Method for routing data of a session initiated between a terminal and a server

By exchanging routing identifiers and configuring session information between the terminal and the server, network slices are dynamically selected, solving the problem of inappropriate network slice allocation in existing technologies and achieving efficient and secure data routing and processing.

CN116684464BActive Publication Date: 2026-05-05ORANGE SA
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ORANGE SA
Filing Date
2018-11-29
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

In existing technologies, the allocation of network slices between terminals and servers lacks flexibility and scalability, resulting in session data not being processed correctly and intermediate devices being unable to access encrypted information, affecting the efficiency and security of data routing.

Method used

Terminals and servers receive and send routing identifiers, configure session information based on communication parameters, dynamically select appropriate network slices for data routing, ensure that data is processed through the appropriate slices, and exchange information using encryption protocols at the transport layer.

Benefits of technology

It achieves efficient and secure data routing, saves resources, improves processing speed, and ensures data privacy and security, adapting to the needs of multi-path and multi-slice sessions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684464B_ABST
    Figure CN116684464B_ABST
Patent Text Reader

Abstract

This invention relates to a method for routing data of an initialized session between a terminal and a server via a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure, the method being implemented by the terminal. The method includes the steps of: receiving from the server at least one routing identifier determined according to at least one communication parameter of the session; configuring session information based on the received at least one identifier; and transmitting to the server subsequent data of the session routed via at least one second slice corresponding to the configured information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application filed on November 29, 2018, with application number 201880077715.3 and invention title "Method for routing data of an initial session between a terminal and a server". Technical Field

[0002] The application of this invention belongs to the field of telecommunications infrastructure and related technologies to what is known in English as "network slices". Background Technology

[0003] Prior to the 4G mobile networks currently being deployed in most countries, network architectures were most commonly based on highly specific equipment dedicated to certain precise functions in both the access network and the core network, particularly those related to packet transmissions to or from mobile terminals. Until now, deployed network infrastructures used a single set of functions regardless of the type of traffic. Therefore, various session flows passed through the same set of functions (routing, addressing, flow control, naming, etc.).

[0004] Because this type of traditional architecture lacks its inherent flexibility and scalability, a more flexible architecture has been considered for the next generation of mobile networks (starting with the generation known as 5G) to allow for rapid response to highly variable demands in terms of traffic or quality of service. It should be noted that 5G networks are designed to cover both mobile and fixed networks. Therefore, the technologies involved in 5G network development are applicable to both fixed and mobile infrastructure.

[0005] Among the solutions considered, one of the most promising is a technique based on network slicing.

[0006] This is because 5G will need to support a wide range of changing use cases and meet extreme requirements (e.g., in terms of speed, energy efficiency, device variety, actor fragmentation), for which network flexibility and scalability are crucial. Network slicing technology is typically based on virtualization-related technologies and can be considered a technique for implementing specific communication path instances on the same physical infrastructure. This technology enables operators to create networks suitable for different requirements (operators, service providers, clients) and to provide solutions that meet the diverse needs of different market segments. These solutions are optimized, for example, in terms of routing functionality, performance, and isolation between applications or clients.

[0007] Currently, based on known technologies, various methods are being considered to assign network "slices" to terminals, and these methods are the subject of proposals, particularly regarding standardization (3GPP TR23.799v2.0.0, December 2016, or the evolution of wireless technologies towards 5G, 3GPP Releases 13 to 15 and higher (5G Americas, February 2017, pp. 163 to 167)).

[0008] There are no solutions that assign slices based on the deployed technology solutions or the deployment process of application vendors (also referred to as "third parties" in some documents). These third parties also play a role in the "vertical" (or "Smart City" in other contexts like healthcare) sector, also known as "Over the Top" (OTT), in the terminology used in 5G network specifications and in the regulations for Communication Service Providers (CSPs). This is because these third parties possess their own technical infrastructure that enables them to provide services to clients via the Internet and fixed or mobile networks. This technical infrastructure typically consists of servers, caches, and routing and streaming service platforms using proprietary or standardized technical solutions. It should be noted that this technical infrastructure may also utilize technologies related to "network slicing," and particularly associates slicing with traffic characteristics.

[0009] However, there is no solution to provide slice visibility at the terminal or server side. Therefore, for example, it is not possible to assign slices based on the communication characteristics of OTT applications at the transport and / or application layers (e.g., in the context of significant evolution of the transport and / or application layers, especially due to the actions of third parties).

[0010] The purpose of this invention is to overcome some of the shortcomings of currently used technologies. Summary of the Invention

[0011] The present invention aims to improve this situation by means of a method for routing data of a session initiated via a first network slice between a terminal and a server, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data, the method being implemented by the terminal and characterized in that the method includes the following steps:

[0012] - Receive from the server at least one routing identifier determined based on at least one communication parameter of the session.

[0013] - Configure session information based on at least one received identifier.

[0014] - Send the subsequent data of the session to the server via at least the second slice route corresponding to the configured information.

[0015] According to existing technology, the dynamic selection of network slices is performed by the terminal (where the terminal holds information that enables it to select slices corresponding to traffic, terminal, or application characteristics, or a combination of these information), or by the operator of the communication infrastructure. As a result of this invention, the remote server detects that the network slice selected for the session is unsuitable for the communication parameters. It is assumed here that the session can be single-path or multi-path and is characterized by end-to-end communication between the terminal and the server for one or more applications. The communication parameters of the session are characterized by information transmitted or received by one end of the session (in this case, the terminal or the server). The communication parameters are not specific to any layer in the OSI (Open Systems Interconnection) model.

