EP4169211A1 - Procédé de configuration d'un dispositif terminal - Google Patents
Procédé de configuration d'un dispositif terminalInfo
- Publication number
- EP4169211A1 EP4169211A1 EP21737728.2A EP21737728A EP4169211A1 EP 4169211 A1 EP4169211 A1 EP 4169211A1 EP 21737728 A EP21737728 A EP 21737728A EP 4169211 A1 EP4169211 A1 EP 4169211A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- terminal device
- identifier
- network
- connection
- data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000000034 method Methods 0.000 title claims abstract description 57
- 238000004891 communication Methods 0.000 claims abstract description 98
- 238000012546 transfer Methods 0.000 claims description 17
- 230000005540 biological transmission Effects 0.000 claims description 9
- 238000004590 computer program Methods 0.000 claims description 8
- 238000003860 storage Methods 0.000 claims description 8
- 230000004931 aggregating effect Effects 0.000 claims description 7
- 238000010200 validation analysis Methods 0.000 claims description 5
- 238000007726 management method Methods 0.000 description 56
- 230000004044 response Effects 0.000 description 8
- 230000008569 process Effects 0.000 description 7
- 238000012545 processing Methods 0.000 description 5
- 238000011161 development Methods 0.000 description 3
- 230000006870 function Effects 0.000 description 3
- 230000008901 benefit Effects 0.000 description 2
- 238000013523 data management Methods 0.000 description 2
- 230000003287 optical effect Effects 0.000 description 2
- 101100468275 Caenorhabditis elegans rep-1 gene Proteins 0.000 description 1
- 206010028916 Neologism Diseases 0.000 description 1
- 230000006978 adaptation Effects 0.000 description 1
- 230000002776 aggregation Effects 0.000 description 1
- 238000004220 aggregation Methods 0.000 description 1
- 239000000969 carrier Substances 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000036541 health Effects 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 230000010354 integration Effects 0.000 description 1
- 230000003993 interaction Effects 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 238000004377 microelectronic Methods 0.000 description 1
- 238000010295 mobile communication Methods 0.000 description 1
- 238000012806 monitoring device Methods 0.000 description 1
- 238000012544 monitoring process Methods 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 238000002360 preparation method Methods 0.000 description 1
- 230000035945 sensitivity Effects 0.000 description 1
- 230000011664 signaling Effects 0.000 description 1
- 238000004088 simulation Methods 0.000 description 1
- 238000012360 testing method Methods 0.000 description 1
- 238000012795 verification Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0806—Configuration setting for initial configuration or provisioning, e.g. plug-and-play
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/04—Network management architectures or arrangements
- H04L41/046—Network management architectures or arrangements comprising network management agents or mobile agents therefor
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/085—Retrieval of network configuration; Tracking network configuration history
- H04L41/0853—Retrieval of network configuration; Tracking network configuration history by actively collecting configuration information or by backing up configuration information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0895—Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/40—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using virtualisation of network functions or resources, e.g. SDN or NFV entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0281—Proxies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W24/00—Supervisory, monitoring or testing arrangements
- H04W24/08—Testing, supervising or monitoring using real traffic
Definitions
- the invention relates to the configuration of a terminal device for connection to a communication network structured in slices associated with a service, a type of terminal, a quality of service criterion.
- the invention aims to associate a connection proxy device with the terminal device so as to be able to correlate and aggregate information relating to the data exchanged between the terminal device and a service device on a network slice.
- a service is increasingly based on an interaction between business processes and processes specific to communications networks.
- the service therefore requires the contribution of different actors making up an ecosystem.
- the object of the present invention is to provide improvements with respect to the state of the art. 3. Disclosure of the invention
- the invention improves the situation using a method of configuring a terminal device capable of being connected to a slot of a communication network, said slot being instantiated to route data between the terminal device and a device.
- service device in accordance with at least one routing criterion, the method being implemented by management equipment of the terminal device capable of communicating with the terminal device and comprising:
- the context comprising a set of identifiers of devices for connecting the terminal to the communication network, one of the identifiers corresponding to an identifier of a proxy device suitable for connection.
- a terminal device such as industrial equipment or a user terminal, connects to a communication network and transmits data to a service device, such as an application server or other industrial equipment, using multiple connection devices. , also called connectors or security gateways.
- connection devices intervene for the routing of the data exchanged between the terminal device and the service device but also for the management of the metadata relating to the transmitted data, as indicated above.
- the connection devices can be found in the transfer plane, in the network control plane or even in the network management plane. The method thus makes it possible to communicate to the terminal device only a single identifier of a connection device, called a connection proxy device, this device ensuring the interfacing with the various devices involved in the routing of the data.
- the only identifier of the connection proxy device allows the management equipment receiving the connection request to identify the different devices. connection required for connection thanks to the identifier of the terminal device and the identifier of the login proxy device.
- the method also enables the manager of the communication network to be able to update his communication network, by replacing, adding or removing connection devices without informing the terminal device.
- the method also allows, for a set of terminal devices of a local network, to associate a connection proxy device specific to each terminal device.
- This thus allows the different terminal devices, according to the type of application used by these terminal devices, according to the performance of this device, according to the needs in terms of security of these terminal devices, can have a number and a type of monitoring devices. suitable connection.
