Method for determining a set of multicast streams which a receiving terminal is authorized to access.
The method addresses the complexity of managing access authorizations in communication networks by using a router to resolve aliases and determine authorized multicast streams, thereby simplifying authorization management and reducing errors.
Patent Information
- Application Number
- FR2023014175
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-14
- Publication Date
- 2025-06-20
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Current communication networks face complexity and risk of errors in managing access authorizations for receiver terminals to multicast content streams, particularly in dynamic environments like 5G mobile networks.
A method for determining authorized multicast streams involves a router receiving an alias from a receiving terminal, resolving it to obtain authorization information, and using this information to implement differentiated processing and subscription to relevant multicast groups.
This method simplifies the management of access authorizations, reduces the risk of errors, and enables quick identification of authorized multicast streams, facilitating efficient resource utilization in communication networks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for determining a set of multicast streams which a receiving terminal is authorized to access. Technical field
[0001] The field of the invention is that of communications within at least one communication network, and in particular that of value-added IP services. More specifically, the invention relates to the implementation of content broadcasting services using a multicast transmission mode in a communication network. Prior art
[0002] The broadcasting of the same content to multiple users is a service commonly offered and implemented via current communication networks, for example in the context of the retransmission of cultural or sporting events (retransmission of a concert in a metaverse, retransmission of a live football match, etc.). On a technical level, the engineering of such broadcasting services is generally based on a transmission mode called "multicast". This mode is in fact particularly suited to group communication schemes, such as the broadcasting of content to several users (receivers), or the implementation of videoconferencing type services between several users where each participant is in turn source or receiver.In Internet Protocol (IP) networks, multicast transmission relies on the computation, establishment, and maintenance of distribution trees by a dynamic routing protocol, such as Protocol Independent Multicast (PIM), RFC 7761. A primary objective of implementing such distribution trees is to optimize network resources based on a deterministic data replication model.
[0003] Communication networks, in particular fifth-generation (5G) mobile networks, also offer the possibility for the operators who operate them to manage authorizations (also called access control) relating to the routing of traffic on the network. Such authorizations are typically based on the application of traffic classification rules, generally applied by a network access point. Such an access point is a node located at the edge of the network, for example deployed in front of customer access or used to connect a network to other neighboring networks. For example, this access point can be located at the connection interface of a gateway (for example a packet gateway, or "Packet Gateway" in English, for the most recent generations - 4G, 5G - of mobile networks) which allows access to the Internet network. Such an access point can also be located at the interface for connecting a mobile terminal (or “User Equipment” or UE in English) to the radio access network (or “Radio Access Network” or RAN in English), in particular to optimize the use of radio resources according to the profile of the traffic that it is likely to carry.
[0004] In this context, the policy for routing content broadcast in multicast on a communication network is based in particular on the authorization of the receiver terminals to access said content. For example, if the communication network implements network slices, it must be able to determine the access capabilities of the receivers to one or other of the slices, depending for example on the nature of the broadcast service to which a receiver has subscribed. Such considerations make it possible to dynamically adjust with an adequate level of granularity (receiver, content) the traffic classification rules which govern the access or not of the receivers to one or other of these slices, and ultimately, to said content.
[0005] However, the implementation and maintenance (e.g. in the event of modifications to the access rights of a terminal or a user) of such classification rules currently involves complex network configurations, with a substantial risk of errors during the configuration operations in question.
[0006] There is therefore a need for a technique making it possible to simplify the management of access authorizations of receiver terminals to multicast content broadcast within a communication network, and more particularly the obtaining of such authorization information by the network. Summary of the invention
[0007] The present invention proposes a solution aimed at remedying certain drawbacks of the prior art. According to one aspect, the present invention relates to a method for determining a set of multicast streams to which a receiving terminal is authorized to access, from among a plurality of multicast streams broadcast by a content service on a communication network. According to the general principle of the proposed invention, such a method comprises, at the level of a router device of said communication network:
[0008] - receiving, from said receiving terminal, a first message of if signaling comprising a resolution key, called an alias, usable by said router equipment to determine said set;
[0009] - implementing a procedure for resolving said alias, comprising obtaining, depending on said alias, one of information from among (i) information representing an authorization of said receiving terminal to access at least one multicast stream of said plurality of multicast streams, comprising at least one multicast group address, called authorized multicast address, of at least one multicast group associated with the broadcasting of said at least one multicast stream; or (ii) information representing a lack of authorization of said receiving terminal to access any of said multicast streams of said plurality of multicast streams.
[0010] In this way, the communication network has means for quickly and simply identifying whether or not a receiving terminal is authorized to access all or part of the multicast streams broadcast by a content service, and is thus, for example, able to implement differentiated processing, for example applying classification rules, based on this information.
[0011] In a particular embodiment, said resolution procedure is implemented entirely within said router equipment.
[0012] In this way, the resolution of an alias can be implemented locally, and therefore more quickly, without the intervention of third-party equipment.
[0013] In another particular embodiment, said resolution procedure is implemented jointly with third-party equipment, said obtaining comprising:
[0014] - the transmission, to said third-party equipment, of a request for resolution of said alias, including said alias.
[0015] - the reception, from said third-party equipment, of said information represented indicating an authorization or lack of authorization.
[0016] According to a particular characteristic, said third-party equipment belongs to the group comprising:
[0017] - equipment for controlling said communication network;
[0018] - a domain name system (DNS) server within said communication network communication;
[0019] - equipment associated with said content service.
[0020] In this way, it is not necessary to propagate the information allowing the resolution of an alias, that is to say the information of correspondences between aliases and associated authorized multicast addresses, to a large number of router devices of a communication network: the router devices can thus rely on third-party devices better adapted or better optimized for such resolution operations.
[0021] In a particular embodiment, said alias has the format of a domain name, comprising one or more hierarchical levels.
[0022] In this way, the third-party equipment used for alias resolution operations can in particular take the form of existing equipment already deployed on the communications network and specialized for this purpose, such as domain name system servers for example.
