EP4409864A1 - Procédé de controle d'un accès à un service applicatif mis en oeuvre dans un réseau de télécommunications, procédé de traitement d'un message de controle d'un accès audit service applicatif, dispositifs, équipement de controle, équipement client, système et programmes d'ordinateur correspondants - Google Patents
Procédé de controle d'un accès à un service applicatif mis en oeuvre dans un réseau de télécommunications, procédé de traitement d'un message de controle d'un accès audit service applicatif, dispositifs, équipement de controle, équipement client, système et programmes d'ordinateur correspondantsInfo
- Publication number
- EP4409864A1 EP4409864A1 EP22793193.8A EP22793193A EP4409864A1 EP 4409864 A1 EP4409864 A1 EP 4409864A1 EP 22793193 A EP22793193 A EP 22793193A EP 4409864 A1 EP4409864 A1 EP 4409864A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- service
- equipment
- access
- processing
- control
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/1066—Session management
- H04L65/1069—Session establishment or de-establishment
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/16—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/50—Network service management, e.g. ensuring proper service fulfilment according to agreements
- H04L41/5003—Managing SLA; Interaction between SLA and QoS
- H04L41/5009—Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/22—Alternate routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/10—Architectures or entities
- H04L65/1016—IP multimedia subsystem [IMS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/1066—Session management
- H04L65/1101—Session protocols
- H04L65/1104—Session initiation protocol [SIP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/14—Session management
- H04L67/141—Setup of application sessions
Definitions
- TITLE Process for controlling access to an application service implemented in a telecommunications network, process for processing a control message for access to said application service, devices, control equipment, client equipment, system and corresponding computer programs.
- the invention lies in the field of telecommunications, and in particular in that of telephony over IP.
- the invention relates to the control of access by client equipment to an application service implemented in a telecommunications network.
- VoIP Voice over IP
- IP protocol for "Internet Protocol”
- IP Telephony must meet customer needs, particularly from the point of view of service quality and availability, which must be at least equivalent to those provided by traditional telephony offers based on the PSTN network.
- PSTN Switched Telephone Network
- quality of service, robustness, high availability and resistance to failures are determining factors for users of telephone services, which are by nature real-time stream exchange services.
- Telecommunications operators, who will also be called service providers, must particularly avoid the phenomena of overloading the elements making up the service and anticipate the anomalies which may disrupt the service as perceived by the customers.
- overload means the inability of the service, or of certain elements of this service, to process a request to establish an application session, for example an audio, video or instant messaging IM call (or "Instant Messaging”, in English), often because of a lack of resources to process said request.
- IM call or "Instant Messaging”, in English
- the management of overloads is all the more delicate as the phenomenon tends to maintain itself. Indeed, the problem of overload is likely to gradually affect the elements of the service involved in the call setup procedure, and which are still trying to clear the traffic: these elements are therefore in turn affected by an overload. of traffic.
- the dimensioning of telephone networks is based in particular on a statistical distribution of calls, governed by Erlang's laws in particular.
- this type of dimensioning does not make it possible to deploy a service that can cope with occasional traffic overloads.
- the origin of a bottleneck at the level of a service platform can be linked to at least two specific situations:
- This type of situation can generate a large number of sessions made to the number in question over a relatively short period, which causes congestion that degrades the quality of service provided as perceived by users.
- IP telephony services The engineering of IP telephony services is essentially based on adequate sizing (including oversizing) to respond to requests for access to the service by customers who have subscribed to the service. They also rely on load sharing mechanisms to limit the risk of overload. However, experience has shown that these engineering choices, while suitable for nominal operational operation, are much less suitable for responding to sudden load peaks caused by exceptional events or behavior. unplanned element of service (e.g. partial software failure that results in random session loss).
- a simple practice implemented today consists of informing customers of the presence of an overload situation in the process of being resolved. This can be done by sending, for example, an error code during an attempt to set up a call, for example according to the SIP protocol, or by real-time communication for the Web or WebRTC (or "Web Real Time Communication”.
- This error code specifies the problem encountered.
- the RFC 3261 document defines the "503" response code which must be transmitted by a service element in an overload situation to any client equipment or user agent UA (for "User Agent", in English) who requested this item.
- Sending a SIP error message with this code means that the requested service element is unable to process the request following a temporary overload or a maintenance operation.
- the service element in question may on this occasion indicate a period after which the client can make a new attempt (thanks to the "Retry-After" header).
- a UA client receiving such a response code is expected to solicit another element of the service to fulfill its request, at least until the expiration of the "Retry-After” time (if indicated) and if the possibility of contacting another element of service is offered to him.
- a procedure for determining such a time limit is difficult to establish. The implementation of such a procedure by the congested service element even risks aggravating the situation and keeping it in a state of permanent overload.
- FIG. 1 shows an exchange of messages which takes place between an agent UA1 of the user and a service element PS, of the relay element type (or “proxy server”).
- UA1 sends an INVITE type request to establish a call to PS.
- PS Public Switched Telephone Network
- PS Public Switched Telephone Network
- PS Public Switched Telephone Network
- Another known practice consists of sending congestion or overload notifications in SIP messages of the OPTIONS or NOTIFY type.