- This adaptation can also make it possible to associate the connection proxy devices and the types or number of connection devices to the network slice or network slices used for the routing of data from the terminal device.
- the configuration context further comprises security data associated with each connection device of the set.
- the configuration context is used in particular to allow equipment of the communication network, a terminal device or a third-party entity to obtain data relating to a session between a terminal device and a service device.
- the security data of the connection devices are used to determine a level of confidence in the data provided by these devices and / or to identify the level of security that can be established between the connection proxy device and the other connection devices, or even to determining if the security data is suitable for the network slice used for the transfer of data between the terminal device and the service device.
- connection devices of the set are part of one or more plans of the communication network among:
- the data aggregated by the proxy device are data exchanged between the terminal device and the service device, therefore relating to the transfer plan but also control plane data, such as terminal device location data or data indicating an attachment status of the terminal device.
- the data can also be management data.
- the connection device of the management plane is able to transmit data such as performance or availability data of the equipment of the communication network.
- the configuration method further comprises the sending to a management entity of the service device of a notification message comprising the identifier of the terminal device and the identifier of the device. connection proxy.
- the method is advantageous for informing the manager of the service device of the connection proxy device.
- the management entity of the service device which wants to know statistics relating to the routing of the data exchanged with the terminal device on the section of the communication network does not have to communicate with each connection device and therefore to know their identifiers.
- it will possibly obtain aggregated information from the proxy device, which saves it from aggregating it itself based on the identifier of the terminal device and / or network slice.
- This also avoids communicating the architecture of the communication network comprising the various connection devices to a third party, represented here by the management entity.
- the notification message further comprises a security parameter used by the management entity of the service device to communicate with the connection proxy device.
- the notification message can advantageously comprise a security parameter, corresponding to a security protocol and / or to a security key and / or to a security level used for communication between the management entity and the connection proxy device. .
- This parameter makes it possible to improve the security of information from a communications network to a third party, this security parameter being able to be associated with the terminal device and / or with the network slice.
- the configuration method comprises prior to the storage, the transmission to an administration entity of the communication network of a connection request from the terminal device, the request comprising the identifier of the terminal device, the at least one routing criterion relating to the required network segment.
- the method can advantageously be implemented at the request of the management entity of the terminal device.
- the management entity of the device thus sends a connection request comprising the elements required to associate connection devices including a connection proxy device corresponding to the quality of service, security and routing criteria included in the connection request.
- the configuration method further comprises receiving, from an administration entity of the communication network, a validation message comprising the identifier of the terminal device, the identifier of the network section, the set of identifiers of the connection devices involved in the routing of the data, the set comprising the identifier of the proxy device for connection.
- the configuration method comprises prior to the storage of the configuration context the information specific to this context, including identifiers of connection devices including an identifier of a proxy device for connection. It should be noted that the validation message can intervene following the reception of a connection request or else independently of this reception, in particular when the set of connection devices is updated.
- the configuration method can advantageously be implemented by access equipment of the local network to which the terminal device is attached.
- the access equipment can be a router, an access gateway, a home gateway also called a Box.
- the method can also be implemented in equipment for managing an operator's network or equipment for monitoring such a network.
- the invention also relates to a method of attaching a terminal device to a slot of a communication network, said slot being able to route data between the terminal device and a service device in accordance with at least one criterion of routing, implemented by the terminal device and comprising:
- connection profile to the network section comprising an identifier of a connection proxy device and an identifier of the communication network section
- the attachment method further comprises receiving an attachment acceptance message if the attachment entity validates the association between the identifier of the terminal device, the identifier of the network slice and the identifier of the connection proxy device.
- the information received from the terminal device, which the latter itself has received from its management entity are used to validate or not its attachment.
- the home entity can compare the identifiers received with identifiers transmitted by the administration entity of the communication network.
- the invention also relates to a device for configuring a terminal device capable of being connected to a slot of a communication network, said slot being instantiated to route data between the terminal device and a service device in accordance with at least one routing criterion, including
- a database capable of storing a configuration context of the terminal device, the context comprising a set of identifiers of devices for connecting the terminal to the communication network, one of the identifiers corresponding to an identifier of a proxy device connection capable of aggregating data relating to the terminal device coming from the other connection devices of the set, an identifier of the network section and an identifier of the terminal device,
- a sender able to send to the terminal device a configuration message comprising the identifier of the connection proxy device and the identifier of the network section.
- This device capable of implementing the configuration method which has just been described in all of its embodiments, is intended to be implemented in a device of a communication network such as access equipment. 'a local network, such as a home gateway, a terminal or a piece of equipment such as a router.
- the invention also relates to a device for attaching a terminal device to a slot of a communication network, said slot being able to route data between the terminal device and a service device in accordance with at least one criterion of routing, including
- a receiver able to receive, from a management equipment of the terminal device, a configuration message comprising an identifier of a connection proxy device and an identifier of the section of the communication network,
- a configurator able to configure a connection profile to the network section comprising an identifier of a connection proxy device and an identifier of the section of the communication network
- a sender able to send to an attachment entity of the communication network an attachment message comprising an identifier of the terminal device, the connection proxy identifier received and the identifier of the network section received.
