DEVICES AND METHODS FOR CONNECTION MANAGEMENT OF A TERMINAL DEVICE IN A COMMUNICATION NETWORK

DE602019082837T2Active Publication Date: 2026-03-25ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2019-07-10
Publication Date
2026-03-25

AI Technical Summary

Technical Problem

Existing 5G network architectures lack flexibility in managing network slices for third parties, as access control and authentication are performed before network slice selection, limiting the ability to adapt to the specific needs of different entities.

Method used

A method and system for decoupling access control and authentication from network functions, allowing third parties to define their own access control policies through software control gateways instantiated within the operator's network, enabling dynamic adaptation and update of access control mechanisms.

Benefits of technology

Enhances network architecture flexibility by allowing third parties to customize access control and authentication policies, simplifying infrastructure and enabling efficient management of network slices without laborious interventions.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Background of the invention

[0001] The invention relates to the general field of telecommunications.

[0002] It relates more specifically to the control of access to an operator's network when communication devices benefit from network connectivity offered via that network but provided by a third party distinct from the network operator.

[0003] The invention is thus applied in a preferential but not limiting way to connected objects (whatever the nature of these objects, for example a digital tablet, a connected light bulb, a connected vehicle, a sensor, etc.) incorporating network connectivity which is not offered directly by the network operator supporting this connectivity but by a third party.

[0004] With fifth-generation (5G) telecommunications networks and the advent of Network Function Virtualization (NFV) technologies, the infrastructures hosting these network functions (from radio functions to routing functions) are intended to take the form of standard IT infrastructures, capable of hosting any virtualized network function as computer code executable on a standard operating system.More specifically, the trend is towards hosting infrastructure dedicated to running centralized network functions in centralized data centers, while infrastructure dedicated to running edge network functions (such as radio base station functions) is intended to be hosted by smaller, local data centers, as proposed in particular in the work carried out by ETSI on "Multi-access Edge Computing" (or MEC) described on the web page http: / / www.etsi.org / technologies-clusters / technologies / multi-access-edge-computing.

[0005] In this context of virtualization, telecommunications networks are increasingly opening up to third parties, meaning actors other than the network operators. In new 5G network architectures, the plan is to dedicate network "slices" to one or more third parties, each slice meeting specific quality of service requirements (bandwidth, latency, reliability, etc.). A network slice refers to a set of resources, including network functions and the hardware infrastructure hosting these functions, which, when combined appropriately, create a network infrastructure that meets given quality and performance requirements.

[0006] Slicing a network into layers allows for the management and operation of multiple virtual networks on a shared physical network infrastructure. For example, a car manufacturer can use one 5G network layer for its vehicles' communication needs, while a lighting manufacturer can use another 5G network layer for its smart bulbs' communication needs. Each of these entities has very different and specific constraints and technical requirements. These network layers rely on virtual functions instantiated within the operator's network, virtually isolated from one another, despite sharing the same physical network resources (in terms of equipment, spectrum, etc.).

[0007] Even though the different network slices can be designed to activate or deactivate certain network functions according to the needs of the third parties to whom they are allocated, other functions remain shared between these network slices and are implemented "outside" the network slices (i.e., before the actual network slice selection) in the current version of the 5G telecommunications network architecture ("Phase 1"). For example, authentication and access control, which are specific to each access network, are performed when devices connect to the operator's network, before the selection of the network slices associated with those devices. In other words, the selection of the network slice associated with a third party is only carried out once the authentication of a device that has subscribed to network connectivity with a third party has been successfully completed.

[0008] 3GPP TR 23.799, SA WG2, V14.0.0, 16.12.2016, is a 3GPP specification that studies the architecture of 5G systems and, in particular, the selection of a bandwidth by a communication terminal. 3GPP TR 33.899, WG3, V1.3.0, 21.08.2017, is also a 3GPP specification that focuses on security aspects.

[0009] It is therefore understandable that since third parties may have very different and specific needs, such an architecture is not necessarily well suited and in any case lacks flexibility. Object and summary of the invention

[0010] The invention is defined by independent claims 1, 8-12 and 14-15. Other embodiments are defined by dependent claims 2-7, 13 and 16.

[0011] The invention makes it possible, in particular, to overcome this drawback by proposing a method for managing the attachment of a communication device to an operator's network, in order to benefit from network connectivity provided by a third party via the operator's network, said method comprising: a step of receiving, from the communication device, a request to attach to the operator's network and a third-party identifier; a step of obtaining, using the third-party identifier, contact information for a software control gateway instantiated to control access to a slice of the network allocated by the operator to the third party, this contact information including a reachability address of the software control gateway or an identifier of the slice of the network allocated to the third party and whose access is controlled by the software control gateway; and a step of sending a message to the device containing the contact information and inviting the communication device to attach to the software control gateway using this contact information.