[0016] The first slice selected by the terminal may be particularly unsuitable because the session data will not be processed by the correct device when it is routed. Therefore, this data may not benefit from advanced processing functions, or, for example, may not be protected. The server then determines that the terminal must use a new slice for this session. This determination is based on communication parameters appearing in the packet header, in the frame used for routing data, or in the session's application data. After the server has determined one or more new routing identifiers, it notifies the terminal of this. It should be noted that a session may be multipath-based and therefore multi-sliced, and multiple network slices will be used to route session data for a single session. For example, one slice might be used for the session's real-time data, while another slice might be used for the session's non-real-time data.

[0017] The terminal then transmits supplementary session data, thereby modifying this data by configuring session information, and thus enabling this data to be routed through one or more different slices based on the configured session information. For example, the terminal can configure information in the fields of the SFC (Service Function Chaining) protocol. Therefore, session data is transmitted through a network slice corresponding to the configured parameters, and the network manager assigns one or more slices corresponding to the configured information. The terminal itself can select one or more new network slices. In this case, the session information is one or more identifiers of the slices. According to another example, the selection of a second network slice or multiple network slices is performed by another device within the infrastructure that routes the session data.

[0018] Therefore, this method enables the terminal to route session data based on recommendations from a remote server, which can thus provide, for example, session-specific processing without systematically analyzing the content of session packets or frames, thereby saving resources and allowing for faster processing.

[0019] Due to specific characteristics, the session is encrypted by the terminal and decrypted by the server.

[0020] The encryption and decryption of a session by these two ends (i.e., the terminal and the server) means that intermediate devices cannot access certain information transmitted between the terminal and the server. Therefore, information used for data routing is typically not encrypted; instead, information related to the application is encrypted. Since the server is the only device that can access the encrypted data, it can use the encrypted data to influence the selection of network slices for routing data within the infrastructure.

[0021] Depending on specific characteristics, the session is initialized by the terminal by configuring default session information.

[0022] If the terminal does not obtain information related to the routing identifier, the session data must still be transmitted through the first slice of the communication infrastructure. If the terminal is not configured with any information, the communication network manager defaults to the first slice. Therefore, the terminal selects default information, such as that corresponding to the application or remote server of the session, so that session data transmitted before or without the routing identifier being sent by the remote server benefits from the first network slice used for routing data.

[0023] Based on specific characteristics, this session information is a data element related to NSSAI information.

[0024] Session information configured by the terminal can advantageously be related to NSSAI (Network Slice Selection Auxiliary Information) information. This information, defined in 3GPP (document TS 23.501, version 1.5.0, November 13, 2017), can be advantageously used, particularly due to its potential widespread use in communication networks. Therefore, data including this NSSAI information can be routed via network slicing implemented by the infrastructure manager, independent of the contract or relationship between the infrastructure manager and the end user.

[0025] Depending on specific characteristics, the terminal stores at least one identifier received based on the communication parameters of the session in its memory.

[0026] To limit the exchange between the server and the terminal, the terminal can advantageously store routing identifiers received for previous sessions, along with the corresponding session's communication parameters, so that these identifiers can be reused in future sessions with the same communication parameters. Therefore, by configuring session information corresponding to the stored identifiers, the first transmitted data can be routed via a network slice suitable for that session's data. However, for example, if another slice is more suitable, or if the first slice initially used for routing the data encounters a problem, the server can transmit a different identifier for the new session to the terminal.

[0027] The various aspects of the routing methods described above can be implemented independently of each other or in combination with each other.

[0028] According to a second aspect, the present invention also relates to a method for determining at least one routing identifier for data of a session initiated between a terminal and a server via a first network slice, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data, the method being implemented by the server and characterized in that the method comprises the following steps:

[0029] - Determine at least one routing identifier based on at least one communication parameter of the session.

[0030] - Transmit at least one determined identifier to the terminal.

[0031] - Receive subsequent data for the session from the terminal via at least the second slice route.

[0032] Upon receiving data transmitted from a terminal, the server identifies that the first network slice used for routing the data is unsuitable. For example, if a set of processes is associated with a network slice, the result of the terminal selecting an unsuitable first network slice is that the processes are not applied to the session data. Based on communication parameters (such as the terminal's address, quality of service parameters, or transport protocol parameters), the server determines that a more suitable second slice (or multiple second slices) must be selected, and determines this new slice based on different parameters. This method allows the server to dynamically update the use of one or more second network slices for session data transmitted by the terminal. For example, this method can be implemented to account for problems arising in the infrastructure, or new requests expressed by the entity responsible for the server or an external entity that has made a request to the server. Furthermore, in the case of encrypted data sessions, the server is the only entity capable of accessing the encrypted communication parameters, thus granting it the authority to determine routing identifiers that its intermediary devices do not possess.

[0033] Depending on the specific characteristics, this at least one parameter is related to the transport layer of the session.

[0034] The transport layer of communication networks is evolving rapidly and includes increasingly more basic processing functions. Multipath transport protocols are also under development. Servers can advantageously leverage the richness of transport parameters to determine one or more second network slices for routing data based on these parameters. These parameters are also increasingly encrypted, and it is useful for servers to access these parameters, which they have already decrypted, to adapt data processing by determining routing identifiers for routing data through one or more network slices. TLS (Transport Layer Security) is one of the leading transport protocols, in particular, providing security for transmitted data. Because data transmitted under TLS can only be accessed by the endpoint and server, servers can, for example, use TLS parameters to determine routing identifiers suitable for the TLS protocol; this data may be shared by multiple applications.

