WO2025003097A1 - Procédés d'accès à un service, procédé de fourniture de services, procédé de contrôle, procédé de gestion, terminal, instance de service, contrôleur, nœud de bordure et programmes d'ordinateur correspondants - Google Patents
Procédés d'accès à un service, procédé de fourniture de services, procédé de contrôle, procédé de gestion, terminal, instance de service, contrôleur, nœud de bordure et programmes d'ordinateur correspondants Download PDFInfo
- Publication number
- WO2025003097A1 WO2025003097A1 PCT/EP2024/067744 EP2024067744W WO2025003097A1 WO 2025003097 A1 WO2025003097 A1 WO 2025003097A1 EP 2024067744 W EP2024067744 W EP 2024067744W WO 2025003097 A1 WO2025003097 A1 WO 2025003097A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- identifier
- terminal
- service
- network
- network slice
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/302—Route determination based on requested QoS
- H04L45/306—Route determination based on the nature of the carried application
Definitions
- the field of the invention is that of communications within at least one communications network, and in particular that of value-added IP services.
- the invention relates to access to at least one service using the network slice resources of a communications network.
- the invention proposes a solution for selecting one or more network slices to be used for all or part of the traffic destined for a terminal.
- a network slice can be defined as a partition of the network such as a virtual private network (VPN) deployed on fixed infrastructure, mobile infrastructure, or a combination of both.
- VPN virtual private network
- the characteristics of a network slice are mainly expressed in terms of capacity (bandwidth) and quality of service (e.g. latency, one-way transit time, etc.), or even security (e.g. preservation of the confidentiality of information transmitted within the VPN through the use of encryption techniques) and service functions (“Service Functions” or SFs).
- bandwidth bandwidth
- quality of service e.g. latency, one-way transit time, etc.
- security e.g. preservation of the confidentiality of information transmitted within the VPN through the use of encryption techniques
- service functions (“Service Functions” or SFs).
- traffic that can be routed within a network slice is authorized (also called access control) to use the paths established within said network slice.
- authorization is typically based on the application of traffic classification rules.
- These rules are generally applied by a network access point within which network slices have been deployed.
- This access point is a node located at the edge of the network and which is generally deployed in front of client accesses or used to connect a network to other neighboring networks.
- an access point can be located at the connection interface of a gateway that provides access to the Internet network.
- This gateway is called a "packet gateway” for the most recent generations (4G, 5G) of mobile networks.
- the traffic classification function could be located at the connection interface of a "packet gateway" to the Internet network.
- the access point may also be located at the interface for connecting a mobile terminal (or “User Equipment” or UE) to the radio access network (or “Radio Access Network” or RAN), in particular to optimize the use of radio resources according to the type of network slice and the profile of the traffic that it is likely to carry.
- a traffic profile is the set of characteristics specific to the traffic. These characteristics may reflect the sensitivity of applications to latency, transit delay or packet loss, but also usage practices, for example traffic that would only be generated over a given period (for example management traffic linked to the execution of a maintenance operation on equipment scheduled during the night).
- the traffic classification and admission control rules are therefore applied at the edge of the network.
- traffic classification rules can be complex, because the level of granularity associated with the engineering and deployment of a network slice can be macroscopic (for example a network slice deployed to route traffic to the Internet), or microscopic (for example a network slice deployed for application traffic exchanged between two mobile terminals).
- This granularity generates an overall complexity of network slice engineering, for example a difficulty in optimizing the use of resources implemented by a network slice, by a set of network slices, or by all network slices, or a difficulty in strictly guaranteeing the isolation of traffic routed within a network slice, or even a difficulty in strictly guaranteeing the level of quality or security associated with a network slice, or even the level of availability and resilience of a given network slice, etc.
- the complexity of the configuration and application of traffic classification rules associated with the implementation of a given network slice evolves with the diversity of traffic, the richness of the organization of the structure that operates the network slice (for example, an accounting department, an R&D department, a production department) or the mode of use of the network slice (for example, management of traffic overloads during busy hours, principles of distribution of the traffic load).
- This complexity can in particular be aggravated by the evolution of the traffic classification rules over time (for example, in the context of the deployment of a network slice for the retransmission of a sporting or cultural event, the traffic classification rules can evolve with the number and profile of users of the network slice).
- Such a method can in particular be implemented by a terminal connected to the communications network.
- Such a terminal obtains during a first step at least a first identifier intended for the classification of the traffic intended for the terminal.
- a first identifier also called tag thereafter, is for example noted “inbound_flow_map” in one embodiment of the invention. It can be associated with a network slice or a type of network slice (for example EMBB, mIoT or URLLC if we consider a 5G network).
- Such a first identifier of the traffic intended for the terminal is different from a network slice identifier used by equipment to connect to a network slice: this other network slice identifier is for example of the NSSAI 3GPP type.
- Such a first identifier of the traffic intended for the terminal is for example generated by a network manager, for example implementing a session management function (“Session Manager Function” or SMF in English) or a network controller.
- Session Manager Function or SMF in English
- the first identifier intended for the classification of traffic to the terminal may in particular be received directly from the SMF manager or a network controller, or via an intermediate router, for example a CPE (“Customer Premises Equipment”) or other network connection equipment.
- a CPE Customer Premises Equipment
- such a first identifier may be inserted in a dedicated header (for example an HTTP header, a QUIC frame) or described in messages formatted according to protocols such as SIP (“Session Initiation Protocol”), SDP (“Session Description Protocol”) or WebRTC.
- the terminal transmits said at least one first identifier to at least one first service instance (“Service Function Instance”, in English, for example an application server), for example by using a network slice configured for this purpose, or a default path.
- a first identifier can be the subject of a parameter subsequently called SOLACE, for “Optimized Slicing A LA Carte”.
- the terminal thus provides at least one first service instance with one or more first identifiers to be used to facilitate the identification of the network slice that the data associated with said at least one service intended for the terminal are authorized to use.
- a service instance can be embedded in a remote terminal.
- the terminal can thus receive a message comprising the data associated with said at least one service.
- data is routed via at least one network slice selected by an edge node of the communication network by applying at least one traffic classification rule known to the edge node (for example previously configured in the edge node following the reception of said at least one rule from a controller).
- the terminal communicates to a service instance a key taking the form of a first identifier intended for the classification of the traffic.
- the service instance can insert this key in the return traffic to the terminal, directly or in a modified form.
- This key can be extracted from the return traffic by an edge node of the communication network through which the return traffic passes, when it is directly inserted in the return traffic to the terminal or when a signaling protocol is used between a service instance and the communication network via a typically edge node, or be deduced or reconstructed by the edge node, when it is inserted in a modified form in the return traffic to the terminal (for example in the form of a digest).
- the edge node can thus identify at least one network slice or a type of network slice associated with this key, without having to inspect the data (for example the content of the service considered, which can be encrypted) and select the network slice or a type of network slice to be used to route the data to the terminal.
- the border node is a node that advertises the IP prefixes allocated to the various devices in the communication network.
- the term "border node” is used here and throughout the rest of the document to designate a node at the edge of the network, for example of the "Autonomous System Border Router” or ASBR type, or a node at the edge of the network, for example of the "Provider Edge (router)" or PE type, in an IP/MPLS network.