[0012] Correspondingly, the invention also relates to a software network entity, instantiated to manage the attachment of at least one communication device to an operator's network in order to benefit from network connectivity provided by a third party via the operator's network, this software network entity comprising: a receiving module, capable of receiving from said communication device a request to join the operator's network and an identifier of the third party; a retrieval module, configured to obtain, using the identifier of the third party, contact information from a software control gateway instantiated to control access to a slice of the network allocated by the operator to the third party, this contact information including a reachability address of the software control gateway or an identifier of the slice of the network allocated by the operator to the third party and whose access is controlled by the software control gateway; and a sending module, configured to send a message to the communication device containing the contact information and inviting the device to join the software control gateway using this contact information.

[0013] The invention also relates to a computer system comprising: a software network entity according to the invention instantiated to manage the attachment of at least one communication device to the operator's network in order to benefit from network connectivity provided by the third party via the operator's network; and a software control gateway instantiated to control access to a slice of the operator's network allocated to the third party.

[0014] There are no limitations attached to the nature of the computer system according to the invention. It may be a server or any other device equipped with computing and network resources, such as, for example, a data center.

[0015] According to another aspect, the invention also relates to a method of accessing, via a communication device, network connectivity provided by a third party through an operator's network, this method comprising: a step of requesting attachment to the operator's network including the provision of a third-party identifier; a step of receiving a message containing contact information for a software control gateway instantiated to control access to a slice of the network allocated by the operator to the third party, this contact information including a reachability address of the software control gateway or an identifier of the network slice whose access is controlled by the software control gateway, said message inviting the communication device to attach to the software control gateway; a step of requesting attachment to the software control gateway using the contact information; and a step of access by the communication device to network connectivity via the slice of the operator's network allocated to the third party.

[0016] Correspondingly, it also concerns a communication system comprising: a first request module, configured to request an attachment to an operator's network in order to benefit from network connectivity provided by a third party via the operator's network, said request module being configured to provide an identifier of the third party; a receive module, capable of receiving a message containing contact information from a software control gateway instantiated to control access to a slice of the network allocated by the operator to the third party, this contact information including a reachability address of the software control gateway or an identifier of the network slice whose access is controlled by the software control gateway, said message inviting the device to attach to the software control gateway; a second request module, configured to request an attachment from the software control gateway using the contact information;and an activated access module, configured to access the operator's network slice and provide the communication device with network connectivity via said operator network slice allocated to the third party.

[0017] There are no limitations attached to the nature of the communication device to which the invention applies. It can be any type of object having means of communication via a network (whatever the network, e.g. wireless, mobile, short range, etc.), such as for example a connected object (e.g. IoT object such as a connected light bulb, a connected vehicle, etc.), a digital tablet, a telephone, etc.

[0018] Thus, the invention proposes decoupling access control and authentication for communication devices benefiting from network connectivity offered by a third party via the operator's network, from the network functions performed by the network operator. This approach increases the flexibility of the operator's network architecture in a context of opening this network to third parties, and allows third parties to adapt the implemented access control to their needs. Indeed, thanks to the invention, the access control and authentication policies and mechanisms implemented are no longer imposed and limited by the access technology used by the communication devices to access the operator's network, but can be defined and chosen by the third parties themselves, in collaboration with the network operator, according to their specific needs.In other words, the invention makes it possible, in a context where communication devices incorporating network connectivity are managed by third parties distinct from the network operator, to offer these third parties the possibility of controlling the access rules to the network slice allocated to them.

[0019] The invention advantageously relies on the instantiation of software access control gateways for each third party benefiting from a network slice within the operator's network. The operator's network redirects communication devices to these gateways when they attempt to attach to the network to obtain network connectivity. More specifically, each software access control gateway associated with a third party is instantiated to control access to the network slice allocated to that third party. According to the invention, access control and authentication of communication devices are therefore performed after the selection of the network slices relevant to the attachment requests of the communication devices in question. These slices can thus be chosen by the third party, which, through its dedicated software access control gateway, can define its own authentication session (i.e., the criteria, algorithms, etc.).selected for this authentication) without being dependent on the choices made in this regard by the network operator. The management method according to the invention is preferably implemented without prior authentication of the communication device with the operator's network.

[0020] The invention is therefore relatively simple to implement and particularly well suited to the current context of opening up telecommunications networks to third parties.

[0021] Furthermore, the use of software functions (software network entity and software control gateway) allows the third party to dynamically adapt and / or update the access control policy it wishes to apply to the communication devices whose network connectivity it manages. In particular, it can easily add access control mechanisms or modify the rules applied by these mechanisms, etc. The invention offers great flexibility in defining access control, which does not require laborious intervention to add, remove, or modify the implemented access control: a simple modification of the computer code executed by the software control gateway is sufficient.

[0022] Furthermore, these various software functions can be easily implemented by a computer system, which greatly simplifies the infrastructure on which the network architecture relies. As mentioned previously, in a particular embodiment, this computer system can be a data center, and the control gateway and network entity can be functions executed by virtual machines (referred to as a virtual control gateway and a virtual network entity) that leverage the computing and network resources of this data center.