[0035] Depending on specific characteristics, this at least one parameter is related to the QUIC protocol.

[0036] The QUIC (Quick UDP Internet Connections) transport protocol, specified in the October 13, 2017 document "draft-ietf-quic-transport-07", is an increasingly widely used transport protocol in communication networks. This protocol includes a wealth of information, including information related to multiple attachment contexts, security information, and data flow information. Its richness in basic functionality and its growing use make this protocol particularly suitable for determining route identifiers.

[0037] Depending on specific characteristics, this at least one parameter is related to the protocol version of the transport layer.

[0038] Transport protocols (especially those in the specification process within standardization bodies) evolve in a fairly regular manner, consistent with the proposed versions. Therefore, a version of a protocol may include quality of service or security parameters not present in previous versions. This is particularly true of different versions of the QUIC protocol. Consequently, depending on the characteristic parameters of the protocol version, session data may require specific processing. Protocol versions can advantageously provide information about the required processing, and the determination of routing identifiers based on protocol versions can be tailored to the requirements of the server manager.

[0039] Based on specific characteristics, at least one identifier is emitted in the data element of the transport protocol.

[0040] To transmit a defined route identifier to the endpoint, the server can use a transport protocol. In fact, transport protocols are evolving quite rapidly and regularly include new features. This is the case with protocols such as QUIC or MPTCP (MultiPath Transport Control Protocol). Furthermore, transport protocols are end-to-end protocols, meaning that if the protocol is encrypted, it cannot be modified. Therefore, it seems useful to transmit the route identifier within the transport protocol to ensure its reliable arrival without modification at the endpoint, which can then use that route identifier to configure session information.

[0041] The various aspects of the determination method described above can be implemented independently of each other or in combination with each other.

[0042] According to a third aspect, the present invention relates to an apparatus for routing data of a session initiated via a first network slice between a terminal and a server, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data, the apparatus being implemented by the terminal and characterized in that the apparatus comprises:

[0043] - A receiver for receiving from the server at least one routing identifier determined based on at least one communication parameter of the session.

[0044] - A configuration module for configuring session information based on at least one received identifier.

[0045] - A transmitter used to transmit subsequent data of the session to the server via at least a second slice route corresponding to the configured information.

[0046] This apparatus, which is capable of implementing the above-described routing method in all its embodiments, is intended for implementation in terminal-type end devices.

[0047] According to a fourth aspect, the present invention also relates to an apparatus for determining at least one routing identifier for data of a session initiated between a terminal and a server via a first network slice, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data, the apparatus being implemented by the server and characterized in that the apparatus comprises:

[0048] - A determination module for determining at least one routing identifier based on at least one communication parameter of the session.

[0049] - A transmitter for transmitting at least one determined identifier to the terminal.

[0050] - Receiver, used to receive subsequent data of the session from the terminal via at least a second slice route.

[0051] This apparatus is capable of implementing the above-described determination method in all its embodiments. This apparatus is intended for implementation in end devices of the data server type.

[0052] According to a fifth aspect, the invention also relates to a system for routing data of a session initiated between a terminal and a server via a first network slice, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data:

[0053] -Including terminals with routing devices,

[0054] -Includes servers that determine the device.

[0055] The present invention also relates to a computer program comprising instructions for implementing the above-described routing method when the processor executes the program.

[0056] The present invention also relates to a computer program comprising instructions for implementing the steps of the determination method described above when the processor executes the program.

[0057] These programs can use any programming language and can be in the form of source code, object code, or code in between, such as partially compiled code or any other desired form of code.

[0058] The present invention also proposes a computer-readable data medium comprising instructions of a computer program as mentioned above.

[0059] The data medium can be any entity or device capable of storing programs. For example, the medium can include storage devices such as ROM (e.g., CD ROM or microelectronic circuit ROM) or magnetic recording devices (e.g., disk (floppy disk) or hard disk).

[0060] On the other hand, the data medium can be a transmissible medium, such as electrical or optical signals, which can be routed via cables or optical fibers, radio, or other means. The program according to the invention can specifically be downloaded from a network such as the Internet.

[0061] Alternatively, the data medium may be an integrated circuit incorporated into the program, which is adapted to perform the methods in question or to be used during the execution of these methods.

[0062] According to a sixth aspect, this disclosure also relates to a routing method for routing data of an HTTP session initiated via a first network slice between a terminal and an application server, the first network slice corresponding to a set of data processing functions of a communication infrastructure, the routing method being implemented by the terminal and the routing method comprising: receiving from the application server via an HTTP protocol at least one routing identifier determined based on at least one communication parameter of the session, configuring session information based on the received at least one routing identifier, and transmitting subsequent data to the application server via a route corresponding to at least a second slice of the configured session information.

[0063] According to the seventh aspect, this disclosure also relates to a method for determining at least one routing identifier for data of an HTTP session initiated via a first network slice between a terminal and an application server, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data, the method being implemented by the application server and the method comprising: determining at least one routing identifier based on at least one communication parameter of the session, transmitting the determined at least one identifier to the terminal via an HTTP protocol, and receiving subsequent data from the terminal routed via at least a second slice.

[0064] According to the eighth aspect, this disclosure also relates to an apparatus for routing data of an HTTP session initiated via a first network slice between a terminal and an application server, the first network slice corresponding to a set of data processing functions of a communication infrastructure, the apparatus being implemented by the terminal, wherein the apparatus comprises: a receiver configured to receive, via HTTP protocol, at least one routing identifier determined based on at least one communication parameter of an end-to-end session from the application server; a processor configured to configure session information based on the received at least one identifier; and a transmitter configured to transmit subsequent data to the application server via a route through at least a second slice corresponding to the configured session information.

