the AF may request the NWDAF to analyze the application event, and provide the NWDAF with packet detection feature information for application detection. NWDAF can obtain the image of the message in the session of the terminal device from the UPF through SMF, perform application detection on the image of the received message according to the packet detection characteristic information, and return the corresponding event report to AF.
由于NWDAF可根据包检测特征信息对终端设备的会话中的报文的镜像执行业务检测,因而上述技术方案可以对不同应用业务的报文进行有效区分,对报文所属的应用业务的业务流进行准确地判断。进一步地,由于包检测特征信息可指示应用业务的业务流中报文的统计特征、包头特征等,相比于现有技术中仅根据报文包头中的明文域名信息执行检测的技术方案,上述技术方案在不同应用业务的报文的包头相同的场景下(例如加密报文或工业应用中不同应用业务的报文具有相同的报文包头等场景),也可以对不同应用业务的报文进行有效区分,从而准确判断应用业务的类型。Since NWDAF can perform service detection on the mirror image of the message in the session of the terminal device according to the packet detection feature information, the above technical solution can effectively distinguish the messages of different application services, and perform the service flow of the application service to which the message belongs. judge accurately. Furthermore, since the packet detection characteristic information can indicate the statistical characteristics and packet header characteristics of the packets in the service flow of the application service, compared with the technical solution in the prior art that only performs detection based on the plaintext domain name information in the packet header, the above-mentioned Technical solution In the scenario where packets of different application services have the same packet header (for example, encrypted packets or packets of different application services in industrial applications have the same packet header), it is also possible to Effectively differentiate, so as to accurately determine the type of application business.
实施例三Embodiment three
请参考图5,为本申请提供的另一种业务感知方法,该方法包括:Please refer to Figure 5, which is another service perception method provided by this application, which includes:
步骤501,AF向PCF发送请求消息7,该请求消息7用于获取终端设备的会话中报文的镜像,该请求消息7中包括镜像目的地址,该镜像目的地址为AF中接收所述镜像的地址。Step 501, the AF sends a request message 7 to the PCF, the request message 7 is used to obtain the mirror image of the message in the session of the terminal device, the request message 7 includes the mirror destination address, and the mirror destination address is the AF receiving the mirror image address.
相应的,PCF接收来自AF的请求消息7。Correspondingly, the PCF receives the request message 7 from the AF.
本申请实施例中,请求消息7可以是策略授权创建/更新请求消息,或者其他消息,本申请并不限定。In this embodiment of the application, the request message 7 may be a policy authorization creation/update request message, or other messages, which are not limited in this application.
可选的,请求消息7中可包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像。若请求消息7中未包括流描述信息,则表示需要转发终端设备的会话中所有报文的镜像。关于流描述信息的具体实施方式,可参考上文中的相关描述,不再赘述。Optionally, the request message 7 may include flow description information, and the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device. If the request message 7 does not include the flow description information, it means that the mirror image of all packets in the session of the terminal device needs to be forwarded. Regarding the specific implementation manner of the flow description information, reference may be made to the relevant description above, and details are not repeated here.
可选的,请求消息7中可包括终端设备的信息,该终端设备的信息用于PCF确定请求消息7对应的终端设备的会话,或者说待检测的终端设备的会话。关于终端设备的信息的具体实施方式,可参考上文中的相关描述,不再赘述。Optionally, the request message 7 may include terminal device information, and the terminal device information is used by the PCF to determine the session of the terminal device corresponding to the request message 7, or the session of the terminal device to be detected. For the specific implementation manner of the information of the terminal device, reference may be made to the relevant description above, and details are not repeated here.
可选的,在执行步骤501之前,如步骤500所示,终端设备可发起会话建立流程,以建立上述终端设备的会话。Optionally, before step 501 is performed, as shown in step 500, the terminal device may initiate a session establishment process to establish a session of the above-mentioned terminal device.
需要说明的是,AF可以直接或间接地向PCF发送请求消息7,与上文中请求消息1的发送类似,不再赘述。It should be noted that the AF may directly or indirectly send the request message 7 to the PCF, which is similar to the sending of the request message 1 above and will not be repeated here.
步骤502,PCF向SMF发送请求消息8,该请求消息8用于请求转发终端设备的会话中报文的镜像,该请求消息8中包括上述镜像目的地址。In step 502, the PCF sends a request message 8 to the SMF, the request message 8 is used to request forwarding the mirroring of the message in the session of the terminal device, and the request message 8 includes the mirroring destination address.
相应的,SMF接收来自PCF的请求消息8。Correspondingly, the SMF receives the request message 8 from the PCF.
本申请实施例中,请求消息8可以是报文订阅请求消息,或事件订阅请求消息,或策略关联/控制更新通知消息,或者其他消息,本申请并不限定。In this embodiment of the application, the request message 8 may be a message subscription request message, or an event subscription request message, or a policy association/control update notification message, or other messages, which are not limited in this application.
可选的,请求消息8中可包括流描述信息,该流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像。该流描述信息可以是PCF从AF获得的,例如,若请求消息7中包括流描述信息,则PCF可从请求消息7中获取该流描述信息,然后将该流描述信息包含在请求消息8中发送给SMF。Optionally, the request message 8 may include flow description information, and the flow description information is used to indicate forwarding the image of the packet matching the flow description information in the session of the terminal device. The flow description information may be obtained by the PCF from the AF, for example, if the request message 7 includes the flow description information, the PCF may obtain the flow description information from the request message 7, and then include the flow description information in the request message 8 Send to SMF.
示例性地,当PCF接收到来自AF的请求消息7后,PCF可根据该请求消息7执行策略决策,生成相应的PCC规则,并通过请求消息8将该PCC规则发送给SMF。该PCC规则可包括镜像目的地址,可选的还包括流描述信息,用于指示SMF向上述镜像目的地址发送终端设备的会话中与流描述信息匹配的报文的镜像。Exemplarily, when the PCF receives the request message 7 from the AF, the PCF can execute policy decisions according to the request message 7, generate corresponding PCC rules, and send the PCC rules to the SMF through the request message 8. The PCC rule may include a mirroring destination address, and optionally flow description information, and is used to instruct the SMF to send a mirror image of a packet matching the flow description information in the session of the terminal device to the mirroring destination address.
步骤503,SMF向UPF发送请求消息9,该请求消息9中包括检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则用于对终端设备的会话中的报文进行镜像转发,该转发规则中包括镜像转发指示和镜像目的地址,该镜像转发指示用于指示转发终端设备的会话中报文的镜像。Step 503, the SMF sends a request message 9 to the UPF, the request message 9 includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used for the traffic The message is mirrored and forwarded, and the forwarding rule includes a mirroring forwarding indication and a mirroring destination address, and the mirroring forwarding indication is used to indicate forwarding the mirroring of the message in the session of the terminal device.
相应的,UPF接收来自SMF的请求消息9。Correspondingly, the UPF receives the request message 9 from the SMF.
本申请实施例中,请求消息9可以是报文订阅请求消息,或事件订阅请求消息,或N4会话修改请求消息,或者其他消息,本申请并不限定。应注意,该请求消息9为N4会话粒度,该请求消息9与终端设备的会话一一对应。In this embodiment of the application, the request message 9 may be a message subscription request message, an event subscription request message, an N4 session modification request message, or other messages, which are not limited in this application. It should be noted that the request message 9 has an N4 session granularity, and the request message 9 corresponds to a session of the terminal device one by one.