[0023] According to a particular characteristic, one or more hierarchically higher levels of said hierarchical levels of said alias, forming a sub-alias called parent alias of said alias, uniquely identify said content service.
[0024] In this way, the content service can be identified directly from the alias.
[0025] In a particular embodiment, said parent alias is used to identify said content service to which to transmit a request for resolution of said alias, when said resolution procedure is configured to be implemented jointly with equipment associated with said content service.
[0026] In this way, the communication network is in particular able to route to the authoritative server of the parent alias any resolution request concerning child aliases.
[0027] In a particular embodiment, said procedure for resolving said alias comprises a step of searching for said alias within a list of aliases marked as having already been resolved, and, in the event of the presence of said alias in said list, the delivery of information representative of a lack of authorization of said receiving terminal to access any one of said multicast streams of said plurality of multicast streams.
[0028] In this way, the present technique makes it possible to set up access restrictions to certain multicast streams, when it is detected that the same alias is potentially shared between several receiving terminals.
[0029] In a particular embodiment, said reception of said signaling message follows the transmission of a first signaling request message sent by said router equipment to a set of receiving terminals connected to said communication network.
[0030] In this way, what can be compared to conventional multicast signaling exchange mechanisms is used in a transparent and clever manner to obtain from the receiving terminals connected to the communication network the aliases that can be used to identify the multicast streams to which these terminals are authorized to access.
[0031] According to a particular characteristic, said first signaling request message comprises at least one identifier of said content service.
[0032] In this way, only receiving terminals that subscribe to a particular content service can be targeted in the signaling request.
[0033] According to a particular characteristic, said resolution procedure is implemented within equipment selected according to said identifier of said content service.
[0034] In this way, the equipment responsible for resolving an alias is easily identified, depending on the content service considered.
[0035] In a particular embodiment, said determination method comprises, in furthermore, when the procedure for resolving said alias delivers information representing an authorization of said receiving terminal to access at least one multicast stream of said plurality of multicast streams:
[0036] - the transmission, to said receiving terminal, of a second message of signaling request comprising said at least one authorized multicast address;
[0037] - the reception, from said receiving terminal, of a second message of si signaling representing a request for subscription of said receiving terminal to at least one multicast group associated with at least one of said at least one authorized multicast address.
[0038] In this way, after obtaining the multicast streams to which a receiving terminal is authorized to access via the communication network, more conventional signaling exchanges can be implemented in order to allow the receiving terminal to indicate the multicast streams to which it wishes to subscribe, and thus to initiate the process allowing said receiving terminal to receive the selected streams.
[0039] According to a particular characteristic, said signaling request and signaling messages are messages respectively of the “Query” and “Report” type according to an adapted IGMP signaling protocol or an adapted MLD signaling protocol.
[0040] In this way, the implementation of the present technique in the existing ecosystem is simplified, since a certain compatibility is ensured with the IGMP and MLD multicast signaling protocols widely used for the implementation of multicast broadcast services in an IP network.
[0041] According to a particular characteristic, said communication network implements network slices, and said reception of the second signaling message allows the implementation of differentiated processing as a function of at least one slice identifier encoded in a multicast address and / or included in a free data field of said second signaling message.
[0042] In this way, the present technique allows in particular the facilitated application of classification rules within the communication network.
[0043] According to another aspect, the invention relates to a method for subscribing a receiver terminal to at least one multicast group associated with the broadcasting of a multicast stream within a communication network, said method being implemented by said receiver terminal and comprising:
[0044] - reception, from a router equipment of said communication network nification, of a first signaling request message, comprising at least one identifier of a content service;
[0045] - the transmission, to said router equipment, of a first message of signaling, comprising at least one resolution key, called alias, selected by said receiving terminal based on said content service identifier;
[0046] - the reception, from said router equipment, of a second message of signaling request, comprising at least one multicast address, called authorized multicast address, of at least one multicast group associated with the broadcasting by said content service of at least one multicast stream that said receiving terminal is authorized to access;
[0047] - the transmission, to said router equipment, of a second message of signaling representing a request for subscription of said terminal to at least one multicast group associated with at least one of said at least one authorized multicast address.
[0048] According to another aspect, the invention relates to a router equipment for determining a set of multicast streams to which a receiver terminal is authorized to access, from among a plurality of multicast streams broadcast by a content service via a communication network, said router equipment comprising at least one processor configured to:
[0049] - receive, from said receiving terminal, a first signal message reading comprising a resolution key, called an alias, usable by said router equipment to determine said set;
[0050] - implementing a procedure for resolving said alias, comprising obtaining, based on said alias, one of the following information:
[0051] — information representing an authorization of said receiving terminal to accessing at least one multicast stream of said plurality of multicast streams, comprising at least one multicast address, called authorized multicast address, of at least one multicast group associated with the broadcasting of said at least one multicast stream; or
[0052] — information representing a lack of authorization of said terminal receiver to access any one of said multicast streams of said plurality of multicast streams.
[0053] Such router equipment may of course have the various characteristics relating to the determination method according to the invention, which may be combined or considered in isolation. Thus, the characteristics and advantages of this equipment are the same as those of the determination method and are not detailed further.
[0054] According to another aspect, the invention relates to a receiver terminal capable of subscribing to one or at least one multicast group associated with the broadcasting of a multicast stream within a communication network, said receiver terminal comprising at least one processor configured to:
[0055] - receive, from a router device of said communication network, a first signaling request message, comprising at least one identifier content service;
[0056] - transmit, to said router equipment, a first signal message lization, comprising at least one resolution key, called alias, selected by said receiving terminal based on said content service identifier;
[0057] - receive, from said router equipment, a second message of signaling request, comprising at least one multicast group address, called authorized multicast address, of at least one multicast group associated with the broadcasting by said content service of at least one multicast stream that said receiving terminal is authorized to access
[0058] - transmit, to said router equipment, a second signal message representative of a request for subscription of said terminal to at least one multicast group associated with at least one of said at least one authorized multicast address.