[0065] According to a ninth aspect, this disclosure also relates to an apparatus for determining at least one routing identifier for data of an HTTP session initiated via a first network slice between a terminal and an application server, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data, the apparatus being implemented by the application server, wherein the apparatus comprises: a processor configured to determine at least one routing identifier based on at least one communication parameter of the session; a transmitter configured to transmit the determined at least one identifier to the terminal via an HTTP protocol; and a receiver configured to receive subsequent data from the terminal routed via at least a second slice.

[0066] According to a tenth aspect, this disclosure also relates to a non-transitory computer-readable recording medium including a computer program recorded thereon, the computer program including instructions that, when executed by a processor of a terminal, are configured to implement a routing method for routing data between the terminal and an application server via an HTTP session initialized through a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure, wherein the instructions configure the terminal to: receive from the application server at least one routing identifier determined based on at least one communication parameter of the session using the HTTP protocol, configure session information based on the received at least one identifier, and transmit subsequent data to the application server via a route through at least a second slice corresponding to the configured session information.

[0067] According to the eleventh aspect, this disclosure also relates to a non-transitory computer-readable recording medium including a computer program recorded thereon, the computer program including instructions, when executed by a processor of an application server, for implementing a determination method for determining at least one routing identifier of data of an HTTP session initiated between a terminal and an application server via a first network slice, the first network slice corresponding to a set of functions of a communication infrastructure for processing the data, wherein the instructions configure the application server to: determine at least one routing identifier based on at least one communication parameter of the session, transmit the determined at least one identifier to the terminal via an HTTP protocol, and receive subsequent data from the terminal routed via at least a second slice. Attached Figure Description

[0068] Other advantages and features of the invention will become more apparent after reading the following description of specific embodiments of the invention, given by way of simple illustrative and non-limiting examples, and the accompanying drawings, in which:

[0069] - Figure 1 A simplified view of a communication infrastructure implementing a data routing method according to one aspect of the present invention is shown.

[0070] - Figure 2 A schematic diagram of a data routing method according to a first embodiment of the present invention is shown.

[0071] - Figure 3 A schematic diagram of a data routing method according to a second embodiment of the present invention is shown.

[0072] - Figure 4 A schematic diagram of a data routing method according to a third embodiment of the present invention is shown.

[0073] - Figure 5An example of the structure of a routing device according to one aspect of the present invention is shown;

[0074] - Figure 6 An example of the structure of a determining device according to one aspect of the present invention is shown. Detailed Implementation

[0075] The remainder of the specification presents examples of several embodiments of the invention in communication infrastructure (which may be fixed and / or mobile).

[0076] First, you should refer to Figure 1 The figure shows a simplified view of a communication infrastructure implementing a data routing method according to one aspect of the present invention.

[0077] exist Figure 1 In this example, two terminals, 51 and 53, are attached to communication infrastructure 10. At terminal 51, three applications, App1, App2, and App3, are active. Data flows related to applications App1 and App2 are routed by transport layer Trans1. Data flows for application App3 at terminal 51 are routed through another transport layer, Trans2. Transport layers Trans1 and Trans2 can be completely different; that is, they can be based on different protocols, such as TCP (Transport Control Protocol) and UDP (User Datagram Protocol). According to another example, these two transport layers, Trans1 and Trans2, can be different versions of the same protocol, such as QUIC version 1 and QUIC version 2. According to yet another example, Trans1 and Trans2 can be the same protocol version but with different configurations. At terminal 53, data flows for applications App4 and App5 are routed by transport layers Trans4 and Trans3, respectively. In the remainder of this document, data for application App1 on transport layer Trans1 will be represented as data App1 / Trans1.

[0078] Assume that application App1 / Trans1 on terminal 51 establishes a data session with server 40 installed on local network 42. This server can be, for example, an HTTP (Hypertext Transfer Protocol) server, and local infrastructure 42 can be a server cluster. Application App2 / Trans1 establishes a session with server 40. Application App3 / trans2 establishes a session with server 40. Application App5 / trans3 establishes a data session with server 50 on local network 52. Application App4 / Trans4 establishes a session with server 60 on local network 62. Like networks 52 and 62, local network 42 may, without limitation, include devices for processing data streams, such as firewalls or optimization features.

[0079] Communication infrastructure 10 is organized into slices, allowing data flows with common characteristics in terms of routing, quality of service, or security to be routed through the same slice. It should be noted that the communication infrastructure manager 10 is responsible for structuring the slices and associating data flows across different slices. In alternative arrangements, infrastructure slices may be implemented solely within infrastructure 10, or they may be instantiated within infrastructure 10 as well as terminals 51 and 53 and / or local networks 42, 52, 62. Figure 1 In this example, assume that data stream App1 / Trans1 is routed to server 40 via network slice Tr1. Data streams App2 / Trans2 and App3 / Trans2 are routed to the same server 40 via slice TR2. Data stream App5 / Trans3 is routed to server 40 via slice TR3, and data stream App4 / Trans4 is routed to server 60 via slice TR4.

[0080] It should also be noted that the same server can host multiple applications, such as Figure 1 The same applies to server 40, which hosts applications App1, App2, and App3. The implemented network slices can be specific to infrastructure 10. In this case, the manager does not transmit any information to the terminals or servers through the network slices of the infrastructure. If, for example, infrastructure manager 10 is also the manager of the terminals and / or servers, or if a contract has been entered into between the various managers, the terminals and / or servers may be aware of the slices deployed by infrastructure manager 10.