检测规则可以是PDR,转发规则可以是FAR或包镜像规则(packet mirror rule,PMR),该转发规则也可以称为镜像规则,或镜像转发规则等。The detection rule can be a PDR, and the forwarding rule can be a FAR or a packet mirror rule (packet mirror rule, PMR). The forwarding rule can also be called a mirroring rule, or a mirroring forwarding rule, etc.
PDR中可包括流描述信息或通配指示信息,其中,流描述信息用于指示转发终端设备的会话中与该流描述信息匹配的报文的镜像,通配指示信息用于指示转发终端设备的会话中所有报文的镜像。若SMF从PCF获得流描述信息,例如请求消息8中包含流描述信息,则SMF可在PDR中包含流描述信息,表示UPF需要上报终端设备的会话中与流描述信息匹配的报文的镜像。若SMF未从NWDAF获得流描述信息,则SMF可在PDR中包含通配指示信息,该通配指示信息也可称为match-all指示,表示UPF需要上报终端设备的会话中所有报文的镜像。通过上述方式,SMF可明确告知UPF需要转发哪些报文的镜像,从而便于UPF执行相应处理。The PDR may include flow description information or wildcard indication information, wherein the flow description information is used to indicate the mirror image of the message matching the flow description information in the session of the forwarding terminal device, and the wildcard indication information is used to indicate the forwarding terminal device Mirroring of all packets in the session. If the SMF obtains the flow description information from the PCF, for example, the request message 8 includes the flow description information, the SMF may include the flow description information in the PDR, indicating that the UPF needs to report the image of the packet matching the flow description information in the session of the terminal device. If SMF does not obtain flow description information from NWDAF, SMF can include wildcard indication information in PDR. This wildcard indication information can also be called match-all indication, indicating that UPF needs to report the mirror image of all packets in the session of the terminal device . Through the above method, the SMF can clearly inform the UPF which mirror image of the message needs to be forwarded, so that the UPF can perform corresponding processing.
示例性地,SMF接收到来自PCF的PCC规则后,可根据该PCC规则生成N4规则,然后通过请求消息9将上述N4规则发送给UPF执行。该N4规则包括PDR和FAR,或者包括PDR和PMR。其中,PDR中包括流描述信息或通配指示信息,FAR或PMR中包括镜像转发指示和镜像目的地址。Exemplarily, after receiving the PCC rule from the PCF, the SMF can generate the N4 rule according to the PCC rule, and then send the N4 rule to the UPF through the request message 9 for execution. The N4 rule includes PDR and FAR, or includes PDR and PMR. Wherein, the PDR includes flow description information or wildcard indication information, and the FAR or PMR includes a mirroring forwarding indication and a mirroring destination address.
步骤504,UPF根据检测规则,检测终端设备的会话中的报文。In step 504, the UPF detects the packets in the session of the terminal device according to the detection rule.
步骤505,UPF根据镜像转发指示和镜像目的地址,向AF发送终端设备的会话中报文的镜像。In step 505, the UPF sends the mirror image of the message in the session of the terminal device to the AF according to the mirror forwarding instruction and the mirror destination address.
相应的,AF接收来自UPF的终端设备的会话中报文的镜像。Correspondingly, the AF receives the mirror image of the message in the session from the terminal device of the UPF.
示例性地,UPF接收到来自SMF的请求消息9之后,可根据其中的PDR进行报文匹配,然后根据与该PDR对应的FAR中的镜像转发指示和镜像目的地址,执行报文镜像,将终端设备的会话中报文的镜像发送至AF。所述报文的镜像也可称为镜像报文,多个报文的镜像可组成业务流的镜像,也可称为镜像业务流。Exemplarily, after the UPF receives the request message 9 from the SMF, it can perform message matching according to the PDR therein, and then perform message mirroring according to the mirroring forwarding indication and the mirroring destination address in the FAR corresponding to the PDR, and the terminal The mirror image of the packet in the session of the device is sent to the AF. The mirroring of the message may also be called a mirroring message, and the mirroring of multiple messages may constitute a mirroring of a service flow, which may also be called a mirroring service flow.
若PDR中包括流描述信息,UPF可将终端设备的会话中与该流描述信息匹配的报文的镜像发送至AF;若PDR中包括通配指示信息,UPF可将终端设备的会话中的所有报文的镜像发送至AF。应注意,上述报文镜像转发过程,并不影响UPF对原始报文的转发。If the PDR includes flow description information, UPF can send the mirror image of the message matching the flow description information in the session of the terminal device to AF; if the PDR includes wildcard indication information, UPF can send all A mirror image of the message is sent to the AF. It should be noted that the above message mirroring forwarding process does not affect the forwarding of the original message by the UPF.
步骤506,AF根据接收到的报文的镜像,执行应用检测。In step 506, the AF performs application detection according to the image of the received message.
此后,AF可根据接收到的终端设备的会话中报文的镜像,确定应用业务的类型,并向终端设备发送相应的管理命令。Thereafter, the AF can determine the type of the application service according to the received image of the message in the session of the terminal device, and send a corresponding management command to the terminal device.
本申请的实施例三中,AF可通过PCF、SMF向UPF发送报文的转发规则,获取终端设备的会话中报文的镜像,进而根据接收到的报文的镜像进行应用检测,并进行后续的管理决策。上述技术方案将应用检测能力开放至AF,使得AF能够感知终端设备实际所发起的应用业务的类型,从而便于AF基于终端设备当前发起的应用业务执行相应的管理决策。In the third embodiment of the present application, the AF can send the forwarding rules of the message to the UPF through the PCF and SMF, obtain the image of the message in the session of the terminal device, and then perform application detection according to the image of the received message, and perform subsequent management decisions. The above technical solution opens the application detection capability to the AF, so that the AF can perceive the type of the application service actually initiated by the terminal device, so as to facilitate the AF to execute corresponding management decisions based on the application service currently initiated by the terminal device.
在该技术方案中,AF可以与终端设备进行直接通信,也可以仅作为终端设备的管理设备,而不直接与终端设备通信。In this technical solution, the AF may directly communicate with the terminal device, or may only serve as a management device for the terminal device without directly communicating with the terminal device.
图6和图7为本申请的实施例提供的可能的通信装置的结构示意图。这些通信装置可以用于实现上述方法实施例中应用功能网元、策略控制功能网元、会话管理功能网元、用户面功能网元或网络数据分析功能网元的功能,因此也能实现上述方法实施例所具备的有益效果。在本申请的实施例中,该通信装置可以是应用功能网元、策略控制功能网元、会话管理功能网元、用户面功能网元或网络数据分析功能网元,也可以是应用于应用功能网元、策略控制功能网元、会话管理功能网元、用户面功能网元或网络数据分析功能网元的模块(如芯片)。FIG. 6 and FIG. 7 are schematic structural diagrams of possible communication devices provided by the embodiments of the present application. These communication devices can be used to implement the functions of the application function network element, the policy control function network element, the session management function network element, the user plane function network element or the network data analysis function network element in the above method embodiment, so the above method can also be implemented Beneficial effects possessed by the embodiment. In the embodiment of the present application, the communication device may be an application function network element, a policy control function network element, a session management function network element, a user plane function network element, or a network data analysis function network element, or it may be an application function network element Modules (such as chips) of network elements, policy control function network elements, session management function network elements, user plane function network elements, or network data analysis function network elements.
如图6所示,通信装置600包括处理单元610和收发单元620。通信装置600用于实现上述图3、图4至图5所示的任一方法实施例中应用功能网元、策略控制功能网元、会话管理功能网元、用户面功能网元或网络数据分析功能网元的功能。As shown in FIG. 6 , a communication device 600 includes a processing unit 610 and a transceiver unit 620 . The communication device 600 is used to implement the application function network element, the policy control function network element, the session management function network element, the user plane function network element or the network data analysis in any of the method embodiments shown in Fig. 3, Fig. 4 to Fig. 5 above. Functional network element function.