[0059] Such a terminal may of course have the various characteristics relating to the subscription method according to the invention, which may be combined or considered in isolation. Thus, the characteristics and advantages of this terminal are the same as those of the subscription method and are not detailed further.
[0060] According to another aspect, the proposed invention also relates to a computer program product downloadable from a communication network and / or stored on a computer-readable medium and / or executable by a microprocessor, comprising program code instructions for the execution of at least one of the methods as described previously in any of its embodiments, when this method is executed on a computer.
[0061] The proposed invention also relates to a computer-readable recording medium on which is recorded a computer program comprising program code instructions for executing the steps of the methods as described above, in any of their embodiments.
[0062] Such a recording medium may be any entity or device capable of storing the program. For example, the medium may comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a USB key or a hard disk.
[0063] On the other hand, such a recording medium may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means, so that the computer program contained therein is remotely executable. The program according to the invention may in particular be downloaded over a network, for example the Internet.
[0064] The different embodiments mentioned above can be combined with each other. for the implementation of the invention. Figures
[0065] Other characteristics and advantages of the invention will appear more clearly on reading the following description of a particular embodiment, given as a simple illustrative and non-limiting example, and the appended drawings, among which:
[0066] [Fig.l] schematically presents the different steps of a method for determining a set of multicast streams to which a receiving terminal is authorized to access, in a particular embodiment of the proposed invention;
[0067] [Fig.2] presents a sequence diagram illustrating the message exchanges of si signaling between a communication network and a receiving terminal, in a particular embodiment of the proposed technique;
[0068] [Fig.3] illustrates an example of the formalism of an IGMP signaling message adapted of type “Query”, in a particular embodiment of the proposed invention;
[0069] [Fig.4] illustrates an example of the formalism of an IGMP signaling message adapted of the “Report” type, in a particular embodiment of the proposed invention;
[0070] [Fig.5] illustrates an example of a mechanism for subscribing a source to a service simplified management of access authorizations to multicast streams, in a particular embodiment of the proposed invention;
[0071] [Fig.6] schematically presents the different stages of a sub-process description of a receiving terminal to a multicast group associated with the broadcasting of a multicast stream within a communication network, in a particular embodiment of the proposed invention;
[0072] [Fig.7] describes a simplified architecture of a router equipment for the implementation work of the proposed invention. Detailed description of the invention
[0073] 1. General principle - method implemented on the network side
[0074] The invention described below makes it possible to overcome some of the aforementioned drawbacks.
[0075] The proposed technique in fact makes it possible to manage in a simplified manner the verification of the authorizations of a terminal, called the receiver terminal, to access multicast content within a communication network. To this end, according to the general principle of the invention and as detailed below, various adaptations of the protocols for subscribing a receiver terminal to a multicast group are proposed, including in particular the implementation of mechanisms allowing the discovery and determination, by the network, of multicast streams to which a device is authorized to access. The invention is called AMUSE (for “Alias-based Multicast Enhanced Service”, in English).
[0076] According to a first aspect, the present invention relates to a method for identifying a set of multicast streams to which a receiver terminal is authorized to access, from among a plurality of multicast streams broadcast by a content service (typically a content broadcasting service) via a communication network. Such a set may possibly be empty, if it is determined at the end of the method that the receiver terminal in question is not authorized to access any of the multicast streams broadcast by the content service.The content service comprises one or more content servers delivering multicast streams, and possibly additional equipment requested to provide other functions associated with the broadcasting service (dedicated resolution server, application server for implementing negotiation phases with the network, for example to subscribe to a simplified authorization management service according to the present technique, etc.), as presented later. The method according to the present technique, illustrated by [Fig.l], is implemented by a router-type device (more simply called a router hereinafter) of the communication network, typically located at the edge of the network (and which can be qualified as such as an access router, or border router).
[0077] In a step 11, such a router receives, according to a reception procedure called RCP, from a receiver terminal connected to the network, a signaling message comprising at least one resolution key, also called AL alias in the context of this document. As detailed below, such an AL alias, which typically takes the form of textual data, is information that can be used by the router to determine the multicast streams to which the receiver terminal is possibly authorized to access. According to a particular characteristic, the signaling message received by the router follows a signaling request message previously sent by the router to a set of receiver terminals connected to the communication network and likely to be candidates for receiving multicast streams.In a particular embodiment, such a signaling request message comprises for example a content service identifier (one or more content servers that can act as a broadcast source for the same content) capable of broadcasting multicast streams on the communication network, on the basis of which the receiving terminal can choose the alias to be transmitted to the network, when such a terminal stores several aliases (for example different aliases linked to different services to which it has subscribed and provided by the different content providers.
[0078] In a step 12, the AL alias received by the router in step 11 is subject to a RES resolution procedure carried out or at least initialized by the router. More In particular, this alias is used by the router as a resolution key to obtain, if necessary, within a so-called authorization data structure, a set of multicast group addresses to which the receiving terminal has the right to access. In other words, such an authorization data structure (for example a database) comprises entries associating aliases with one or more multicast group addresses. Other additional information may also be associated with an alias in the authorization data structure, such as for example a service identifier associated with the alias, a validity period of the alias, information representing a current validity of the alias, etc.If the alias presented by a receiving terminal in step 11 is present in the authorization data structure and is associated with multicast group addresses for a given service, then the receiving terminal is a priori authorized to access the multicast streams associated with these multicast group addresses (provided that any additional conditions for access to the corresponding multicast streams, for example a check of the absence of multiple uses of the same alias by different receiving terminals as presented later in the document, are also verified). If, on the other hand, the alias presented by a receiving terminal in step 11 is not present for this service in the authorization data structure, or if it is present but it is not associated with any multicast group address or if it is associated with another service, then the receiving terminal is not authorized to access any multicast stream on the basis of the alias presented.The alias resolution procedure delivers, at the end of step 12, information IH, representing an authorization or an absence of authorization of the receiving terminal to access all or part of the multicast streams broadcast by a content source. According to different embodiments described below, the alias resolution procedure can be implemented entirely within the router, or jointly with third-party equipment.