- This attachment device able to implement in all its embodiments the attachment method which has just been described, is intended to be implemented in a terminal, such as a sensor, industrial equipment ( machine, control station, etc.) or any type of device capable of communicating with a communication network using a wired or wireless network.
- a terminal such as a sensor, industrial equipment ( machine, control station, etc.) or any type of device capable of communicating with a communication network using a wired or wireless network.
- the invention further relates to a system for configuring a terminal device capable of being connected to a section of a communication network, comprising:
- - management equipment for the terminal device comprising a configuration device
- the invention also relates to computer programs comprising instructions for implementing the steps of the respective configuration and attachment methods which have just been described, when these programs are both executed by a computer. processor and a recording medium readable respectively by a configuration and attachment device on which computer programs are recorded.
- the programs mentioned above can use any programming language, and be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in n any other desirable shape.
- a medium may include a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or else a magnetic recording means.
- a storage means such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or else a magnetic recording means.
- Such a storage means can for example be a hard disk, a flash memory, etc.
- an information medium can be a transmissible medium such as an electrical or optical signal, which can be conveyed via an electrical or optical cable, by radio or by other means.
- a program according to the invention can in particular be downloaded over an Internet type network.
- an information medium can be an integrated circuit in which a program is incorporated, the circuit being adapted to execute or to be used in the execution of the processes in question.
- FIG. 1 presents an architecture of a communication network in which the configuration method according to a first aspect of the invention is implemented
- FIG 2 shows an architecture of a communication network in which the configuration method according to a second aspect of the invention is implemented
- FIG 3 shows an implementation of the configuration method according to one embodiment of the invention
- FIG 4 shows an implementation of the configuration method according to another embodiment of the invention
- FIG 5 shows a configuration device according to one embodiment of the invention
- FIG 6 shows an attachment device according to one embodiment of the invention.
- This architecture can be implemented to route communications data to fixed or mobile terminals and the architecture, deployed from specific equipment or virtualized functions, may be intended to route and process data from residential or mobile customers. business.
- FIG 1 shows an architecture of a communication network in which the configuration method according to a first aspect of the invention is implemented.
- a factory 20 comprises three industrial equipments 10, 11, 12 also identified as terminal devices. These industrial equipment 10, 11, 12 can equally well be machines, control consoles, communication equipment such as computers or smartphones or any other type of equipment capable of communicating with a correspondent via a communication network 100.
- the communication network 100 can be a fixed or mobile infrastructure administered by one or more operators, the operator also being able to be the manager of the plant 20.
- the communication network 100 is made up of 3 planes 110, 120, 130.
- the plan 110 is a management plan comprising equipment and services allowing the management or administration of the communication network 100.
- the devices of the network 100 are administered by specific devices of the management plane, the services implemented from the network 100 are themselves administered from functions and devices of the management plane 110.
- the management plane 110 carries management data.
- the communication network 100 further comprises a control plane 120.
- the control plane 120 groups together the equipment and services linked to the data routing protocols in the communication network 100.
- the plan 120 further comprises the equipment and services making it possible to implement a management of the quality of service of the data conveyed on the network 100 as well as a billing of these data services.
- the plane 120 carries signaling data.
- the communication network 100 further comprises a switching plane 130, also called data plane 130 or transfer plane 130 (in English “forwarding plane” or “data plane” or “user plane”).
- the transfer plane 130 routes the data of the applications, also called useful traffic or useful data, sent or received by the industrial equipment 10, 11, 12 or by the applications installed on this industrial equipment 10, 11, 12.
- the plan 110 of control comprises one or more connection devices 40 in charge of routing management data in the communication network.
- the routed management data relate to payload data routed in the data plane 130 and / or relate to an industrial device 10, 11, 12 transmitting or receiving this payload data.
- the connection device 40 can be an administration server, a security gateway of the management plane 110 or else an item of equipment in charge of routing the management data into the management plane 110.
- the control plane 120 comprises one or more connection devices 50 in charge of routing the control data into the control plane 120.
- the connection device 50 can be of the same type as the device 40 except that it routes data from the control plane 120.
- the data plane 130 also includes one or more devices 60, 70 for connecting the data plane.
- This data plan 130 is further characterized by the implementation of a network slice, comprising equipment and / or services, in charge of routing data requiring the same type of processing.
- the communication operator 100 can deploy as many network slices as necessary and he can associate the slices with terminal devices, with applications, with quality of service characteristics or with routing criteria other than those mentioned above. -before. It is considered that the industrial equipment 11 and 12 transmit and receive data on a slot S2 of the data plane 130 of the communication network 100 and that the industrial equipment 10 transmits and receives data on an SI slot of the data plane 130 of the communication network 100.
- the data of the slot S 1 is routed by the connection device 60 and the data of the S2 slot is routed by the connection device 70.
- the devices 60 and 70 can be of the same type as the connection devices 40 and 50.
- the devices 40, 50, 60, 70 for connection of the various plans (management, control, data) are connected to a connection proxy device 30.
- This connection proxy device 30, can be deployed in the communication network 100.
- This connection proxy device 30 is further connected to connection devices 80 and 90.
