Methods for accessing a service, method for providing services, control method, management method, and corresponding terminal, service function instance, controller, border node and computer programs

EP4736394A1Pending Publication Date: 2026-05-06ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
ORANGE SA
Filing Date
2024-06-25
Publication Date
2026-05-06

AI Technical Summary

Technical Problem

The complexity of traffic classification rules in network slices leads to difficulties in optimizing resource use, ensuring traffic isolation, quality, security, and availability, particularly in dynamic traffic scenarios such as sporting or cultural events, where traditional methods struggle to efficiently route return traffic to terminals.

Method used

A method involving the use of first identifiers, or 'tags,' associated with network slices, which are transmitted by terminals to service instances and edge nodes, allowing for automatic and secure identification and routing of network slices without inspecting the service data, enabling optimized resource utilization and quality of service.

Benefits of technology

This approach enhances the efficient use of network slice resources by allowing terminals to access optimized network slices for return traffic, improving quality of service and security, and simplifying traffic management in dynamic scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024067744_02012025_PF_FP_ABST
    Figure EP2024067744_02012025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for accessing at least one service by a terminal (11) via a communication network using network slices, the method involving: • obtaining (111) at least one identifier for classifying the traffic to said terminal, said at least one identifier being associated with at least one network slice or one type of network slice, • transmitting (112) the at least one identifier to at least one first service function instance (131) that is able to provide said at least one service to the terminal, • receiving (113) a message comprising data associated with the at least one service routed via at least one network slice that is associated with the at least one identifier and is selected by a border node (141) in the communication network by applying at least one traffic classification rule known to said border node.
Need to check novelty before this filing date? Find Prior Art

Description

Methods of accessing a service, method of providing services, control method, management method, terminal, service instance, controller, edge node and corresponding computer programs. 1. Technical field

[0001] The field of the invention is that of communications within at least one communications network, and in particular that of value-added IP services.

[0002] More specifically, the invention relates to access to at least one service using the network slice resources of a communications network.

[0003] In particular, the invention proposes a solution for selecting one or more network slices to be used for all or part of the traffic to a terminal. 2. Prior art

[0004] A network slice can be defined as a partition of the network such as a virtual private network (VPN) deployed on fixed infrastructure, mobile infrastructure, or a combination of both.

[0005] The characteristics of a network slice are mainly expressed in terms of capacity (bandwidth) and quality of service (e.g. latency, one-way transit time, etc.), or even security (e.g. preservation of the confidentiality of information transmitted within the VPN through the use of encryption techniques) and service functions (“Service Functions” or SF).

[0006] The characteristics of a network slice are for example presented in the document “A Framework for IETF Network Slices” by A. Farrel et al., version 21 published on June 15, 2023.

[0007] An example of using network slices deployed in a 5G mobile infrastructure is presented in the document “A Realization of IETF Network Slices for 5G Networks Using Current IP / MPLS Technologies” by KG Szarkowicz et al., version 9 published on May 23, 2023.

[0008] Traditionally, traffic that can be routed within a network slice is subject to authorization (also called access control) to use the paths established within said network slice. Such authorization is typically based on the application of traffic classification rules. These rules are generally applied by a network access point within which network slices have been deployed. This access point is a node located at the edge of the network and is generally deployed in front of client access or used to connect a network to other neighboring networks. For example, such an access point may be located at the connection interface of a gateway that provides access to the Internet. This gateway is called a "packet gateway" for the most recent generations (4G, 5G) of mobile networks.In this case, the traffic classification function could be located at the connection interface of a packet gateway to the Internet network. The access point can also be located at the connection interface of a mobile terminal (or User Equipment or UE) to the radio access network (or Radio Access Network or RAN), in particular so as to optimize the use of radio resources according to the type of network slice and the profile of the traffic that it is likely to carry. A traffic profile is the set of characteristics specific to the traffic. These characteristics can reflect the sensitivity of applications to latency, transit delay or packet loss, but also usage practices, for example traffic that would only be generated over a given period (for example management traffic linked to the execution of a maintenance operation on equipment scheduled during the night).Traffic classification and admission control rules are therefore applied at the edge of the network.

[0009] It should also be noted that the 3GPP organization has defined different types of network slices, depending on their characteristics: a first type of network slices allowing the provision of an improved mobile broadband service ("Enhanced Mobile BroadBand" or EMBB in English); a second type of network slices allowing the provision of a service as part of a (massive) deployment of the Internet of Things ("massive Internet of Things" or mIoT in English); and a third type of network slices allowing the provision of an ultra-reliable, low-latency communication service ("Ultra Reliable Low Latency Communications" or URLLC in English).

[0010] The choice to design and deploy one or other of these types of network slice is conditioned by the nature of the traffic characteristic of the applications or services used or subscribed to by a user. For example, a so-called "immersive" service that uses augmented or virtual reality techniques is generally very demanding in terms of latency and reliability of data exchanges: the use of URLLC type slices is therefore preferred for an immersive service of this type.

[0011] It is also noted that traffic classification rules can be complex, because the level of granularity associated with the engineering and deployment of a network slice can be macroscopic (for example, a network slice deployed to route traffic to the Internet), or microscopic (for example, a network slice deployed for application traffic exchanged between two mobile terminals).

[0012] This granularity generates an overall complexity in the engineering of network slices, for example a difficulty in optimizing the use of resources implemented by a network slice, by a set of network slices, or by all network slices, or a difficulty in strictly guaranteeing the isolation of traffic routed within a network slice, or even a difficulty in strictly guaranteeing the level of quality or security associated with a network slice, or even the level of availability and resilience of a given network slice, etc.

[0013] In particular, the complexity of configuring and applying traffic classification rules associated with the implementation of a given network slice evolves with the diversity of traffic, the richness of the organization of the structure that operates the network slice (for example, an accounting department, an R&D department, a production department) or the mode of use of the network slice (for example, management of traffic overloads during busy hours, principles of traffic load distribution). This complexity can be aggravated in particular by the evolution of traffic classification rules over time (for example, in the context of the deployment of a network slice for the retransmission of a sporting or cultural event, the traffic classification rules can evolve with the number and profile of users of the network slice).

[0014] There is therefore a need for a new service access technique seeking to improve the use of network slice resources, particularly for routing return traffic to the terminal. 3. Statement of the invention

[0015] The invention proposes a solution not having all the drawbacks of the prior art in the form of a method for accessing at least one service by a terminal, via a communication network implementing network slices, comprising:obtaining at least one first identifier intended for classifying traffic to said terminal, said at least one first identifier being associated with at least one network slice or a type of network slice,transmitting said at least one first identifier to at least one first service instance capable of providing said at least one service to said terminal,receiving a message comprising data associated with said at least one service routed via at least one network slice associated with said at least one first identifier, selected by an edge node of said communication network by applying at least one traffic classification rule known to said edge node.

[0016] Such a method can in particular be implemented by a terminal connected to the communications network.