[0079] In a first particular embodiment, the resolution of the alias is carried out locally, that is to say entirely by the router which received the alias from the receiving terminal. In such an embodiment, the authorization data structure (or at least a copy of such a data structure) is available locally, within the router itself. The resolution is then immediate and does not require any additional resolution time.
[0080] In other particular embodiments, the resolution of the alias is implemented jointly with a third-party device, different from the router device that received the alias from the receiving terminal. In such an embodiment, the authorization data structure is generally not available within the router itself, so the latter requests a third-party device having access to this data structure. To this end, the router transmits to the third-party device, a resolution request including the alias obtained in step 11, and it receives in return authorization information from the third-party equipment, once the latter has carried out the resolution of the alias via a consultation of the authorization data structure.
[0081] The third-party equipment may, for example, be a communications network control equipment (more simply called a network controller in the remainder of this document). In certain embodiments, in particular in connection with a particular alias format detailed below, the third-party equipment may also be a domain name system server (or DNS servers, "Domain Name System" in English), or even a content service, an equipment associated with the content service (for example a content service associated with this service, or a dedicated resolution server deployed for this service) which provides the multicast streams for which it is desired to verify the possible authorizations of a receiving terminal.
[0082] As detailed below, the router has previously been configured, for example during a subscription phase to the simplified authorization management service, with the resolution mode to be implemented (local resolution or via third-party equipment, and in connection with which third-party equipment if applicable). When the router is configured to request third-party equipment for alias resolution, the configuration parameters provided to this router include the necessary information allowing the router to contact this third-party equipment, possibly accompanied by information allowing mutual authentication with such third-party equipment. One or more third-party equipment may be configured within the same router. In addition, dedicated or separate equipment per service may be provided to a router. In this case, the router selects the third-party equipment to contact depending on the target service.
[0083] In all cases, at the end of the alias resolution procedure by the router, whether it has been implemented entirely by the router or jointly with third-party equipment, the router obtains authorization information, which may be:
[0084] - information representing an authorization of the receiving terminal to access at least one multicast stream broadcast by the content service via the communications network, in which case the authorization information received includes the multicast group address(es) associated with the broadcast of the multicast stream(s) that the receiving terminal is authorized to receive (such multicast group addresses are then referred to as authorized multicast group addresses);
[0085] - information representing a lack of authorization of the receiving terminal to access any of the multicast streams broadcast by the content service on the communications network.
[0086] In a particular embodiment, when the information obtained by the router at the end of step 12 is representative of an authorization of the receiving terminal to access at least one multicast stream broadcast by the content service via the communication network, and that the router therefore has at this stage knowledge of at least one multicast group address associated with said stream, and possibly, of the unicast addresses of the sources involved in the broadcasting of a requested content, new signaling messages are exchanged between the router (i.e. the network) and the receiving terminal in order to allow the receiving terminal to join one of these groups. Such an exchange is based for example on signaling protocols designed for this purpose, possibly adapted in the context of the present technique, such as for example the IGMP protocol ("Internet Group Management Protocol", RFC3376) in the context of an IPv4 environment, or the MLD protocol ("Multicast Listener Discovery", RFC3810) in the context of an IPv6 environment.It should be remembered that these existing signaling protocols are based on similar operating principles: a device requesting communication from the network, typically a router, regularly sends "Query" type messages to receivers connected to the network (via a multicast address available for this purpose, for example the address 224.0.0.1 in the case of IGMP signaling), which receivers can form "Report" type messages in response to subscribe to a particular group listed in the "Query" message, and thus indicate that they wish to receive the multicast stream associated with this group. A "Report" type message explicitly provides the receiver's reachability information (typically an IP address) as well as the multicast group address(es) that the receiver wishes to access.The use of conventional IGMP / MLD messages as previously described does not, however, allow the implementation of the present technique, at least not without adaptation, if only because additional message exchanges for obtaining and resolving the alias, not provided for in these protocols, are required. Such operations can be carried out by means of dedicated messages. However, for the purposes of simplifying integration into the existing ecosystem, in an implementation example described below in connection with [Fig.2], an implementation based on adjustments and extensions to existing IGMP / MLD messages is proposed in a particular embodiment.
[0087] More particularly, in a step 21, a requesting device of the communication network, typically a router R, sends at regular frequency messages which can be assimilated to “Query” type messages to the receivers connected to the network (via a multicast group address available for this purpose, for example the address 224.0.0.1 in the case of IGMP signaling). As a conventional "Query" message, such a message constitutes a first signaling request message. However, unlike a conventional "Query" message, it does not identify any multicast group, and therefore does not include any explicit multicast group address. An example of a first signaling request message in an embodiment of the present technique is illustrated in [Fig. 3]. According to a particular characteristic, such a message may optionally include a service identifier.
[0088] In response to this first signaling request message, a receiving terminal TR transmits to the requesting equipment R, in a step 22, a message which can be likened to a first signaling message of the “Report” type. This message explicitly provides the reachability information of the receiving terminal TR (typically an IP address). It further comprises at least one alias, possibly selected by the receiving terminal TR as a function of the service identifier, when such an identifier is included in the previously received signaling request message. Such a signaling message is of course only transmitted if at least one alias is associated with the receiving terminal (and, in addition, where appropriate, with the target service identified in the signaling request message).
[0089] Upon receipt of the signaling message comprising at least one alias, the requesting equipment R proceeds in a step 23 to resolve this alias, according to the methods already described previously (for example locally or via third-party equipment, depending on the previously established configuration of the router R). Where appropriate, at the end of this alias resolution procedure, the requesting equipment has at least one multicast group address of at least one multicast group associated with the alias obtained in step 22.
[0090] In a step 24, the requesting equipment R then sends to the receiving terminal a second signaling request message, which can also be compared to a conventional “Query” type message, in that it contains a list of addresses of multicast groups to which the receiving terminal can subscribe. However, this message differs from a conventional “Query” message in that it is adapted so as to target a particular receiving terminal (the receiving terminal which responded in step 22 to the first signaling request message), and in that it only includes the addresses of the multicast groups to which this receiving terminal is authorized to access, obtained in step 23. These multicast group addresses are possibly accompanied by the corresponding alias as conveyed in this second signaling request message.