- a common characteristic of these practices is the involvement of the congested service element in the resolution, notification and management of the overload situation.
- both have a number of limitations.
- An alternative consists in the addition by the elements of the service of an information field dedicated to the processing of congestion/overload phenomena.
- the objective of this alternative is to provide a better qualification of the state of congestion and to minimize the approximations of the mechanisms described previously. It is based on a dedicated SIP header, called "CONGESTION", which can be inserted into any SIP response.
- CONGESTION a dedicated SIP header
- RFC7339 defines different control methods and associated algorithms. It describes in particular how an overloaded service element can indicate to the other service elements which request it to reduce the number of messages that they send to it so that they regulate the incoming requests in the event of overload. To do this, SIP parameters dedicated to load management and called “oc” (for "overload control”, in English), “oc-algo”, “oc-validity”, and “oc-seq” have been defined to include various information to characterize the rate and conditions of the overload.
- oc for "overload control", in English
- oc-algo for "oc-validity"
- oc-seq have been defined to include various information to characterize the rate and conditions of the overload
- elements other than the service platform involved in the implementation of the service suffer failures or encounter anomalies.
- Such elements are, for example, border elements which relay messages for establishing application sessions between the user terminals and the service platform. These sessions are supported by service access networks through which user agents transmit service access requests, or interconnecting elements to other networks (e.g., PSTN interconnect or PLMN (Public Land Mobile Network).
- PSTN interconnect or PLMN (Public Land Mobile Network).
- PLMN Public Land Mobile Network
- the invention proposes a mechanism making it possible to manage such a situation.
- the invention meets this need by proposing a method for controlling access by at least one client equipment to an application service in a telecommunications network, said at least one client equipment being configured to access said application service, said method comprising :
- the invention proposes a completely new and inventive approach to the management of a situation of overload or failure suffered by a system for implementing an application service in a telecommunications network. It consists of observing the operation of the service equipment of this system by collecting information relating to message processing events exchanged during access to this service at the level of this equipment, and, in the event of an anomaly detected with to one or more given service execution criteria, to decide on one or more control actions for the processing of at least one request for access to the service by said client equipment.
- the control action has the effect of modifying an initial network configuration made when the client equipment is started.
- it comprises for example one or more parameters for controlling the processing of a request for access to the service by the client equipment.
- the invention applies to client equipment already configured to access the service and which already has access to it.
- the mechanism for controlling the processing of a request for access to the application service by the client equipment according to the invention therefore differs from an initial configuration procedure of a client equipment intended to enable it to access the service.
- processing anomalies that could induce a crisis/overload situation and impact the proper execution of the service as defined by the said criteria are managed in anticipation, at the source of requests for access to the service and outside the system, without impacting the equipment of the service core (or service platform).
- execution criteria generic to the various services and/or specific to the service considered are defined and taken into account, and used to detect processing anomalies such as deviations from nominal operating conditions, which makes it possible to make a relevant decision on the most appropriate control action(s).
- control actions are intended for the client equipment themselves so as to act as close as possible to the source of the requests for access to the service while minimizing the impact on the operation of the heart of the system.
- This makes it possible to modify the way in which they process a service access request or an application session establishment message and offers many more adjustment possibilities than a simple random filtering of traffic at the entrance to the service platform, as proposed by the prior art.
- the invention makes it possible to adapt the control carried out on the client equipment.
- control action includes a configuration parameter of the client equipment so that the latter modifies its initial configuration.
- the invention relies on known signaling mechanisms already used for providing the service, without requiring any particular extension.
- a network equipment configuration management protocol such as NETCONF or RESTCONF can be used.
- NETCONF network equipment configuration management protocol
- RESTCONF RESTCONF
- a protocol relies on the XML language to code the configuration data as well as the messages of the protocol.
- a data modeling language such as YANG can be used, by defining a dedicated YANG module.
- the invention applies to any type of application service, but it is particularly advantageous in the case of a telephony service over IP, in particular when it is faced with a situation of the “Flash Crowds” type.
- said method comprises the prior learning of a classification model of a system for automatically detecting said processing anomaly from a learning set comprising processing events previously labeled with the aid of at least two classes comprising an anomaly presence class and an anomaly absence class and said detection of an anomaly is carried out by said system from the information of processing events obtained for one or more service equipment involved in the implementation of the service considered, said system producing as output one of the at least two classes.
- such a system implements a classification model determined using artificial intelligence techniques such as machine learning to collect and classify the observed data and an algorithm (such as reinforcement learning) to assist decision-making relating to the handling of the crisis situation.
- artificial intelligence techniques such as machine learning to collect and classify the observed data
- algorithm such as reinforcement learning
- One advantage is to determine an optimal operating situation of a service equipment item or of a set of service equipment items to render the service considered.
- said control action belongs to a group comprising at least:
- a control action of a replacement number of the telephone number associated with the service requested by said client equipment - an action of controlling a priority of the service, comprising the configuration of priority levels assigned to the requested services and to the other services which said client equipment can access;
- One advantage is that the adjustment of the configuration of the service equipment and/or of the client equipment proposed by the invention makes it possible to regulate, redirect, or even prioritize the traffic according to the service requested.