- the communication network (or more precisely the network edge node) thus knows which network slice(s) it can use to route traffic to the terminal.
- traffic classification rules can be described in a traffic classification table, or algorithmically for example. No assumptions are made as to how the traffic classification rules are described.
- this classification of network slices or types of network slices associated with forward and/or return traffic may be based on service logic (which may be integrated into the application embedded in the terminal) and/or decided by the network (for example by network equipment).
- the classification may also be the subject of a decision taken by the terminal (for example, according to the choices and instructions of the terminal user).
- the transmission mode can be negotiated during the phase of establishing a connection to a network slice between the terminal and the communication network.
- the method implements the transmission, by the terminal, of a first indicator signaling that the terminal is able to implement a collaborative procedure for routing data associated with said at least one service and to said terminal based on the processing of said at least one first identifier.
- This collaborative procedure is called SOLACE.
- such a first indicator may be provided globally (e.g. when the terminal connects to the network) or when a network slice is activated.
- the terminal implements the reception of a second indicator signaling that the provider of the network slices is able to implement a collaborative SOLACE procedure for the routing of data associated with said at least one service and to said terminal based on the processing of said at least one first identifier (SOLACE).
- Such a second indicator is also noted as “Collaborative-Solace-Capable” subsequently.
- the valuation of this parameter to "1" indicates for example that the said network supports the process described above.
- said obtaining comprises obtaining at least one first identifier per network to which said terminal is connected.
- a first different identifier per network can be obtained (for example a first tag TAG1 for the processing of data sent to the terminal by the service instance via the 5G network, and a second tag TAG2 for the processing of data sent to the terminal by the service instance via the Wi-Fi® network).
- said method comprises transmitting, to the first service instance, at least one traffic classification rule.
- the terminal explicitly indicates the destination address corresponding to each network to which it is connected.
- the terminal can transmit several first identifiers each corresponding to at least one address of the terminal in the network concerned.
- the application of the traffic classification rules allows the data associated with the service that the terminal wishes to access to be correctly routed via the network in which the terminal is identified by the corresponding destination address.
- the use of an identifier different from that associated with a given network implies incorrect application of the classification rule for data sent by a service instance. The data sent by the service instance may then be rejected instead of being routed to the terminal.
- classification rules can also take into account a destination port number.
- the method implements a prior selection of said at least one first service instance authorized to receive said at least one first identifier.
- the terminal can thus set up a selection procedure to choose the service or service instance authorized to receive the first identifier intended for the classification of traffic intended for the terminal.
- the invention in another embodiment, relates to a terminal suitable for implementing the method of accessing at least one service described above.
- a terminal suitable for implementing the method of accessing at least one service described above.
- Such a terminal can of course have the various characteristics relating to the method of accessing at least one service according to the invention, which can be combined or considered in isolation.
- the characteristics and advantages of this terminal are the same as those of the method and are not detailed further.
- Such a method can in particular be implemented by a network controller, for example an SDN (“Software-Defined Networking”) controller.
- a network controller for example an SDN (“Software-Defined Networking”) controller.
- such a controller obtains at least a first identifier of the traffic destined for the terminal.
- a first identifier can be generated by a SMF (“Session Manager Function”).
- the first identifier can be generated by the controller.
- the controller transmits the first identifier to the terminal, directly or via at least one intermediate router, for example a CPE.
- the controller can also transmit to at least one edge node of the communication network at least one traffic classification rule, for example making it possible to associate said at least one first identifier with at least one network slice.
- the second controller can in particular receive said at least one traffic classification rule from the first controller.
- rules can be configured in the edge node, or transmitted in the form of an algorithm intended to be implemented by the edge node.
- the controller can also transmit to the edge node(s) instructions specifying whether the identifier(s) (first identifier or second identifier) that an edge node receives from a service instance must be removed or maintained in the message comprising the data that will be transmitted via the selected network slice.
- the method comprises transmitting said at least one first identifier to at least one other terminal connected to said communications network.
- the same first identifier can be negotiated with several terminals. It is thus possible to share the traffic classification rules maintained by the edge nodes.
- the invention in another embodiment, relates to a controller adapted to implement the method for controlling the provision of at least one service described above.
- a controller can of course have the different characteristics relating to the method for controlling the provision of at least one service according to the invention, which can be combined or considered in isolation.
- the characteristics and advantages of this controller are the same as those of the method and are not detailed further.
- said data being intended to be routed via at least one network slice associated with said at least one first identifier
- said at least one network slice being selected by said border node by applying at least one traffic classification rule known to said border node
- said at least one second identifier being a function of said at least one first identifier.
- Such a method may in particular be implemented by a service instance, which provides the service that the terminal wishes to access.
- a service instance is an application server hosted by the service provider or another infrastructure.
- such a service instance receives at least a first identifier, coming from the terminal (directly or via an intermediate router).
- the first service instance can then return, to the terminal, a message containing the data associated with the service and at least a second identifier, a function of said first identifier.
- a second identifier corresponds either to a first identifier received from the terminal, or to a new identifier obtained from a first identifier received from the terminal.
- a second identifier is obtained by applying a hash function to a first identifier.
- Other functions can be used, as long as they allow the two identifiers to be linked: the second identifier must be obtainable from the first identifier, and the first identifier must be found from the second identifier.
- This message passes through an edge node that provides access to the terminal.
- the edge node extracts the second identifier(s). If the second identifier matches a first identifier, the edge node identifies the network slice(s), or network slice type(s), associated with that first identifier. If the second identifier is obtained by applying a function distinct from an identity function to a first identifier, the edge node retrieves the first identifier, and identifies the network slice(s) associated with that first identifier, and the corresponding traffic classification rules.
- the edge node may then relay the data to the terminal via the network slice(s), or type(s) of network slice(s) thus selected according to the application of traffic classification rules.
- the edge node may remove the second identifier(s) from the message before transmitting the data to the terminal.
- the method comprises receiving at least one traffic classification rule for routing data associated with said at least one first identifier, and storing said at least one traffic classification rule and said at least one associated first identifier.
- Such a step is notably implemented when several first identifiers are communicated to the service instance, for example a first identifier A corresponding to a first address of the terminal and a first identifier B corresponding to a second address of the same terminal.
- the first service instance receives at least two first identifiers each associated with at least one network slice and applies at least one traffic classification rule to select one of the first identifiers.
- the service instance may select a first identifier associated with a network slice of type URLLC, rather than a first identifier associated with an EMBB network slice.
- the first service instance implements the transmission of the message comprising said at least one second identifier and data associated with said at least one service to at least one second service instance capable of providing said at least one service.
- a single service can thus involve a plurality of service instances, without requiring the terminal to transmit the first identifier(s) of the traffic to the service instances. This avoids unnecessary consumption of communication network resources.
- Traffic classification rules resulting from the completeness of the SOLACE procedure can thus be synchronized between multiple service instances.
- the invention relates to a service instance capable of implementing the method for providing at least one service described above.
- a service instance can of course have the different characteristics relating to the method for providing at least one service according to the invention, which can be combined or considered in isolation.
- the characteristics and advantages of this service instance are the same as those of the method and are not detailed further.
- Such a method can in particular be implemented in an edge node of the communication network.
- such an edge node can thus receive at least a second identifier and data associated with the service that the terminal wishes to access.