当通信装置600用于实现图3所示的方法实施例中会话管理功能网元的功能时:收发单元620,用于向用户面功能网元发送第一请求消息,该第一请求消息中包括检测规则和用量上报规则,该检测规则包括应用业务的标识和包检测特征信息,该检测规则用于检测会话中所述应用业务的业务流,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该用量上报规则包括第一事件标识,该第一事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;收发单元620,还用于接收来自用户面功能网元的第一事件报告,该第一事件报告用于指示所述应用业务的业务流的事件。When the communication device 600 is used to realize the function of the session management function network element in the method embodiment shown in FIG. 3: the transceiver unit 620 is configured to send a first request message to the user plane function network element, and the first request message includes A detection rule and a usage reporting rule, the detection rule includes the identification of the application service and packet detection feature information, the detection rule is used to detect the service flow of the application service in the session, and the packet detection feature information is used to indicate the application service The matching feature of the service flow, the usage reporting rule includes a first event identifier, the first event identifier is used to indicate the event of reporting the service flow of the application service, and the event is an application start event or an application end event; the transceiver unit 620, It is further used for receiving a first event report from a user plane functional network element, where the first event report is used to indicate an event of the service flow of the application service.
当通信装置600用于实现图3所示的方法实施例中用户面功能网元的功能时:收发单元620,用于接收来自会话管理功能网元的第一请求消息,该第一请求消息中包括检测规则和用量上报规则,该检测规则包括应用业务的标识和包检测特征信息,该检测规则用于检测会话中所述应用业务的业务流,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该用量上报规则包括第一事件标识,该第一事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;处理单元610,用于根据所述包检测特征信息对接收到的所述会话中的报文执行应用检测;若检测到所述应用业务的业务流的事件,收发单元620,用于向会话管理功能网元发送第一事件报告,该第一事件报告用于指示所述事件。When the communication device 600 is used to implement the functions of the user plane function network element in the method embodiment shown in FIG. 3: the transceiver unit 620 is configured to receive a first request message from the session management function network element, in which Including a detection rule and a usage reporting rule, the detection rule includes the identification of the application service and packet detection feature information, the detection rule is used to detect the service flow of the application service in the session, and the packet detection feature information is used to indicate that the application service The matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, the first event identifier is used to indicate the event of reporting the service flow of the application service, and the event is an application start event or an application end event; the processing unit 610 , configured to perform application detection on the received packets in the session according to the packet detection feature information; if an event of the service flow of the application service is detected, the transceiver unit 620 is used to send the session management function network element A first event report is sent, the first event report indicating the event.
当通信装置600用于实现图3所示的方法实施例中策略控制功能网元的功能时:收发单元620,用于接收来自应用功能网元的第三请求消息,该第三请求消息中包括应用业务的标识、包检测特征信息和第三事件标识,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该第三事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;收发单元620,还用于向会话管理功能网元发送第二请求消息,该第二请求消息用于请求订阅所述事件,该第二请求消息中包括所述应用业务的标识、包检测特征信息和第二事件标识,该第二事件标识用于指示上报所述事件;收发单元 620,还用于接收来自会话管理功能网元的第二事件报告,该第二事件报告用于指示所述事件;收发单元620,还用于向应用功能网元发送第三事件报告,该第三事件报告用于指示所述事件。When the communication device 600 is used to realize the function of the policy control function network element in the method embodiment shown in FIG. 3: the transceiver unit 620 is configured to receive a third request message from the application function network element, the third request message includes An application service identifier, packet detection feature information, and a third event identifier, where the packet detection feature information is used to indicate the matching feature of the service flow of the application service, and the third event identifier is used to indicate reporting of the service flow of the application service event, the event is an application start event or an application end event; the transceiver unit 620 is further configured to send a second request message to the session management function network element, where the second request message is used to request to subscribe to the event, and the second request The message includes the identifier of the application service, packet detection feature information, and a second event identifier, and the second event identifier is used to indicate reporting of the event; the transceiver unit 620 is also configured to receive the second event identifier from the session management function network element An event report, where the second event report is used to indicate the event; the transceiver unit 620 is further configured to send a third event report to the application function network element, where the third event report is used to indicate the event.
当通信装置600用于实现图3所示的方法实施例中应用功能网元的功能时:收发单元620,用于向策略控制功能网元发送第三请求消息,该第三请求消息中包括应用业务的标识、包检测特征信息和第三事件标识,该包检测特征信息用于指示所述应用业务的业务流的匹配特征,该第三事件标识用于指示上报所述应用业务的业务流的事件,该事件为应用开始事件或应用结束事件;收发单元620,还用于接收来自策略控制功能网元的第三事件报告,该第三事件报告用于指示所述事件。When the communication device 600 is used to implement the functions of the application function network element in the method embodiment shown in FIG. 3: the transceiver unit 620 is configured to send a third request message to the policy control function network element, the third request message includes A service identifier, packet detection characteristic information, and a third event identifier, where the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service, and the third event identifier is used to indicate the reporting of the service flow of the application service An event, where the event is an application start event or an application end event; the transceiver unit 620 is further configured to receive a third event report from a network element with a policy control function, where the third event report is used to indicate the event.
当通信装置600用于实现图4所示的方法实施例中网络数据分析功能网元的功能时:收发单元620,用于接收来自应用功能网元的第四请求消息,该第四请求消息用于请求分析应用业务的业务流的事件,该事件为应用开始事件或应用结束事件,该第四请求消息中包括所述应用业务的标识和包检测特征信息,该包检测特征信息用于指示所述应用业务的业务流的匹配特征;收发单元620,还用于向会话管理功能网元发送第五请求消息,该第五请求消息用于请求转发终端设备的会话中报文的镜像;处理单元610,用于根据包检测特征信息,对接收到的来自会话管理功能网元或用户面功能网元的所述镜像执行应用检测;若检测到所述应用业务的业务流的事件,收发单元620还用于向应用功能网元发送事件报告,该事件报告用于指示所述事件。When the communication device 600 is used to realize the function of the network element with the network data analysis function in the method embodiment shown in FIG. An event that requests to analyze the service flow of the application service, the event is an application start event or an application end event, the fourth request message includes the identification of the application service and packet detection characteristic information, and the packet detection characteristic information is used to indicate the The matching feature of the service flow of the application service; the transceiver unit 620 is also configured to send a fifth request message to the session management function network element, and the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device; the processing unit 610, configured to perform application detection on the image received from the session management function network element or the user plane function network element according to the packet detection characteristic information; if the event of the service flow of the application service is detected, the transceiver unit 620 It is also used to send an event report to the application function network element, where the event report is used to indicate the event.