[0023] The selection of the network slice corresponding to the third party providing the communication device with network connectivity, and thus of the gateway controlling access to this network slice, is made possible by the identifier of the third party transmitted by the communication device to the operator's network when it requests attachment.

[0024] In a particular embodiment, the third party identifier is provided in the attachment request sent by the communication device to the network.

[0025] Thanks to this identifier, the network can easily identify which software control gateway to direct the communication device to attach to.

[0026] There is no limitation attached to the nature of this identifier: it can be a name, a code or any alphanumeric string, a cryptographic key (e.g. a public encryption key), etc., transmitted in plain text or in encrypted form to the network when the communication device is attached.

[0027] Alternatively, the third party's identifier can be provided by the communication device during an exchange established between the network and the communication device as part of its connection request. For example, it can be the subject of a random challenge implemented using cryptographic hardware embedded in the communication device and provided by the third party to the operator's network.

[0028] In one particular embodiment, the management process includes: a preliminary step of instantiating the software control gateway to execute computer code implementing a function defined by the third party to control access to the network slice allocated by the operator to the third party; and a step of storing, in a database, an identifier of the third party in association with a reachability address (e.g. a URL for Uniform Resource Locator or a URI for Uniform Resource Identifier, or a pointer) of the instantiated software control gateway or with an identifier of the network slice allocated by the operator to the third party.

[0029] In this embodiment, the software access control gateway that manages access to the network segment allocated to the third party is instantiated prior to receiving any attachment request from a communication device that has subscribed to network connectivity with the third party. The instantiation of the access control gateway associated with the third party can be performed, for example, when the third party reaches an agreement with the network operator to obtain a network segment to provide network connectivity to the communication devices it manages. This accelerates the processing of attachment requests issued by the communication devices managed by the third party.

[0030] In another embodiment, the software control gateway is instantiated dynamically, following receipt of the communication device attachment request, to execute computer code implementing a function defined by the third party to control access to the network slice allocated by the operator to the third party, this computer code being obtained by querying a library of software network functions using the third party identifier.

[0031] In particular, the software control gateway attached to a third party can be instantiated when the operator's network receives the first request from a communication device managed by the third party.

[0032] In a particular embodiment, the management process is implemented by a software network entity hosted in a so-called proximity data center, said proximity data center also hosting the software control gateway and an access point of an access network to which the communication device is connected and used by the communication device to access the operator's network.

[0033] Such an access point is, for example, a base station, i.e., an eNodeB for 4G radio technology or a gNodeB for 5G radio technology. The software network entity and the software control gateway can then either be implemented independently or rely on some of the functions already performed by the access point.

[0034] Correspondingly, the data center according to the invention may include an access point of an access network to which the communication device is connected and used by the communication device to access the operator's network.

[0035] In this embodiment, the invention proposes an innovative approach defining a minimalist access network architecture capable of implementing the main network functions necessary to support opening the network to third parties without predefining the core network. This approach relies on decoupling, a technique previously underutilized in network architecture design, which increases the overall flexibility of the architecture. Furthermore, this embodiment greatly simplifies the operator's core network architecture by offloading functions that are performed at the network edge within the access network.

[0036] In addition, the use of software functions, as mentioned previously, simplifies the possible updating of access control implemented for each network segment.

[0037] In a particular embodiment, the different steps of the management process and / or the access process are determined by computer program instructions.

[0038] Consequently, the invention also relates to a computer program on an information medium, this program being capable of being implemented in a software network entity, in a communication device or more generally in a computer, this program comprising instructions adapted to the implementation of the steps of a management process or an access process as described above.

[0039] This program can use any programming language, and be in the form of source code, object code, or code somewhere between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0040] The invention also relates to a computer-readable information or recording medium, and comprising instructions for a computer program as mentioned above.

[0041] The information or recording medium can be any entity or device capable of storing the program. For example, the medium may include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a hard drive.

[0042] On the other hand, the information or recording medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. The program according to the invention can, in particular, be uploaded to a network such as the Internet.

[0043] Alternatively, the information or recording medium may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the process in question.

[0044] The invention also relates to a communication system comprising: a communication device according to the invention having subscribed to network connectivity provided by a third party via a slice of an operator's network; a software network entity according to the invention instantiated to manage the attachment of the device to the operator's network in order to benefit from said network connectivity; and a software control gateway instantiated to control access to the slice of the operator's network allocated to the third party.

[0045] It can also be envisaged, in other embodiments, that the management process, the software network entity, the access process, the communication device and the system according to the invention present in combination all or part of the aforementioned characteristics. Brief description of the drawings

[0046] Other features and advantages of the present invention will become apparent from the description below, with reference to the accompanying drawings, which illustrate an example of an embodiment without being limiting in any way. In the figures: there figure 1 represents, schematically, a communication system conforming to the invention in a particular embodiment; the figures 2 and 3 represent the hardware architecture of a data center and a communication device according to the invention in a particular embodiment; the figure 4 represents the main steps of a management process and an access process according to the invention in a particular embodiment. Detailed description of the invention

[0047] There figure 1represents, in its environment, a communication system 1 according to the invention, in a particular embodiment in which it allows a communication device 2 to benefit from network connectivity offered by a third party 3RD via an operator's (OP) network NW. The NW network is, for example, a 5G telecommunications network. However, this assumption is not limiting in itself, and other types of telecommunications networks can be considered, such as a wired communication network (fiber or ADSL).