- said control action comprises configuring at least one telephone number, called an alias number, to replace a telephone number. telephone associated with the service.
- an alias number makes it possible to access the switchboard via another network route.
- the objective is for the service to be provided for all access requests received by the system.
- An advantage of the invention is to allow the configuration of another telephone number through which the emergency center, although saturated on its main telephone number, can still be reached. This configuration is transparent for the user who can continue to dial the usual telephone number and does not even realize that his request has been redirected.
- the invention thus proposes a reliable solution for managing an overload peak at the level of an application service, in particular a public safety call center (for "Public Safety Answering Point", in English), without requiring a user in a state of extreme stress to consult a social network to find out about an alternative telephone number set up by the service operator, for example.
- a public safety call center for "Public Safety Answering Point", in English
- said control action comprises the automatic programming of an announcement server of a replacement telephone number of a destination telephone number.
- a destination telephone number e.g. associated with the switchboard, an emergency centre, an international call
- the programming server announces to the user the replacement number to dial.
- said at least one service execution criterion comprises a telephone communication establishment failure rate equal to zero and a telephone communication establishment delay less than a predetermined threshold.
- the invention also relates to a device for controlling access by at least one client equipment to an application service in a telecommunications network, said at least one client equipment being configured to access said application service, said device being configured to implement work :
- said device configured to implement the steps of the access control method as described previously.
- said device is integrated into a control equipment of at least one service equipment involved in the implementation of an application service in a telecommunications network.
- control equipment is included in a system for implementing an application service in a telecommunications network, said system comprising a plurality of service equipment involved in the implementation of said service.
- the system, the control equipment and the control device have at least the same advantages as those conferred by the aforementioned control method.
- the invention also relates to a method for processing a control message for access to an application service involving at least one service device in a telecommunications network, said method being executed by a client device configured to access said application service, said method comprising:
- control message comprising at least one control action of a processing of at least one request for access to said service by said client equipment
- control equipment acts on the client equipment so as to adjust the way in which it processes the requests for access to the application service. It thus intervenes at the source so as to correct without delay the operating anomalies observed at the level of one or more service equipment constituting the system for implementing the application service.
- the execution of the action includes:
- the client equipment performs this replacement in the “Request URI” field of the “To” header of the service access request.
- An advantage of making this change at the client device level is that the headers are not yet encrypted. Indeed, commonly, service equipment uses protocols for encrypting certain message headers or certain information fields contained in these headers.
- the invention also relates to a device for processing a message controlling access to an application service involving at least one service device in a telecommunications network, said device being intended to be executed by a client device configured to access said application service, said device being configured to implement:
- control message coming from a control equipment of said telecommunications network, said control message comprising at least one control action of a processing of at least one request for access to said service by said customer equipment, and
- said device configured to implement the steps of the method for processing an access control message as described previously.
- the system, the client equipment and the processing device have at least the same advantages as those conferred by the aforementioned control method.
- the invention also relates to computer program products comprising program code instructions for implementing the methods as described previously, when they are executed by a processor.
- a program may use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in partially compiled form, or in any other desirable form.
- the invention also relates to a recording medium readable by a computer on which is recorded a computer program comprising program code instructions for the execution of the steps of the methods according to the invention as described above.
- Such recording medium can be any entity or device capable of storing the program.
- the medium may include a storage medium, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or else a magnetic recording medium, for example a mobile medium (memory card) or a hard drive or SSD.
- such a recording medium may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means, so that the program computer it contains is executable remotely.
- the program according to the invention can in particular be downloaded on a network, for example the Internet network.
- the recording medium may be an integrated circuit in which the programs are incorporated, the circuit being adapted to execute or to be used in the execution of the aforementioned methods.
- the present technique is implemented by means of software and/or hardware components.
- the term "module" may correspond in this document to a software component, a hardware component or a set of hardware and software components.
- a software component corresponds to one or more computer programs, one or more sub-programs of a program, or more generally to any element of a program or software capable of implementing a function or a set of functions, as described below for the module concerned.
- Such a software component is executed by a data processor of a physical entity (terminal, server, gateway, set-top-box, router, etc.) and is likely to access the hardware resources of this physical entity (memories, recording media, communication bus, electronic input/output cards, user interfaces, etc.).
- resources means all sets of hardware and/or software elements supporting a function or a service, whether unitary or combined.