[0081] refer to Figure 2 The diagram shows a schematic of a data routing method according to a first embodiment of the present invention.

[0082] Figure 2The purpose of the outline diagram is to describe the implementation phases of the method in a communication infrastructure in a general way.

[0083] In phase P1, the terminal initiates a session with the server. This can be an application session of type HTTP or FTP (File Transfer Protocol), or it can be, but is not limited to, a P2P (Point-to-Point) session.

[0084] By default, during session initialization, if the terminal does not have session information sent by the server, the terminal configures default session information in the message sent to the server. As an example, this session information can also be the latest information obtained from the server. This information can be a specific field of a service chaining protocol (such as SFC), or a data element added to a protocol (such as a transport protocol or application protocol), which can be used by the communication infrastructure that routes data to the server.

[0085] If the session information cannot be directly used to route session data via slices, it is interpreted by a network device responsible for routing the flow of various sessions to slices within the communication infrastructure. Upon receiving session data transmitted by the terminal, this device establishes a correspondence between the session information and the slice, so that the session data is transmitted via a slice called the first slice. In this case, the session data is routed via the first default slice according to default information configured by the terminal. In the described example, the terminal adds session information NSSAI1, and the communication infrastructure device adds a first slice identifier that corresponds to the session information NSSAI1 configured by the terminal. For example, the terminal adds this session information to a field of the transport protocol used for routing session data.

[0086] In phase P2, the server receives the session data transmitted by the terminal in phase P1 and determines that the terminal must use a new routing identifier for the remaining data of that session. To determine that the terminal must use a new routing identifier, the server analyzes the session's communication parameters. Among these parameters, the server identifies, for example, session information NSSAI1 added by the terminal, and other fields related to the possible transport protocol and / or application protocol. Different examples are shown in... Figure 3 and Figure 4 As shown in the diagram. If the identifier (i.e., the first slice identifier used by the communication infrastructure) has already been sent to the server, the server can also use it to determine this identifier.

[0087] In phase P3, the server determines a routing identifier corresponding to the parameters analyzed in phase P2. The server manager already knows the network slices implemented in the communication network routing session data and their characteristics. The server selects at least one routing identifier whose characteristics correspond to the session parameters and transmits this routing identifier to the terminal. This routing identifier can be an identifier of a slice of the communication infrastructure, but it can also be a routing identifier belonging to both the server and the terminal, for which a mapping must be established between the identifiers and the slice identifiers of the communication infrastructure. The server transmits the identifier to the terminal in the protocol field used for the session, or alternatively, uses a specific protocol to transmit this information. If the session is an HTTP / TCP type session, the server can send this information using either the HTTP or TCP protocol, or even different protocols.

[0088] In phase P4, upon receiving a new identifier transmitted by the server, the terminal configures new session information NSSAI2 corresponding to the received routing identifier. According to the example, this session information can be exactly the same as the routing identifier. It can also be information to be updated in the protocol, such as quality of service parameters. Subsequently, session data is transmitted along with this updated session information.

[0089] In phase P5, the terminal transmits session data along with the updated session information, enabling the session data to be routed through a second network slice corresponding to the characteristics of the session, which are formalized by the session information. This session information is interpreted by network devices, which add a second slice identifier to the data carried in the communication infrastructure, enabling it to be routed to a slice suitable for the session characteristics in phase P6.

[0090] It should be noted that server and communication infrastructure devices may select the routing identifier and second slice identifier based on session information. Therefore, these two entities must be coordinated in advance to ensure that their respective choices are consistent.

[0091] Now refer to Figure 3 The figure shows a schematic diagram of a data routing method according to a second embodiment of the present invention.

[0092] In the initialization phase of this method, server 50App1 sends a message to device 80Acc1 of communication infrastructure 10 in step E1 so that message M0 transmits the routing identifier that it must interpret to device 80, thereby routing the data of the data session to server 50. For simplicity, message M0 is sent directly to Figure 3The device 80 is mentioned above. Alternatively, message M0 can be sent to the management server of infrastructure 10, which in turn transmits this information to the various access devices of infrastructure 10, particularly to prevent direct communication between individual servers and these access devices. Message M0 may also include session characteristics related to routing identifiers, in a manner that allows device 80 to select network slices suitable for these session characteristics. According to an example, the routing identifier may correspond to the identifier of the slice used in the communication infrastructure and / or correspond to data related to routing options, for example, when a CDN (Content Delivery Network) architecture is implemented. Upon receiving message M0 in step E2, device 80 can route session data to server 50 via the network slices of the communication infrastructure.

[0093] In a corresponding manner, server 40App2 sends message M'0 to device 90 in step E3, and device 90 receives the message in step E4. Therefore, server 40 is able to route data to server 40. For simplicity, the exchange is not shown in the figure, but each server 50 and 40 notifies device 90 and 80 respectively in a corresponding manner.

[0094] In step E5, terminal 51 (Term 1) registers itself on the communication infrastructure by sending message M1 to device 90. In this message, terminal 51 informs device 90 of the default session information it is using, so that device 90 pre-assigns a default network slice. When device 90 receives message M1 in step E6, it transmits this information to other devices, so that any device receiving data from the terminal can associate with the default network slice.