[0048] The term "third party" here refers to any actor distinct from the network operator (NW) that has an agreement with the NW operator granting it a virtual slice of the NW network, denoted SLI(3RD). Communication devices managed by the third party can access this slice to communicate with other devices and benefit from network connectivity, meaning access to all of the third party's resources connected to the same network slice, as well as potentially to other resources via the Internet or other virtual network slices. For example, the manufacturer of the communication devices in question could be considered a third party.As mentioned previously, a network slice refers to a set of resources, including network functions and hardware infrastructure hosting these network functions, which, when combined appropriately, make it possible to create a network medium that meets given quality and performance requirements (in this case, those defined by the third party 3RD).

[0049] There are no limitations regarding the nature of the communication device 2. It can be any type of wireless communicating object, that is, one that incorporates a network connectivity module to communicate with other devices, which in this case are means (such as a card, a communication interface, etc.) of connecting to the NW network. Such a communicating object is, for example, a connected object such as a connected vehicle, a smart bulb, etc., a tablet, a phone, etc. We are particularly interested here in the case where the authentication software located in the network connectivity module embedded in the communication device 2 is designed by the third party 3RD and not by the NW network operator (OP).

[0050] According to the invention, the communication system 1 comprises a computer system 3 (comprising one or more computers) hosting a software network entity 4 according to the invention, and a software control gateway 5(3RD) instantiated for the 3RD third party to control access to the SLI(3RD) slice of the NW network allocated to the third party by the operator OP.

[0051] In the embodiment envisaged at the figure 1 , the computer system 3 is a so-called proximity data center, located on the periphery of the NW network, and more specifically at the level of the radio access network used by the communication device 2 to access the NW network.

[0052] Furthermore, the software control gateway 5 (3RD) and the software network entity 4 are virtual functions executed by virtual machines in the data center 3. Such virtual functions, as is known, abstract the physical resources of the system on which they are hosted and do not execute directly on those physical resources. This abstraction allows multiple virtual machines to share the system's physical resources. It should be noted, however, that this assumption is not limiting: the control gateway and the network entity are generally software functions regardless of whether or not a computer resource virtualization technology is used. Virtualization facilitates the implementation of such software functions but is not a prerequisite for the invention.Other technologies, such as OSGi (Open Services Gateway initiative) technology, can be used as an alternative to implement the invention and instantiate the control gateway and software network entity.

[0053] More specifically, in the embodiment described here, the data center 3 also integrates the hardware elements (e.g., computer servers; digital links to radio antennas) and software functions typically included in an access point of the access network (collectively designated by reference numeral 6), also more commonly called a Base Band Unit (BBU) in the context of cellular networks. There are no limitations on the radio access technology implemented by the access point 6 (for communicating, in particular, with the communication device 2): it can be a cellular access technology, Wi-Fi, etc.

[0054] It is noted that in the example considered in the figure 1 The access point 6 and the software network entity 4 are represented as autonomous entities. However, in one embodiment, the software network entity 4 according to the invention can be implemented by reusing some of the functions implemented by the access point 6, supplemented by additional computer code instructions in order to fulfill its function as a software network entity according to the invention.

[0055] In the embodiment described here, the data center 3 has the hardware architecture of a computer as illustrated in the figure 2 .

[0056] It includes in particular a processor 7, a random access memory 8, a read-only memory 9, a mass storage 10 (e.g. non-volatile flash memory, hard drive, etc.), as well as means of communication 11 enabling it to communicate with the equipment of the NW network and with the communication device 2 via the access point 6.

[0057] In the embodiment described herein, the read-only memory 9 of the data center 3 contains the computer code executed by the software network entity 4 according to the invention. The read-only memory 9 constitutes a storage medium according to the invention, readable by the processor 7, on which is stored a computer program PROG3 according to the invention, comprising instructions for executing the steps of the management process according to the invention. It is assumed here that the access control gateways instantiated for each third party (and in particular gateway 5(3RD)) are software functions stored in the mass storage 10 of the data center 3.