- the edge node can in particular extract the second identifier(s), corresponding either to the first identifier(s) or to a function of the first identifier(s). In the latter case, the edge node can implement an inverse function to find the first identifier(s).
- the edge node can then apply a traffic classification rule to check whether a network slice, or a type of network slice, is associated with this or these first identifier(s). If so, the data can be transmitted to the terminal via the network slice or the type of network slice thus identified. Otherwise, the data is not transmitted to the terminal or it is transmitted via a default path, or a route determined according to a classic IP routing scheme for example, which does not necessarily rely on the use of network slices.
- the message received from the service instance may include the first identifier(s), encoded in a single field or in several fields, explicitly or implicitly.
- the message In explicit mode, the message directly carries the first identifier(s).
- the message In implicit mode, the message carries information (second identifiers) allowing the first identifier(s) to be found.
- the edge node may remove the second identifier(s) from the message before transmitting the data to the terminal.
- the invention relates to an edge node adapted to implement the method for managing access to at least one service described above.
- an edge node can of course have the different characteristics relating to the method for managing access to at least one service according to the invention, which can be combined or considered in isolation.
- the characteristics and advantages of this edge node are the same as those of the method and are not detailed further.
- said at least one first identifier is associated with a validity period.
- a first identifier may change over time.
- said at least one second identifier may be associated with a validity period, identical to or different from that associated with the first identifier from which the second identifier is constructed.
- said at least one first identifier may be associated with a security key, for example a token or a random number.
- a random or pseudo-random number unique to a terminal, is also communicated to the terminal with the first identifier(s)/tag(s).
- a security key can be used for authorization purposes. This improves the robustness of the process and prevents a terminal from using an identifier communicated to another terminal.
- At least one of said network slices may be composed of at least one local network slice deployed in at least one subnetwork of the communication network (for example in an access network, a collection network, a core network, a transit network).
- the invention further relates to at least one computer program comprising instructions for implementing at least one of the methods described above, when this or these programs are executed by a processor, as well as to at least one computer-readable information medium comprising instructions of at least one computer program as mentioned above.
- the method according to the invention can be implemented in various ways, in particular in wired form or in software form.
- the general principle of the invention is based on the use of one or more first identifiers (tags) intended for the classification of traffic destined for a terminal, to identify the network slice that traffic destined for a terminal is authorized to use.
- This principle is part of a context where a terminal wishes to access at least one service via a communication network implementing network slices.
- an edge node of the communication network can identify the network slice(s) via which the return traffic (i.e. destined for the terminal) must be routed, without having to inspect the data associated with the service considered.
- the proposed solution offers, according to at least one embodiment, a mechanism for automatic and secure discovery of network slices deployed (or instantiated) on a fixed and/or mobile infrastructure and reserved for a certain use, for example the retransmission of a sporting or musical event.
- the terminal does not control access to the network slice(s) used to route the data associated with the service in question and does not thus allow benefiting from the resources of the network slice that optimizes the quality of the service in question, as it can be perceived by the user of the terminal, in particular.
- the terminal therefore does not have the means to verify that the network slice to which the service instance connects is the one that implements a traffic routing policy optimized for the service in question and as subscribed to by the customer.
- the invention proposes a solution to this problem.
- Such a system comprises a terminal UE 11 (“User Equipment” in English) wishing to access at least one service via a communication network SSP 12 (“Slice Service Provider” in English, or service provider based on network slices) implementing network slices, for example two network slices Sl. #1 161 and Sl. #2 162 (“Slice” in English).
- UE 11 User Equipment
- SSP 12 Session Service Provider
- Terminal 11 may optionally be connected to network 12 via an intermediate router, for example a CPE.
- an intermediate router for example a CPE.
- the service may be provided by at least one service instance, for example by two service instances SFI #1 131 and SFI #2 132.
- a service instance may be connected to the network 12 via a network edge node.
- the first instance 131 is connected to the network 12 via the first border node BR 141 (“Border Router”), and the second instance 132 is connected to the network 12 via the second border node BR 142.
- the service instances are not necessarily directly connected to the edge nodes.
- At least one network controller 15 may be used to transmit to at least one edge node of the network 12 (for example in the edge nodes 141 and 142) traffic classification rules (for example in algorithmic form, or in the form of at least one traffic classification table, or in any other form).
- the controller 15 may also transmit to the terminal 11 the first identifier(s) (also called “tags”) of the traffic destined for the terminal.
- the controller 15, or the edge node may maintain at least one traffic classification rule, making it possible to associate a first identifier of the traffic with at least one network slice. It is noted that the configuration of the edge nodes and the terminals may be carried out by separate network entities.
- the controller 15 obtains during a step 151 at least one first TAG identifier intended for the classification of traffic to the terminal 11.
- a first identifier is associated with at least one network slice or one type of network slice.
- the controller maintains a traffic classification rule according to which the first TAG identifier #1 is associated with the network slice Sl #1.
- said at least one first TAG identifier is transmitted to the terminal 11, directly or via at least one intermediate router.
- the controller 15 transmits, to at least one edge node of the communication network, for example the BR1 node 141, at least one traffic classification rule for selecting at least one network slice intended to route to the terminal data associated with said at least one service.
- at least one edge node of the communication network for example the BR1 node 141
- at least one traffic classification rule for selecting at least one network slice intended to route to the terminal data associated with said at least one service.
- rules can be configured in the edge node, or implemented by the execution of an algorithm known to the edge node (received from a controller).
- step 153 can be implemented before steps 151 and/or 152.
- the transmission of the traffic classification rules to the border node can be implemented before or after having transmitted said at least one first TAG identifier to the terminal 11.
- step 153 can be implemented by another controller.
- the terminal 11 therefore receives said at least one first TAG identifier, from the controller 15, directly or via at least one intermediate router.
- the terminal 11 transmits said at least one first TAG identifier to at least one first service instance capable of providing the service in question, for example to the first service instance SFI #1 131.
- the first service instance 131 therefore receives said at least one first TAG identifier.
- the first service instance 131 transmits, via at least one border node, for example the first border node BR 141, a message MSG1 comprising at least a second identifier and data D associated with the service considered.
- This data D is intended for the terminal 11.
- the second identifier is equal to the first identifier TAG.
- the first identifier is used to calculate a second identifier which can be included in said message.
- the second identifier is obtained by applying a hash function “Hash” to the first identifier.
- the second identifier is equal to the first TAG identifier.
- the message MSG1 sent by the first service instance 131 therefore comprises said at least one first TAG identifier and the data D.
- the first border node 141 therefore receives the message MSG1 from the first service instance 131 comprising said at least one first TAG identifier and the data D.
- the first border node 141 checks whether at least one network slice is associated with said at least one first TAG identifier by applying at least one traffic classification rule known to the first border node 141 (for example configured during a step 1411), and selects said at least one corresponding network slice.
- the first border node 141 transmits the data D associated with the service considered on said at least one selected network slice.
- the first border node 141 can retransmit to the terminal 11 the message MSG1 comprising said at least one first TAG identifier and the data D as received from the first service instance 131, or delete said at least one first TAG identifier to send only the data D to the terminal 11 in a message MSG1’.
- the terminal 11 therefore receives the message MSG1’ comprising the data D routed via at least one network slice associated with said at least one first TAG identifier.