- These connection devices 80 and 90 for example route data to partners of the plant 20 to which data sent and received from industrial equipment 10, 11, 12 are routed. These may be connection devices for example. 'other factories, companies working with factory 20 or even entities in charge of auditing factory 20.
- Connection devices 80 and 90 can themselves be proxy connection devices for others. connection devices of the entity exchanging data with the industrial equipment 10, 11, 12 of the plant 20.
- the proxy device 30 can be of the same type as the devices 40, 50, 60, 70 and has the advantage of allow data exchanges between devices 40, 50, 60, 70 and external entities including devices 80, 90 while reducing the number of connections between the respective connecting devices and limiting network security issues 100 vis with regard to external entities, the connection proxy device 30 playing the role of security gateway. Furthermore, the implementation of the connection device 30 makes it possible to hide the topology of the network 100 from the devices 90 and 80. In the absence of the device 30, each device 80 and 90 of the external entities with respect to the network 100 and to the factory 20 should in fact exchange data with the various devices 40, 50, 60, 70 of the plans (management, control, data) of the communication network 100.
- connection devices are identified here as connectors.
- the communication network 100 has two network sections (Slice S1 and Slice S2) for connecting the terminal devices 11 and 12 of the plant 20 to the external environment (or external “Data Space”).
- Devices 11 and 12 use the same Slice S2 network slice because they have the same characteristic for external data exchange, as opposed to device 10 (sensor) which uses another network slice Slice SI.
- the characteristics of the data exchange which justify the installation of network slices can for example be the volume of the data or the level of sensitivity of the industrial data.
- a relay connector 30 is implemented to interconnect the internal connectors of the network 100 into a single external interface to the external environment.
- This relay connector 30 acts as an external connector vis-à-vis external entities.
- Relay connector 30 has the following interface configuration:
- the I_C S interface interconnects the relay connector 30 with at least one internal connector 70 specific to the slice S2.
- the I CC interface interconnects the relay connector 30 with the internal connector 50 of the control plane 120.
- the I_CG interface interconnects the relay connector 30 with the internal connector 40 of the management plan 110.
- the I CE interface interconnects the relay connector 30 with an external connector 80. This I CE interface makes it possible to hide the internal topology of the operator's network and in particular the deployed network slice architecture.
- the I BdD interface interconnects the relay connector 30 with a database 400 that stores network level context data such as the association of at least one slice identifier (Slice S2) to which devices 11, 12 are attached.
- the network architecture of the internal connectors 40, 50, 70, of the relay connector 30 and of the database 400 constitutes an equivalent of data space (in English “Data Space”) internal to the operator of the network 100. Indeed, this architecture allows the relay connector 30 to be a consumer of the data supplied by the internal connectors 40, 50, 70 via the I_CG, I CC and I CS interfaces.
- the database 400 also plays the role of “internal broker” to allow the relay connector 30 to know the internal connectors 40, 50, 70 to be contacted in order to collect these context data from the terminal devices 11, 12.
- FIG 3 shows an implementation of the configuration method according to one embodiment of the invention.
- the factory 20 comprises a terminal device 11, as described in [Fig 1] and [Fig 2] under the term industrial equipment, as well as an equipment 200 for managing the terminal device 11.
- This equipment can be a router. 'access, a gateway (also called a "box"), or even an administration entity of a communication network of the plant 20.
- the communication network 100 comprises an entity 150 for administering the communication network 100 as well as an entity 160 for attaching to the communication network 100 for the data plane.
- the administration entity 150 is a management station of the communication network 100 such as a connection manager to the data space of the network 100 and the attachment entity 160 is an equipment item.
- the network 100 further includes equipment 140 for managing the resources of the communication network 100.
- An industrial partner 300 of the plant 20 is also present in [Fig 3]
- the partner 300 comprises in particular an entity 310 for managing a service device not shown in [Fig 3], this service device exchanging data with the terminal device 11 of the plant 20 via a section of the communication network 100, the section not being shown in [Fig 3]
- the equipment 200 for managing the terminal device 11 transmits to an entity 150 for administering the communication network 100 a connection request comprising in particular identification information for the terminal 11, the type of section of network and in particular the quality of service characteristics required, as well as a level of security of the required connection.
- the factory 20 thus indicates the level of security desired for the transfer of data from the terminal device 11.
- the level of security can correspond to the security levels as defined in the document IEC 62443 (https: // webstore .iec.ch / preview / info_iec62443-4-2% 7Bedl.0% 7Db.pdf).
- the administration entity 150 chooses the connection devices (40, 50, 70) as well as the type of connection proxy device 30 as well as the associated interfaces (I_CG, I CC, I CS, I_CE).
- the connection devices are not shown in [Fig 3] but are presented in [Fig 1] and [Fig 2] Security and capacity requirements are considered in particular in the choice of connection devices present in the inventory the 400 database of connection to an external data space (represented here by industrial partner 300).
- the administration entity 150 transmits to a network resource management entity 140 100 a deployment request comprising the following information: identifier of the terminal device 11, type of network slice required, list of connection devices.
- This deployment request relates to the implementation of the network slice as well as to the architecture of the connection devices and the connection proxy device of step E2.