- FIG. 1 figure 1 (already described) schematically illustrates an example of notification of an overload state by a service equipment involved in the implementation of an application service to a client equipment which wishes to access in the service, according to the prior art;
- FIG. 2 schematically illustrates an example of architecture of a system for implementing an application service in a telecommunications network accessed by client equipment according to one embodiment of the invention ;
- FIG. 3 details an example of the structure of control equipment of such a system and of client equipment according to one embodiment of the invention
- FIG. 4 schematically illustrates an example of architecture of a system for implementing an application service according to another embodiment of the invention
- FIG. 5 describes in the form of a flowchart the steps of a method for controlling access to an application service implemented in a telecommunications network, according to an exemplary embodiment of the invention ;
- FIG. 6 describes in the form of a flowchart the steps of a method for processing a message for controlling access to an application service implemented in a telecommunications network, according to an example of carrying out the invention
- FIG. 7 schematically illustrates an example of nominal operation of the application service
- FIG. 9 schematically illustrates an example of control performed on client equipment according to one embodiment of the invention
- FIG. 10 describes an example of the hardware structure of a device for controlling access to an application service according to the invention.
- FIG U Figure 11 describes an example of hardware structure of a device for processing a control message according to the invention.
- the general principle of the invention is based on the control of access by at least one client equipment to an application service implemented by a system comprising a plurality of service equipment in a telecommunications network.
- This control is based on obtaining event information relating to the processing by at least one of the service equipment of the system, of messages exchanged within the framework of the implementation of said application service, the detection, from information obtained, of a processing anomaly by said service equipment with respect to at least one given service execution criterion, and the transmission of at least one control message comprising at least one control action of a processing of said at least one request for access to said service by said client equipment.
- the invention applies to any type of application service which is accessed by establishing an application session between a requesting client device and such a system, for example an audio, video or instant messaging IM call.
- equipment or service element will designate without distinction any element requested for the provision of a service (and in particular for the establishment of an application session).
- Such an item of equipment or element can be involved in the exchange of control messages (for example using the SIP protocol), the exchange of payload data (for example using the RTP protocol), or even both.
- the implementation of a service may involve one or more service elements.
- the order of invocation of service elements can be static and service-specific (e.g. conforming to the IMS architecture) or be established on demand (e.g. achieved using a chaining technique). service).
- a service element can be implemented in software and/or hardware.
- One or more service elements can be embedded in the same physical equipment.
- FIG. 2 schematically illustrates an example of the architecture of a system S for the implementation of an IP telephony service deployed by a service provider in a telecommunications network RT, according to an embodiment of the invention.
- a client device or user agent UA or “User Agent”, in English
- This user agent can also be embedded in a CPE (or “Customer Premises Equipment”) user terminal. It is typically any equipment installed at or carried by the user to create, route or terminate a communication between the user and the system of the operator or the service provider, for example a residential or professional gateway (or “gateway", in English) or a smart phone (or “smartphone", in English).
- the UA can also be integrated into dedicated equipment.
- the latter generally embeds a relay equipment (or “proxy server”, in English), not represented.
- the client equipment UA, CPE accesses the network RT via an access network AN, for example of the cellular radio, fiber or ADSL type.
- an access network AN for example of the cellular radio, fiber or ADSL type.
- System S in Figure 2 includes the following elements:
- SBE Session Border Element
- DBE Data Border Element
- SBE element is responsible for processing signaling messages
- DBE element is responsible for processing media streams.
- P-CSCF Proxy-call/session control function
- BGF Border Gateway Function
- SBC Session Border Controller
- these SBE/DBE elements When these SBE/DBE elements are directly connected to the UAs, they are the contact points of the system implementing the service. In this configuration, the UAs have no visibility of the internal structure of a PFC core platform for implementing the service. These elements can also be used for interconnection requirements with other domains (identified by “RLM# r” in FIG. 2, with r an integer between 2 and 5). These areas can be other IP telephony domains, another telecommunications network such as the PSTN network or a mobile network, etc.
- the PFC core platform composed of elements called CF (“Core Functions”) located in the CN core network, not shown.
- CF Core Functions
- the invention can be used generally independently of the architecture of the underlying service, which is for example an IMS (or “IP Multimedia Subsystem”) architecture or any other future architecture. No assumption is made as to the nature of the CFs, their number, or the invocation sequencing of these CFs for the establishment of an application session.
- the system S also comprises a control equipment, or controller CTR, configured to control the service equipment and the client equipment UA, CPE.
- a control equipment or controller CTR, configured to control the service equipment and the client equipment UA, CPE.
- This is for example an SDN (or “Software-Defined Networking”) controller, as illustrated in Figure 3. It is responsible for the management and configuration of service elements.
- the NETCONF or RESTCONF protocols are used as an example to manage and configure these elements, but other protocols can be used.
- the control equipment CTR comprises a device 100 for controlling access by at least one client equipment to an application service in a telecommunications network, said at least one client equipment being configured to access said application service. It is configured to obtain event information relating to the processing by at least one service equipment involved in the implementation of the application service, of messages exchanged during at least one access to said application service, to detect, from the information obtained, a processing anomaly by at least one said service equipment with respect to at least one given service execution criterion; and transmitting at least one control message comprising at least one control action for the processing of at least one access request to said service by said client equipment.
- the device 100 thus implements the method for controlling access to the service according to the invention which will be detailed below in relation to FIG. 5.
- the device 100 can be independent of the control equipment, but connected to the latter by any link, wired or not.
- the device 100 can be integrated with other equipment of the telecommunications network, for example a service equipment.
- controllers can be deployed, as shown in Figure 4.