[0017] Such a terminal obtains during a first step at least a first identifier intended for the classification of the traffic to the terminal. Such a first identifier, also called tag thereafter, is for example noted “inbound_flow_map” in one embodiment of the invention. It can be associated with a network slice or a type of network slice (for example EMBB, mIoT or URLLC if we consider a 5G network). Such a first identifier of the traffic to the terminal is different from a network slice identifier used by equipment to connect to a network slice: this other network slice identifier is for example of the NSSAI 3GPP type. Such a first identifier of the traffic to the terminal is for example generated by a network manager, for example implementing a session management function (“Session Manager Function” or SMF in English) or a network controller.

[0018] The first identifier intended for the classification of traffic to the terminal may in particular be received directly from the SMF manager or a network controller, or via an intermediate router, for example a CPE (“Customer Premises Equipment”) or other network connection equipment. In particular, such a first identifier may be inserted in a dedicated header (for example an HTTP header, a QUIC frame) or described in messages formatted according to protocols such as SIP (“Session Initiation Protocol”), SDP (“Session Description Protocol”) or WebRTC.

[0019] During a second step, the terminal transmits said at least one first identifier to at least one first service instance (“Service Function Instance”, in English, for example an application server), for example using a network slice configured for this purpose, or a default path. In particular, such a first identifier may be the subject of a parameter subsequently called SOLACE, for “Optimized Slicing A LA Carte”. The terminal thus provides at least one first service instance with one or more first identifiers to be used to facilitate the identification of the network slice that the data associated with said at least one service intended for the terminal are authorized to use. It is noted that a service instance may be embedded in a remote terminal.

[0020] During a third step, the terminal can thus receive a message comprising the data associated with said at least one service. Such data is routed via at least one network slice selected by an edge node of the communication network by applying at least one traffic classification rule known to the edge node (for example previously configured in the edge node following the reception of said at least one rule from a controller).

[0021] In this way, the terminal communicates to a service instance a key in the form of a first identifier intended for traffic classification. For example, the service instance can insert this key into the return traffic to the terminal, directly or in a modified form. This key can be extracted from the return traffic by an edge node of the communication network through which the return traffic passes, when it is directly inserted into the return traffic to the terminal or when a signaling protocol is used between a service instance and the communication network via a border node typically, or be deduced or reconstructed by the border node, when it is inserted in a modified form into the return traffic to the terminal (for example in the form of a digest).The border node can thus identify at least one network slice or type of network slice associated with this key, without having to inspect the data (for example the content of the service in question, which may be encrypted) and select the network slice or type of network slice to be used to route the data to the terminal. For example, the border node is a node that announces the IP prefixes allocated to the various devices in the communication network. The term "border node" is used here and throughout the rest of the document to designate a node at the edge of the network, for example of the "Autonomous System Border Router" or ASBR type, or a node at the edge of the network, for example of the "Provider Edge (router)" or PE type, in an IP / MPLS network.

[0022] The communication network (or more precisely the network edge node) thus knows which network slice(s) it can use to route traffic to the terminal.

[0023] Note that traffic classification rules can be described in a traffic classification table, or algorithmically for example. No assumptions are made about how the traffic classification rules are described.

[0024] In a particular embodiment, said at least one network slice or said type of network slice is associated with a transmission mode belonging to the group comprising: the routing of data to the terminal, the routing of data from the terminal, the routing of data to the terminal and from the terminal.

[0025] For example, this classification of network slices or types of network slices associated with forward and / or return traffic may be based on service logic (which may be integrated into the application embedded in the terminal) and / or decided by the network (for example by network equipment). The classification may also be the subject of a decision taken by the terminal (for example, according to the choices and instructions of the terminal user).

[0026] The transmission mode can be negotiated during the phase of establishing a connection to a network slice between the terminal and the communication network.

[0027] In a particular embodiment, the method implements the transmission, by the terminal, of a first indicator signaling that the terminal is capable of implementing a collaborative procedure for routing data associated with said at least one service and to said terminal based on the processing of said at least one first identifier. This collaborative procedure is called SOLACE.

[0028] For example, such a first indicator is subsequently noted as "Collaborative-Solace-Capable". Setting this parameter to "1" indicates, for example, that the terminal supports the process described above.

[0029] In particular, such a first indicator may be provided globally (e.g. when the terminal connects to the network) or upon activation of a network slice.

[0030] In a particular embodiment, the terminal implements the reception of a second indicator signaling that the provider of the network slices is able to implement a collaborative SOLACE procedure for the routing of data associated with said at least one service and to said terminal based on the processing of said at least one first identifier (SOLACE).

[0031] For example, such a second indicator is also noted as "Collaborative-Solace-Capable" thereafter. Setting this parameter to "1" indicates, for example, that the said network supports the process described above.

[0032] According to a particular characteristic, said obtaining comprises obtaining at least one first identifier per network to which said terminal is connected.

[0033] For example, if the terminal is connected to a service instance via different networks (for example in 5G and in Wi-Fi®), a first different identifier per network can be obtained (for example a first tag TAG1 for the processing of data sent to the terminal by the service instance via the 5G network, and a second tag TAG2 for the processing of data sent to the terminal by the service instance via the Wi-Fi® network).

[0034] In a particular embodiment, said method comprises transmitting, to the first service instance, at least one traffic classification rule.

[0035] For example, in a multihoming context in which the terminal is connected to several networks, the terminal explicitly indicates the destination address corresponding to each network to which it is connected. In other words, the terminal can transmit several first identifiers, each corresponding to at least one address of the terminal in the network concerned. The application of traffic classification rules ensures that the data associated with the service that the terminal wishes to access is correctly routed via the network in which the terminal is identified by the corresponding destination address. The use of an identifier different from that associated with a given network implies incorrect application of the classification rule for data sent by a service instance. The data sent by the service instance may then be rejected instead of being routed to the terminal.

[0036] In another example, classification rules can also take into account a destination port number.

[0037] In a particular embodiment, the method implements a prior selection of said at least one first service instance authorized to receive said at least one first identifier.

[0038] The terminal can thus set up a selection procedure to choose the service or service instance authorized to receive the first identifier intended for the classification of traffic to the terminal.

[0039] In another embodiment, the invention relates to a terminal adapted to implement the method of accessing at least one service described above. Such a terminal can of course have the different characteristics relating to the method of accessing at least one service according to the invention, which can be combined or considered in isolation. Thus, the characteristics and advantages of this terminal are the same as those of the method and are not detailed further.

[0040] The invention further relates to a method for controlling the provision of at least one service to a terminal, via a communication network implementing network slices, comprising:obtaining at least one first identifier intended for classifying traffic to said terminal, said at least one first identifier being associated with at least one network slice or type of network slice,transmitting said at least one first identifier to said terminal, directly or via at least one intermediate router,transmitting, to at least one edge node of said communication network, at least one traffic classification rule for selecting at least one network slice intended to route data associated with said at least one service to said terminal.

[0041] Such a method can in particular be implemented by a network controller, for example an SDN (“Software-Defined Networking”) controller.