- the resource management entity 140 checks the correct availability of the resources required for the terminal device 11 as present in the request received during step E3.
- Resource availability relates to the connectivity, compute and storage resources to implement network connectivity based on network slices and the architecture of the selected connectors.
- a step E5 if the resources are indeed available, the resource management entity 140 transmits to an attachment entity 160 of the communication network 100 a request for instantiation of the configuration.
- This request includes an identifier of the terminal device 11, the type of network slice required as well as the list of connection devices as identified in step E2. If the resources are not available, a configuration error or failure message is transmitted to the management equipment 200.
- the purpose of this step is to require the deployment and then the configuration of the network elements (including the network slices) constituting the transfer plan (or data plan), control and management as well as the architecture of the selected connectors.
- the network attachment entity 160 100 saves the configuration context by terminal device.
- This context as maintained by the attachment entity 160, comprises the identifier of the terminal device 11, the identifier of the slot implemented or used for the routing of data between the terminal device 11 and a remote device.
- partner service 300 the identifiers of the connection devices including the identifier of the proxy connection device.
- the context can also include security data associated with the connection devices, as well as data relating to the plans (transfer, control, management) of the respective connection devices.
- Context data is saved in the database 400 (or internal “broker” as indicated in [Fig 2]) and then make it possible to link, for a given terminal device, the network information associated with it: at least one slice identifier attached to it, at least one connection device identifier of the transfer plane, the identifier of the connection proxy device, the properties of the connection devices in terms of security, capacity, interface with the connection proxy device and also the selected security level.
- These context data are typically stored at the control plane level in a UDM ("Unif ⁇ ed Data Management") type database (according to the 3GPP TS 29.503 "5G System; Unif ⁇ ed Data Management Services; Stage 3") specification) .
- the attachment entity 160 transmits an acceptance message comprising the context information saved by the attachment entity 160. This acceptance message is transmitted to the resource management equipment 140 when the configuration of the network equipment and connection devices is effective for the terminal device 11.
- the resource management equipment 140 transmits to the network administration entity 150 a setting message comprising an identifier of the terminal device 11, the identifier of the network section set. works for the routing of data, the identifier of the connection proxy device and connection devices.
- This message is transmitted in response to the deployment request transmitted in step E3 and indicates the network slice identifier and the identifiers of the connection devices allocated to the terminal device 11.
- the network administration entity 150 sends to the management equipment 200 of the terminal device 11 a validation message comprising the identifiers received during step E8.
- This validation message is transmitted in response to the connection request transmitted during step El.
- This message includes security data associated with the respective connection identifiers as well as a security level implemented by the network operator 100 for the network section.
- the security data item may correspond to a security protocol used, to the type of security key to be used.
- This message also indicates the architecture of the connection devices by virtue of the type of connection proxy device deployed.
- the management equipment of the terminal device 11 stores the configuration context.
- This context includes the identifier of the network section, the identifier of the terminal device 11 as well as a set of identifiers of the connection devices relating to the terminal device 11, including the identifier of the proxy connection device ensuring the interface between the terminal device 11 and the connection devices of the external partners.
- These identifiers implemented and communicated by the operator of the communication network 100 are for example recorded in a database of the management equipment 200.
- the identifiers of the connection devices can correspond to identifiers of devices of the data plane and / or of the control plane and / or of the management plane of the communication network 100. If security data is received during step E10 or if the management equipment 200 is informed of these security data independently, the configuration context can then, according to one example, include security data associated with the security data. connection devices.
- the management equipment 200 sends to the terminal device 11 a configuration message comprising the identifier of the connection proxy device as well as the identifier of the network section conveying the data of the terminal device 11.
- the configuration message thus allows the terminal device 11 to exchange data with a service device.
- This information is used by the terminal device for the configuration of a connection profile to the network slice comprising the identifier of a connection proxy device and the identifier of the communication network slice.
- this profile can also include the identifiers of the connection devices involved in the routing of data on the network section if these are transmitted to the terminal device during step Eli.
- the equipment 200 for managing the terminal device 11 sends, to an entity 310 for managing a service device with which the device 11 is capable of communicating, a notification message comprising the identifier of the terminal device 11 and the identifier of the connection proxy device.
- the factory 20 notifies all of its industrial partners, including the partner 300, of information relating to the connection proxy devices, including the connection proxy device of the terminal device 11.
- the notification message includes a security setting (security protocol to be used to communicate with the connection proxy device, type of security key to be used for communication, encryption or not of the data exchanged with the connection proxy device, etc.) associated with any communication with the proxy device connection.
- This notification message also allows the plant 20 to notify a broker in the event that an external data space is implemented by the operator of the network 100.
- the management entity 310 saves the context by terminal device with information relating to the identifier of the terminal device, the identifier of the connection proxy device and possibly with the associated security parameter.
- Each industrial partner of the plant 20 and / or "external" broker notified in step E12 stores in their internal databases the information relating to the terminal device 11 received in step E1 2.
- the terminal device 11 sends to the entity 160 for attachment to the network 100 a message for attachment to the network 100.
- the message d The attachment comprises the identifier of the terminal device 11, the identifier of the network section and the identifier of the connection proxy device. This information is sufficient for the attachment entity 160 to respond to the attachment message.