- a network slice of the communication network can be associated with other network slices to provide value-added services.
- a service provider can rely on slices set up in different subnetworks to provide a service whose traffic is intended to be routed in the "global" network slice composed of slices deployed in the different subnetworks. This is called a “multi-domain slice” (or “stitched slices” or “hierarchical slices” in English).
- Such a network slice can indeed reflect a hierarchical structure.
- the SSP network 12 may be composed of several subnetworks 121, 122 and 123. Each subnetwork may support one or more network slices.
- the first subnetwork 121 supports four network slices
- the second subnetwork 122 supports three network slices
- the third subnetwork 123 supports four network slices.
- the first network slice Sl. #1 161 of the communication network is for example composed of the network slices Sl. #3 deployed on the subnetwork 121, Sl. #2 deployed on the subnetwork 122 and Sl. #2 deployed on subnet 123.
- connection interfaces between adjacent slices are for example managed using the mechanisms described in the document "YANG Data Models for 'Attachment Circuits'-as-a-Service (ACaaS)" by M. Boucadair et al., version 6 published on May 3, 2023.
- each subnetwork may be associated with a distinct domain (for example, a communications network may consist of an access network, a collection network, a core network, and a transit network).
- a communications network may consist of an access network, a collection network, a core network, and a transit network).
- Each of these domains supports network slices whose engineering and operation are characteristic of the domain (for example, a slice deployed on a 5G mobile core network may use traffic processing and operating functions characteristic of a 5G mobile core network).
- each domain access, collection, core, transit, etc.
- each domain may exploit different technologies deployed in this domain for the realization of the network slices.
- a first domain associated with the first subnet 121 sets up IPsec tunnels which are used to route traffic in the slices deployed in this domain
- a second domain associated with the second subnet 122 uses network-level virtual private network engineering (Layer 3 VPN or L3VPN) combined with traffic engineering mechanisms ("Traffic Engineering” or TE in English) to route traffic in the slices deployed in this domain
- a third domain associated with the third subnet 123 uses the resources of segment routing based on the IPv6 protocol (“Segment Routing IPv6" or SRv6 in English) to route traffic in the slices deployed in this domain.
- a network slice in a mobile network may be based on the implementation of network slices in the following different subnetworks/segments: Radio Access Network (RAN), Core Network (CN) and Transport Network (TN).
- RAN Radio Access Network
- CN Core Network
- TN Transport Network
- the association between a network slice, for example a 5G network slice in the case of a latest generation mobile network, and the network slices deployed in each of the segments/subnetworks composing the 5G mobile network is performed in the control plane and at the edge of each of the RAN, CN and TN networks.
- the network slice deployed in the TN network is sometimes called an “IETF Network Slice”.
- no assumption is made as to the nature of the network slices, their number, and the "mapping" between network slices of neighboring domains (e.g. RAN and TN, TN and CN).
- neighboring domains e.g. RAN and TN, TN and CN.
- the same network slice can be used to aggregate traffic from one or more services.
- a first service S1 served by one or more service instances 51 can be provided to a first client UE1 via a network slice Sl.
- a second service S2 served by one or more service instances 52 can be provided to a second client UE2 via the same network slice Sl.
- a third service S3 served by one or more service instances 53 can be provided to the second client UE2 via the same network slice Sl. #3 of the SSP network.
- a network slice may involve one or more service functions (or “Service Functions” in English, according to the terminology used by RFC7665 - “Service Function Chaining (SFC) Architecture” by J. Halpern et al. published in October 2015, or "Network Functions” such as gNB (“gNodeB”) or UPF ("User Plane Functions”) according to the terminology used by 3GPP).
- SFC Service Function Chaining
- a single service function may be provided by one or more service instances.
- a service instance may be hosted by the SSP (e.g. service instances 63 and 64) or within another infrastructure (e.g. service instance 65).
- service chains (“Service Function Chain” or SFC in English) can be set up in order to facilitate the routing of traffic of different nature and having different profiles for the needs of the realization of a network slice or within a network slice (for example the service instances 611, 612 and 613 of the ).
- the terminal 11 and the SSP 12 exchange messages to ensure that they both support the SOLACE procedure (“Slicing Optimisé A LA Carte”).
- the terminal 11 values a first indicator or parameter noted “Collaborative-Solace-Capable” at a given value, for example “1”, to indicate to the SSP 12 that it is able to implement a collaborative procedure for routing data associated with at least one service which the terminal wishes to access and intended for the terminal, based on the processing of at least one identifier (tag) intended for the classification of traffic intended for the terminal.
- a first indicator or parameter noted “Collaborative-Solace-Capable” at a given value for example “1”
- This indication of support for the SOLACE procedure can be provided globally or when activating each network slice.
- the SSP 12 If the SSP 12 supports the SOLACE procedure, it returns a second indicator or parameter “Collaborative-Solace-Capable” set to a given value, for example “1”, to indicate to the terminal 11 that it is capable of implementing a collaborative procedure for routing data associated with at least one service which the terminal wishes to access and to the terminal, based on the processing of at least one identifier (tag).
- a second indicator or parameter “Collaborative-Solace-Capable” set to a given value, for example “1” to indicate to the terminal 11 that it is capable of implementing a collaborative procedure for routing data associated with at least one service which the terminal wishes to access and to the terminal, based on the processing of at least one identifier (tag).
- the second indicator may be returned to the terminal 11 in response to receipt of the first indicator.
- it is the first indicator that is returned by the terminal 11 in response to receipt of the second indicator.
- a network controller 15 can transmit to the terminal 11 at least one identifier (tag) intended for the classification of the traffic destined for the terminal 11.
- a tag noted for example “Inbound-Flow-Map”
- the network controller 15 can in particular keep up to date at least one traffic classification rule associating at least one identifier of the traffic destined for the terminal, or tag, with at least one network slice.
- the SOLACE collaborative mode can be negotiated with each of the networks to which the terminal can connect.
- the terminal 11 can retrieve distinct tags per network to which the terminal 11 is connected.
- a validity period or expiration may be associated with the tag.
- a new tag (“Inbound-Flow-Map”) may be renegotiated with the network upon said expiration or upon expiration of said validity period.
- a security key may be associated with the tag. For example, a random or pseudo-random number, or “nonce,” unique to a terminal is also communicated to the terminal with the tag(s). Such a security key may be used for authorization purposes.
- the network controller 15 may also transmit to the edge nodes, for example to the first edge node BR 141 and to the second edge node BR 142, traffic classification rules to associate the traffic entering the edge node with the network slice(s) negotiated with the terminal 11 (and thus associate the identifier of the traffic destined for the associated terminal, or tag, with the network slice(s) negotiated with the terminal 11).
- the terminal 11 can thus associate the return traffic of each service eligible for the operation of slices with at least one network slice, using at least one tag.
- the return traffic of the same service can be associated with several network slices depending on the nature of the service.
- the classification of each of these categories according to a type of network slice can be defined by the logic of the service (for example integrated into the application embedded in the terminal 11) or provided by the SSP network 12.
- the classification of the different traffics can also be the subject of a decision taken by the terminal 11 (for example, according to the choices and instructions of the user of the terminal 11).
- the terminal 11 can transmit one or more tags to at least one service instance capable of providing the service that the terminal wishes to access.