[0091] In response to this second signaling request message, the receiving terminal TR transmits to the requesting equipment R, in a step 25, a message which can be compared to a classic “Report” type message. This message comprises the addresses of the multicast groups to which the receiving terminal TR wishes to subscribe, among those listed in the second signaling request message. An example of such a signaling message in an embodiment of the present technique is illustrated by [Fig.4]. Note that in the case of use of a communication network implementing network slices, such a message can be sent at the end of a phase of connection of the receiving terminal to a network slice. For example, the terminal extracts an identifier of the slice encoded in a multicast group address received in the second signaling request message sent in step 24 after resolution of the alias. Several scenarios can then arise. If the connection to the identified slice is already effective, the receiving terminal adds the corresponding multicast group address to the list of addresses to be sent in the “Report” message sent in step 25.If the connection to the identified slice is not yet effective, and in the absence of contrary instructions obtained by the receiving terminal, the latter connects to the slice in question and, once the connection is established, it adds the corresponding multicast group address to the list of addresses to be sent in the “Report” message sent in step 25. The receiving terminal is then able to receive the multicast stream routed along an ad hoc distribution tree deployed in the slice to which it has connected. In the event of an impossibility of establishing a connection to the identified slice, the receiving terminal excludes the corresponding multicast group address from the list of multicast addresses to be sent in the message in the “Report” message sent in step 25.
[0092] Thus the receiving terminal only has the possibility of having access to the multicast streams to which it is authorized to access, the addresses of the multicast groups to which it does not have the right to subscribe never being communicated to it.
[0093] We are now interested in an embodiment of the present technique, in which the alias has a particular formalism. More particularly, in this particular embodiment, the alias is constructed on a format similar to a domain name (see for example RFC 1035), comprising one or more hierarchical levels. It is thus for example formed from a “label” or a concatenation of several labels separated by the same separator (typically the dot character “.”) and ordered according to a predefined hierarchical structure. An alias can for example have a format of the type “ <alias-petit-fils> . <alias-fils> . <alias-parent>» (according to an example with three hierarchical levels, given for purely illustrative and non-limiting purposes).
[0094] Such an alias format is interesting for several reasons.
[0095] Firstly, it allows for clever use of system servers domain name (or DNS servers, "Domain Name System" in English) to resolve aliases. In other words, we exploit the capacity of these servers to return IP addresses based on a domain name, but for a different use than the common use of determining an IP address of a server to contact from a domain name, for example included in a URL (Uniform Resource Locator). Thus, in the context of the present technique, these DNS servers are used as third-party equipment to be contacted by a router for the resolution of aliases formatted as domain names, and return on the basis of these aliases the addresses of multicast groups identifying multicast streams to which receiving terminals are authorized to access. In addition, the use of such a structure also makes it possible to present the alias in the security certificates associated with a receiving terminal.This builds on an architecture and mechanisms that already exist and are optimized for alias resolution, which simplifies the implementation of this technique and saves money in terms of costs and development and / or deployment time, for example.
[0096] Second, the hierarchical structure of an alias in the format of a domain name can be exploited to provide even more flexibility to the alias resolution mechanism according to the present technique. For example, in a particular embodiment, one or more hierarchically higher levels of the alias, forming a sub-alias called a parent alias within the alias, can be used to uniquely identify a content service.Such a feature allows, for example, a router configured to request alias resolutions from a third-party device (e.g., a server operated by a content service provider, a dedicated resolution server of a content service provider, a server involved in providing the content service) to identify, based on the parent alias, to which device (e.g., operated by a content service provider) it should actually forward its resolution request. Thus, such a router will know, for example, that it should request: .
[0097] - the sel content service if it receives an alias “encoding3.content.scl” or “ contenul4.sc 1 » (because the common parent alias of these aliases is “sel”);
[0098] - the sc2 content service if it receives an alias contenul.sc2 or sc2 (because the parent alias common to these aliases is "sc2");
[0099] - the sc3 content service if it receives an alias “contentl.sc3” or “ encoding2.content2.sc3” or “receiver44.sc3” (because the common parent alias of these aliases is “sc3”);
[0100] - etc.
[0101] The preceding examples are of course given for purely illustrative and non-limiting purposes.
[0102] For the purposes of these exchanges for resolution purposes, the router may in particular have and maintain an address table mapping parent aliases to IP addresses to contact associated content servers. 2. Subscription to the service
[0103] In relation to [Fig.5], a subscription phase to the service for managing access authorizations to multicast streams according to the proposed technique is presented, implemented upstream of the signaling operations previously presented by which a receiving terminal manifests its intention to join a multicast group. This subscription phase is implemented by equipment of a content service (called source) SRC which has the capacity to broadcast them according to the multicast transmission mode via the communication network. Such a source can for example be a content server of the content service, a resolution server associated with this service, or even equipment dedicated to this service.In a particular embodiment, the network's ability to support management of access authorizations to multicast streams according to the present invention is for example exposed by the network by means of a dedicated application programming interface (API). According to a particular characteristic, a dynamic negotiation protocol such as the CPNP protocol (Connectivity Provisioning Negotiation Protocol, RFC8921) is used to expose such an interface, the network hosting a CPNP server while a content service device (typically an application server) embeds a CPNP client. This example is however non-limiting, and other protocols such as for example the RESTCONF protocol (RFC8040) can also be used to expose this API.