[0095] In step E7, terminal 51 sends message M2 to server 40App2. This message M2 is a HELLO message of type HTTP / QUIC / UDP / IP. Message M2 is routed in communication infrastructure 10 according to default session information added by terminal 51, and device 90 of the communication infrastructure associates a slice for this session information. Message M2 (which is initially sent to device 90 and then retransmitted to server 40) includes QUIC protocol transmission information, containing information related to the version of the QUIC protocol and the signaling compression algorithm version used. Based on this received data, server 40App2 detects that the version of the QUIC protocol used is inappropriate, for example, because a newer version exists or because the version is not suitable for the application. The server also wants subsequent data sent from the terminal to be transmitted via a second network slice that is more suitable for the characteristics of the application. Alternatively, server 40 uses metadata-type information present in the data routed by the QUIC protocol, such as CDNI (Content Distribution Network Information) type information, to determine the routing identifier. The data may be related to the QUIC protocol, or it may be application data routed using the QUIC protocol. Therefore, the session information (and here corresponding to the QUIC version) present in message M2 must be modified by terminal 51. In step E9, server 40 determines a new routing identifier so that the session data can be routed through a more suitable second slice of communication network 10.

[0096] According to the example, if the routing identifier sent to terminal 51 has not yet been transmitted to device 90 in step E3, the server transmits the routing identifier along with the associated characteristics to device 90 in message M3 in step E10 to ensure that data with the characteristics corresponding to this identifier is routed in the appropriate second network slice. Upon receiving this message in step E11, device 90 is able to route the session data updated by the terminal based on the received routing identifier in the second network slice of infrastructure 10.

[0097] In step E12, terminal 40 transmits message M4, which includes a routing identifier, to server 51. Therefore, subsequent data for the session initiated by terminal 51 by sending message M2 is routed via a second network slice to match the session's characteristics. According to this example, server 40 transmits an HTTP / QUIC / UDP / IP message including information about the routing identifier to be used for the session, which is inserted into a data element of the QUIC protocol. In this example, server 40 transmits information about NSSAI to terminal 51, which receives this information in step E13. Server 40 also instructs the terminal in message M4 to use the latest version of the QUIC protocol. The routing identifier will consist of this NSSAI information and the version of the QUIC protocol to be used.

[0098] In step E14, terminal 51 configures session information based on the routing identifier received in message M4. According to the example, terminal 51 updates the QUIC protocol version based on the content of message M4 and inserts the identifier NSSAI into the QUIC protocol data element. In this example, the session information is exactly the same as the received routing identifier; however, according to other examples, the session information may differ from the received routing identifier. Especially if terminal 51 cannot insert the received NSSAI information because it does not support this option, the terminal updates the QUIC version and may also insert supplementary information into fields such as the flow label and / or traffic class fields in the IPv6 datagram header or the type of service field in the IPv4 datagram header.

[0099] In step E15, terminal 51 updates its registration on the communication infrastructure by sending message M5 to device 90. In this message, terminal 51 notifies device 90 of the session information configured in step E14, enabling device 90 to assign a second network slice. Upon receiving message M5 in step E16, device 90 transmits this information to other devices in infrastructure 10, enabling any device receiving data from the terminal to associate the second network slice associated with the session information. Alternatively, this communication with other devices can be conducted via management server 70 of infrastructure 10, which then notifies the individual access devices. According to this alternative, device 90 sends message G1, including the session information, to management server 71 in step F1, which retransmits it to device 80 in step F3 upon receiving the session message in step F2. Device 80 accepts message G1 in step F4 and is able to associate the second slice with the message including the session information received from terminal 51.

[0100] According to the alternative, in step E17, device 90 notifies server 40 of the update of the second network slice used for session data by transmitting message M6. This message M6 includes session information configured by terminal 51 and the associated slice, which allows server 40 to ensure that device 40 is routing session data through the appropriate slice, and also to know the session information configured by terminal 51 for the session.

[0101] In step E19, according to an alternative, the terminal stores the routing identifier received for the session. This storage allows the terminal to directly configure appropriate session information when initiating a new session with the exact same communication parameters as the previous session. Therefore, the first data of this new session is directly routed through a network slice corresponding to the characteristics of this new session.

[0102] In step E20, terminal 51 transmits session data to server 40 in message M7. This data is updated with session information configured by terminal 51. This data is transmitted via communication infrastructure 10, or more precisely device 90, which routes the session data to server 40 through a second network slice suitable for the characteristics of the session.

[0103] According to an alternative, when the infrastructure device 90 associates a slice with session information of message M7 transmitted by the terminal, it stores the data of the received message M7 in memory, making it possible to associate the same slice with a session having the same data. For example, device 90 can store the data of message M7 (source IP address, destination IP address, source port, destination port, protocol, version, slice identifier, TLS session ticket, QUIC connection identifier) ​​in memory to enable association of the message with the selected slice. For example, some QUIC messages use short headers that do not include a version field, but they can still be associated with that slice because, for example, data associated with the slice selected for message M7 was stored in a previous session. Additionally, the stored data can also be advantageously used to assign slices to messages transmitted from server 40 to terminal 51.

[0104] When server 40 receives message M7 in step E21, it accepts the session data transmitted by terminal 51 and also checks, if necessary, whether the session information configured by the terminal corresponds to the routing identifier transmitted in message M4, referring to message M6. According to this embodiment, server E21 checks whether the QUIC protocol version and NSSAI information correspond to its previously transmitted data elements.

[0105] Now refer to Figure 4 The figure shows a schematic diagram of a data routing method according to a third embodiment of the present invention.

[0106] Steps E1 to E4 and Figure 3 The corresponding steps are exactly the same.