- the identifier of the terminal device 11 can for example be obtained from the source address used to send the attachment message to the attachment entity 160.
- the attachment entity 160 verifies the information received from the terminal device 11. It verifies the validity of the attachment request by verifying the association of the identifier of the terminal device 11 with the identifier of the indicated network slice and the identifier of the transmitted connection proxy device. This verification is performed from a consultation of an internal database and from the data saved in step E6.
- the attachment entity 160 validates the association between the identifiers of the terminal device 11, of the identification of the network section and of the connection proxy device and sends to the device of the terminal device 11 a acceptance message. If the association is not valid, for example because there is no association between the identifiers received, the attachment entity 160 will transmit to the terminal device 11 a message of failure of the connection request. leaving for example the possibility of transmitting a new connection request.
- the terminal device 11 transmits data relating to one or more applications on the identified network section, to a service device via data transmission. This data exchange is possible once the terminal device 11 has attached itself to the attachment entity 160 of the network 100.
- the identifier of the terminal device 11 can be either an IP, IPv4 and / or IPv6 address, an FQDN identifier (in English "Fully Qualified Domain Name"), or any identifier allowing it to be recognized by the operator of the network 100 and the partner 300.
- the identifier of the network section can be any sequence of alphanumeric characters making it possible to be recognized by the entities involved in the configuration process.
- the identifier of a connecting device can be a Mac address, an IP address, an FQDN identifier or any string of alphanumeric characters.
- a device 80 for connecting a partner for example the partner 300 of [Fig 3]
- a request Req 1 which corresponds to a request for access to data relating to a device.
- Beta terminal of an Alpha company not shown in [Fig 4]
- the operator of a network must identify and collect various data corresponding to a network context relating to this terminal device.
- the request may consist in collecting the various data relating to a communication session between a terminal device and one or more service devices of a partner for which the connection device 80 sends the request Req 1.
- the proxy connection device 30 receives the request Req 1 during step F3.
- the proxy connection device 30 queries the database 400 (or “broker” internal to the communication network) by transmitting an Ident message to the database 400 in order to find out the connection devices of the network in charge of the context data relating to the request Req 1 and in particular the identifier of the connection device of the data plane terminating the network slice for the exchange of data between the terminal device Beta and the service device (s).
- the database 400 transmits back to the connection proxy device 30 identifiers of the connection devices 40, 50, 70.
- the proxy connection device 30 sends during a step F5 respective requests Req SRCig, Req SRCic and Req SRCis to the devices 40, 50, 70 for connecting the management, control, transfer (or data) plans. of the communication network.
- the Req SRCis request relates to the transfer plan and allows the terminal device Beta (sensor, machine, computer, etc.) to supply the data expected by the external connector 80.
- the Req SRCig and Req SRCic requests make it possible to retrieve network context data relating to the management plane and to the control plane.
- these are for example performance or alarm data for network equipment involved in the connectivity of the terminal device to the communication network.
- For the control plane this is, for example, data on the location, billing or the network attachment status of the terminal device.
- the number of requests sent to connection devices are saved, for example by a request aggregation module.
- the connection device 40 receives the Req SRCig request in step F8.
- the device 40 analyzes the request and identifies the information required by the proxy connection device 30 from the information on the terminal device Beta, the identifier of the network slot used for the transmission of data, or even the 'identifier of the service device with which the Beta terminal device exchanges data, and optionally a session identifier.
- the connection device 40 sends the identified data to the connection proxy device 30 in a response Rep SRCig.
- the devices 50 and 70 perform the tasks corresponding to the tasks F8 to F10 and transmit the data in Rep SRCic and Rep SRCis messages to the connection proxy device 30.
- Fe proxy connection device 30 receives and aggregates the data received during step F6 and optionally checks whether the number of responses received corresponds to the number of requests sent. From these aggregated data, the proxy connection device 30 establishes, during a step F7, a consolidated response comprising all the context information for the management, control and transfer plans for the data exchanged by the Beta terminal device on a section of the communication network with one or more service devices. It transmits this response Rep 1 to the connection device 80 of the partner who sent the request during step F1. The device 80 receives this response during step F2 and can thus use it.
- the device 80 has only requested the connection proxy device, possibly in a secure manner, without it knowing the various connection devices 40, 50, 70 involved in the management, control and routing of data.
- the configuration device 500 implements the configuration method, of which various embodiments have just been described.
- the configuration device 500 can be implemented in an implementation in a device of a communication network such as access equipment of a local network, such as a home gateway, a terminal or a device. router type.
- the device 500 comprises a processing unit 530, equipped for example with an mR microprocessor, and controlled by a computer program 510, stored in a memory 520 and implementing the counting method according to the invention.
- a computer program 510 stored in a memory 520 and implementing the counting method according to the invention.
- the code instructions of the computer program 510 are, for example, loaded into a RAM memory, before being executed by the processor of the processing unit 530.