当通信装置600用于实现图4所示的方法实施例中会话管理功能网元的功能时:收发单元620,用于接收来自网络数据分析功能网元的第五请求消息,该第五请求消息用于请求转发终端设备的会话中报文的镜像;收发单元620,还用于向用户面功能网元发送第六请求消息,该第六请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话的业务流,该转发规则中包括镜像转发指示,该镜像转发指示用于指示所述镜像。When the communication device 600 is used to implement the function of the session management function network element in the method embodiment shown in FIG. 4: the transceiver unit 620 is configured to receive the fifth request message from the network data analysis function network element, the fifth request message It is used to request forwarding of the mirror image of the message in the session of the terminal device; the transceiver unit 620 is also used to send a sixth request message to the user plane functional network element, the sixth request message includes a detection rule and a forwarding rule, and the detection rule uses For detecting the service flow of the session of the terminal device, the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate the mirroring.
当通信装置600用于实现图4所示的方法实施例中用户面功能网元的功能时:收发单元620,用于接收来自会话管理功能网元的第六请求消息,该第六请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则中包括镜像转发指示,该镜像转发指示用于指示转发终端设备的会话中报文的镜像;处理单元610,用于根据所述检测规则,检测终端设备的会话中的报文;收发单元620,还用于根据镜像转发指示,向会话管理功能网元或网络数据分析功能网元发送所述镜像。When the communication device 600 is used to implement the functions of the user plane function network element in the method embodiment shown in FIG. 4: the transceiver unit 620 is configured to receive a sixth request message from the session management function network element, in which Including a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate forwarding the mirroring of the message in the session of the terminal device; processing The unit 610 is configured to detect the message in the session of the terminal device according to the detection rule; the transceiver unit 620 is also configured to send the image to the session management function network element or the network data analysis function network element according to the image forwarding instruction .
当通信装置600用于实现图4所示的方法实施例中应用功能网元的功能时:收发单元620,用于向网络数据分析功能网元发送第四请求消息,该第四请求消息用于请求分析应用业务的业务流的事件,该事件为应用开始事件或应用结束事件,该第四请求消息中包括所述应用业务的标识和包检测特征信息,该包检测特征信息用于指示所述应用业务的业务流的匹配特征;收发单元620,还用于接收来自网络数据分析功能网元的事件报告,该事件报告用于指示所述事件。When the communication device 600 is used to realize the function of the application function network element in the method embodiment shown in FIG. 4: the transceiver unit 620 is configured to send a fourth request message to the network data analysis function network element, the fourth request message is used for An event requesting to analyze the service flow of the application service, the event is an application start event or an application end event, the fourth request message includes the identification of the application service and packet detection characteristic information, and the packet detection characteristic information is used to indicate the The matching feature of the service flow of the application service; the transceiver unit 620 is further configured to receive an event report from a network element with a network data analysis function, where the event report is used to indicate the event.
当通信装置600用于实现图5所示的方法实施例中应用功能网元的功能时:收发单元620,用于向策略控制功能网元发送第七请求消息,该第七请求消息用于获取终端设备的会话中报文的镜像,该第七请求消息中包括镜像目的地址,该镜像目的地址为应用功能网元中接收所述镜像的地址;收发单元620,还用于接收来自用户面功能网元的所述镜像;处理单元610,用于根据所述镜像执行应用检测。When the communication device 600 is used to realize the function of the application function network element in the method embodiment shown in FIG. For the mirroring of the message in the session of the terminal device, the seventh request message includes the mirroring destination address, and the mirroring destination address is the address receiving the mirroring in the application function network element; the transceiver unit 620 is also used to receive the The image of the network element; a processing unit 610, configured to perform application detection according to the image.
当通信装置600用于实现图5所示的方法实施例中策略控制功能网元的功能时:收发单元620,用于接收来自应用功能网元的第七请求消息,该第七请求消息用于获取终端设备的会话中报文的镜像,该第七请求消息中包括镜像目的地址,该镜像目的地址为应用功能网元中接收所述镜像的地址;收发单元620,还用于向会话管理功能网元发送第八请求消息,该第八请求消息用于请求转发所述镜像,该第八请求消息中包括所述镜像目的地址。When the communication device 600 is used to realize the function of the policy control function network element in the method embodiment shown in FIG. 5: the transceiver unit 620 is configured to receive the seventh request message from the application function network element, the seventh request message is used Obtain the mirror image of the message in the session of the terminal device, the seventh request message includes the mirror image destination address, and the mirror image destination address is the address receiving the mirror image in the application function network element; the transceiver unit 620 is also used to report to the session management function The network element sends an eighth request message, where the eighth request message is used to request forwarding of the image, and the eighth request message includes the image destination address.
当通信装置600用于实现图5所示的方法实施例中会话管理功能网元的功能时:收发单元620,用于接收来自策略控制功能网元的第八请求消息,该第八请求消息用于请求转发终端设备的会话中报文的镜像,该第八请求消息中包括镜像目的地址,该镜像目的地址为应用功能网元中接收所述镜像的地址;收发单元620,还用于向用户面功能网元发送第九请求消息,该第九请求消息中包括检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则用于对终端设备的会话中的报文进行镜像转发,该转发规则中包括镜像转发指示和所述镜像目的地址,该镜像转发指示用于指示转发所述镜像。When the communication device 600 is used to realize the function of the session management function network element in the method embodiment shown in FIG. For requesting forwarding of the mirroring of the message in the session of the terminal device, the eighth request message includes the mirroring destination address, and the mirroring destination address is the address receiving the mirroring in the application function network element; the transceiver unit 620 is also used to send the user The surface function network element sends a ninth request message, the ninth request message includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, and the forwarding rule is used for the traffic flow in the session of the terminal device The message is mirrored and forwarded, and the forwarding rule includes a mirroring forwarding indication and the mirroring destination address, and the mirroring forwarding indication is used to instruct forwarding of the mirroring.
当通信装置600用于实现图5所示的方法实施例中用户面功能网元的功能时:收发单元620,用于接收来自会话管理功能网元的检测规则和转发规则,该检测规则用于检测终端设备的会话中的业务流,该转发规则用于对终端设备的会话中的报文进行镜像转发,该转发规则中包括镜像转发指示和镜像目的地址,该镜像目的地址为应用功能网元中接收镜像的地址;处理单元610,用于根据检测规则检测终端设备的会话中的报文;收发单元620,用于根据镜像转发指示和镜像目的地址向应用功能网元发送所述镜像。When the communication device 600 is used to realize the functions of the user plane function network element in the method embodiment shown in FIG. 5: the transceiver unit 620 is used to receive the detection rule and the forwarding rule from the session management function network element. Detect the service flow in the session of the terminal device. The forwarding rule is used to mirror and forward the packets in the session of the terminal device. The forwarding rule includes a mirror forwarding instruction and a mirror destination address. The mirror destination address is the application function network element Receive the address of the mirror image; the processing unit 610 is used to detect the message in the session of the terminal device according to the detection rule; the transceiver unit 620 is used to send the mirror image to the application function network element according to the mirror forwarding instruction and the mirror destination address.