[0107] In step E'5, terminal 53Term2 registers itself on device 80Acc2 by sending message M'1. In the case of a 5G network, this registration step enables terminal 53 to register itself, in particular, on NGRAN (New Generation Radio Access Network), and upon receiving message M'1 in step E'6, enables NGRAN to select an AMF (Access and Mobility Management Function) device according to the 3GPP TR 23.799 specification (version 14.0, December 16, 2016).

[0108] In step E'7, terminal 53 sends message M'2 to server 50 Serv App2. Message M'2 is a (HTTP / 2) / TLS / IP message. Upon receiving message M'2, server 50 analyzes the communication parameters of message M'2. Specifically, the server checks the parameters of the TLS transport protocol and the HTTP / 2 protocol of message M'2 sent by terminal 53.

[0109] Specifically, the communication parameters of the TLS protocol, as defined in Section 5 of document IETF RFC 8095 (March 2017) and IETF document https: / / tools.ietf.org / html / draft-pauly-taps-transport-security-00 (July 3, 2015), are analyzed. After receiving message M'2 in step E'8, the server also analyzes HTTP / 2 parameters, as defined in document IETF RFC 7540 (May 2015). It should also be noted that terminal 53 has already used the default first network slice identifier to transmit message M'2. According to this alternative, terminal 53 itself inserts the first network slice identifier, which the communication infrastructure 10 can use to route data transmitted by terminal 53.

[0110] In step E'9, the server has analyzed the various parameters and has found that the network slice that routes message M'2 (whose identifier has already been obtained in message M'2) is not suitable for certain TLS and / or HTTP / 2 parameters of message M'2. Based on these parameters, server 50 determines a new routing identifier for subsequent messages to be transmitted by terminal 53 for this (HTTP / 2) / TLS / IP session. According to this example, the determined routing identifier takes into account parameters such as encryption (TLS), flow control, HTTP / 2 application stream multiplexing, and compression parameters. According to another example, and to optimize the determination of the routing identifier, server 50 only considers the protocol version used to determine the routing identifier, since a set of parameters corresponds to a protocol version. By referring to the protocol version in message M'2 received from terminal 53, server 50 knows whether a certain number of the parameters defined in the above-referenced documents are present or absent in message M'2.

[0111] Steps E'10 to E'13 are equivalent to Figure 3 Steps E10 to E13 differ only in that message M'4 includes a routing identifier and communication parameters to be updated for the terminal. This routing identifier includes an identifier of a slice of communication network 10. Alternatively, server 50 can determine multiple routing identifiers, allowing data transmitted by the terminal to be routed through multiple network slices within the communication infrastructure, referred to as second slices. This alternative is facilitated by the development of multipath protocols and the possibility of attaching a terminal to multiple communication infrastructures simultaneously.

[0112] Upon receiving message M'4, in step E'13, terminal 53 configures the second slice identifier received in message M'4 in the data session message to be transmitted to server 50. This second slice identifier replaces the initially used default first slice identifier. Terminal 53 also updates the communication parameters transmitted by server 50. This update is optional. This is because if the terminal cannot use these parameters, it cannot configure them in the message to be transmitted.

[0113] Steps E'15 to E'19 correspond to Figure 3 Steps E15 to E19.

[0114] In step E'20, terminal 53 transmits session data to server 50, which has been configured using a second network slice identifier of communication infrastructure 10 received from server 50. Specifically, this embodiment is implemented either when terminal 53, server 50, and communication infrastructure 10 are managed by a single manager, or when the managers of terminal 53, server 50, and infrastructure 10 are working collaboratively. Alternatively, terminal 53 can manage multiple network slices and transmit session data through one or more second network slices (whose identifiers have been transmitted to the terminal by server 50).

[0115] Figure 2 , Figure 3 and Figure 4 The embodiments are not exclusive, and combinations of these embodiments are possible.

[0116] refer to Figure 5 An example of the structure of a routing device according to one aspect of the present invention is shown.

[0117] The routing device 100 implements a routing method, and different embodiments of the routing method have been described above.

[0118] Such a device 100 can be implemented in a terminal or more generally in an infrastructure access device (fixed terminal, mobile terminal, or box). The access device can be equipment of a residential or enterprise customer connected to a fixed or mobile network.

[0119] For example, device 100 includes a processing unit 106 equipped with, for example, a microprocessor μP and controlled by a computer program 105 stored in memory 107 and implementing the routing method according to the invention. During initialization, the code instructions of the computer program 105 are loaded into, for example, RAM memory before being executed by the processor of processing unit 106.

[0120] This device 100 includes:

[0121] - Receiver 120, configured to receive from the server at least one routing identifier determined based on at least one communication parameter of the session.

[0122] - Configuration module 101, used to configure session information based on at least one received identifier.

[0123] - Transmitter 110 is used to transmit subsequent data of the session to the server via at least a second slice route corresponding to the configured information.

[0124] refer to Figure 6An example of the structure of a determining device according to one aspect of the present invention is shown.

[0125] The routing device 200 implements a determination method, and different embodiments of this determination method have been described above.

[0126] Such a device 200 can be implemented in a server or more generally in an end device capable of establishing a session with a terminal.

[0127] For example, device 200 includes a processing unit 206 equipped with, for example, a microprocessor μP and controlled by a computer program 205 stored in memory 207 and implementing the routing method according to the invention. During initialization, the code instructions of the computer program 205 are loaded into, for example, RAM memory before being executed by the processor of processing unit 206.