- Such a device 500 comprises:
- a database 502 capable of storing a configuration context of the terminal device, the context comprising a set of identifiers of devices for connecting the terminal device to the communication network, one of the identifiers corresponding to an identifier of a proxy connection device capable of aggregating data relating to the terminal device coming from the other connection devices of the set, an identifier of the network section and an identifier of the terminal device,
- a transmitter 503 capable of transmitting to the terminal device a configuration message Conf comprising the identifier of the connection proxy device and the identifier of the network section.
- a configuration message Conf comprising the identifier of the connection proxy device and the identifier of the network section.
- Attachment device 600 implements the attachment method, various embodiments of which have just been described.
- the attachment device 600 can be implemented in a terminal, such as a sensor, industrial equipment (machine, control station, etc.) or any type of device capable of communicating with a communication network using a wired or wireless network.
- the device 600 comprises a processing unit 630, equipped for example with an mR microprocessor, and controlled by a computer program 610, stored in a memory 620 and implementing the counting method according to the invention.
- a computer program 610 stored in a memory 620 and implementing the counting method according to the invention.
- the code instructions of the computer program 610 are, for example, loaded into a RAM memory, before being executed by the processor of the processing unit 630.
- Such a device 600 comprises:
- a receiver 601 able to receive from a management equipment of the terminal device a configuration message Conf including an identifier of a connection proxy device and an identifier of the section of the communication network,
- a configurator 602 able to configure a connection profile to the network section comprising the identifier of the connection proxy device received and the identifier of the section of the communication network received
- a transmitter 603 capable of transmitting to an attachment entity of the communication network an Attachment message comprising an identifier of the terminal device, the identifier of the configured connection proxy device and the identifier of the section network configured.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR2006353A FR3111512A1 (fr) | 2020-06-18 | 2020-06-18 | Procédé de configuration d’un dispositif terminal |
| PCT/FR2021/051074 WO2021255382A1 (fr) | 2020-06-18 | 2021-06-15 | Procédé de configuration d'un dispositif terminal |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4169211A1 true EP4169211A1 (fr) | 2023-04-26 |
Family
ID=73038086
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP21737728.2A Pending EP4169211A1 (fr) | 2020-06-18 | 2021-06-15 | Procédé de configuration d'un dispositif terminal |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US12074758B2 (fr) |
| EP (1) | EP4169211A1 (fr) |
| FR (1) | FR3111512A1 (fr) |
| WO (1) | WO2021255382A1 (fr) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR3111512A1 (fr) * | 2020-06-18 | 2021-12-17 | Orange | Procédé de configuration d’un dispositif terminal |
| JP2024062162A (ja) * | 2022-10-24 | 2024-05-09 | キヤノン株式会社 | 通信装置、制御方法、プログラム、及びシステム |
| US20250286935A1 (en) * | 2024-03-09 | 2025-09-11 | Nutanix, Inc. | Reducing network traffic for zero-touch computing node initialization |
Family Cites Families (37)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CA2299824C (fr) * | 2000-03-01 | 2012-02-21 | Spicer Corporation | Systeme de controle des ressources d'un reseau |
| US7831693B2 (en) * | 2003-08-18 | 2010-11-09 | Oracle America, Inc. | Structured methodology and design patterns for web services |
| JP4267633B2 (ja) * | 2006-02-27 | 2009-05-27 | 株式会社日立製作所 | ネットワークシステム及びトラヒック情報集約装置 |
| US9197600B2 (en) * | 2011-09-29 | 2015-11-24 | Israel L'Heureux | Smart router |
| US9496971B2 (en) * | 2012-12-10 | 2016-11-15 | Qualcomm Incorporated | Techniques for determining actual and/or near states of proximity between mobile devices |
| US11468095B2 (en) * | 2015-08-06 | 2022-10-11 | Convida Wireless, Llc | Mechanisms for multi-dimension data operations |
| CN106455119B (zh) * | 2015-08-10 | 2022-02-25 | 北京三星通信技术研究有限公司 | 一种wlan聚合控制的方法和设备 |
| EP3439351A4 (fr) * | 2016-03-29 | 2019-03-13 | NTT DoCoMo, Inc. | Procédé de changement d'informations de tranche et système de communication |
| CN107277850B (zh) * | 2016-04-01 | 2022-04-19 | 北京三星通信技术研究有限公司 | 无线局域网聚合的控制方法和相关设备 |
| CN114900858A (zh) * | 2016-12-30 | 2022-08-12 | 英特尔公司 | 用于无线电通信的方法和设备 |
| CN109548175B (zh) * | 2017-08-15 | 2021-11-19 | 华为技术有限公司 | 一种会话处理方法及装置 |