该通信装置中涉及的处理单元610可以由至少一个处理器或处理器相关电路组件实现,收发单元620可以由至少一个收发器或收发器相关电路组件或通信接口实现。可选的,该通信装置中还可以包括存储单元,该存储单元可以用于存储数据和/或指令,收发单元620和/或处理单元610可以读取存储单元中的数据和/或指令,从而使得通信装置实现相应的方法。该存储单元例如可以通过至少一个存储器实现。上述存储单元、处理单元和收发单元可以分离存在,也可以全部或者部分模块集成,例如存储单元和处理单元集成,或者处理单元和收发单元集成等。The processing unit 610 involved in the communication device may be realized by at least one processor or processor-related circuit components, and the transceiver unit 620 may be realized by at least one transceiver or transceiver-related circuit components or a communication interface. Optionally, the communication device may further include a storage unit, which may be used to store data and/or instructions, and the transceiver unit 620 and/or the processing unit 610 may read the data and/or instructions in the storage unit, thereby The communication device is made to implement a corresponding method. The storage unit can be realized, for example, by at least one memory. The above-mentioned storage unit, processing unit and transceiver unit may exist separately, or may be integrated in whole or in part, for example, the storage unit is integrated with the processing unit, or the processing unit is integrated with the transceiver unit.
该通信装置中的各个单元的操作和/或功能分别为了实现图3至图5中所示方法的相应流程,为了简洁,在此不再赘述。The operations and/or functions of each unit in the communication device are to implement the corresponding processes of the methods shown in FIG. 3 to FIG. 5 , and for the sake of brevity, details are not repeated here.
如图7所示,通信装置700包括处理器710和接口电路720。处理器710和接口电路720之间相互耦合。可以理解的是,接口电路720可以为收发器或输入输出接口。可选的,通信装置700还可以包括存储器730,用于存储处理器710执行的指令或存储处理器710运行指令所需要的输入数据或存储处理器710运行指令后产生的数据。As shown in FIG. 7 , a communication device 700 includes a processor 710 and an interface circuit 720 . The processor 710 and the interface circuit 720 are coupled to each other. It can be understood that the interface circuit 720 may be a transceiver or an input-output interface. Optionally, the communication device 700 may further include a memory 730 for storing instructions executed by the processor 710, or storing input data required by the processor 710 to execute the instructions, or storing data generated by the processor 710 after executing the instructions.
当通信装置700用于实现图3至图5所示的方法时,处理器710用于实现上述处理单元610的功能,接口电路720用于实现上述收发单元620的功能。When the communication device 700 is used to implement the methods shown in FIGS. 3 to 5 , the processor 710 is used to implement the functions of the processing unit 610 , and the interface circuit 720 is used to implement the functions of the transceiver unit 620 .
可以理解的是,本申请的实施例中的处理器可以是中央处理单元(central processing unit,CPU),还可以是其它通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(application specific integrated circuit,ASIC)、现场可编程门阵列(field programmable gate array,FPGA)或者其它可编程逻辑器件、晶体管逻辑器件,硬件部件或者其任意组合。通用处理器可以是微处理器,也可以是任何常规的处理器。It can be understood that the processor in the embodiments of the present application can be a central processing unit (central processing unit, CPU), and can also be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application-specific integrated circuits (application specific integrated circuit, ASIC), field programmable gate array (field programmable gate array, FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. A general-purpose processor can be a microprocessor, or any conventional processor.
本申请的实施例中的方法步骤可以通过硬件的方式来实现,也可以由处理器执行软件 指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于随机存取存储器、闪存、只读存储器、可编程只读存储器、可擦除可编程只读存储器、电可擦除可编程只读存储器、寄存器、硬盘、移动硬盘、CD-ROM或者本领域熟知的任何其它形式的存储介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于基站或终端中。当然,处理器和存储介质也可以作为分立组件存在于基站或终端中。The method steps in the embodiments of the present application may be implemented by means of hardware, or may be implemented by means of a processor executing software instructions. Software instructions can be composed of corresponding software modules, and software modules can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only Memory, registers, hard disk, removable hard disk, CD-ROM or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such the processor can read information from, and write information to, the storage medium. Of course, the storage medium may also be a component of the processor. The processor and storage medium can be located in the ASIC. In addition, the ASIC can be located in the base station or the terminal. Certainly, the processor and the storage medium may also exist in the base station or the terminal as discrete components.
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机程序或指令。在计算机上加载和执行所述计算机程序或指令时,全部或部分地执行本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、基站、用户设备或者其它可编程装置。所述计算机程序或指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机程序或指令可以从一个网站站点、计算机、服务器或数据中心通过有线或无线方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是集成一个或多个可用介质的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,例如,软盘、硬盘、磁带;也可以是光介质,例如,数字视频光盘;还可以是半导体介质,例如,固态硬盘。该计算机可读存储介质可以是易失性或非易失性存储介质,或可包括易失性和非易失性两种类型的存储介质。In the above embodiments, all or part of them may be implemented by software, hardware, firmware or any combination thereof. When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer programs or instructions. When the computer program or instructions are loaded and executed on the computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer may be a general purpose computer, a special purpose computer, a computer network, a base station, user equipment or other programmable devices. The computer program or instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instructions may be downloaded from a website, computer, A server or data center transmits to another website site, computer, server or data center by wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center integrating one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disk; and it may also be a semiconductor medium, such as a solid state disk. The computer readable storage medium may be a volatile or a nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
在本申请的各个实施例中,如果没有特殊说明以及逻辑冲突,不同的实施例之间的术语和/或描述具有一致性、且可以相互引用,不同的实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。In each embodiment of the present application, if there is no special explanation and logical conflict, the terms and/or descriptions between different embodiments are consistent and can be referred to each other, and the technical features in different embodiments are based on their inherent Logical relationships can be combined to form new embodiments.
本申请中,“至少一个”是指一个或者多个,“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B的情况,其中A,B可以是单数或者复数。在本申请的文字描述中,字符“/”,一般表示前后关联对象是一种“或”的关系;在本申请的公式中,字符“/”,表示前后关联对象是一种“相除”的关系。In this application, "at least one" means one or more, and "multiple" means two or more. "And/or" describes the association relationship of associated objects, indicating that there may be three types of relationships, for example, A and/or B, which can mean: A exists alone, A and B exist simultaneously, and B exists alone, where A, B can be singular or plural. In the text description of this application, the character "/" generally indicates that the contextual objects are an "or" relationship; in the formulas of this application, the character "/" indicates that the contextual objects are a "division" Relationship.
可以理解的是,在本申请的实施例中涉及的各种数字编号仅为描述方便进行的区分,并不用来限制本申请的实施例的范围。上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定。It can be understood that the various numbers involved in the embodiments of the present application are only for convenience of description, and are not used to limit the scope of the embodiments of the present application. The size of the serial numbers of the above-mentioned processes does not mean the order of execution, and the execution order of each process should be determined by its functions and internal logic.