[0104] The SRC content service wishing to subscribe to the access authorization management service transmits, by means of the dedicated API previously described, an SBSC subscription request, comprising at least one source identifier, for example an IP address (possibly associated with a port number) at which the SRC content service capable of broadcasting multicast content can be contacted, or an identifier extracted from a certificate presented to this content service in a request to establish a security association (TLS (“Transport Layer Security”, in English), DTLS (“Datagram Transport Layer Security”, in English), etc.). According to a particular characteristic, the SBSC subscription request also includes data relating to aliases already generated, or that the content service is configured to generate such aliases within the framework of the present technique.Thus, by way of example and according to a particular characteristic, the messages exchanged with the network within the framework of a subscription request include at least one generic alias, corresponding to a parent alias as previously presented (for example “sel”) associated with the SRC content service. In . As part of the subscription mechanism, the network is asked to associate this parent alias and / or child domain names of this parent alias (typically, to use the previous example, any domain name in the format "*.scl", e.g. "content?.sel", "encoding l.content3.sel", "receptor45.scl") with one or more multicast group addresses used by the network for the distribution of content according to the multicast transmission mode, depending on the desired authorizations. The parent alias also identifies the third-party server to use for alias resolution. For example, during resolution, the communications network can route any resolution requests for child aliases to the authoritative server of the parent alias. To do this, a router device only needs to locally maintain the identity of a server associated with a parent alias, and does not need to maintain specific entries for each child alias.
[0105] According to a particular characteristic, the SBSC subscription request also includes data relating to a desired alias resolution mode. An “ALIAS_RESOLUTION_MODE” parameter may for example be used for this purpose. Thus, by way of illustration:
[0106] - if “ALIAS_RESOLUTIONS_MODE == LOCAL”, then it is the router which receives the alias which takes care of the resolution itself;
[0107] - if "ALIAS_RESOLUTIONS_MODE == DNS", then the name system of DNS domain is used for alias resolution;
[0108] - if "ALIAS_RESOLUTION_MODE == SC", then all re queries solution of a child alias of a parent alias must be relayed to the SRC content service. In the latter case, optionally, an "ALIAS_RESOLVER" parameter can also be communicated to the network if necessary, to indicate the IP address(es) of additional equipment (typically resolution servers) associated with the content service, when the latter does not perform the resolution itself.
[0109] To complete the subscription process to the method for managing access authorizations to multicast streams, several iterations of information exchanges between the content service at the origin of the request for said subscription and the network may prove necessary. In response to the request for subscription to said method, once all the exchanges have been finalized, an element of the network, such as a network controller, sends to the content service an ACK_SBSC message confirming the correct subscription to the method for managing access authorizations to multicast streams.
[0110] 3. Alias Diversity - Communication of Aliases to the Receiving Terminal
[0111] We are now interested in the process of generating aliases, and their communication to the receiving terminal.
[0112] As previously presented, an alias is a resolution key that can be used to identify, in a so-called authorization data structure, addresses of multicast groups to which a device that is aware of the alias - typically a receiving terminal - is authorized to access.
[0113] In the context of the present technique, it should be noted that aliases can be associated with different entities, depending on the intended purpose. For example, depending on the desired use, it is possible to have different types of aliases, such as:
[0114] - aliases associated with receiving terminals: the alias is then used, for example to retrieve a plurality of multicast group addresses allowing access to a set of content - typically a catalog of content offered by a content provider - which the receiving terminal holding the alias is authorized to access;
[0115] - aliases associated with one or more contents: the alias is then used for example to retrieve a plurality of multicast group addresses associated with the same content available in several encodings (SD, HD, 4K, etc.) which the receiving terminal holding the alias is authorized to access;
[0116] - aliases associated with content in a particular encoding: the alias is then by example used to retrieve a multicast group address associated with content in a given encoding that the receiving terminal holding the alias is authorized to access;
[0117] - in the case of a communication network implementing network slices, aliases associated with a network slice used to receive multicast content: the alias is then, for example, used to retrieve a multicast group address associated with content to which the receiving terminal holding the alias is authorized to access, together with additional information (for example encoded in the multicast address) relating to a network slice to be used to receive the content in question;
[0118] - aliases associated with classes of service used in the communications network to receive multicast content;
[0119] -etc.
[0120] In other words, the aliases are not necessarily all associated with the same type of information, but all have in common the capacity to allow a particular receiving terminal to identify one or more multicast group addresses (i.e. associated with one or more multicast contents) to which a receiving terminal is authorized to access.
[0121] Aliases can be made available to a receiving terminal in several ways.
[0122] In a particular embodiment, an alias is transmitted by a content service that generated it to a receiving terminal via an established encrypted transmission on a communication network. It can for example be obtained by the receiving terminal by means of a dedicated application installed on this receiving terminal, or by a connection to a dedicated server via a browser or any other application installed on this terminal. In another embodiment, an alias can be displayed on a dedicated HTTP page accessible to a user after authentication, in order to be entered directly by the user in a dedicated application of the receiving terminal. In other particular embodiments, an alias (in particular an alias associated with a receiving terminal) may have been stored in a memory of the receiving terminal upon manufacture of this terminal such as a TV decoder or a Set-Top Box (STB), where applicable, or at least before its marketing.
[0123] In a particular embodiment, the generation of aliases by a content service is carried out so as to guarantee a uniqueness of alias per receiver likely to be authorized to access all or part of the broadcast content. In other words, the content service generates a unique alias per receiver. Such a mode is advantageous in that it makes it possible, on the one hand, to simplify the operations of authorization of access to content of a content service, and on the other hand to facilitate the implementation of traffic classification rules at the edge of the network and to avoid the sharing of the same identifier between several terminals. Thus, the detection of duplicate aliases during the resolution procedure can be considered as an anomaly in a particular embodiment of the proposed technique.The authorization to access multicast streams may then, for example, be issued to only one receiving terminal among those that have the same alias (for example, to the receiving terminal that has T alias for the first time). Alternatively, the content broadcasting service may, for example, be refused to all receiving terminals that have the same alias, without distinction, and access to the multicast streams is then refused to all of said terminals.According to a particular characteristic, in order to implement the restrictions relating to duplicate aliases previously mentioned, the procedure for resolving an alias comprises a step of searching for said alias within a list of aliases marked as having already been resolved, and, in the event of the presence of said alias in said list, the delivery of information representative of a lack of authorization of the receiving terminal having presented the alias to access any of the multicast streams broadcast by the content service with which the alias is associated.Depending on the embodiment implemented, the uniqueness of the alias can be implemented at the level of a content service considered (the alias is then unique per service, but the same alias is likely to be used in connection with several distinct content provider services), or be universal (an alias is then assumed to be globally unique, including in a context where the receiving terminals are authorized to access content broadcast by distinct content providers).