[0058] The PROG3 computer program here defines functional and software modules of the software network entity 4 that use or rely on the previously mentioned hardware elements 7-11 of the data center 3. These modules include, in particular, as illustrated in the figure 1 :a 4A receiving module, capable of receiving from a communication device such as communication device 2 a request to join the NW network of the operator OP and an ID(3RD) identifier of the 3RD third party managing the network connectivity of communication device 2. No limitation is attached to the nature of the ID(3RD) identifier: it can be an alphanumeric string such as a code, or cryptographic material such as a public encryption key allocated to the 3RD third party, etc.; a 4B obtaining module, configured to obtain, using the ID(3RD) identifier of the 3RD third party, contact information for a software control gateway instantiated to control access to a slice of the network allocated by the operator to the 3RD third party, in other words here, contact information for the software control gateway 5(3RD).This contact information can take various forms, but it allows direct or indirect access to the 5(3RD) software control gateway. For example, it could be a @5(3RD) reachable address for the 5(3RD) software control gateway, such as a URL (Uniform Resource Locator) or a pointer to that gateway.Alternatively, it may be an identifier denoted IDSLI(3RD) of the SLI(3RD) network slice allocated by the operator OP to the 3RD third party and whose access is controlled by the software control gateway, this identifier being associated at the data center level 3, and more specifically at the access point 6, with the reachability address @5(3RD) of the control gateway 5(3RD) associated with the 3RD third party; and a sending module 4C, configured to send a message to the communication device 2 containing the contact information (@5(3RD) or IDSLI(3RD)) and inviting the communication device 2 to attach itself to the software control gateway 5(3RD) using this contact information.

[0059] The functions of modules 4A to 4C are described in more detail later with reference to the steps of the management process according to the invention.

[0060] Similarly, in the embodiment described here, the communication device 2 has the hardware architecture of a computer as illustrated in the figure 3 .

[0061] It includes in particular a processor 12, a RAM 13, a ROM 14, a non-volatile flash memory 15, as well as communication means 16 enabling it to communicate with the equipment of the NW network via the access point 6.

[0062] In the embodiment described here, the read-only memory 14 of the communication device 2 constitutes a recording medium according to the invention, readable by the processor 12 and on which is recorded a computer program PROG2 according to the invention, comprising instructions for the execution of the steps of the access process according to the invention.

[0063] This computer program PROG2 defines functional and software modules of the communication device 2 that use or rely on the hardware elements 12-16 of the communication device 2 mentioned previously. These modules include, in particular, as illustrated in the figure 1 : a first request module 2A, configured to request an attachment to the NW network of the operator OP in order to benefit from the network connectivity provided by the third party 3RD via the NW network, this first request module 2A being configured to provide an ID(3RD) identifier of the third party (3RD); a receive module 2B, capable of receiving from the software network entity 4 a message containing contact information for the software control gateway 5(3RD) instantiated to control access to the SLI(3RD) slice of the NW network allocated by the operator OP to the third party 3RD, this contact information including, as previously indicated, the reachability address @5(3RD) of the software control gateway 5(3RD) or the IDSLI(3RD) identifier of the SLI network slice(3RD) whose access is controlled by the software control gateway 5(3RD).According to the invention, this message invites the communication device 2 to attach itself to the software control gateway 5(3RD); a second request module 2C, configured to request an attachment from the software control gateway 5(3RD) using the received contact information; an authentication module 2D (optional), configured to authenticate the communication device 2 to the software control gateway 5(3RD); and an access module 2E configured to access the SLI(3RD) slice of the NW network of the operator OP and thus provide the communication device 2 with network connectivity via this SLI(3RD) slice of the NW network.

[0064] The functions of modules 2A to 2E are now described in more detail with reference to the steps of the access process according to the invention.

[0065] There figure 4represents, in diagram form, the main steps of a management process and the main steps of an access process as they are implemented respectively, in a first embodiment, by the software network entity 4 and by the communication device 2.

[0066] In the embodiment shown in the figure 4It is assumed that during a preliminary step following the allocation of the SLI(3RD) virtual network slice by the NW network operator (OP) to the 3RD tier, the control gateway 5(3RD) is instantiated in the proximity data center 3 (step E10). This instantiation is performed, in the embodiment described here, by the software network entity 4, which is provided with the ID(3RD) of the 3RD tier (in encrypted or unencrypted form), and which instantiates (i.e., creates) a software module (this software module being, in the embodiment described here, a virtual machine or any other container) to execute computer code defining the access control mechanism intended to be applied to control access to the SLI(3RD) network slice.It is assumed that this mechanism has been selected or predefined by the 3RD third party (in agreement with the operator OP) and encoded as computer code used by the software network entity 4 to instantiate the gateway 5(3RD). This computer code is available, for example, in a third-party software network function library (virtual network functions in the embodiment described here), associated with the ID(3RD) of the 3RD third party. This function library can be stored at the data center 3 or in another data center (for example, in a centralized data center as described above located in the NW network).

[0067] Alternatively, gateway 5(3RD) can be instantiated by an entity other than software network entity 4, such as a software network function management function instantiated in data center 3 and as described in the ETSI MANO (NFV Management and Orchestration) project. Upon instantiation of gateway 5(3RD), the ID(3RD) is provided to software network entity 4.