Claims (26)

  1. 一种业务感知方法,其特征在于,所述方法包括:A service perception method, characterized in that the method comprises:
    向用户面功能网元发送第一请求消息,所述第一请求消息中包括检测规则和用量上报规则,所述检测规则包括应用业务的标识和包检测特征信息,所述检测规则用于检测会话中所述应用业务的业务流,所述包检测特征信息用于指示所述应用业务的业务流的匹配特征,所述用量上报规则包括第一事件标识,所述第一事件标识用于指示上报所述应用业务的业务流的事件,所述事件为应用开始事件或应用结束事件;Send a first request message to the user plane functional network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes the identification of the application service and packet detection feature information, and the detection rule is used to detect session In the service flow of the application service, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, and the usage reporting rule includes a first event identifier, and the first event identifier is used to indicate the reporting An event of the service flow of the application service, where the event is an application start event or an application end event;
    接收来自所述用户面功能网元的第一事件报告,所述第一事件报告用于指示所述应用业务的业务流的所述事件。receiving a first event report from the user plane functional network element, where the first event report is used to indicate the event of the service flow of the application service.
  2. 根据权利要求1所述的方法,其特征在于,所述方法还包括:The method according to claim 1, further comprising:
    接收来自策略控制功能网元的第二请求消息,所述第二请求消息用于订阅所述事件,所述第二请求消息中包括所述应用业务的标识、所述包检测特征信息和第二事件标识,所述第二事件标识用于指示上报所述事件;receiving a second request message from a policy control function network element, where the second request message is used to subscribe to the event, and the second request message includes the identifier of the application service, the packet detection feature information, and the second An event identifier, where the second event identifier is used to indicate to report the event;
    向所述策略控制功能网元发送第二事件报告,所述第二事件报告用于指示所述事件。Sending a second event report to the policy control function network element, where the second event report is used to indicate the event.
  3. 根据权利要求1或2所述的方法,其特征在于,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。The method according to claim 1 or 2, wherein the packet detection feature information includes statistical features and/or packet header features of packets in the service flow of the application service.
  4. 根据权利要求1至3中任一项所述的方法,其特征在于,所述检测规则还包括流描述信息,所述流描述信息用于指示所述包检测特征信息适用的业务流。The method according to any one of claims 1 to 3, wherein the detection rule further includes flow description information, and the flow description information is used to indicate a service flow to which the packet detection feature information applies.
  5. 一种业务感知方法,其特征在于,所述方法包括:A service perception method, characterized in that the method comprises:
    接收来自会话管理功能网元的第一请求消息,所述第一请求消息中包括检测规则和用量上报规则,所述检测规则包括应用业务的标识和包检测特征信息,所述检测规则用于检测会话中所述应用业务的业务流,所述包检测特征信息用于指示所述应用业务的业务流的匹配特征,所述用量上报规则包括第一事件标识,所述第一事件标识用于指示上报所述应用业务的业务流的事件,所述事件为应用开始事件或应用结束事件;Receive a first request message from a session management function network element, the first request message includes a detection rule and a usage reporting rule, the detection rule includes an application service identifier and packet detection feature information, and the detection rule is used to detect The service flow of the application service in the session, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, the usage reporting rule includes a first event identifier, and the first event identifier is used to indicate Reporting an event of the service flow of the application service, where the event is an application start event or an application end event;
    根据所述包检测特征信息对接收到的所述会话中的报文执行应用检测;performing application detection on received packets in the session according to the packet detection feature information;
    若检测到所述应用业务的业务流的所述事件,向所述会话管理功能网元发送第一事件报告,所述第一事件报告用于指示所述事件。If the event of the service flow of the application service is detected, a first event report is sent to the session management function network element, where the first event report is used to indicate the event.
  6. 根据权利要求5所述的方法,其特征在于,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。The method according to claim 5, wherein the packet detection feature information includes statistical features and/or packet header features of packets in the service flow of the application service.
  7. 根据权利要求5或6所述的方法,其特征在于,所述检测规则还包括流描述信息,所述流描述信息用于指示所述包检测特征信息适用的业务流;The method according to claim 5 or 6, wherein the detection rule further includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection characteristic information is applicable;
    根据所述包检测特征信息对接收到的报文执行应用检测,包括:Perform application detection on the received message according to the packet detection feature information, including:
    根据所述包检测特征信息,对所述会话中与所述流描述信息匹配的报文执行应用检测。According to the packet detection feature information, application detection is performed on packets matching the flow description information in the session.
  8. 一种通信系统,其特征在于,所述系统包括会话管理功能网元和用户面功能网元;A communication system, characterized in that the system includes a session management function network element and a user plane function network element;
    所述会话管理功能网元,用于向所述用户面功能网元发送第一请求消息,所述第一请求消息中包括检测规则和用量上报规则,所述检测规则包括应用业务的标识和包检测特征信息,所述检测规则用于检测会话中所述应用业务的业务流,所述包检测特征信息用于指示所述应用业务的业务流的匹配特征,所述用量上报规则包括第一事件标识,所述第一事件标识用于指示上报所述应用业务的业务流的事件,所述事件为应用开始事件或应用结束 事件;The session management function network element is configured to send a first request message to the user plane function network element, the first request message includes a detection rule and a usage reporting rule, and the detection rule includes an application service identifier and packet Detection feature information, the detection rule is used to detect the service flow of the application service in the session, the packet detection feature information is used to indicate the matching feature of the service flow of the application service, and the usage reporting rule includes the first event An identifier, the first event identifier is used to indicate an event for reporting the service flow of the application service, and the event is an application start event or an application end event;
    所述用户面功能网元,用于接收来自所述会话管理功能网元的第一请求消息,根据所述包检测特征信息对接收到的所述会话中的报文执行应用检测,以及若检测到所述应用业务的业务流的所述事件,向所述会话管理功能网元发送第一事件报告,所述第一事件报告用于指示所述事件;The user plane functional network element is configured to receive the first request message from the session management functional network element, perform application detection on the received packets in the session according to the packet detection characteristic information, and if detected For the event of the service flow of the application service, send a first event report to the session management function network element, where the first event report is used to indicate the event;
    所述会话管理功能网元还用于,接收来自所述用户面功能网元的所述第一事件报告。The session management functional network element is further configured to receive the first event report from the user plane functional network element.
  9. 根据权利要求8所述的系统,其特征在于,所述系统还包括策略控制功能网元;The system according to claim 8, further comprising a network element with a policy control function;
    所述策略控制功能网元,用于向所述会话管理功能网元发送第二请求消息,所述第二请求消息用于请求订阅所述事件,所述第二请求消息中包括所述应用业务的标识、所述包检测特征信息和第二事件标识,所述第二事件标识用于上报所述事件;The policy control function network element is configured to send a second request message to the session management function network element, the second request message is used to request to subscribe to the event, and the second request message includes the application service The identification of the packet detection feature information and the second event identification, the second event identification is used to report the event;
    所述会话管理功能网元,还用于接收来自所述策略控制功能网元的所述第二请求消息,以及向所述策略控制功能网元发送第二事件报告,所述第二事件报告用于指示所述事件;The session management function network element is further configured to receive the second request message from the policy control function network element, and send a second event report to the policy control function network element, and the second event report uses on the events mentioned in the instructions;
    所述策略控制功能网元,还用于接收来自所述会话管理功能网元的所述第二事件报告。The policy control function network element is further configured to receive the second event report from the session management function network element.
  10. 根据权利要求9所述的系统,其特征在于,所述系统还包括应用功能网元;The system according to claim 9, further comprising an application function network element;
    所述应用功能网元,用于向所述策略控制功能网元发送第三请求消息,所述第三请求消息中包括所述应用业务的标识、所述包检测特征信息和第三事件标识,所述第三事件标识用于上报所述事件;The application function network element is configured to send a third request message to the policy control function network element, where the third request message includes the identifier of the application service, the packet detection feature information, and a third event identifier, The third event identifier is used to report the event;
    所述策略控制功能网元,还用于接收来自所述应用功能网元的所述第三请求消息,以及向所述应用功能网元发送第三事件报告,所述第三事件报告用于指示所述事件;The policy control function network element is further configured to receive the third request message from the application function network element, and send a third event report to the application function network element, where the third event report is used to indicate said event;
    所述应用功能网元,还用于接收来自所述策略控制功能网元的所述第三事件报告。The application function network element is further configured to receive the third event report from the policy control function network element.
  11. 一种业务感知方法,其特征在于,所述方法包括:A service perception method, characterized in that the method comprises:
    接收来自应用功能网元的第四请求消息,所述第四请求消息用于请求分析应用业务的业务流的事件,所述事件为应用开始事件或应用结束事件,所述第四请求消息中包括所述应用业务的标识和包检测特征信息,所述包检测特征信息用于指示所述应用业务的业务流的匹配特征;Receive a fourth request message from an application function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, the event is an application start event or an application end event, and the fourth request message includes The identification of the application service and packet detection feature information, the packet detection feature information is used to indicate the matching feature of the service flow of the application service;
    向会话管理功能网元发送第五请求消息,所述第五请求消息用于请求转发终端设备的会话中报文的镜像;Sending a fifth request message to the session management function network element, where the fifth request message is used to request forwarding the image of the message in the session of the terminal device;
    根据所述包检测特征信息,对接收到的所述会话管理功能网元或用户面功能网元的所述镜像执行应用检测;performing application detection on the received image of the session management function network element or the user plane function network element according to the packet detection feature information;
    若检测到应用业务的业务流的所述事件,向所述应用功能网元发送事件报告,所述事件报告用于指示所述事件。If the event of the service flow of the application service is detected, an event report is sent to the application function network element, where the event report is used to indicate the event.
  12. 根据权利要求11所述的方法,其特征在于,所述包检测特征信息包括所述应用业务的业务流中报文的统计特征和/或包头特征。The method according to claim 11, wherein the packet detection feature information includes statistical features and/or packet header features of packets in the service flow of the application service.
  13. 根据权利要求11或12所述的方法,其特征在于,所述第四请求消息中还包括流描述信息,所述流描述信息用于指示所述包检测特征信息适用的业务流;The method according to claim 11 or 12, wherein the fourth request message further includes flow description information, and the flow description information is used to indicate the service flow to which the packet detection characteristic information is applicable;
    所述第五请求消息中包括所述流描述信息,所述流描述信息用于指示转发所述终端设备的会话中与所述流描述信息匹配的报文的镜像。The fifth request message includes the flow description information, and the flow description information is used to instruct forwarding the image of the packet matching the flow description information in the session of the terminal device.
  14. 根据权利要求11至13中任一项所述的方法,其特征在于,所述第五请求消息中还包括镜像目的地址,所述镜像目的地址为网络数据分析功能网元中接收所述镜像的地址。The method according to any one of claims 11 to 13, wherein the fifth request message further includes a mirroring destination address, and the mirroring destination address is a network element with a network data analysis function that receives the mirroring address.
  15. 根据权利要求11至14中任一项所述的方法,其特征在于,所述第四请求消息中还 包括事件标识,所述事件标识用于指示上报所述事件;The method according to any one of claims 11 to 14, wherein the fourth request message also includes an event identifier, and the event identifier is used to indicate to report the event;
    所述事件报告中包括所述应用业务的标识和所述事件标识。The event report includes the identifier of the application service and the event identifier.
  16. 一种业务感知方法,其特征在于,所述方法包括:A service perception method, characterized in that the method comprises:
    接收来自网络数据分析功能网元的第五请求消息,所述第五请求消息用于请求转发终端设备的会话中报文的镜像;receiving a fifth request message from a network element with a network data analysis function, where the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device;
    向用户面功能网元发送第六请求消息,所述第六请求消息中包括检测规则和转发规则,所述检测规则用于检测所述终端设备的会话的业务流,所述转发规则中包括镜像转发指示,所述镜像转发指示用于指示转发所述镜像。Send a sixth request message to the user plane functional network element, the sixth request message includes a detection rule and a forwarding rule, the detection rule is used to detect the service flow of the session of the terminal device, and the forwarding rule includes a mirror image A forwarding indication, where the image forwarding indication is used to instruct forwarding the image.
  17. 根据权利要求16所述的方法,其特征在于,所述第五请求消息中包括流描述信息,所述流描述信息用于指示转发所述终端设备的会话中与所述流描述信息匹配的报文的镜像;The method according to claim 16, wherein the fifth request message includes flow description information, and the flow description information is used to instruct forwarding the packets matching the flow description information in the session of the terminal device. the mirror image of the text;
    所述检测规则中包括所述流描述信息。The detection rule includes the flow description information.
  18. 根据权利要求16所述的方法,其特征在于,所述检测规则中包括通配指示信息,所述通配指示信息用于转发所述终端设备的会话中所有报文的镜像。The method according to claim 16, wherein the detection rule includes wildcard indication information, and the wildcard indication information is used to forward mirror images of all messages in the session of the terminal device.
  19. 根据权利要求16至18中任一项所述的方法,其特征在于,所述第五请求消息中还包括镜像目的地址,所述镜像目的地址为所述网络数据分析功能网元中接收所述镜像的地址。The method according to any one of claims 16 to 18, wherein the fifth request message further includes a mirroring destination address, and the mirroring destination address is the The address of the mirror.
  20. 根据权利要求19所述的方法,其特征在于,所述方法还包括:The method according to claim 19, further comprising:
    接收来自所述用户面功能网元的所述镜像,并根据所述镜像目的地址向所述网络数据分析功能网元发送所述镜像;或者,receiving the image from the user plane functional network element, and sending the image to the network data analysis function network element according to the image destination address; or,
    所述转发规则中还包括所述镜像目的地址。The mirroring destination address is also included in the forwarding rule.
  21. 一种通信系统,其特征在于,所述系统包括网络数据分析功能网元和会话管理功能网元;其中,A communication system, characterized in that the system includes a network data analysis function network element and a session management function network element; wherein,
    所述网络数据分析功能网元,用于接收来自应用功能网元的第四请求消息,所述第四请求消息用于请求分析应用业务的业务流的事件,所述事件为应用开始事件或应用结束事件,所述第四请求消息中包括所述应用业务的标识和包检测特征信息,所述包检测特征信息用于指示所述应用业务的业务流的匹配特征;以及,向所述会话管理功能网元发送第五请求消息,所述第五请求消息用于请求转发终端设备的会话中报文的镜像;The network data analysis function network element is used to receive a fourth request message from the application function network element, the fourth request message is used to request to analyze the event of the service flow of the application service, and the event is an application start event or an application An end event, the fourth request message includes the identification of the application service and packet detection characteristic information, the packet detection characteristic information is used to indicate the matching characteristics of the service flow of the application service; and, to the session management The functional network element sends a fifth request message, where the fifth request message is used to request forwarding the mirror image of the message in the session of the terminal device;
    所述会话管理功能网元用于,接收来自所述网络数据分析功能网元的第五请求消息,以及向用户面功能网元发送第六请求消息,所述第六请求消息中包括检测规则和转发规则,所述检测规则用于检测所述终端设备的会话中的业务流,所述转发规则中包括镜像转发指示,所述镜像转发指示用于指示转发所述镜像;The session management function network element is configured to receive a fifth request message from the network data analysis function network element, and send a sixth request message to the user plane function network element, and the sixth request message includes detection rules and A forwarding rule, the detection rule is used to detect the service flow in the session of the terminal device, the forwarding rule includes a mirroring forwarding indication, and the mirroring forwarding indication is used to indicate forwarding of the mirroring;
    所述网络数据分析功能网元,还用于接收来自所述会话管理功能网元或用户面功能网元的所述镜像,根据所述包检测特征信息对所述镜像执行应用检测,并向所述应用功能网元发送事件报告,所述事件报告用于指示所述事件。The network data analysis function network element is further configured to receive the image from the session management function network element or the user plane function network element, perform application detection on the image according to the packet detection characteristic information, and report to all The application function network element sends an event report, where the event report is used to indicate the event.
  22. 根据权利要求21所述的系统,其特征在于,所述系统还包括所述应用功能网元;The system according to claim 21, further comprising the application function network element;
    所述应用功能网元,用于向所述网络数据分析功能网元发送所述第四请求消息,以及接收来自所述网络数据分析功能网元的所述事件报告。The application function network element is configured to send the fourth request message to the network data analysis function network element, and receive the event report from the network data analysis function network element.
  23. 根据权利要求21或22所述的系统,其特征在于,所述系统还包括所述用户面功能网元;The system according to claim 21 or 22, wherein the system further comprises the user plane functional network element;
    所述用户面功能网元用于,接收来自所述会话管理功能网元的第六请求消息,根据所述检测规则,检测所述终端设备的会话中的报文,以及根据所述镜像转发指示,向所述会话管理功能网元或所述网络数据分析功能网元发送所述镜像。The user plane functional network element is configured to receive the sixth request message from the session management functional network element, detect the message in the session of the terminal device according to the detection rule, and forward the instruction according to the mirroring , sending the image to the network element with the session management function or the network element with the network data analysis function.
  24. 一种通信装置,其特征在于,包括用于执行如权利要求1至4中任一项所述方法的模块,或者包括用于执行如权利要求16至20中任一项所述方法的模块。A communication device, characterized by comprising a module for performing the method according to any one of claims 1 to 4, or comprising a module for performing the method according to any one of claims 16 to 20.
  25. 一种通信装置,其特征在于,包括用于执行如权利要求5至7中任一项所述方法的模块。A communication device, characterized by comprising a module for performing the method according to any one of claims 5 to 7.
  26. 一种通信装置,其特征在于,包括用于执行如权利要求11至15中任一项所述方法的模块。A communication device, characterized by comprising a module for performing the method according to any one of claims 11-15.
PCT/CN2022/109737 2021-08-13 2022-08-02 Service awareness method, communication apparatus, and communication system WO2023016298A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110929598.2 2021-08-13
CN202110929598.2A CN115942362A (en) 2021-08-13 2021-08-13 Service sensing method, communication device and communication system