[0042] In a first step, such a controller obtains at least a first identifier of the traffic to the terminal. As indicated previously, such a first identifier may be generated by an SMF (“Session Manager Function”). Optionally, the first identifier may be generated by the controller.

[0043] In a second step, the controller transmits the first identifier to the terminal, directly or via at least one intermediate router, for example a CPE.

[0044] The controller (first controller), or another controller (second controller), may also transmit to at least one edge node of the communication network at least one traffic classification rule, for example making it possible to associate said at least one first identifier with at least one network slice. The second controller may in particular receive said at least one traffic classification rule from the first controller. For example, such rules may be configured in the edge node, or transmitted in the form of an algorithm intended to be implemented by the edge node.

[0045] According to a particular embodiment, the controller may also transmit to the edge node(s) instructions specifying whether the identifier(s) (first identifier or second identifier) ​​that an edge node receives from a service instance must be removed or maintained in the message comprising the data that will be transmitted via the selected network slice.

[0046] In a particular embodiment, the method comprises transmitting said at least one first identifier to at least one other terminal connected to said communication network.

[0047] In this way, the same first identifier can be negotiated with several terminals. It is thus possible to share the traffic classification rules maintained by the edge nodes.

[0048] In another embodiment, the invention relates to a controller adapted to implement the method for controlling the provision of at least one service described above. Such a controller can of course have the different characteristics relating to the method for controlling the provision of at least one service according to the invention, which can be combined or considered in isolation. Thus, the characteristics and advantages of this controller are the same as those of the method and are not detailed further.

[0049] The invention further relates to a method for providing at least one service to a terminal, via a communication network implementing network slices, comprising:receiving at least one first identifier intended for classifying traffic to said terminal, said at least one first identifier being associated with at least one network slice or type of network slice,transmitting, via at least one edge node of said communication network, a message comprising at least one second identifier and data associated with said at least one service,

[0050] said data being intended to be routed via at least one network slice associated with said at least one first identifier,

[0051] said at least one network slice being selected by said border node by applying at least one traffic classification rule known to said border node, and

[0052] said at least one second identifier being a function of said at least one first identifier.

[0053] Such a method may in particular be implemented by a service instance, which provides the service that the terminal wishes to access. For example, such a service instance is an application server hosted by the service provider or another infrastructure.

[0054] Thus, during a first step, such a service instance, called the first service instance, receives at least a first identifier, from the terminal (directly or via an intermediate router).

[0055] The first service instance can then return, to the terminal, a message containing the data associated with the service and at least a second identifier, a function of said first identifier.

[0056] In other words, a second identifier corresponds either to a first identifier received from the terminal, or to a new identifier obtained from a first identifier received from the terminal. For example, a second identifier is obtained by applying a hash function to a first identifier. Other functions can be used, as long as they allow the two identifiers to be linked: the second identifier must be obtainable from the first identifier, and the first identifier must be found from the second identifier.

[0057] This message passes through an edge node that provides access to the terminal. The edge node extracts the second identifier(s). If the second identifier matches a first identifier, the edge node identifies the network slice(s), or type(s) of network slice(s), associated with this first identifier. If the second identifier is obtained by applying a function distinct from an identity function to a first identifier, the edge node retrieves the first identifier, and identifies the network slice(s) associated with this first identifier, and the corresponding traffic classification rules.

[0058] The edge node may then relay the data to the terminal via the network slice(s), or type(s) of network slice(s) thus selected according to the application of traffic classification rules. Optionally, the edge node may remove the second identifier(s) from the message before transmitting the data to the terminal.

[0059] In a particular embodiment, the method comprises receiving at least one traffic classification rule for routing data associated with said at least one first identifier, and storing said at least one traffic classification rule and said at least one associated first identifier.

[0060] Such a step is notably implemented when several first identifiers are communicated to the service instance, for example a first identifier A corresponding to a first address of the terminal and a first identifier B corresponding to a second address of the same terminal.

[0061] In a particular embodiment, the first service instance receives at least two first identifiers each associated with at least one network slice and applies at least one traffic classification rule to select one of the first identifiers.

[0062] For example, if the service is of type immersive, the service instance may select a first identifier associated with a network slice of type URLLC, rather than a first identifier associated with an EMBB network slice.

[0063] In a particular embodiment, the first service instance implements the transmission of the message comprising said at least one second identifier and data associated with said at least one service to at least one second service instance capable of providing said at least one service.

[0064] A single service can thus involve a plurality of service instances, without requiring the terminal to transmit the first identifier(s) of the traffic to the service instances. This avoids unnecessary consumption of communication network resources.

[0065] Traffic classification rules resulting from the completeness of the SOLACE procedure can thus be synchronized between several service instances.

[0066] In another embodiment, the invention relates to a service instance capable of implementing the method for providing at least one service described above. Such a service instance can of course have the different characteristics relating to the method for providing at least one service according to the invention, which can be combined or considered in isolation. Thus, the characteristics and advantages of this service instance are the same as those of the method and are not detailed further.

[0067] The invention also relates to a method for managing access to at least one service by a terminal, via a communication network, comprising: receiving at least one message from at least one first service instance capable of providing said at least one service, said message comprising at least one second identifier, a function of at least one first identifier intended for the classification of the traffic to said terminal and the data associated with said at least one service,

[0068] said at least one first identifier being associated with at least one network slice or type of network slice, selecting at least one network slice associated with said at least one first identifier by applying at least one known traffic classification rule (received from a controller), transmitting said data associated with said at least one service on said at least one selected network slice.

[0069] Such a method can in particular be implemented in an edge node of the communication network.

[0070] As indicated previously, such an edge node can thus receive at least a second identifier and data associated with the service that the terminal wishes to access. The edge node can in particular extract the second identifier(s), corresponding either to the first identifier(s) or to a function of the first identifier(s). In the latter case, the edge node can implement an inverse function to find the first identifier(s). The edge node can then apply a traffic classification rule to check whether a network slice, or a type of network slice, is associated with this or these first identifier(s). If so, the data can be transmitted to the terminal via the network slice or type of network slice thus identified.Otherwise, the data is not transmitted to the terminal or it is transmitted via a default path, or a route determined according to a classic IP routing scheme for example, which does not necessarily rely on the use of network slices.

[0071] Thus, the message received from the service instance may contain the first identifier(s), encoded in a single field or in several fields, explicitly or implicitly. In explicit mode, the message directly carries the first identifier(s). In implicit mode, the message carries information (second identifiers) allowing the first identifier(s) to be found.

[0072] Optionally, the edge node may remove the second identifier(s) from the message before transmitting the data to the terminal.

[0073] In another embodiment, the invention relates to an edge node adapted to implement the method for managing access to at least one service described above. Such an edge node can of course have the different characteristics relating to the method for managing access to at least one service according to the invention, which can be combined or considered in isolation. Thus, the characteristics and advantages of this edge node are the same as those of the method and are not detailed further.

[0074] In the various embodiments envisaged, said at least one first identifier is associated with a validity period. For example, such a first identifier may change over time. Similarly, said at least one second identifier may be associated with a validity period, identical to or different from that associated with the first identifier from which the second identifier is constructed.