[0124] It should be noted that in the context of the present technique, the multicast group addresses associated with an alias may in certain cases evolve according to various parameters.For example, when the communication network implements network slices, and the multicast group addresses are constructed so as to encode within them particular network slices to be used for routing traffic (a multicast group address then being in fact associated with a network slice), it may prove advantageous in certain situations - for example depending on data representative of a current state of the communication network, received from various control devices deployed within the network - to modify the multicast group address(es) associated with an alias so as to allow a switch of traffic to a different network slice than that associated with the multicast group address(es) initially associated with the alias in the authorization data structure.Data representative of a current state of the communication network includes, for example, data indicating the unavailability or congestion of certain slices, excessively long latency times measured on certain slices, excessively long unidirectional transit times, excessively high data loss rates, etc., which constitute all indicators likely to encourage a redirection of multicast traffic from one slice to another (in particular if these indicators degrade over time). Thus, depending on the results of the resolution of an alias and the traffic routing conditions within the different slices, a redirection of traffic to another network slice can be automatically implemented.Such redirection can be performed at the initiative of the communication network (typically by a controller in charge of allocating and managing network resources, or by a router device based on information transmitted by the controller in order to allow it to select the slice to which to direct the multicast traffic). Alternatively, the redirection of multicast traffic can also be performed at the initiative of the content service. In this case, a server associated with this service informs the network (for example via an API) of a new multicast group address to use for a given alias. A network controller can then identify the entities (router devices and receiving terminals) involved in subscribing to the corresponding multicast group and in routing the corresponding multicast traffic, and inform these entities of the modification of the multicast group address.In this context, a "Query" type signaling message including the new group address is sent by the requesting routers (i.e. the routers which include the IGMP Querier or MLD Querier function) to the receiving terminals concerned. Upon receipt of this message, the receiving terminals in question respond to the requesting equipment with a "Report" type message, according to the methods previously described in relation. with [Fig.2], when they wish to continue receiving the corresponding content. It should be noted that in the event of a decision to redirect traffic, additional mechanisms according to a dynamic routing protocol are also implemented, in order to allow the connection of the receiving terminal to an ad hoc distribution tree. 4. Process implemented on the terminal side
[0125] According to another aspect, the invention also relates to a method for subscribing a receiver terminal to at least one multicast group associated with the broadcasting of a multicast stream within a communication network implementing network slices. Such a method, illustrated by [Fig.6] in a particular embodiment, is implemented by a receiver terminal connected to the communication network.
[0126] In a step 61, the receiving terminal receives a first signaling request message from the network, typically from a router device. As described previously in relation to the method implemented on the network side, such a message may for example take the form of a “Query” type signaling message adapted for the needs of the present technique. This first signaling request message comprises, in a particular embodiment, a service identifier (here, content broadcasting service).
[0127] Upon receipt of this message, and possibly on the basis of the service identifier included therein, the receiving terminal determines, for example within a data structure stored in a memory of this terminal, at least one alias intended to be used as a resolution key by the network to determine whether or not the receiving terminal is authorized to access multicast streams associated with said service identifier, and where appropriate, the multicast groups to which the receiving terminal is authorized to access.
[0128] In a step 62, in response to the first signaling request message, the receiving terminal transmits to the router equipment a first signaling message, comprising said alias. As described previously in relation to the method implemented by the network, such a message may for example take the form of a signaling message of the “Report” type (i.e. of the “Rapport” type, in French) adapted for the needs of the present technique.
[0129] In a step 63, the receiving terminal receives a second signaling request message from the communication network, after the latter has resolved the alias. This second signaling request message, which may also, for example, take the form of a “Query” type signaling message adapted for the needs of the present technique, comprises at least one multicast group address, called address authorized multicast, identifying at least one multicast group associated with the broadcast by a content service (and where applicable, the content broadcast service identified by the identifier received in step 61) of at least one multicast stream to which the receiving terminal is authorized to access.
[0130] In a step 64, in response to the second signaling request message, the receiving terminal transmits to the router equipment a second signaling message representative of a subscription request from the receiving terminal to at least one multicast group associated with at least one of said at least one authorized multicast group address. 5. Devices
[0131] Finally, in relation to [Fig.7], we present the simplified structures of an entity, for example a router device of a communication network or a receiving terminal, according to at least one embodiment described above.
[0132] As illustrated by [Fig.7], such an entity comprises at least one memory 71 comprising a buffer memory, at least one processing unit 72, equipped for example with a programmable computing machine or a dedicated computing machine, for example a processor P, and controlled by the computer program 73, implementing steps of at least one method according to at least one embodiment of the invention.
[0133] At initialization, the code instructions of the computer program 73 are for example loaded into a RAM memory before being executed by the processor of the processing unit 72.
[0134] If the entity is a router device of the communication network, the processor of the processing unit 72 implements steps of the method for determining a set of multicast streams to which a receiving terminal is authorized to access from among a plurality of multicast streams broadcast by a content service via the communication network, as described previously, according to the instructions of the computer program 73, for:
[0135] - receive, from said receiving terminal, a first signal message reading comprising a resolution key, called an alias, usable by said router equipment to determine said set;
[0136] - implementing a procedure for resolving said alias, comprising obtaining, depending on said alias, one of the following information: (i) information representing an authorization of said receiving terminal to access at least one multicast stream of said plurality of multicast streams, comprising at least one multicast group address, called authorized multicast address, of at least one multicast group associated with the broadcasting of said at least one multicast stream; or (ii) information representing an absence of authorization of said receiving terminal to access any one (or at least one) of said multicast streams of said plurality of multicast streams.