| US10819148B2 (en) * | 2017-08-18 | 2020-10-27 | Google Llc | Smart-home device switching circuitry with integrated power stealing control |
| CN109511115B (zh) * | 2017-09-14 | 2020-09-29 | 华为技术有限公司 | 一种授权方法和网元 |
| WO2019117773A1 (fr) * | 2017-12-14 | 2019-06-20 | Telefonaktiebolaget Lm Ericsson (Publ) | Régulation de l'accès d'un terminal de communications à un réseau de communication |
| JP7107324B2 (ja) * | 2018-01-16 | 2022-07-27 | ソニーグループ株式会社 | 管理装置、通信制御装置、制御方法、及びプログラム |
| CN110324164B (zh) * | 2018-03-29 | 2020-10-16 | 华为技术有限公司 | 一种网络切片的部署方法及装置 |
| US11729782B2 (en) * | 2018-06-11 | 2023-08-15 | Apple Inc. | Enhanced uplink beam management |
| CN114826903A (zh) * | 2018-06-30 | 2022-07-29 | 华为技术有限公司 | 用于获取网络切片的方法、装置和系统 |
| WO2020124230A1 (fr) * | 2018-12-19 | 2020-06-25 | Conversant Intellectual Property Management Inc. | Système et procédé pour un service d'accès au réseau |
| US11792290B2 (en) * | 2019-01-04 | 2023-10-17 | Convida Wireless, Llc | Methods to enable automated M2M/IoT product management services |
| US11496475B2 (en) * | 2019-01-04 | 2022-11-08 | Ping Identity Corporation | Methods and systems for data traffic based adaptive security |
| US11902872B2 (en) * | 2019-01-23 | 2024-02-13 | Nokia Solutions And Networks Oy | Marking an uplink data packet |
| US11937132B2 (en) * | 2019-01-29 | 2024-03-19 | Apple Inc. | Fast return to 5G systems (5GS) after handover to evolved packet system (EPS) due to EPS fallback from 5GS |
| WO2020167820A1 (fr) * | 2019-02-12 | 2020-08-20 | Apple Inc. | Systèmes et procédés permettant de déployer une fonction de plan d'utilisateur (upf) et des fonctions de réseau virtualisées de calcul de bord (vnf) dans des réseaux d'environnement de virtualisation de fonctions de réseau (nfv) |
| US11950151B2 (en) * | 2019-02-13 | 2024-04-02 | Apple Inc. | Self-organizing networks (SON) for mobility robustness optimization (MRO) and automatic network slice creation |
| EP3900233A1 (fr) * | 2019-02-14 | 2021-10-27 | Apple Inc. | Procédés d'établissement de snr, d'es et de noc pour des exigences de performances nr |
| EP3925392B1 (fr) * | 2019-02-14 | 2024-01-10 | Apple Inc. | Procédés, appareil et media d'assurance d'équité dans un réseau de relais à sauts multiples |
| US12041476B2 (en) * | 2019-02-15 | 2024-07-16 | Apple Inc. | Inter-GNB exchange for intended UL/DL directions |
| WO2020168322A1 (fr) * | 2019-02-15 | 2020-08-20 | Apple Inc. | Indication de signal de référence de démodulation (dmrs) pour une transmission unique multipoint d'émission et de réception (trp) d'informations de commande de liaison descendante (dci) |
| WO2020172656A1 (fr) * | 2019-02-22 | 2020-08-27 | Apple Inc. | Système et procédé de réduction d'interruptions de transfert intercellulaire |
| US11483762B2 (en) * | 2019-02-22 | 2022-10-25 | Vmware, Inc. | Virtual service networks |
| WO2020198713A1 (fr) * | 2019-03-27 | 2020-10-01 | Apple Inc. | Indication d'information d'assistance pour sélection d'outil de technologies d'accès radio et d'interface pour véhicule à tout (v2x) de nouvelle radio |
| US11568305B2 (en) * | 2019-04-09 | 2023-01-31 | Genesys Telecommunications Laboratories, Inc. | System and method for customer journey event representation learning and outcome prediction using neural sequence models |
| CN112448831B (zh) * | 2019-08-30 | 2022-04-12 | 华为技术有限公司 | 一种网络管理的方法及设备 |
| CN116193431B (zh) * | 2020-04-30 | 2025-06-06 | 华为技术有限公司 | 切片认证方法及装置 |
| FR3111512A1 (fr) * | 2020-06-18 | 2021-12-17 | Orange | Procédé de configuration d’un dispositif terminal |
| US11778514B2 (en) * | 2021-09-20 | 2023-10-03 | T-Mobile Innovations Llc | Data router connectivity to wireless communication slices |
-
2020
- 2020-06-18 FR FR2006353A patent/FR3111512A1/fr not_active Ceased
-
2021
- 2021-06-15 US US18/002,111 patent/US12074758B2/en active Active
- 2021-06-15 WO PCT/FR2021/051074 patent/WO2021255382A1/fr not_active Ceased
- 2021-06-15 EP EP21737728.2A patent/EP4169211A1/fr active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| US20230308346A1 (en) | 2023-09-28 |
| FR3111512A1 (fr) | 2021-12-17 |
| US12074758B2 (en) | 2024-08-27 |
| WO2021255382A1 (fr) | 2021-12-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11876637B2 (en) | System and method for providing network support services and premises gateway support infrastructure | |
| CN109039772B (zh) | 管理直接网络对等操作的接口 | |
| EP4169211A1 (fr) | Procédé de configuration d'un dispositif terminal | |
| EP3676992B1 (fr) | Procédé de taxation de données d'une application acheminées sur une tranche d'un réseau de communication | |
| Qarawlus et al. | Demonstration of data-sovereign telemetry broker for open and disaggregated optical networks | |
| AU2017206220B2 (en) | Interfaces to manage direct network peerings |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20230110 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20250305 |