[0075] In particular, said at least one first identifier may be associated with a security key, for example a token or a random number.

[0076] For example, a random or pseudo-random number, unique to a terminal, is also communicated to the terminal with the first identifier(s) / tag(s). Such a security key can be used for authorization purposes. This improves the robustness of the process and prevents a terminal from using an identifier communicated to another terminal.

[0077] In the various embodiments envisaged, at least one of said network slices may be composed of at least one local network slice deployed in at least one subnetwork of the communication network (for example in an access network, a collection network, a core network, a transit network).

[0078] The invention further relates to at least one computer program comprising instructions for implementing at least one of the methods described above, when this or these programs are executed by a processor, as well as to at least one computer-readable information medium comprising instructions of at least one computer program as mentioned above.

[0079] The method according to the invention can be implemented in various ways, in particular in wired form or in software form. 4. List of figures

[0080] Other characteristics and advantages of the invention will appear more clearly on reading the following description of a particular embodiment, given as an illustrative and non-limiting example, and the appended drawings, among which:represents a system in which the invention can be implemented;illustrates the main steps of the methods according to at least one embodiment of the invention;illustrates the main messages exchanged during the implementation of the methods according to the;illustrates an example of a communication network composed of several sub-networks;illustrates an example of aggregation of several services within the same network slice;illustrates an example of deployment of several service instances;presents the different entities involved in the running of the collaborative mode of the SOLACE procedure;illustrates an example of traffic association with network slices and arriving at an edge node and destined for the terminal;illustrates an example of a problem preventing the association of traffic with network slices and arriving at an edge node;illustrates an example of activation of the SOLACE procedure in the presence of a CPE;presents an example of a PCP (“Port Control Protocol”) option implemented by a terminal to obtain at least a first identifier intended for the classification of traffic destined for the terminal and authorized to be routed via a given slice;presents the simplified structure of the different entities according to a particular embodiment.;

[0081] 5. Description of an embodiment of the invention 5.1 General principle

[0082] The general principle of the invention is based on the use of one or more first identifiers (tags) intended for the classification of traffic to a terminal, to identify the network slice that traffic to a terminal is authorized to use. This principle is part of a context where a terminal wishes to access at least one service via a communication network implementing network slices. In this way, an edge node of the communication network can identify the network slice(s) via which the return traffic (i.e. to the terminal) must be routed, without having to inspect the data associated with the service in question.

[0083] Thus, the proposed solution offers, according to at least one embodiment, a mechanism for automatic and secure discovery of network slices deployed (or instantiated) on a fixed and / or mobile infrastructure and reserved for a certain use, for example the retransmission of a sporting or musical event.

[0084] In particular, most existing solutions assume that the outbound traffic between the terminal and the service provider, and the return traffic between the service provider and the terminal are routed via the same network slice. According to the prior art, the terminal does not control access to the network slice(s) used to route the data associated with the service in question and thus does not allow it to benefit from the resources of the network slice that optimizes the quality of the service in question, as it may be perceived by the user of the terminal, in particular. The terminal therefore has no means of verifying that the network slice to which the service instance connects is the one that implements a traffic routing policy optimized for the service in question and as subscribed to by the customer.

[0085] The invention, according to at least one embodiment, proposes a solution to this problem.

[0086] Illustrates an example of a system in which the invention can be implemented. Such a system comprises a terminal UE 11 (“User Equipment” in English) wishing to access at least one service via a communication network SSP 12 (“Slice Service Provider” in English, or service provider based on network slices) implementing network slices, for example two network slices Sl. #1 161 and Sl. #2 162 (“Slice” in English).

[0087] Terminal 11 may optionally be connected to network 12 via an intermediate router, for example a CPE.

[0088] The service may be provided by at least one service instance, for example by two service instances SFI #1 131 and SFI #2 132. A service instance may be connected to the network 12 via a network border node. For example, the first instance 131 is connected to the network 12 via the first border node BR 141 (Border Router), and the second instance 132 is connected to the network 12 via the second border node BR 142. The service instances are not necessarily directly connected to the border nodes.

[0089] At least one network controller 15 may be used to transmit to at least one edge node of the network 12 (for example in the edge nodes 141 and 142) traffic classification rules (for example in algorithmic form, or in the form of at least one traffic classification table, or in any other form). The controller 15 may also transmit to the terminal 11 the first identifier(s) (also called “tags”) of the traffic destined for the terminal. The controller 15, or the edge node, may maintain at least one traffic classification rule, making it possible to associate a first identifier of the traffic with at least one network slice. It is noted that the configuration of the edge nodes and the terminals may be carried out by separate network entities.

[0090] We now present, in relation to the, the main steps implemented by the different methods according to an embodiment of the invention.

[0091] It is considered that the controller 15 obtains during a step 151 at least one first TAG identifier intended for the classification of the traffic intended for the terminal 11. Such a first identifier is associated with at least one network slice or one type of network slice. For example, the controller maintains a traffic classification rule according to which the first TAG identifier #1 is associated with the network slice Sl #1.

[0092] During a step 152, said at least one first TAG identifier is transmitted to the terminal 11, directly or via at least one intermediate router.

[0093] During a step 153, the controller 15 transmits, to at least one border node of the communication network, for example the BR1 node 141, at least one traffic classification rule for the selection of at least one network slice intended to route to the terminal data associated with said at least one service. For example, such rules can be configured in the border node, or implemented by the execution of an algorithm known to the border node (received from a controller).

[0094] It is noted that step 153 can be implemented before steps 151 and / or 152. In other words, the transmission of the traffic classification rules to the border node can be implemented before or after having transmitted said at least one first TAG identifier to the terminal 11. Optionally, step 153 can be implemented by another controller.

[0095] During a step 111, the terminal 11 therefore receives said at least one first TAG identifier, from the controller 15, directly or via at least one intermediate router.

[0096] During a step 112, the terminal 11 transmits said at least one first TAG identifier to at least one first service instance capable of providing the service in question, for example to the first service instance SFI #1 131.

[0097] During a step 1311, the first service instance 131 therefore receives said at least one first TAG identifier.

[0098] During a step 1312, the first service instance 131 transmits, via at least one border node, for example the first border node BR 141, a message MSG1 comprising at least a second identifier and data D associated with the service in question. This data D is intended for the terminal 11. For example, the second identifier is equal to the first identifier TAG. In a variant, the first identifier is used to calculate a second identifier which can be included in said message. For example, the second identifier is obtained by applying a hash function “Hash” to the first identifier.

[0099] In the illustrated example, the second identifier is considered to be equal to the first TAG identifier. The message MSG1 sent by the first service instance 131 therefore comprises said at least one first TAG identifier and the data D.

[0100] During a step 1412, the first border node 141 therefore receives the message MSG1 from the first service instance 131 comprising said at least one first TAG identifier and the data D.