[0128] This device 200 includes:

[0129] - Determine module 201, for determining at least one routing identifier based on at least one communication parameter of the session.

[0130] - Transmitter 210, for transmitting at least one determined identifier to the terminal.

[0131] - Receiver 220, for receiving subsequent data of the session from the terminal via at least a second slice route.

[0132] The implementation of the routing and determination methods is effective for any type of infrastructure (whether fixed or mobile), including hybrid fixed and mobile networks where terminals are simultaneously attached to both fixed and mobile infrastructure. Multipath sessions, in particular, enable improved data transmission speed and data routing reliability. The routing methods allow for the implementation of multipath architectures and enable the selection of network slices based on multiple distinct paths or alternatively multiple network slices, each slice allowing data to be routed via one or more paths.

[0133] Therefore, even if the terminal is multi-attached, network slices can be assigned to the terminal for a given session, regardless of the network type. Besides multi-attachment, another trend in infrastructure evolution involves the confidentiality of communications, and therefore, the encryption of data. This approach is particularly suitable for this situation because, with only a few exceptions related to requirements typically associated with security features deployed by governments, the intermediate device cannot access the so-called payload information transmitted by the terminal and / or server. Based on the contributions of the terminal and server to assigning network slices to a given traffic, the routing method is perfectly applicable to encrypted communications. The intermediate device routing the traffic still contributes to the method through exchanges with the terminal and / or server, but without needing to decrypt data transmitted in fields intended for use by one or more well-defined recipients.

Claims

1. A routing method for routing data of an initialized session between a terminal and an application server via a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure, the routing method being implemented by the terminal and the routing method comprising: Receive at least one routing identifier determined based on at least one communication parameter of the session from the application server using the Hypertext Transfer Protocol (HTTP). Configure session information based on at least one received routing identifier, and Subsequent data is transmitted to the application server via at least a second network slice route corresponding to the configured session information.

2. The routing method as described in claim 1, wherein, The session is encrypted by the terminal.

3. The routing method as described in claim 1, wherein, The session is initialized by the terminal by configuring default session information.

4. The routing method as described in claim 1, wherein, The session information is a data element related to the Network Slice Selection Assistance Information (NSSAI) information.

5. The routing method of claim 1, further comprising the terminal storing the at least one routing identifier received based on at least one communication parameter of the session in a memory.

6. The routing method as described in claim 1, wherein the session is an HTTP session.

7. A method for determining at least one routing identifier for determining data of an initialized session between a terminal and an application server via a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure, the method being implemented by the application server and the method comprising: At least one routing identifier is determined based on at least one communication parameter of the session. Transmit at least one determined routing identifier to the terminal using the Hypertext Transfer Protocol (HTTP) protocol, and Receive subsequent data from the terminal via at least a second network slice route.

8. The determination method as described in claim 7, wherein, The at least one communication parameter is related to the transport layer of the session.

9. The determining method as described in claim 7, wherein, The at least one communication parameter is related to the Quick User Datagram Protocol Internet Connection (QUIC) protocol.

10. The determination method as described in claim 7, wherein, The at least one communication parameter is related to the protocol version of the transport layer.

11. The determination method as described in claim 7, wherein, The at least one routing identifier is transmitted in the data element of the transport protocol.

12. The determination method of claim 7, wherein the session is an HTTP session.

13. An apparatus for routing data of an initialized session between a terminal and an application server via a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure, the apparatus being implemented by the terminal. The device includes: The receiver is configured to receive, via the Hypertext Transfer Protocol (HTTP) protocol, at least one routing identifier determined based on at least one communication parameter of a session from the application server. The configuration module is configured to configure session information based on at least one received route identifier, and The transmitter is configured to transmit subsequent data to the application server via at least a second network slice route corresponding to the configured session information.

14. The apparatus of claim 13, wherein the session is an HTTP session.

15. An apparatus for determining at least one routing identifier for data of an initialized session between a terminal and an application server via a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure, the apparatus being implemented by the application server, wherein the apparatus comprises: The module is configured to determine at least one route identifier based on at least one communication parameter of the session. The transmitter is configured to transmit at least one determined routing identifier to the terminal using the Hypertext Transfer Protocol (HTTP) protocol, and The receiver is configured to receive subsequent data from the terminal via at least a second network slice route.

16. A terminal, comprising the means for routing data of an initialized session between the terminal and an application server as described in claim 13.

17. A non-transitory computer-readable recording medium including a computer program recorded thereon, the computer program including instructions that, when executed by a processor of a terminal, are configured to implement a routing method for routing data of an initialized session between the terminal and an application server via a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure. The instructions therein configure the terminal as follows: At least one routing identifier determined by receiving at least one communication parameter based on a session from the application server using the Hypertext Transfer Protocol (HTTP). Configure session information based on at least one received routing identifier, and Subsequent data is transmitted to the application server via at least a second network slice route corresponding to the configured session information.

18. A non-transitory computer-readable recording medium including a computer program recorded thereon, the computer program including instructions that, when executed by a processor of an application server, are configured to implement a determination method for determining at least one routing identifier for data of an initialized session between a terminal and an application server via a first network slice, the first network slice corresponding to a set of data processing functions of a communication infrastructure. The instructions therein configure the application server as follows: Determine at least one routing identifier based on at least one communication parameter of the session. Transmit at least one determined routing identifier to the terminal using the Hypertext Transfer Protocol (HTTP) protocol, and Receive subsequent data from the terminal via at least a second network slice route.

Citation Information

Patent Citations

  • Security-based slice selection and assignment

    WO2017200978A1