[0068] Following the instantiation of gateway 5(3RD), the software network entity 4 stores in a table, for example in its non-volatile memory 10, the ID(3RD) of the 3RD third party in association with contact information for the newly instantiated gateway 5(3RD) (step E20). In the embodiment described here, this contact information is a reachable address @5(3RD) of the gateway 5(3RD), such as a URL or a pointer to the software module instantiating gateway 5(3RD).

[0069] Alternatively, this contact information can be the IDSLI(3RD) identifier of the SLI(3RD) network slice allocated to the 3RD third party by the operator OP.

[0070] We now assume that communication device 2 wishes to connect to the NW network to benefit from the network connectivity offered (and managed) by the third party 3RD. Connecting a communication device to a network is a well-known process that typically allows the device to establish an initial connection with an access point on that network (for example, after the device has been powered off, etc.). Such a process might include, for example, authenticating the communication device, retrieving its service profile (and its permissions), registering the device's location to enable data routing to that device, and so on.

[0071] To this end, the communication device 2 sends, via its first request module 2A and the access point 6, an attachment request to the NW network designated by ATTACH-NW (step E30). This attachment request contains the ID(3RD) of the third party 3RD providing it with network connectivity and is received or intercepted by the software network entity 4 via its receive module 4A. The ID(3RD) can be provided in clear text or encrypted in the attachment request addressed to the NW network.

[0072] Alternatively, the ID(3RD) identifier can be provided to the software network entity 4 not directly in the ATTACH-NW attachment request, but during an exchange established between the software network entity 4 and the communication device 2 following the receipt by the software network entity 4 of the ATTACH-NW attachment request. For example, the ID(3RD) identifier can be the subject of a random challenge implemented between the software network entity 4 and the communication device 2 using cryptographic hardware embedded (e.g., by the third party 3RD if it is the manufacturer of the communication device 2) in the communication device 2 and previously provided by the third party 3RD to the software network entity 4.

[0073] Using the ID(3RD) of the third party contained in the attachment request, the software network entity 4 obtains, via its retrieval module 4B, the contact information of the control gateway 5(3RD) instantiated to perform access control to the SLI(3RD) network slice allocated to the third party 3RD (step E40). In the embodiment described here, this contact information is the address @5(3RD) stored in its non-volatile memory 10 in association with the ID(3RD).

[0074] Note that the software network entity 4 can reroute the ATTACH-NW attachment request to the control gateway 5 (3RD) to perform additional checks, such as a first level of access control (based, for example, on a list of MAC addresses authorized by the control gateway 5 (3RD) and communicated to the network entity 4, etc.). If this first level of access control is successful for the communication device 2, the network entity 4 can provide it with a token that it will subsequently use as proof of this prior authorization with the control gateway 5 (3RD). This allows for filtering of attachment requests.

[0075] Then, the software network entity 4, through its sending module 4C, sends as a response to the attachment request ATTACH-NW a message marked INVIT containing the contact information @5(3RD) of the control gateway 5(3RD) and inviting the communication device 2 to attach to the control gateway 5(3RD) (that is to say in particular to establish a connection with it and to authenticate itself with it) using the contact information transmitted (step E50).

[0076] Alternatively, as mentioned previously, the gateway contact information 5(3RD) obtained by the software network entity 4 can be the IDSLI(3RD) identifier of the SLI(3RD) network slice allocated to the 3RD third party and to which the software entity 4 invites the communication device 2 to connect to attach to the control gateway 5(3RD) which manages and controls access to that network slice.

[0077] Upon receiving the INVIT message via its receiving module 2B, the communication device 2, through its second request module 2C, sends an attachment request denoted ATTACH-GW to the control gateway 5(3RD) using the reachability address @5(3RD) (step E60). This attachment request passes through the access point 6; thus, to ensure that the attachment request destined for the control gateway 5(3RD) is correctly routed from access point 6 to it, the second request module 2C of the communication device 2 can include the address @5(3RD) in the attachment request, allowing access point 6 to identify the entity to be contacted.

[0078] Alternatively, if the contact information received by communication device 2 is the IDSLI(3RD) identifier of the virtual network slice allocated to the 3RD third party, the second request module 2C of communication device 2 can include the IDSLI(3RD) identifier in the attachment request. This identifier is then used by access point 6 to determine the @5(3RD) address of the entity to be contacted. For this purpose, access point 6 may have been previously configured by default with the @5(3RD) address of the control gateway 5(3RD) associated with the 3RD third party and instantiated to perform access control to the network slice identified by IDSLI(3RD). This default configuration is, for example, implemented so that access point 6 forwards all messages carried on the network slice identified by IDSLI(3RD) to the aforementioned gateway.