[0101] During a step 1413, the first border node 141 checks whether at least one network slice is associated with said at least one first TAG identifier by applying at least one traffic classification rule known to the first border node 141 (for example configured during a step 1411), and selects said at least one corresponding network slice.

[0102] During a step 1414, the first border node 141 transmits the data D associated with the service considered on said at least one selected network slice. The first border node 141 can retransmit to the terminal 11 the message MSG1 comprising said at least one first TAG identifier and the data D as received from the first service instance 131, or delete said at least one first TAG identifier to send only the data D to the terminal 11 in a message MSG1'.

[0103] During a step 113, the terminal 11 therefore receives the message MSG1' comprising the data D routed via at least one network slice associated with said at least one first TAG identifier.

[0104] This is a flowchart illustrating the messages exchanged according to the main steps described in.

[0105] More generally, it is considered that a network slice of the communication network can be associated with other network slices to provide value-added services. For example, a service provider can rely on slices set up in different subnets to provide a service whose traffic is intended to be routed in the "global" network slice composed of slices deployed in the different subnets. This is called a "multi-domain slice" (or "stitched slices" or "hierarchical slices"). Such a network slice can indeed reflect a hierarchical structure.

[0106] For example, as illustrated by the, the SSP network 12 may be composed of several subnetworks 121, 122 and 123. Each subnetwork may support one or more network slices. For example, the first subnetwork 121 supports four network slices, the second subnetwork 122 supports three network slices, and the third subnetwork 123 supports four network slices. The first network slice Sl. #1 161 of the communication network is for example composed of network slices Sl. #3 deployed on the subnetwork 121, Sl. #2 deployed on the subnetwork 122 and Sl. #2 deployed on subnet 123. The connection interfaces between adjacent slices ("Attachment Circuits" in English) are for example managed using the mechanisms described in the document "YANG Data Models for 'Attachment Circuits'-as-a-Service (ACaaS)" by M. Boucadair et al., version 6 published on May 3, 2023.

[0107] For example, each subnetwork may be associated with a distinct domain (e.g., a communications network may be composed of an access network, a collection network, a core network, and a transit network). Each of these domains supports network slices whose engineering and operation are characteristic of the domain (e.g., a slice deployed on a 5G mobile core network may use traffic processing and operation functions characteristic of a 5G mobile core network). Thus, each domain (access, collection, core, transit, etc.) may exploit different technologies deployed in this domain for the realization of the network slices.

[0108] Thus, the creation of a network slice that extends over several domains is not conditioned by the availability or activation of the same technologies used for the creation of the slices "local" to each domain.

[0109] For example, with reference to the, a first domain associated with the first subnet 121 sets up IPsec tunnels which are used to route traffic in the slices deployed in this domain, while a second domain associated with the second subnet 122 uses network-level virtual private network engineering (Layer 3 VPN or L3VPN) combined with traffic engineering mechanisms (Traffic Engineering or TE) to route traffic in the slices deployed in this domain, while a third domain associated with the third subnet 123 uses the resources of segment routing based on the IPv6 protocol (Segment Routing IPv6 or SRv6) to route traffic in the slices deployed in this domain.

[0110] As another example, a network slice in a mobile network (e.g. 5G) may be based on the implementation of network slices in the following different subnetworks / segments: radio access network (RAN), core network (CN) and transport network (TN).

[0111] The association between a network slice, for example a 5G network slice in the case of a latest generation mobile network, and the network slices deployed in each of the segments / subnetworks composing the 5G mobile network is carried out in the control plane and at the edge of each of the RAN, CN and TN networks. The network slice deployed in the TN network is sometimes called an “IETF Network Slice”.

[0112] According to the invention, no assumption is made as to the nature of the network slices, their number, and the "mapping" between network slices of neighboring domains (for example RAN and TN, TN and CN).

[0113] For example, the mechanisms described in the previously cited document “A Realization of IETF Network Slices for 5G Networks Using Current IP / MPLS Technologies” are implemented for the realization of network slices in an IP / MPLS network (which is an example of a transport network within the meaning of 3GPP).

[0114] It is further noted that the same network slice can be used to aggregate the traffic of one or more services. Thus, as illustrated by the, a first service S1 served by one or more service instances 51 can be provided to a first client UE1 via a network slice Sl. #3 of the SSP network, a second service S2 served by one or more service instances 52 can be provided to a second client UE2 via the same network slice Sl. #3 of the SSP network, a third service S3 served by one or more service instances 53 can be provided to the second client UE2 via the same network slice Sl. #3 of the SSP network.

[0115] Additionally, a network slice may involve one or more service functions (or "Service Functions" in English, according to the terminology used by RFC7665 - "Service Function Chaining (SFC) Architecture" by J. Halpern et al. published in October 2015, or "Network Functions" such as gNB ("gNodeB") or UPF ("User Plane Functions") according to the terminology used by 3GPP). A single service function may be provided by one or more service instances.

[0116] Illustrates an example of deploying service instances. In particular, a service instance may be hosted by the SSP (e.g., service instances 63 and 64) or within another infrastructure (e.g., service instance 65).

[0117] In a particular embodiment, service chains (Service Function Chain or SFC) can be set up in order to facilitate the routing of traffic of different nature and having different profiles for the needs of the creation of a network slice or within a network slice (for example the service instances 611, 612 and 613 of the). 5.2 Implementation examples

[0118] Examples of implementation of the invention are now presented. For the sake of simplification, the first identifier and the second identifier are considered to be identical below. The term “identifier” is therefore simply used.

[0119] Referring again to the, it is considered that the terminal 11 negotiates with the SSP 12 a list of at least one network slice that the terminal 11 is likely to use to send or receive traffic. The terminal 11 can indicate, if applicable, the transmission mode envisaged for each of the network slices of said list: the routing of data to the terminal 11 (“receive-only”), the routing of data from the terminal 11 (“send-only”), the routing of associated data to the terminal 11 and from the terminal 11 (“send-receive”).

[0120] According to this example of implementation of the invention, the terminal 11 and the SSP 12 exchange messages to ensure that they both support the SOLACE procedure (“Optimized Slicing A LA Carte”).

[0121] For example, the terminal 11 values ​​a first indicator or parameter noted “Collaborative-Solace-Capable” at a given value, for example “1”, to indicate to the SSP 12 that it is capable of implementing a collaborative procedure for routing data associated with at least one service which the terminal wishes to access and to the terminal, based on the processing of at least one identifier (tag) intended for the classification of traffic to the terminal.

[0122] This indication of support for the SOLACE procedure can be provided globally or upon activation of each network slice.

[0123] If the SSP 12 supports the SOLACE procedure, it returns a second indicator or parameter “Collaborative-Solace-Capable” set to a given value, for example “1”, to indicate to the terminal 11 that it is capable of implementing a collaborative procedure for routing data associated with at least one service which the terminal wishes to access and to the terminal, based on the processing of at least one identifier (tag).

[0124] The second indicator may be returned to the terminal 11 in response to receiving the first indicator. Alternatively, it is the first indicator that is returned by the terminal 11 in response to receiving the second indicator.