Publications (1)

Publication Number Publication Date
WO2023016298A1 true WO2023016298A1 (en) 2023-02-16

Family

ID=85199902

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/109737 WO2023016298A1 (en) 2021-08-13 2022-08-02 Service awareness method, communication apparatus, and communication system

Country Status (2)

Country Link
CN (1) CN115942362A (en)
WO (1) WO2023016298A1 (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110351899A (en) * 2018-04-02 2019-10-18 华为技术有限公司 Discharge the method and apparatus of user plane functions network element
CN110519750A (en) * 2018-05-21 2019-11-29 华为技术有限公司 Message processing method, equipment and system
CN110580256A (en) * 2018-05-22 2019-12-17 华为技术有限公司 Method, device and system for identifying application identifier
WO2020001795A1 (en) * 2018-06-25 2020-01-02 Telefonaktiebolaget Lm Ericsson (Publ) A method of reporting traffic metrics by a user plane function, upf, to a session management function, smf, in a telecommunication network, as well as a corresponding upf
CN111586642A (en) * 2019-02-19 2020-08-25 华为技术有限公司 Communication method and device

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110351899A (en) * 2018-04-02 2019-10-18 华为技术有限公司 Discharge the method and apparatus of user plane functions network element
CN110519750A (en) * 2018-05-21 2019-11-29 华为技术有限公司 Message processing method, equipment and system
CN110580256A (en) * 2018-05-22 2019-12-17 华为技术有限公司 Method, device and system for identifying application identifier
WO2020001795A1 (en) * 2018-06-25 2020-01-02 Telefonaktiebolaget Lm Ericsson (Publ) A method of reporting traffic metrics by a user plane function, upf, to a session management function, smf, in a telecommunication network, as well as a corresponding upf
CN111586642A (en) * 2019-02-19 2020-08-25 华为技术有限公司 Communication method and device

Also Published As

Publication number Publication date
CN115942362A (en) 2023-04-07

Similar Documents

Publication Publication Date Title
US20210274436A1 (en) Resource information sending method, first network element and system
US20200053802A1 (en) Session management with relaying and charging for indirect connection for internet of things applications in 3gpp network
JP2022517176A (en) Methods and equipment to support local area networks (LANs)
CN115039425A (en) Extending Npcf _ EventExposure by using a condition monitoring event
WO2020108002A1 (en) Transmission policy determination method, policy control method, and device
US20230061152A1 (en) Communication method, apparatus, and system
WO2022222817A1 (en) Method and apparatus for selecting edge application server
US20230269608A1 (en) Nf discovery and selection based on service response latency measurements
US20220394595A1 (en) Communication method, apparatus, and system
US20240155418A1 (en) Method and apparatus for connecting qos flow based terminal in wireless communication system
US20240080716A1 (en) Wireless communication method, communication apparatus, and communication system
CN115915196A (en) Link state detection method, communication device and communication system
WO2023213177A1 (en) Communication method and apparatus
WO2022267652A1 (en) Communication method, communication apparatus, and communication system
WO2023284551A1 (en) Communication method, device and system
WO2023016298A1 (en) Service awareness method, communication apparatus, and communication system
WO2021218244A1 (en) Communication method, apparatus and system
WO2021138784A1 (en) Network access method, apparatus and system
WO2023056784A1 (en) Data collection method, communication apparatus and communication system
WO2023030077A1 (en) Communication method, communication apparatus, and communication system
WO2023082858A1 (en) Method for determining mobility management policy, communication apparatus, and communication system
WO2023231450A1 (en) Time synchronization method and communication apparatus
WO2023005440A1 (en) Communication method, communication apparatus and communication system
WO2023061207A1 (en) Communication method, communication apparatus, and communication system
WO2023050781A1 (en) Communication method and communication apparatus

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22855281

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 22855281

Country of ref document: EP

Kind code of ref document: A1