- the terminal 11 uses a new parameter hereinafter called “Solace”, to transmit the tag(s) in a message that it sends to a service instance, for example to the first service instance SFI #1 131.
- Solace parameter contains only one "Inbound-Flow-Map" tag, then this tag applies for all traffic emitted by the service instance.
- this Solace parameter contains a list of "Inbound-Flow-Map" tags, then traffic classification rules are also provided by the terminal 11 to the service instance, so that the traffic emitted by the service instance and the associated tag can be identified.
- the terminal 11 In a context where the terminal 11 is connected to several communication networks (context of “multihoming” for example), the terminal 11 ensures that the traffic classification rules thus generated make it possible to associate the traffic with the tag of the network intended to route said traffic.
- the terminal 11 can be connected to a first communication network SSP1 and to a second communication network SSP2.
- the terminal 11 can explicitly indicate, for example via the Solace parameter, its destination address in each communication network as a traffic classification rule, corresponding here to a demultiplexing parameter.
- the new Solace parameter can be inserted into a dedicated header (e.g. HTTP header, QUIC frame) or described in characteristic messages of protocols such as SDP ("Session Description Protocol") or WebRTC.
- a dedicated header e.g. HTTP header, QUIC frame
- SDP Session Description Protocol
- WebRTC WebRTC
- the tag “156” (i.e. the identifier intended for the classification of traffic destined for the terminal) can be used by the service instance if the destination address used to send the traffic to the terminal 11 is “2001:db8::1”, while the tag “651” can be used by the service instance if the destination address used to send the traffic to the terminal 11 is “2001:db8::123”.
- the message with the "Solace" parameter sent to a service instance is routed from terminal 11 using a network slice configured for this purpose or using a default path if no network slice is available or enabled to route traffic to that service instance.
- the service instance Upon receipt of the message with the “Solace” parameter, the service instance checks for the presence of at least one tag (“Inbound-Flow-Map”).
- the service instance extracts and then locally saves the traffic classification rule(s) transmitted by the terminal, as well as the associated tag(s).
- the service instance confirms the correct implementation of the traffic classification rules.
- This confirmation can be communicated to the terminal 11 using a dedicated acknowledgment parameter (e.g. HTTP header, QUIC frame) or described explicitly in messages characteristic of protocols such as SIP, SDP or WebRTC.
- a dedicated acknowledgment parameter e.g. HTTP header, QUIC frame
- the absence of an error message can also be interpreted as an implicit acknowledgment and confirmation.
- the service instance marks the traffic with the corresponding tag.
- the service instance can send an MSG1 message comprising one or more tags “tag” and, for each tag, the data associated with the service that the terminal wishes to access according to the traffic classification rules communicated by the terminal.
- the tag(s) can be inserted in a UDP option, an HTTP header, a SIP header, the “Flow Label” field of an IPv6 packet header, an IPv6 extension header, etc.
- the first service instance SFI #1 131 can forward the MSG1 message to other service instances involved in providing the service, such as the second service instance SFI #2 132.
- This is advantageous because a single service can involve a plurality of service instances without having to repeat the phase of communication of the tags by the terminal with all the service instances.
- This synchronization is particularly advantageous for services that use anycast addressing (i.e., the service instances can be reached from the same IP address).
- the return traffic (from at least one service instance and destined for the terminal 11) is received by at least one border node, for example the first border node BR 141 and/or second border node BR 142.
- the border node BR inspects, then extracts the tag(s) if necessary.
- traffic is processed according to a default routing rule. For example, traffic is routed to terminal 11 via a default route (e.g. a route that is not established in any of the deployed network slices, or a network slice dedicated to so-called “Best Effort” traffic).
- a default route e.g. a route that is not established in any of the deployed network slices, or a network slice dedicated to so-called “Best Effort” traffic.
- the edge node BR 141 of the first SSP1 network receives data D1 and the identifier TAG1 from the service instance 131, and can select, from reading the traffic classification table, the network slice associated with the identifier TAG1 for routing the data D1 via the first SSP1 network, for example the network slice Sl. #3.
- the edge node BR 842 of the second SSP2 network receives data D2 and the identifier TAG2 from the service instance 131, and can select, from reading the traffic classification table, the network slice associated with the identifier TAG2 for routing the data D2 via the second SSP2 network, for example the slice SL. #1.
- the data D1 and D2 may be the same or different.
- the edge node BR 141 of the first SSP1 network receives data D1 and the identifier TAG2 from the service instance 131, no entry is found in the traffic classification table.
- the data D1 is therefore routed to the terminal 11 using a default route, or a route determined according to a classic IP routing scheme for example.
- the BR edge node can remove the tag(s) before forwarding the data to the terminal.
- the edge node BR checks for the presence of a security key, for example the presence of a valid “nonce” parameter associated with the terminal in question, before injecting the traffic into a network slice.
- a security key for example the presence of a valid “nonce” parameter associated with the terminal in question.
- the verification of the validation of the “nonce” can be performed locally or by involving a network controller, for example controller 15. The verification is not necessarily performed systematically for all packets of the MSG1 message that carry a tag and a security key.
- the BR edge node can calculate a hash based on a first packet of the MSG1 message, and this hash can then be used to validate subsequent packets without requiring the intervention of a network controller.
- the terminal 11 is not connected directly to the communication network, but via a connection equipment (for example a CPE or other intermediate router).
- the connection equipment can implement the SOLACE procedure as if the terminal were directly connected to the network.
- the CPE can negotiate with the terminal the activation of the SOLACE procedure. For example, the communication of tags to service instances is performed by the terminal.
- the CPE inserts tags according to rules local to the CPE. These rules can be configured by the user or communicated by the terminal via a dedicated mechanism (PCP, for example).
- PCP dedicated mechanism
- the controller 15 can transmit the tag(s) to the CPE 10.
- the terminal 11 can contact the CPE 10 to retrieve the tags associated with each network slice.
- the terminal 11 uses new options that can be supported by different protocols such as PCP (Port Control Protocol), DHCP (Dynamic Host Configuration Protocol), RA (Router Advertisement message in IPv6 environment), etc., to obtain the tags.
- PCP Port Control Protocol
- DHCP Dynamic Host Configuration Protocol
- RA Raster Advertisement message in IPv6 environment
- the "Tag count” field indicates the number of tags included in the PCP option.
- the "Traffic Selector” field can be filled in for a tag. This field describes for example the traffic classification rule eligible for marking with said tag (for example destination IP address, destination port number, protocol identifier), by a service instance, of the data associated with the service considered. If no rule is indicated, then the marking of the data with a tag is applicable to all traffic entering the service instance (i.e. to the terminal).
- the terminal may indicate in a message to a service instance the list of network slices negotiated with the network.
- the service instance may choose to invoke a slice distinct from the one used to route this message, for all or part of the traffic to the terminal.
- a network slice can be deployed on a fixed infrastructure, mobile infrastructure, or a combination of the two.
- such an entity comprises at least one memory 121 comprising a buffer memory, at least one processing unit 122, equipped for example with a programmable computing machine or a dedicated computing machine, for example a processor P, and controlled by the computer program 123, implementing steps of at least one method according to at least one embodiment of the invention.
- the code instructions of the computer program 123 are for example loaded into a RAM memory before being executed by the processor of the processing unit 122.