[0125] The collaborative mode of the SOLACE procedure is then activated by terminal 11 and SSP 12.

[0126] Conversely, if the second indicator or parameter “Collaborative-Solace-Capable” returned by the SSP 12 is equal to “0”, then the terminal 11 deactivates the collaborative mode of the SOLACE procedure.

[0127] It is then assumed that the collaborative mode of the SOLACE procedure is activated.

[0128] As illustrated by the, a network controller 15 can transmit to the terminal 11 at least one identifier (tag) intended for the classification of the traffic destined for the terminal 11. Such a tag, noted for example “Inbound-Flow-Map”, can be returned for each network slice negotiated with the terminal 11. The network controller 15 can in particular maintain up to date at least one traffic classification rule associating at least one identifier of the traffic destined for the terminal, or tag, with at least one network slice.

[0129] Thus, the absence of the tag and / or the second indicator "Collaborative-Solace-Capable" is an implicit indication of the non-support of the collaborative mode of the SOLACE procedure by the SSP 12.

[0130] In particular, the SOLACE collaborative mode can be negotiated with each of the networks to which the terminal can connect. In this case, the terminal 11 can retrieve separate tags per network to which the terminal 11 is connected.

[0131] In a particular embodiment, a validity period or an expiry date may be associated with the tag. In this case, a new tag ("Inbound-Flow-Map") may be renegotiated with the network at said expiry date or at the expiration of said validity period.

[0132] In another variation, a security key may be associated with the tag. For example, a random or pseudo-random number, or "nonce," unique to a terminal, is also communicated to the terminal with the tag(s). Such a security key may be used for authorization purposes.

[0133] The network controller 15 (or another network controller) may also transmit to the edge nodes, for example to the first edge node BR 141 and to the second edge node BR 142, traffic classification rules to associate the incoming traffic on the edge node with the network slice(s) negotiated with the terminal 11 (and thus associate the identifier of the traffic destined for the associated terminal, or tag, with the network slice(s) negotiated with the terminal 11).

[0134] Note that the same tag can be negotiated with multiple terminals to optimize the size of traffic classification tables when traffic classification rules are stored in tables maintained by edge nodes.

[0135] The terminal 11 can thus associate the return traffic of each service eligible for the operation of slices with at least one network slice, using at least one tag. The return traffic of the same service can be associated with several network slices depending on the nature of the service. The classification of each of these categories according to a type of network slice can be defined by the logic of the service (for example integrated into the application embedded in the terminal 11) or provided by the SSP network 12. The classification of the different traffic can also be the subject of a decision taken by the terminal 11 (for example, according to the choices and instructions of the user of the terminal 11).

[0136] To do this, the terminal 11 can transmit one or more tags to at least one service instance capable of providing the service that the terminal wishes to access. For example, the terminal 11 uses a new parameter hereinafter called “Solace”, to transmit the tag(s) in a message that it sends to a service instance, for example to the first service instance SFI #1 131.

[0137] If the Solace parameter contains only one "Inbound-Flow-Map" tag, then this tag applies to all traffic emitted by the service instance.

[0138] If this Solace parameter contains a list of "Inbound-Flow-Map" tags, then traffic classification rules are also provided by the terminal 11 to the service instance, so that the traffic emitted by the service instance and the associated tag can be identified.

[0139] In a context where the terminal 11 is connected to several communication networks (context of “multihoming” for example), the terminal 11 ensures that the traffic classification rules thus generated make it possible to associate the traffic with the tag of the network intended to route said traffic.

[0140] For example, as illustrated in, the terminal 11 may be connected to a first communication network SSP1 and to a second communication network SSP2. The terminal 11 may explicitly indicate, for example via the Solace parameter, its destination address in each communication network as a traffic classification rule, corresponding here to a demultiplexing parameter.

[0141] Thus, the Solace parameter contains for example a list of tags including a first tag TAG1 corresponding to the address of the terminal via the first SSP1 network (noted dst@1), and a second tag TAG2 corresponding to the address of the terminal via the second SSP2 network (noted dst@2): Solace {dst@1=TAG1, dst@2=TAG2}.

[0142] In particular, the new Solace parameter can be inserted into a dedicated header (e.g. HTTP header, QUIC frame) or described in messages characteristic of protocols such as SDP ("Session Description Protocol") or WebRTC.

[0143] The following example illustrates the use of a new SDP attribute for transmitting the Solace parameter between terminal 11 and a service instance, hereinafter called "a=slice-tag":v=0o=- 25678 753849 IN IP6 2001:db8::1s=c=IN IP6 2001:db8::1t=0 0m=audio 12340 RTP / AVP 0 8a=slice-tag:156 IP6 2001:db8::1 45678a=slice-tag:651 IP6 2001:db8::123 12340

[0144] According to this example, the tag “156” (i.e. the identifier intended for the classification of traffic to the terminal) can be used by the service instance if the destination address used to send the traffic to the terminal 11 is “2001:db8::1”, while the tag “651” can be used by the service instance if the destination address used to send the traffic to the terminal 11 is “2001:db8::123”.

[0145] It is understood that this example is provided for illustration purposes only; other parameters to characterize the traffic associated with each tag can be indicated in an SDP offer / answer for example.

[0146] Returning to the, the message with the parameter "Solace" sent to a service instance is routed from terminal 11 using a network slice configured for this purpose or using a default path if no network slice is available or enabled to route traffic to this service instance.

[0147] Upon receiving the message with the “Solace” parameter, the service instance checks for the presence of at least one tag (“Inbound-Flow-Map”).

[0148] For example, the service instance extracts and then locally saves the traffic classification rule(s) transmitted by the terminal, as well as the associated tag(s).

[0149] If applicable, these tags replace those already present for the same traffic classification rules.

[0150] Optionally, the service instance confirms the correct implementation of the traffic classification rules. This confirmation can be communicated to the terminal 11 using a dedicated acknowledgment parameter (e.g. HTTP header, QUIC frame) or described explicitly in messages characteristic of protocols such as SIP, SDP or WebRTC. For some services, the absence of an error message can also be interpreted as an implicit acknowledgment and confirmation.

[0151] If outgoing traffic (from at least one service instance and destined for the terminal 11) is associated with a traffic classification rule communicated by the terminal, then the service instance marks the traffic with the corresponding tag. In other words, the service instance can send an MSG1 message comprising one or more tags and, for each tag, the data associated with the service to which the terminal wishes to access according to the traffic classification rules communicated by the terminal. For example, the tag(s) can be inserted into a UDP option, an HTTP header, a SIP header, the Flow Label field of an IPv6 packet header, an IPv6 extension header, etc.

[0152] For example, as illustrated by the, the first service instance SFI #1 131 can transfer the message MSG1 to other service instances involved in the provision of the service, such as the second service instance SFI #2 132. This is advantageous because the same service can involve a plurality of service instances without having to repeat the phase of communication of the tags by the terminal with all the service instances. This synchronization is particularly advantageous for services that use anycast addressing (i.e., the service instances can be reached from the same IP address).