- a first controller is responsible for the service provider's service elements, while a second controller is used for managing client equipment (UA, CPE ).
- client equipment U, CPE
- the client equipment UA, CPE comprises a device 200 for processing a control message for access to the application service involving at least one service equipment in the telecommunications network RT.
- This device 200 is configured to receive a control message coming from the control equipment of the telecommunications network, said control message comprising at least one action for controlling processing of at least one request for access to said service by said client equipment, and performing the control action when processing said request.
- the device 200 thus implements the method for processing an access control message to the application service according to the invention which will be detailed below in relation to FIG. 6.
- FIG. 5 in the form of a flowchart, an example of implementation of a method for controlling access to an application service by at least one client equipment, according to an embodiment of the invention.
- this method is implemented by the aforementioned device 100.
- event information relating to the processing by at least one service equipment involved in an implementation of the application service, of messages exchanged during at least one access to said application service is obtained.
- control device 100 receives this information (directly or indirectly) from the service equipment that it controls. They reflect the status of such service equipment.
- a memory M1 structured or not.
- a memory is organized in the form of a database and indexed by an identifier of the service equipment concerned by the information or information received.
- the format of the notifications comprising this information is defined using a data modeling language.
- a data modeling language for modeling data which can be conveyed for example in messages of the NETCONF or RESTCONF protocols.
- It is a modular language representing data structures in an XML tree format.
- the data modeling language comes with a number of built-in data types. Other application-specific data types can be derived from the built-in data types.
- the data types of the information received from the service equipment by the control equipment can be specified in a dedicated Yang module. This processing event information may or may not be solicited.
- the solicited responses are responses to explicit requests such as GET requests sent by the control device 100, whereas the unsolicited responses are typically notifications sent by a service equipment without a specific request having been sent.
- NETCONF/RESTCONF notifications are examples of unsolicited responses.
- notifications can be generated based on filters maintained locally by this service equipment. These notifications may consist of informing the controller:
- a failure rate for establishing application sessions to a specific destination or service e.g., a server identified by an IP address, a website, an E.164 number, or a SIP alias
- a specific destination or service e.g., a server identified by an IP address, a website, an E.164 number, or a SIP alias
- a response time i.e., time between the time of sending a request and the time of receiving a corresponding response
- a processing anomaly by at least one said service equipment item is detected on the basis of the information obtained and with respect to at least one given service execution criterion.
- anomalies at the level of the service can also be detected in addition to anomalies at the level of a service equipment.
- a first criterion can be a call session establishment failure rate equal to zero and a call establishment time of less than one minute, for example. .
- This or these given execution criteria contribute to defining a nominal operation of the service and also of the service equipment involved and the detection of an anomaly according to the invention comprises the detection of at least one operating deviation of said at least one equipment service compared to nominal operation.
- the method comprises learning a classification model of an automatic decision system from a learning set comprising processing event information previously labeled using at least two classes comprising an anomaly presence class and an anomaly absence class and the detection is carried out by the decision system which takes as input the processing event information obtained for one or more service equipment involved in the setting implementation of the service considered and outputs a decision of detected anomaly or no anomaly detected.
- learning implements machine learning techniques ML (or “Machine Learning”) and feeds the calculation logic of the device 100 and determines the classification model.
- the detection of anomalies can be done by service equipment, for the plurality of service equipment involved in the implementation of the service considered, for the service equipment associated with the same global PFC core platform with several services , etc.
- an anomaly decision can be taken on the basis of an accumulation of processing anomalies detected at the level of different service equipment.
- a decision to order the execution of at least one action for controlling a processing of at least one request for access to said service by at least one client equipment UA, CPE is taken.
- control device 100 decides to proceed:
- This number can optionally be defined by range of telephone numbers, typically a larger number can be defined for emergency calls than for other application services;
- Announcement Server an announcement server which makes it possible to announce replacement numbers when the UA calls the abbreviated number of the service
- control actions are intended for client equipment which requests access to the application service, but that they can also be ordered from service equipment, in particular edge equipment (SBE). This is particularly the case for the action of prioritizing certain telephone numbers by setting up dedicated filters.
- SBE edge equipment
- control device 100 can decide, in order to allow the restarting of an application service without the latter being collapsed by the traffic peaks immediately after the restart, to act on the spreading out of the processing of requests establishment of application sessions sent by a UA and/or on the establishment of the relay by edge equipment an SBE/DBE and/or on the redirection of requests to an announcement server, etc.
- At least one control message comprising at least one control action is transmitted to one or more client equipments UA, CPE.
- FIG. 6 there is now presented, in relation to FIG. 6, in the form of a flowchart, an example of implementation of a method for processing a message for controlling access to an application service involving at least one service equipment in a telecommunications network.
- this method is implemented by the aforementioned device 200, integrated into a client equipment UA, CPE configured to access said application service.
- a control message MC is received from a control equipment CTR of said telecommunications network, said control message comprising at least one control action AC of a processing of at least one request for access to said service by said customer equipment. For example, it saves the control action received in a memory M2.
- the device 200 modifies its initial configuration to take into account the control action received.