- said at least one network slice being selected by said border node by applying at least one traffic classification rule known to said border node.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
- un premier type de tranches réseau permettant d’offrir un service mobile large bande amélioré (« Enhanced Mobile BroadBand » ou EMBB en anglais) ;
- un deuxième type de tranches réseau permettant d’offrir un service dans le cadre d’un déploiement (massif) de l’Internet des Objets (« massive Internet of Things » ou mIoT en anglais) ; et
- un troisième type de tranches réseau permettant d’offrir un service de communication ultra fiable et à faible latence (« Ultra Reliable Low Latency Communications ou URLLC en anglais).
- l’obtention d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- la transmission dudit au moins un premier identifiant à au moins une première instance de service apte à fournir ledit au moins un service audit terminal,
- la réception d’un message comportant des données associées audit au moins un service acheminées via au moins une tranche réseau associée audit au moins un premier identifiant, sélectionnée par un nœud de bordure dudit réseau de communication en appliquant au moins une règle de classification de trafic connue dudit nœud de bordure.
- l’acheminement de données à destination du terminal,
- l’acheminement de données en provenance du terminal,
- l’acheminement de données à destination du terminal et en provenance du terminal.
- l’obtention d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- la transmission dudit au moins un premier identifiant audit terminal, directement ou via au moins un routeur intermédiaire,
- la transmission, à au moins un nœud de bordure dudit réseau de communication, d’au moins une règle de classification de trafic pour la sélection d’au moins une tranche réseau destinée à acheminer vers ledit terminal des données associées audit au moins un service.
- la réception d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- la transmission, via au moins un nœud de bordure dudit réseau de communication, d’un message comportant au moins un deuxième identifiant et des données associées audit au moins un service,
- la réception d’au moins un message en provenance d’au moins une première instance de service apte à fournir ledit au moins un service, ledit message comportant au moins un deuxième identifiant, fonction d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal et des données associées audit au moins un service,
- la sélection d’au moins une tranche réseau associée audit au moins un premier identifiant en appliquant au moins une règle de classification de trafic connue (reçue d’un contrôleur),
- la transmission desdites données associées audit au moins un service sur ladite au moins une tranche réseau sélectionnée.
- la
représente un système dans lequel l’invention peut être mise en œuvre ; - la
illustre les principales étapes des procédés selon au moins un mode de réalisation de l’invention ; - la
illustre les principaux messages échangés lors de la mise en œuvre des procédés selon la ; - la
illustre un exemple de réseau de communication composé de plusieurs sous-réseaux ; - la
illustre un exemple d’agrégation de plusieurs services au sein d’une même tranche réseau ; - la
illustre un exemple de déploiement de plusieurs instances de service ; - la
présente les différentes entités intervenant dans le déroulement du mode collaboratif de la procédure SOLACE ; - la
illustre un exemple d’association de trafic à des tranches réseau et arrivant à un nœud de bordure et à destination du terminal ; - la
illustre un exemple de problème empêchant l’association de trafic à des tranches réseau et arrivant à un nœud de bordure ; - la
illustre un exemple d’activation de la procédure SOLACE en présence d’un CPE ; - la
présente un exemple d’option PCP (« Port Control Protocol ») mis en œuvre par un terminal pour obtenir au moins un premier identifiant destiné à la classification du trafic à destination du terminal et habilité à être acheminé via une tranche donnée ; - la
présente la structure simplifiée des différentes entités selon un mode de réalisation particulier.
- l’acheminement de données à destination du terminal 11 ( « receive-only »),
- l’acheminement de données en provenance du terminal 11 (« send-only »),
- l’acheminement de données associées à destination du terminal 11 et en provenance du terminal 11 (« send-receive »).
| v=0 o=- 25678 753849 IN IP6 2001:db8::1 s= c=IN IP6 2001:db8::1 t=0 0 m=audio 12340 RTP/AVP 0 8 a=slice-tag:156 IP6 2001:db8::1 45678 a=slice-tag:651 IP6 2001:db8::123 12340 |
- si aucune entrée dans la table de classification de trafic n’est trouvée, alors le trafic peut être acheminé vers le terminal 11 via une route par défaut, ou bien bloqué. Par exemple, en
, le nœud de bordure BR 142 ne dispose pas, dans la table de classification de trafic, d’une entrée descriptive de la tranche réseau associée au tag reçu dans le message MSG1. Les données sont donc acheminées selon une route par défaut, qui ne repose pas nécessairement sur l’utilisation de tranches réseau. - si une entrée dans la table de classification de trafic est identifiée par le nœud de bordure BR, alors celui-ci achemine le trafic selon le contenu de cette entrée, c'est-à-dire via la tranche réseau identifiée à partir du tag. Par exemple, en
, le nœud de bordure BR 141 reconnaît que le tag reçu dans le message MSG1 est associé à la tranche réseau Sl. #2. Il peut donc transmettre les données au terminal 11 via la tranche réseau Sl. #2.
- renvoyer les instructions de marquage à l’instance de service, i.e. renvoyer le paramètre Solace,
- négocier une nouvelle procédure SOLACE avec le réseau, i.e. renégocier la liste de tranches réseau que le terminal est susceptible d’utiliser pour envoyer ou recevoir du trafic,
- ajuster les règles de classification de trafic.
- obtenir au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal,
- transmettre dit au moins un premier identifiant à au moins une première instance de service apte à fournir ledit au moins un service audit terminal,
- recevoir un message comportant des données associées audit au moins un service acheminées via au moins une tranche réseau associée audit au moins un premier identifiant, ladite au moins une tranche réseau étant sélectionnée par un nœud de bordure dudit réseau de communication en appliquant au moins une règle de classification de trafic connue dudit nœud de bordure.
- obtenir au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal,
- transmettre ledit au moins un premier identifiant audit terminal, directement ou via au moins un routeur intermédiaire,
- transmettre, à au moins un nœud de bordure dudit réseau de communication, au moins une règle de classification de trafic pour la sélection d’au moins une tranche réseau destinée à acheminer vers ledit terminal des données associées audit au moins un service.
- recevoir au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal,
- la transmission, via au moins un nœud de bordure dudit réseau de communication, d’un message comportant au moins un deuxième identifiant, fonction dudit au moins un premier identifiant, et des données associées audit au moins un service, lesdites données étant destinées à être acheminées via au moins une tranche réseau associée audit au moins un premier identifiant,
- recevoir au moins un message en provenance d’au moins une première instance de service apte à fournir ledit au moins un service, ledit message comportant au moins un deuxième identifiant, fonction d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, et des données associées audit au moins un service,
- sélectionner au moins une tranche réseau associée audit au moins un premier identifiant en appliquant au moins une règle de classification de trafic connue,
- transmettre lesdites données associées audit au moins un service sur ladite au moins une tranche réseau sélectionnée.
Claims (20)
- Procédé d’accès à au moins un service par un terminal (11), via un réseau de communication mettant en œuvre des tranches réseau, comprenant :
- l’obtention (111) d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- la transmission (112) dudit au moins un premier identifiant à au moins une première instance de service (131) apte à fournir ledit au moins un service audit terminal,
- la réception (113) d’un message comportant des données associées audit au moins un service acheminées via au moins une tranche réseau associée audit au moins un premier identifiant, sélectionnée par un nœud de bordure (141) dudit réseau de communication en appliquant au moins une règle de classification de trafic connue dudit nœud de bordure.