[0153] The return traffic (from at least one service instance and destined for the terminal 11) is received by at least one border node, for example the first border node BR 141 and / or second border node BR 142. On receipt of the MSG1 message sent by the service instance, the border node BR inspects, then extracts the tag(s) if necessary.

[0154] If no tag is present, then the traffic is processed according to a default routing rule. For example, traffic is routed to terminal 11 via a default route (e.g., a route that is not established in any of the deployed network slices, or a network slice dedicated to so-called "Best Effort" traffic).

[0155] If a tag is present, the border node BR applies ad hoc traffic classification rules (e.g. by consulting a traffic classification table that it maintains locally) to identify the network slice associated with the tag: if no entry in the traffic classification table is found, then the traffic can be routed to the terminal 11 via a default route, or blocked. For example, in, the border node BR 142 does not have, in the traffic classification table, an entry describing the network slice associated with the tag received in the MSG1 message. The data is therefore routed according to a default route, which does not necessarily rely on the use of network slices. if an entry in the traffic classification table is identified by the border node BR, then the latter routes the traffic according to the content of this entry, i.e. via the network slice identified from the tag.For example, in, the edge node BR 141 recognizes that the tag received in the message MSG1 is associated with the network slice Sl. #2. It can therefore transmit the data to the terminal 11 via the network slice Sl. #2.

[0156] Returning to the, the edge node BR 141 of the first SSP1 network receives D1 data and the identifier TAG1 from the service instance 131, and can select, from the reading of the traffic classification table, the network slice associated with the identifier TAG1 for routing the D1 data via the first SSP1 network, for example the network slice Sl. #3. The edge node BR 842 of the second SSP2 network receives D2 data and the identifier TAG2 from the service instance 131, and can select, from the reading of the traffic classification table, the network slice associated with the identifier TAG2 for routing the D2 data via the second SSP2 network, for example the slice SL. #1. The D1 and D2 data can be the same or different.

[0157] On the other hand, as illustrated by the, if the edge node BR 141 of the first network SSP1 receives data D1 and the identifier TAG2 from the service instance 131, no entry is found in the traffic classification table. The data D1 is therefore routed to the terminal 11 using a default route, or a route determined according to a conventional IP routing scheme for example.

[0158] Optionally, the BR edge node can remove the tag(s) before retransmitting the data to the terminal.

[0159] In a variant, the border node BR checks for the presence of a security key, for example the presence of a valid “nonce” parameter associated with the terminal in question, before injecting the traffic into a network slice. The verification of the validation of the “nonce” can be performed locally or by involving a network controller, for example the controller 15. The verification is not necessarily performed systematically for all the packets of the MSG1 message which carry a tag and a security key.

[0160] Alternatively, the edge node BR may calculate a hash based on a first packet of the MSG1 message, and this hash may then be used to validate subsequent packets without requiring intervention from a network controller.

[0161] If the terminal 11 detects an anomaly / inconsistency between the network slice used for return traffic of a given service and the indications communicated to the service instance, in particular the tag intended for the classification of the return traffic and / or the security key, the terminal can proceed as follows: resend the marking instructions to the service instance, i.e. resend the Solace parameter, negotiate a new SOLACE procedure with the network, i.e. renegotiate the list of network slices that the terminal is likely to use to send or receive traffic, adjust the traffic classification rules.

[0162] In another embodiment, the terminal 11 is not connected directly to the communication network, but via a connection equipment (for example a CPE or other intermediate router). In this embodiment, the connection equipment can implement the SOLACE procedure as if the terminal were directly connected to the network.

[0163] Alternatively, the CPE can negotiate with the terminal the activation of the SOLACE procedure. For example, the communication of tags to service instances is performed by the terminal.

[0164] In another variant, the CPE inserts tags according to rules local to the CPE. These rules can be configured by the user or communicated by the terminal via a dedicated mechanism (PCP, for example).

[0165] Thus, as illustrated by the, the controller 15 can transmit the tag(s) to the CPE 10. The terminal 11 can contact the CPE 10 to retrieve the tags associated with each network slice. For example, the terminal 11 uses new options that can be supported by different protocols such as PCP (Port Control Protocol), DHCP (Dynamic Host Configuration Protocol), RA (Router Advertisement message in IPv6 environment), etc., to obtain the tags.

[0166] An example of a PCP option used for this purpose is provided in. According to this example, the "Tag count" field indicates the number of tags included in the PCP option. Optionally, the "Traffic Selector" field can be filled in for a tag. This field describes, for example, the traffic classification rule eligible for marking with said tag (e.g., destination IP address, destination port number, protocol identifier), by a service instance, of the data associated with the service in question. If no rule is indicated, then the marking of data with a tag is applicable to all traffic entering the service instance (i.e., to the terminal).

[0167] If the collaborative mode of the SOLACE procedure is disabled, the terminal may indicate in a message to a service instance the list of network slices negotiated with the network. Upon receipt of this message, the service instance may choose to invoke a slice distinct from the one used to route this message, for all or part of the traffic to the terminal.

[0168] Various examples of implementation of the invention have been described above. Of course, these examples are purely illustrative and non-limiting. In particular, as already indicated, no assumption is made according to the invention as to the nature of the network slices, their number, and the possible “mapping” between network slices of neighboring domains (for example RAN and TN, TN and CN). In particular, a network slice can be deployed on a fixed infrastructure, mobile infrastructure, or a combination of both.

[0169] 5.3 Simplified structure of the corresponding entities

[0170] Finally, in relation to the, the simplified structures of an entity are presented, for example a terminal, a controller, a service instance, or an edge node according to at least one embodiment described above.

[0171] As illustrated by the, such an entity comprises at least one memory 121 comprising a buffer memory, at least one processing unit 122, equipped for example with a programmable computing machine or a dedicated computing machine, for example a processor P, and controlled by the computer program 123, implementing steps of at least one method according to at least one embodiment of the invention.

[0172] Upon initialization, the code instructions of the computer program 123 are for example loaded into a RAM memory before being executed by the processor of the processing unit 122.

[0173] If the entity is a terminal, the processor of the processing unit 122 implements steps of the method of accessing at least one service described previously, according to the instructions of the computer program 123, to: obtain at least a first identifier intended for the classification of the traffic intended for said terminal,

[0174] said at least one first identifier being associated with at least one network slice or one type of network slice,transmitting said at least one first identifier to at least one first service instance capable of providing said at least one service to said terminal,receiving a message comprising data associated with said at least one service routed via at least one network slice associated with said at least one first identifier, said at least one network slice being selected by an edge node of said communication network by applying at least one traffic classification rule known to said edge node.

[0175] If the entity is a controller, the processor of the processing unit 122 implements steps of the method for controlling the provision of at least one service described previously, according to the instructions of the computer program 123, to: obtain at least a first identifier intended for the classification of the traffic intended for said terminal,

[0176] said at least one first identifier being associated with at least one network slice or one type of network slice,transmitting said at least one first identifier to said terminal, directly or via at least one intermediate router,transmitting, to at least one edge node of said communication network, at least one traffic classification rule for the selection of at least one network slice intended to route to said terminal data associated with said at least one service.