- the device 200 saves this number alias in a memory and modifies its procedure so as to systematically replace the telephone number associated with the service with this alias.
- the actions are for example defined using regular expressions (“regexp”).
- this action of the UA is transparent for the user and it is immediately executed. Having this action performed by the UA is particularly advantageous in the case of the use of encryption protocols (and the "sips" URI) by the service equipment, because it takes place at the source, therefore before the encryption is carried out ).
- a nominal configuration for a given destination for example an emergency call center located in a destination domain, for example the IP domain RLM#5 and associated to a telephone number, for example the abbreviated number 18.
- a destination domain RLM#5 can also be reached with another telephone number, called an alias.
- a call sent by the client equipment UA, CPE is routed to the call center under nominal operating conditions. In other words, the application session is successfully established within a period of less than a maximum authorized period.
- FIG. 8 illustrates an example of failure to establish an application session requested by the client equipment UA, CPE. It is assumed that the access control method according to the invention implemented by the control equipment CTR has detected an operating failure of an edge equipment SDE5/DBE5, more precisely of interconnection between the core network CN and the RLM#5 IP domain. This failure impacts the implementation of one or more application services, whose call management center is located in this IP domain.
- control equipment transmits a control message to the client equipment UA, CPE.
- This message includes a control action which consists of configuring a list of aliases associating an alias number with the telephone number of each of the services concerned.
- the client equipment UA, CPE modifies its initial configuration so as to use this list to automatically rewrite the "Request URI" (and "To") field of any establishment request an application session to access one of these services, replacing the telephone number associated with the requested service with its alias.
- the call can be routed successfully via the neighboring RLM#4 IP domain.
- Said list of aliases can also be associated with a validity date beyond which it is automatically deleted from the memory of the UA, CPE unless a control action is received with a date update request. validity on another date, later or earlier depending on the speed with which the malfunction is corrected.
- the processing control of an access to the service can also be carried out by the control equipment CTR at the level of the CPE of the user or of the edge equipment SBE1 located in the access network AN.
- the controller configures the CPE or SBE1 with a list of aliases. This list is used by the edge equipment SBE1 to carry out the rewriting of the “Request URI” (and “To”) field of the request to establish an application session.
- the emergency call can be successfully routed through the neighboring RLM#4 IP domain.
- the redirection of all or part of the traffic to the requested destination as implemented according to the invention also makes it possible to reduce the processing load of the faulty service equipment and facilitates the conduct of maintenance operations such as a restart For example.
- an electronic voting service Each voter is invited to submit his vote (on the occasion of a television program or an election, for example) by accessing a website.
- the vote validation procedure is based on an acknowledgment mechanism which consists of sending the voter a message confirming that the vote has been taken into account (and that it complies with the electoral rule, if applicable).
- the submission of such a vote may be subject to strong time constraints, liable to cause a traffic overload at the level of several network resources. These include those of the network used to route the votes, those of the server equipment intended to receive and count the votes, those of the acknowledgment system mentioned above, or any combination of these resources. .
- the invention is based on processing devices 200 embedded in client equipment, user agents UA or CPE or even in other equipment typically located at the periphery of the network, such as routers of the network of access, core network routers, voting site access equipment or server equipment in charge of processing the votes.
- These devices 200 are configured to receive control actions decided and transmitted by a control device 100 as previously described, for example embedded in a control equipment CTR of the network. Such control actions are aimed at smoothing the flow of traffic.
- a traffic conditioning function based for example on a token bucket algorithm (as long as there are tokens in the bucket, the traffic can be routed, when there are no more tokens , the traffic can be stored in a queue (for the time that the volume of traffic falls below the 70% threshold) or else be redirected on another uncongested path but allowing the vote processing site to be reached ),
- voting traffic is initially tagged with DSCP AF12 (meaning the traffic is stored in a particular queue) and then re-tagged as AF11 or Best Effort (DSCP set to zero) , when traffic has reached the 70% threshold cited as an example,
- the policy for assigning metrics to interfaces is generally a least cost policy which takes account of the bandwidth associated with each interface. For example, a 10 Gbit/s interface is assigned a metric of 1 while a 100 Mbit/s interface is assigned a metric of 100.
- the metric of the corresponding interfaces could be increased, for example, to 200.
- the dynamic routing protocol will select paths at the lowest cost, for example, a path passing through the interface at 100 Mbit/s,
- control actions make it possible to prevent any risk of overloading the server equipment configured to receive the votes, in particular.
- These control actions are executed by certain network elements (even CPE client devices) according to information that can be conveyed in messages conforming to the PCEP protocol (or “Path Computation Element Protocol”) for the establishment of new routes, for example.
- the invention thus makes it possible to anticipate a context of overload and to streamline both the vote submission messages and the acknowledgment messages.
- a device 100 for controlling access by at least one client equipment to an application service in a telecommunications network said at least one client equipment being configured to access said application service
- said device comprising a module for obtaining event information relating to the processing by at least one service equipment involved in an implementation of the application service, of messages exchanged during at least one access to said application service, a module for detecting, from the information obtained, a processing anomaly by at least one said service equipment with respect to at least one given service execution criterion; and a module for transmitting at least one control message comprising at least one action for controlling processing of at least one request for access to said service by said client equipment.