- Procédé selon la revendication 1, caractérisé en ce que ladite au moins une tranche réseau ou ledit type de tranche réseau est associé à un mode de transmission appartenant au groupe comprenant :
- l’acheminement de données à destination dudit terminal,
- l’acheminement de données en provenance dudit terminal,
- l’acheminement de données à destination dudit terminal et en provenance dudit terminal.
- Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que ladite obtention comprend l’obtention d’au moins un premier identifiant par réseau auquel ledit terminal est connecté.
- Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce qu’il comprend la transmission, à ladite première instance de service, d’au moins une règle de classification de trafic.
- Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce qu’il met en œuvre une sélection préalable de ladite moins une première instance de service habilitée à recevoir ledit au moins un premier identifiant.
- Procédé de contrôle de la fourniture d’au moins un service à un terminal (11), via un réseau de communication mettant en œuvre des tranches réseau, comprenant :
- l’obtention (151) d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- la transmission (152) dudit au moins un premier identifiant audit terminal, directement ou via au moins un routeur intermédiaire,
- la transmission (153), à au moins un nœud de bordure (141) dudit réseau de communication, d’au moins une règle de classification de trafic pour la sélection d’au moins une tranche réseau destinée à acheminer vers ledit terminal des données associées audit au moins un service.
- Procédé selon la revendication 6, caractérisé en ce qu’il comprend la transmission dudit au moins un premier identifiant à au moins un autre terminal connecté audit réseau de communication.
- Procédé de fourniture d’au moins un service à un terminal (11), via un réseau de communication mettant en œuvre des tranches réseau, comprenant :
- la réception (1311) d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- la transmission (1312), via au moins un nœud de bordure (141) dudit réseau de communication, d’un message comportant au moins un deuxième identifiant, fonction dudit au moins un premier identifiant, et des données associées audit au moins un service, lesdites données étant destinées à être acheminées via au moins une tranche réseau associée audit au moins un premier identifiant, sélectionnée par ledit nœud de bordure en appliquant au moins une règle de classification de trafic connue dudit nœud de bordure.
- Procédé selon la revendication 8, caractérisé en ce qu’il comprend la réception d’au moins une règle de classification de trafic pour l’acheminement des données associées audit au moins un premier identifiant, et le stockage de ladite au moins une règle de classification de trafic et dudit au moins un premier identifiant associé.
- Procédé selon l'une quelconque des revendications 8 et 9, caractérisé en ce que ladite réception comprend la réception d’au moins deux premiers identifiants associés chacun à au moins une tranche réseau et l’application d’au moins une règle de classification de trafic pour sélectionner l’un desdits premiers identifiants.
- Procédé selon l'une quelconque des revendications 8 à 10, caractérisé en ce qu’il comprend la transmission dudit message comportant ledit au moins un deuxième identifiant et des données associées audit au moins un service à au moins une deuxième instance de service apte à fournir ledit au moins un service.
- Procédé de gestion de l’accès à au moins un service par un terminal, via un réseau de communication, comprenant :
- la réception (1412) d’au moins un message en provenance d’au moins une première instance de service (131) apte à fournir ledit au moins un service, ledit message comportant au moins un deuxième identifiant, fonction d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, et des données associées audit au moins un service,
ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau, - la sélection (1413) d’au moins une tranche réseau associée audit au moins un premier identifiant en appliquant au moins une règle de classification de trafic connue,
- la transmission (1414) desdites données associées audit au moins un service sur ladite au moins une tranche réseau sélectionnée.
- la réception (1412) d’au moins un message en provenance d’au moins une première instance de service (131) apte à fournir ledit au moins un service, ledit message comportant au moins un deuxième identifiant, fonction d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, et des données associées audit au moins un service,
- Procédé selon l'une quelconque des revendications 1 à 12 caractérisé en ce que ledit au moins un premier identifiant est associé à une durée de validité.
- Procédé selon l'une quelconque des revendications 1 à 13 caractérisé en ce que ledit au moins un premier identifiant est associé à une clé de sécurité.
- Procédé selon l'une quelconque des revendications 1 à 14 caractérisé en ce qu’au moins une desdites tranches réseau est composée d’au moins une tranche réseau locale déployée dans au moins un sous-réseau dudit réseau de communication.
- Terminal (11) apte à accéder à au moins un service, via un réseau de communication mettant en œuvre des tranches réseau, comprenant au moins un processeur configuré pour :
- obtenir au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- transmettre dit au moins un premier identifiant à au moins une première instance de service apte à fournir ledit au moins un service audit terminal,
- recevoir un message comportant des données associées audit au moins un service acheminées via au moins une tranche réseau associée audit au moins un premier identifiant, sélectionnée par un nœud de bordure dudit réseau de communication en appliquant au moins une règle de classification de trafic connue dudit nœud de bordure.
- Contrôleur (15) apte à contrôler la fourniture d’au moins un service à un terminal, via un réseau de communication mettant en œuvre des tranches réseau, comprenant au moins un processeur configuré pour :
- obtenir au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- transmettre ledit au moins un premier identifiant audit terminal, directement ou via au moins un routeur intermédiaire,
- transmettre, à au moins un nœud de bordure dudit réseau de communication, au moins une règle de classification de trafic pour la sélection d’au moins une tranche réseau destinée à acheminer vers ledit terminal des données associées audit au moins un service.
- Instance de service (131, 132) apte à fournir au moins un service à un terminal, via un réseau de communication mettant en œuvre des tranches réseau, comprenant au moins un processeur configuré pour :
- recevoir au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau,
- la transmission, via au moins un nœud de bordure dudit réseau de communication, d’un message comportant au moins un deuxième identifiant, fonction dudit au moins un premier identifiant, et des données associées audit au moins un service, lesdites données étant destinées à être acheminées via au moins une tranche réseau associée audit au moins un premier identifiant, sélectionnée par ledit nœud de bordure en appliquant au moins une règle de classification de trafic connue dudit nœud de bordure.
- Nœud de bordure (141, 142) apte à gérer l’accès à au moins un service par un terminal, via un réseau de communication, comprenant au moins un processeur configuré pour :
- recevoir au moins un message en provenance d’au moins une première instance de service apte à fournir ledit au moins un service, ledit message comportant au moins un deuxième identifiant, fonction d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, et des données associées audit au moins un service,
ledit au moins un premier identifiant étant associé à au moins une tranche réseau ou un type de tranche réseau, - sélectionner au moins une tranche réseau associée audit au moins un premier identifiant en appliquant au moins une règle de classification de trafic connue,
- transmettre lesdites données associées audit au moins un service sur ladite au moins une tranche réseau sélectionnée.