[0079] In the embodiment described here, upon receiving the ATTACH-GW attachment request, the control gateway 5(3RD) initiates an authentication session with the communication device 2 in order to authenticate the latter (step E70). There are no limitations on the means used during this authentication session to authenticate the communication device 2. Thus, for example, the communication device can be authenticated via the exchange of a login and password, or via an asymmetric or symmetric cryptography mechanism. The authentication mechanisms to be used may have been agreed upon beforehand between the communication device 2 and the third party 3RD (for example, during the design of the communication device 2 or its firmware), or may be chosen dynamically through negotiation between the communication device 2 and the control gateway 5(3RD).In other words, thanks to the invention, via in particular the control gateway instantiated for the third party 3RD, the latter can define its own authentication mechanisms (without going through the network operator).

[0080] Alternatively, no authentication mechanism for communication device 2 is implemented by the control gateway.

[0081] In a particular embodiment, if the authentication of communication device 2 is successful, the control gateway 5 (3RD) generates an authorization token (TOK2) containing the access control rules defined by the third party 3RD, to which communication device 2 must adhere, for example, in terms of bandwidth limits, authorization validity period, etc. (step E80). Such a token containing the access rights of communication device 2 can, for example, be generated in JWT (JSON Web Token) format and / or be signed by the control gateway 5 (3RD) to guarantee its origin.

[0082] The TOK(2) token generated by the control gateway 5(3RD) can be sent by it to the communication device 2, which in turn transmits it to the software network entity 4 when the network entity 4 wishes to verify the access rights of the communication device 2.

[0083] Alternatively, the TOK(2) token generated by the control gateway 5(3RD) can be provided directly by the control gateway 5(3RD) to the software network entity 4 or to any other entity in the SLI(3RD) network slice that needs at some point to control the access rights of the communication device 2.

[0084] Communication device 2 can then access, via its access module 2E, the SLI(3RD) network slice dedicated to the third party 3RD and benefit from network connectivity via the NW network (step E90). Software network entity 4, upon receiving messages destined for or sent by communication device 2, can verify, using the content of the TOK(2) token, whether these messages comply with the access control rules defined by the third party 3RD and to which communication device 2 must adhere.

[0085] In another variant, the control gateway 5(3RD) does not generate a TOK(2) token but configures an interface of the software network entity 4 or of the access point 6 with the access control rules to which the communication device 2 must submit or more generally with the access rights of the communication device 2.

[0086] In another variant, all messages emitted by the communication device 2 can pass through the control gateway 5 (3RD), which, in addition to an access control function, can perform a routing function for these messages. Specifically, they can be sent directly from the gateway to a network managed by the third party 3RD. This network can be of any type, such as an Ethernet network (in which case the gateway 5 (3RD) acts as an Ethernet switch on this network).

[0087] In the first embodiment just described, the control gateway 5(3RD) is instantiated during a prior step E10, even before an attachment request is sent to it by a communication device managed by the third party 3RD.

[0088] In a second embodiment, the control gateway 5 (3RD) can be dynamically instantiated, for example, upon receiving the first attachment request from a communication device 2 managed by the third party 3RD. In this embodiment (which does not include, prior to step E30, steps E10 and E20 illustrated in the figure 4), following the receipt of the ATTACH-NW attachment request from the communication device 2 containing the ID(3RD) identifier of the 3RD third party, the software network entity 4 checks if the ID(3RD) identifier of the 3RD third party is associated in its non-volatile memory 10 with contact information from an access control gateway (reachability address or network slice identifier).

[0089] If so, this means that a 5(3RD) access control gateway has already been instantiated for the SLI(3RD) network slice and the 3RD tier. Steps E40 to E90 are then carried out identically to what was described previously with reference to the figure 4 and to the first embodiment.

[0090] Alternatively, in the second embodiment described here, the software network entity 4 queries a third-party network function library to obtain computer code associated with the ID(3RD), defining the access control function to be implemented by the access control gateway 5(3RD) to control access to the SLI(3RD) network slice. This library can be located either within the data center 3 as described previously, or in a centralized data center located in the NW network, for example.

[0091] The computer code corresponding to the ID(3RD) identifier is sent by the library to the software network entity 4.

[0092] Upon receiving this computer code, the software network entity controls the instantiation of the access control gateway 5(3RD). More precisely, it instantiates (i.e. creates) a software module (such as a virtual machine or any other container in the embodiment described here) to execute the computer code obtained from the network function library.

[0093] Alternatively, gateway 5(3RD) can be instantiated by an entity other than software network entity 4, such as a software network function management function instantiated in data center 3 and as described in the ETSI MANO (NFV Management and Orchestration) project. Upon instantiation of gateway 5(3RD), the ID(3RD) is provided to software network entity 4.

[0094] Steps E20 and E40 to E90 are then implemented in a similar way to what was described previously for the first embodiment.

Claims

1. Method for management of attachment of a communication device (2) to a network (NW) of an operator, in order for the communication device (2) to benefit from network connectivity provided by a third party via the network of the operator, said method comprising the following steps executed by a software network entity (4) instantiated to manage attachment of the communication device (2) to the network (NW): - a step of receiving (E30), from the communication device, a request for attachment to the network of the operator and an identifier of the third party (ID(3RD)); - a step of obtaining (E40), using the identifier of the third party, contact information of a software control gateway (5(3RD)) instantiated to control access to a network slice allocated by the operator to the third party, this contact information comprising a reachability address of the software control gateway or an identifier of the network slice allocated to the third party and access to which is controlled by the software control gateway; and - a step of sending (E50) a message to the communication device (2) containing the contact information and inviting the communication device (2) to attach to the software control gateway using this contact information.