- module can correspond both to a software component and to a hardware component or a set of hardware and software components, a software component itself corresponding to one or more computer programs or sub-programs or in a more general to any element of a program capable of implementing a function or a set of functions.
- such a device 100 comprises a random access memory 103 (for example a RAM memory), a processing unit 102 equipped for example with a processor, and controlled by a computer program Pgl, representative of the modules for obtaining, detection and transmission, stored in a read only memory 101 (for example a ROM memory or a hard disk).
- a read only memory 101 for example a ROM memory or a hard disk.
- the code instructions of the computer program are for example loaded into the random access memory 103 before being executed by the processor of the processing unit 102.
- the random access memory 103 can also contain the information of event obtained.
- FIG. 10 only illustrates one particular way, among several possible, of making the device 100 so that it performs the steps of the method for controlling access to the service as detailed above, in relation to FIG. 5, in its various embodiments.
- a reprogrammable calculation machine a PC computer, a DSP processor or a microcontroller
- a program comprising a sequence of instructions
- a dedicated calculation machine for example a set of logic gates such as an FPGA or an ASIC, or any other hardware module
- the corresponding program (that is to say the sequence of instructions) could be stored in a removable storage medium (such as for example an SD card , a USB key, a CD-ROM or a DVD-ROM) or not, this storage medium being partially or totally readable by a computer or a processor.
- a removable storage medium such as for example an SD card , a USB key, a CD-ROM or a DVD-ROM
- a device 200 for processing an access control message to an application service involving at least one service equipment item in a telecommunications network comprising a module for receiving a control message from a control device of said telecommunications network, said control message comprising at least one control action for processing at least one access request to said service by said client equipment, and a module for executing the control action during the processing of said request.
- module can correspond both to a software component and to a hardware component or a set of hardware and software components, a software component itself corresponding to one or more computer programs or sub-programs or in a more general to any element of a program capable of implementing a function or a set of functions.
- such a device 200 comprises a random access memory 203 (for example, a RAM memory), a processing unit 202 equipped for example with a processor, and controlled by a computer program Pg2, representative of the reception modules and execution, stored in a read only memory 201 (for example, a ROM memory or a hard disk).
- a random access memory 203 for example, a RAM memory
- a processing unit 202 equipped for example with a processor
- a computer program Pg2 representative of the reception modules and execution
- a read only memory 201 for example, a ROM memory or a hard disk.
- the code instructions of the computer program are for example loaded into the random access memory 203 before being executed by the processor of the processing unit 202.
- the random access memory 203 can also contain the action of control received in the control message.
- FIG. 11 only illustrates one particular way, among several possible, of making the device 200 so that it performs the steps of the method for processing a message for controlling access to an application service as detailed above, in relation to FIG. 6, and in its various embodiments. Indeed, these steps can be carried out either on a reprogrammable calculation machine (a PC computer, a DSP processor or a microcontroller) running a program comprising a sequence of instructions, or on a dedicated calculation machine (for example a set of logic gates such as an FPGA or an ASIC, or any other hardware module).
- a reprogrammable calculation machine a PC computer, a DSP processor or a microcontroller
- a dedicated calculation machine for example a set of logic gates such as an FPGA or an ASIC, or any other hardware module.
- the corresponding program (that is to say the sequence of instructions) can be stored in a removable storage medium (such as for example an SD card , a USB key, a CD-ROM or a DVD-ROM) or not, this storage medium being partially or totally readable by a computer or a processor.