- recevoir au moins un message en provenance d’au moins une première instance de service apte à fournir ledit au moins un service, ledit message comportant au moins un deuxième identifiant, fonction d’au moins un premier identifiant destiné à la classification du trafic à destination dudit terminal, et des données associées audit au moins un service,
- Programme d’ordinateur comportant des instructions pour la mise en œuvre d’un procédé selon l'une quelconque des revendications 1 à 15 lorsque ce programme est exécuté par un processeur.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24734902.0A EP4736394A1 (fr) | 2023-06-29 | 2024-06-25 | Procédés d'accès à un service, procédé de fourniture de services, procédé de contrôle, procédé de gestion, terminal, instance de service, contrôleur, noeud de bordure et programmes d'ordinateur correspondants |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR2306885A FR3150670A1 (fr) | 2023-06-29 | 2023-06-29 | Procédés d’accès à un service, procédé de fourniture de services, procédé de contrôle, procédé de gestion, terminal, instance de service, contrôleur, nœud de bordure et programmes d’ordinateur correspondants. |
| FRFR2306885 | 2023-06-29 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025003097A1 true WO2025003097A1 (fr) | 2025-01-02 |
Family
ID=88779705
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2024/067744 Ceased WO2025003097A1 (fr) | 2023-06-29 | 2024-06-25 | Procédés d'accès à un service, procédé de fourniture de services, procédé de contrôle, procédé de gestion, terminal, instance de service, contrôleur, nœud de bordure et programmes d'ordinateur correspondants |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4736394A1 (fr) |
| FR (1) | FR3150670A1 (fr) |
| WO (1) | WO2025003097A1 (fr) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2017200978A1 (fr) * | 2016-05-16 | 2017-11-23 | Idac Holdings, Inc. | Sélection et attribution de tranches à base de sécurité |
| US10785652B1 (en) * | 2019-09-11 | 2020-09-22 | Cisco Technology, Inc. | Secure remote access to a 5G private network through a private network slice |
| US20220141713A1 (en) * | 2020-10-30 | 2022-05-05 | Verizon Patent And Licensing Inc. | Systems and methods of application mapping for network slicing using group segmentation |
-
2023
- 2023-06-29 FR FR2306885A patent/FR3150670A1/fr not_active Withdrawn
-
2024
- 2024-06-25 EP EP24734902.0A patent/EP4736394A1/fr active Pending
- 2024-06-25 WO PCT/EP2024/067744 patent/WO2025003097A1/fr not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2017200978A1 (fr) * | 2016-05-16 | 2017-11-23 | Idac Holdings, Inc. | Sélection et attribution de tranches à base de sécurité |
| US10785652B1 (en) * | 2019-09-11 | 2020-09-22 | Cisco Technology, Inc. | Secure remote access to a 5G private network through a private network slice |
| US20220141713A1 (en) * | 2020-10-30 | 2022-05-05 | Verizon Patent And Licensing Inc. | Systems and methods of application mapping for network slicing using group segmentation |
Non-Patent Citations (5)
| Title |
|---|
| DE A. FARREL ET AL., A FRAMEWORK FOR IETF NETWORK SLICES, 15 June 2023 (2023-06-15) |
| DE J. HALPERN ET AL., SERVICE FUNCTION CHAINING (SFC) ARCHITECTURE, October 2015 (2015-10-01) |
| DE K. G. SZARKOWICZ ET AL., A REALIZATION OF IETF NETWORK SLICES FOR 5G NETWORKS USING CURRENT IP/MPLS TECHNOLOGIES, 23 May 2023 (2023-05-23) |
| DE M. BOUCADAIR ET AL., YANG DATA MODELS FOR 'ATTACHMENT CIRCUITS'-AS-A-SERVICE (ACAAS, 3 May 2023 (2023-05-03) |
| WEI Y ET AL: "Network Service Header (NSH) Metadata Type 2 Variable-Length Context Headers ;rfc9263.txt", 9 August 2022 (2022-08-09), pages 1 - 9, XP015154231, Retrieved from the Internet <URL:https://tools.ietf.org/html/rfc9263> [retrieved on 20220809] * |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4736394A1 (fr) | 2026-05-06 |
| FR3150670A1 (fr) | 2025-01-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3646557A1 (fr) | Procédé de communication quic via des chemins multiples | |
| EP3284224B1 (fr) | Procédé d'émulation dune connexion à chemins multiples | |
| FR3053197A1 (fr) | Procede de communication udp via des chemins multiples entre deux terminaux | |
| WO2008077928A1 (fr) | Procede de reservation et d'allocation dynamique de creneaux temporels dans un reseau avec garantie de service | |
| EP3739843A1 (fr) | Procédé de communication udp via des chemins multiples entre deux terminaux | |
| WO2020260813A1 (fr) | Procédé de gestion d'une communication entre terminaux dans un réseau de communication, et dispositifs pour la mise en oeuvre du procédé | |
| FR3072238B1 (fr) | Dispositif et procede de transmission de donnees | |
| EP3682601A1 (fr) | Routage de donnees dans une passerelle residentielle mettant en oeuvre l'agregation de liens | |
| EP3682600B1 (fr) | Gestion de la connexion avec d'autres passerelles residentielles d'une passerelle residentielle mettant en oeuvre l'agregation de liens | |
| WO2025003097A1 (fr) | Procédés d'accès à un service, procédé de fourniture de services, procédé de contrôle, procédé de gestion, terminal, instance de service, contrôleur, nœud de bordure et programmes d'ordinateur correspondants | |
| CA3240305A1 (fr) | Mecanismes de communication avec un service accessible via un reseau de telecommunication prenant en compte la mobilite des services, des utilisateurs et des equipements | |
| EP1432210A1 (fr) | Dispositif de contrôle de traitements associés a des flux au sein d'un reseau de communications | |
| FR3150669A1 (fr) | Procédés d’accès à un service et de fourniture de services, terminal, instance de service, et programmes d’ordinateur correspondants. | |
| FR3154268A1 (fr) | Procédés de vérification, de gestion, de contrôle, d’exécution d’une vérification de l’accessibilité d’un équipement, équipement, serveur de contrôle, contrôleur réseau, entité relais et programme d’ordinateur correspondants. | |
| EP2640004B1 (fr) | Procede de gestion des echanges de flux de donnees dans un reseau de telecommunication autonomique | |
| WO2025078597A1 (fr) | Procédés d'acheminement de données, de configuration, d'allocation d'identifiants et d'accès à un service dans un réseau de communication mettant en œuvre des tranches réseau, entités et programme d'ordinateur correspondants | |
| WO2025078594A1 (fr) | Procédés de sélection de tranches réseau adaptées à un service, de gestion d'au moins une tranche réseau et de communication, et entités configurées pour mettre en œuvre ces procédés | |
| FR3157769A1 (fr) | Procédé d’accès à un service par un dispositif de communication via au moins un réseau de communication | |
| WO2025093520A1 (fr) | Procédés et dispositifs pour la configuration et l'utilisation d'un réseau supportant des tranches réseau | |
| EP4595404A1 (fr) | Procédé de gestion du trafic de données entre une entité source et une entité destinataire, entité et programme d'ordinateur correspondants | |
| FR3153206A1 (fr) | Procédés, dispositifs et système de contrôle d’une communication dans un réseau | |
| EP2439901A1 (fr) | Procédé de traitement dans un module d'un dispositif d'accès adapté pour connecter un réseau distant à une pluralité de réseaux locaux, module et programme d'ordinateur associés |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24734902 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024734902 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2024734902 Country of ref document: EP Effective date: 20260129 |
|
| ENP | Entry into the national phase |
Ref document number: 2024734902 Country of ref document: EP Effective date: 20260129 |