[0177] If the entity is a service instance, the processor of the processing unit 122 implements steps of the method for providing at least one service described previously, according to the instructions of the computer program 123, to: receive at least a first identifier intended for the classification of the traffic intended for said terminal,

[0178] said at least one first identifier being associated with at least one network slice or one type of network slice, the transmission, via at least one edge node of said communication network, of a message comprising at least one second identifier, a function of said at least one first identifier, and data associated with said at least one service, said data being intended to be routed via at least one network slice associated with said at least one first identifier,

[0179] said at least one network slice being selected by said border node by applying at least one traffic classification rule known to said border node.

[0180] If the entity is an edge node, the processor of the processing unit 122 implements steps of the method for managing access to at least one service described previously, according to the instructions of the computer program 123, to:receive at least one message from at least one first service instance capable of providing said at least one service, said message comprising at least one second identifier, a function of at least one first identifier intended for the classification of the traffic intended for said terminal, and data associated with said at least one service,

[0181] said at least one first identifier being associated with at least one network slice or one type of network slice,selecting at least one network slice associated with said at least one first identifier by applying at least one known traffic classification rule,transmitting said data associated with said at least one service on said at least one selected network slice.

Claims

A method for accessing at least one service by a terminal (11), via a communication network implementing network slices, comprising:obtaining (111) at least one first identifier intended for classifying traffic to said terminal, said at least one first identifier being associated with at least one network slice or type of network slice,transmitting (112) said at least one first identifier to at least one first service instance (131) capable of providing said at least one service to said terminal,receiving (113) a message comprising data associated with said at least one service routed via at least one network slice associated with said at least one first identifier, selected by an edge node (141) of said communication network by applying at least one traffic classification rule known to said edge node. Method according to claim 1, characterized in that said at least one network slice or said type of network slice is associated with a transmission mode belonging to the group comprising: the routing of data to said terminal, the routing of data from said terminal, the routing of data to said terminal and from said terminal. Method according to any one of the preceding claims, characterized in that said obtaining comprises obtaining at least one first identifier per network to which said terminal is connected. Method according to any one of the preceding claims, characterized in that it comprises the transmission, to said first service instance, of at least one traffic classification rule. Method according to any one of the preceding claims, characterized in that it implements a prior selection of said at least one first service instance authorized to receive said at least one first identifier. A method for controlling the provision of at least one service to a terminal (11), via a communication network implementing network slices, comprising:obtaining (151) at least one first identifier intended for classifying traffic to said terminal, said at least one first identifier being associated with at least one network slice or type of network slice,transmitting (152) said at least one first identifier to said terminal, directly or via at least one intermediate router,transmitting (153), to at least one border node (141) of said communication network, at least one traffic classification rule for selecting at least one network slice intended to route data associated with said at least one service to said terminal. Method according to claim 6, characterized in that it comprises the transmission of said at least one first identifier to at least one other terminal connected to said communication network. A method for providing at least one service to a terminal (11), via a communication network implementing network slices, comprising:receiving (1311) at least one first identifier intended for classifying traffic to said terminal, said at least one first identifier being associated with at least one network slice or type of network slice,transmitting (1312), via at least one border node (141) of said communication network, a message comprising at least one second identifier, a function of said at least one first identifier, and data associated with said at least one service, said data being intended to be routed via at least one network slice associated with said at least one first identifier, selected by said border node by applying at least one traffic classification rule known to said border node. Method according to claim 8, characterized in that it comprises receiving at least one traffic classification rule for routing data associated with said at least one first identifier, and storing said at least one traffic classification rule and said at least one associated first identifier. Method according to any one of claims 8 and 9, characterized in that said reception comprises the reception of at least two first identifiers each associated with at least one network slice and the application of at least one traffic classification rule to select one of said first identifiers. Method according to any one of claims 8 to 10, characterized in that it comprises the transmission of said message comprising said at least one second identifier and data associated with said at least one service to at least one second service instance capable of providing said at least one service. A method for managing access to at least one service by a terminal, via a communication network, comprising:receiving (1412) at least one message from at least one first service instance (131) capable of providing said at least one service, said message comprising at least one second identifier, a function of at least one first identifier intended for classifying traffic to said terminal, and data associated with said at least one service, said at least one first identifier being associated with at least one network slice or type of network slice, selecting (1413) at least one network slice associated with said at least one first identifier by applying at least one known traffic classification rule, transmitting (1414) said data associated with said at least one service on said at least one selected network slice. Method according to any one of claims 1 to 12, characterized in that said at least one first identifier is associated with a validity period. Method according to any one of claims 1 to 13, characterized in that said at least one first identifier is associated with a security key. Method according to any one of claims 1 to 14, characterized in that at least one of said network slices is composed of at least one local network slice deployed in at least one subnetwork of said communication network. Terminal (11) capable of accessing at least one service, via a communication network implementing network slices, comprising at least one processor configured to:obtain at least one first identifier intended for the classification of traffic to said terminal, said at least one first identifier being associated with at least one network slice or a type of network slice,transmit said at least one first identifier to at least one first service instance capable of providing said at least one service to said terminal,receive a message comprising data associated with said at least one service routed via at least one network slice associated with said at least one first identifier, selected by a border node of said communication network by applying at least one traffic classification rule known to said border node. Controller (15) capable of controlling the provision of at least one service to a terminal, via a communication network implementing network slices, comprising at least one processor configured to:obtain at least one first identifier intended for the classification of traffic to said terminal, said at least one first identifier being associated with at least one network slice or a type of network slice,transmit said at least one first identifier to said terminal, directly or via at least one intermediate router,transmit, to at least one edge node of said communication network, at least one traffic classification rule for the selection of at least one network slice intended to route to said terminal data associated with said at least one service. Service instance (131, 132) capable of providing at least one service to a terminal, via a communication network implementing network slices, comprising at least one processor configured to:receive at least one first identifier intended for the classification of traffic to said terminal, said at least one first identifier being associated with at least one network slice or type of network slice,transmit, via at least one edge node of said communication network, a message comprising at least one second identifier, a function of said at least one first identifier, and data associated with said at least one service, said data being intended to be routed via at least one network slice associated with said at least one first identifier, selected by said edge node by applying at least one traffic classification rule known to said edge node. Edge node (141, 142) capable of managing access to at least one service by a terminal, via a communication network, comprising at least one processor configured to:receive at least one message from at least one first service instance capable of providing said at least one service, said message comprising at least one second identifier, a function of at least one first identifier intended for classifying traffic to said terminal, and data associated with said at least one service, said at least one first identifier being associated with at least one network slice or type of network slice,select at least one network slice associated with said at least one first identifier by applying at least one known traffic classification rule,transmit said data associated with said at least one service on said at least one selected network slice. Computer program comprising instructions for implementing a method according to any one of claims 1 to 15 when this program is executed by a processor.