2. Management method according to Claim 1, characterized in that it is implemented without prior authentication of the communication device by the network of the operator.

3. Management method according to Claim 1 or 2, wherein the identifier of the third party is provided in the request for attachment to the network of the operator.

4. Management method according to any of Claims 1 to 3, wherein the software control gateway is dynamically instantiated, following receipt of the attachment request from the communication device, to execute a computer code implementing a function defined by the third party to control access to the network slice allocated by the operator to the third party, this computer code being obtained by interrogating a library of software network functions by means of the identifier of the third party.

5. Management method according to any of Claims 1 to 3, comprising: - a preliminary step (E10) of instantiating the software control gateway to execute a computer code implementing a function defined by the third party to control access to the network slice allocated by the operator to the third party; and - a step of storing (E20), in a database, an identifier of the third party in association with a reachability address of the instantiated software control gateway or with an identifier of the network slice allocated by the operator to the third party.

6. Management method according to any of Claims 1 to 5, characterized in that it is implemented by a software network entity (4) hosted in a data centre (3) called the proximity data centre, which is located in an access network used by the communication device to access the network of the operator, the proximity data centre also hosting the software control gateway (5(3RD)).

7. Management method according to Claim 6, wherein the proximity data centre is located in an access point (6) of the access network.

8. Method for access by a communication device (2) to network connectivity provided by a third party via a network (NW) of an operator, this method comprising the following steps executed by the communication device (2): - a step (E30) of requesting attachment to the network of the operator comprising providing an identifier of the third party (ID(3RD)), sent to a software network entity (4) instantiated to manage attachment of a communication device to the network (NW); - a step (E50) of receiving, from the software network entity (4), a message containing contact information of a software control gateway (5(3RD)) instantiated to control access to a network slice allocated by the operator to the third party, this contact information comprising a reachability address of the software control gateway or an identifier of the network slice to which access is controlled by the software control gateway, said message inviting the communication device to attach to the software control gateway; - a step (E60) of requesting attachment to the software control gateway (5(3RD)) using the contact information; and - a step (E90) of access by the communication device (2) to network connectivity via the slice of the network of the operator allocated to the third party.

9. Computer program (PROG4, PROG2) comprising instructions for executing the steps of the management method according to any of Claims 1 to 7 or for executing the steps of the access method according to Claim 8 when said program is executed by a computer.

10. Computer-readable storage medium (9, 14) on which a computer program according to Claim 9 is stored.

11. Software network entity (4), instantiated to manage attachment of at least one communication device to a network of an operator in order to benefit from network connectivity provided by a third party via the network of the operator, said virtual network entity comprising: - a receiving module (4A), capable of receiving from said communication device a request for attachment to the network of the operator and an identifier of the third party; - an obtaining module (4B), configured to obtain, using the identifier of the third party, contact information of a software control gateway instantiated to control access to a network slice allocated by the operator to the third party, this contact information comprising a reachability address of the software control gateway or an identifier of the network slice allocated by the operator to the third party and access to which is controlled by the software control gateway; and - a sending module (4C), configured to send a message to the communication device containing the contact information and inviting the communication device to attach to the software control gateway using this contact information.

12. Computer system (3) comprising: - a software network entity (4) according to Claim 11 instantiated to manage attachment of at least one communication device to the network of the operator in order to benefit from network connectivity provided by the third party via the network of the operator; and - a software control gateway (5(3RD)) instantiated to control access to a network slice of the operator allocated to the third party.

13. Computer system (3) according to Claim 12, further comprising an access point of an access network to which the communication device is connected and used by the communication device to access the network of the operator.

14. Communication device (2) comprising: - a first requesting module (2A), configured to request attachment to a network of an operator in order to benefit from network connectivity provided by a third party via the network of the operator, said requesting module being configured to provide an identifier of the third party; - a receiving module (2B), capable of receiving a message containing contact information of a software control gateway instantiated to control access to a network slice allocated by the operator to the third party, this contact information comprising a reachability address of the software control gateway or an identifier of the network slice to which access is controlled by the software control gateway, said message inviting the device to attach to the software control gateway; - a second requesting module (2C), configured to request attachment to the software control gateway using the contact information; and - an accessing module (2E), configured to access the network slice of the operator and provide the communication device with network connectivity via said network slice of the operator allocated to the third party.

15. Communication system (1) comprising: - a communication device (2) according to Claim 14 having subscribed to network connectivity provided by a third party via a slice of a network of an operator; and - a computer system (3) according to Claim 12 or 13.

16. Communication system (1) according to Claim 15, wherein the computer system is a data centre.