- a removable storage medium such as for example an SD card , a USB key, a CD-ROM or a DVD-ROM
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Multimedia (AREA)
- General Business, Economics & Management (AREA)
- Business, Economics & Management (AREA)
- Software Systems (AREA)
- Medical Informatics (AREA)
- Evolutionary Computation (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Databases & Information Systems (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Artificial Intelligence (AREA)
- Telephonic Communication Services (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR2110174A FR3127663A1 (fr) | 2021-09-27 | 2021-09-27 | Procédé de contrôle d’un accès à un service applicatif, procédé de traitement d’un message de contrôle d’un accès audit service, dispositifs, système et programmes d’ordinateur correspondants. |
| PCT/FR2022/051802 WO2023047068A1 (fr) | 2021-09-27 | 2022-09-26 | Procede de controle d'un acces a un service applicatif mis en œuvre dans un reseau de telecommunications, procede de traitement d'un message de controle d'un acces audit service applicatif, dispositifs, equipement de controle, equipement client, systeme et programmes d'ordinateur correspondants |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4409864A1 true EP4409864A1 (fr) | 2024-08-07 |
Family
ID=79018293
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP22793193.8A Pending EP4409864A1 (fr) | 2021-09-27 | 2022-09-26 | Procédé de controle d'un accès à un service applicatif mis en oeuvre dans un réseau de télécommunications, procédé de traitement d'un message de controle d'un accès audit service applicatif, dispositifs, équipement de controle, équipement client, système et programmes d'ordinateur correspondants |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20240406175A1 (fr) |
| EP (1) | EP4409864A1 (fr) |
| CN (1) | CN118044170A (fr) |
| FR (1) | FR3127663A1 (fr) |
| WO (1) | WO2023047068A1 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20250080539A1 (en) * | 2023-09-06 | 2025-03-06 | Capital One Services, Llc | Systems and methods for dynamic access control for secure systems based on user tuning subject to system controls |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE10131561A1 (de) * | 2001-06-29 | 2003-01-16 | Nokia Corp | Verfahren zur Übertragung von Anwendungspaketdaten |
| EP1753198A1 (fr) * | 2005-08-09 | 2007-02-14 | Alcatel | Architecture de réseau de voix sur IP |
| FR2909823B1 (fr) * | 2006-12-06 | 2012-12-14 | Soc Fr Du Radiotelephone Sfr | Procede et systeme de gestion de sessions multimedia, permettant de controler l'etablissement de canaux de communication |
| FR2928801A1 (fr) | 2008-03-17 | 2009-09-18 | France Telecom | Procede de gestion de charge d'un equipement d'un systeme de mise en oeuvre d'un service applicatif |
| US11589083B2 (en) * | 2014-09-26 | 2023-02-21 | Bombora, Inc. | Machine learning techniques for detecting surges in content consumption |
| CN119420737A (zh) * | 2024-10-31 | 2025-02-11 | 深圳大道云科技有限公司 | 基于sip协议的通话方法、设备及存储介质 |
-
2021
- 2021-09-27 FR FR2110174A patent/FR3127663A1/fr not_active Ceased
-
2022
- 2022-09-26 EP EP22793193.8A patent/EP4409864A1/fr active Pending
- 2022-09-26 WO PCT/FR2022/051802 patent/WO2023047068A1/fr not_active Ceased
- 2022-09-26 CN CN202280065001.7A patent/CN118044170A/zh active Pending
- 2022-09-26 US US18/695,571 patent/US20240406175A1/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| US20240406175A1 (en) | 2024-12-05 |
| FR3127663A1 (fr) | 2023-03-31 |
| WO2023047068A1 (fr) | 2023-03-30 |
| CN118044170A (zh) | 2024-05-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9043453B1 (en) | Systems and methods for optimizing application data delivery over third party networks | |
| US9432292B2 (en) | Overload call control in a VoIP network | |
| EP3503508B1 (fr) | Procédé de traitement de requêtes et serveur proxy | |
| EP2591587B1 (fr) | Accès confidentiel ou protégé à un réseau de noeuds répartis sur une architecture de communication à l'aide d'un serveur de topoloqie | |
| FR3023108A1 (fr) | Procede et dispositif d'orchestration de ressources | |
| EP3357202B1 (fr) | Système de restauration de services fournis par une passerelle résidentielle | |
| EP3085065B1 (fr) | Procédé de mise a jour dynamique d'informations obtenues de la part d'un serveur dns | |
| EP2366238B1 (fr) | Procede et systeme de regulation du trafic de redemarrage dans un reseau de telecommunications | |
| EP2460322B1 (fr) | Procede et systeme pour la selection automatique de media de transmission | |
| EP1479203A1 (fr) | Correlation des requetes en qualite de service | |
| FR2859588A1 (fr) | Dispositif de traitement de mesures de parametres et/ou de trafics, en vue d'une comptabilisation locale de l'utilisation de ressources, pour un equipement de reseau de communications | |
| WO2023047068A1 (fr) | Procede de controle d'un acces a un service applicatif mis en œuvre dans un reseau de telecommunications, procede de traitement d'un message de controle d'un acces audit service applicatif, dispositifs, equipement de controle, equipement client, systeme et programmes d'ordinateur correspondants | |
| EP2396950B1 (fr) | Procede et systeme de gestion de la signalisation dans un reseau de telecommunications | |
| US10230679B1 (en) | Systems and methods for optimizing application data delivery over third party networks | |
| WO2006108989A2 (fr) | Procede de lutte contre l'envoi d'information vocale non sollicitee | |
| EP1349319B1 (fr) | Dispositif de gestion de service réseau utilisant le protocole cops pour la configuration d'un réseau privé virtuel | |
| WO2009122071A2 (fr) | Procede de gestion de charge d'un equipement d'un systeme de mise en oeuvre d'un service applicatif | |
| EP2103055A1 (fr) | Procédé d'optimisation du partage d'une pluralité de ressources réseau entre une pluralité de flux applicatifs | |
| EP2801178B1 (fr) | Procédé dynamique de détermination d'une liste de services dans un réseau sip | |
| WO2024068725A1 (fr) | Procédé de gestion du trafic de données entre une entité source et une entité destinataire, entité et programme d'ordinateur correspondants | |
| EP3231137B1 (fr) | Réseau superposé pour reseau de communication connectant des centres de données d'un fournisseur de services en nuage | |
| FR3044195A1 (fr) | Procede et dispositif de traitement d'une annonce non legitime d'un bloc d'adresses ip |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20240314 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20260128 |