[0137] If the entity is a receiving terminal wishing to receive a multicast stream, the processor of the processing unit 72 implements steps of the method of subscribing to a multicast group described previously, according to the instructions of the computer program 73, to:
[0138] - receive, from a router device of said communication network, a first signaling request message, comprising at least one content service identifier;
[0139] - transmit, to said router equipment, a first signal message lization, comprising at least one resolution key, called alias, selected by said receiving terminal based on said content service identifier;
[0140] - receive, from said router equipment, a second message of signaling request, comprising at least one multicast group address, called authorized multicast address, of at least one multicast group associated with the broadcasting by said content service of at least one multicast stream that said receiving terminal is authorized to access
[0141] - transmit, to said router equipment, a second signal message representative of a request for subscription of said terminal to at least one multicast group associated with at least one of said at least one authorized multicast address. < / alias-fils> < / alias-petit-fils>
Claims
Claims
1. Method for determining a set of multicast streams to which a receiving terminal is authorized to access, from among a plurality of multicast streams broadcast by a content service via a communication network, said method being characterized in that it comprises, at the level of a router device of said communication network: - the reception (RCP), from said receiving terminal, of a first signaling message comprising a resolution key, called alias (AL), usable by said router device to determine said set;- implementing a resolution procedure (RES) for said alias, comprising obtaining, as a function of said alias, information (IH) from among: — information representing an authorization of said receiving terminal to access at least one multicast stream of said plurality of multicast streams, comprising at least one multicast group address, called authorized multicast address, of at least one multicast group associated with the broadcasting of said at least one multicast stream; or — information representing an absence of authorization of said receiving terminal to access any one of said multicast streams of said plurality of multicast streams.;
2. Method according to claim 1, characterized in that said resolution procedure is implemented entirely within said router equipment.
3. Method according to claim 1, characterized in that said resolution procedure is implemented jointly with third-party equipment, said obtaining comprising: - the transmission, to said third-party equipment, of a request for resolution of said alias, comprising said alias. - the reception, from said third-party equipment, of said information representative of an authorization or an absence of authorization.
4. Method according to claim 3, characterized in that said third-party equipment belongs to the group comprising: - equipment for controlling said communication network; - a domain name system (DNS) server within said communication network; - equipment associated with said content service.
5. Method according to claim 4, characterized in that said alias has the format of a domain name, comprising one or more hierarchical levels.
6. Method according to claim 5, characterized in that one or more hierarchically higher levels of said hierarchical levels of said alias, forming a sub-alias called parent alias of said alias, uniquely identify said content service.
7. Method according to claim 6, characterized in that said parent alias is used to identify said content service to which to transmit a request for resolution of said alias, when said resolution procedure is configured to be implemented in conjunction with equipment associated with said content service.
8. Method according to claim 1, characterized in that said procedure for resolving said alias comprises a step of searching for said alias within a list of aliases marked as having already been resolved, and, in the event of the presence of said alias in said list, the delivery of information representative of a lack of authorization of said receiving terminal to access any one of said multicast streams of said plurality of multicast streams.
9. Method according to claim 1, characterized in that said reception of said signaling message follows the transmission of a first signaling request message sent by said router equipment to a set of receiving terminals connected to said communication network.
10. Method according to claim 9, characterized in that said first signaling request message comprises at least one identifier of said content service.
11. Method according to claim 10, characterized in that said resolution procedure is implemented within equipment selected according to said identifier of said content service.
12. Method according to claim 1, characterized in that it further comprises, when the procedure for resolving said alias delivers information representative of an authorization of said receiving terminal to access at least one multicast stream of said plurality of multicast streams: - the transmission, to said receiving terminal, of a second signaling request message comprising said at least one authorized multicast address; - the reception, from said receiving terminal, of a second signaling message representing a request for subscription from said receiving terminal to at least one multicast group associated with at least one of said at least one authorized multicast address.
13. Method according to claim 12, characterized in that said signaling request and signaling messages are messages respectively of the “Query” and “Report” type according to a suitable IGMP signaling protocol or a suitable MLD signaling protocol.
14. Method according to claim 12, characterized in that said communication network implements network slices, and in that said reception of the second signaling message allows the implementation of differentiated processing as a function of at least one slice identifier encoded in a multicast address and / or included in a free data field of said second signaling message.
15. Method for subscribing a receiving terminal to at least one multicast group associated with the broadcasting of a multicast stream within a communication network, said method being characterized in that it comprises, by said receiving terminal: - the reception (61), from a router equipment of said communication network, of a first signaling request message, comprising at least one identifier of a content service; - the transmission (62), to said router equipment, of a first signaling message, comprising at least one resolution key, called alias, selected by said receiving terminal as a function of said content service identifier;- receiving (63), from said router equipment, a second signaling request message, comprising at least one multicast address, called authorized multicast address, of at least one multicast group associated with the broadcasting by said content service of at least one multicast stream that said receiving terminal is authorized to access; - transmitting (64), to said router equipment, a second signaling message representing a subscription request from said terminal to at least one multicast group associated with at least one of said at least one authorized multicast address.;
16. Router equipment for determining a set of multicast streams to which a receiving terminal is authorized to access, among a plurality of multicast streams broadcast by a content service via a communications network, said router equipment comprising at least one processor configured to: - receive, from said receiving terminal, a first signaling message comprising a resolution key, called an alias, usable by said router equipment to determine said set; - implement a procedure for resolving said alias, including obtaining, based on said alias, information from among: — information representing an authorization of said receiving terminal to access at least one multicast stream of said plurality of multicast streams, comprising at least one multicast address, called authorized multicast address, of at least one multicast group associated with the broadcasting of said at least one multicast stream; or — information representing a lack of authorization of said receiving terminal to access any of said multicast streams of said plurality of multicast streams.
17. Receiving terminal capable of subscribing to one or at least one multicast group associated with the broadcasting of a multicast stream within a communication network, said receiving terminal comprising at least one processor configured to: - receive, from a router device of said communication network, a first signaling request message, comprising at least one content service identifier; - transmit, to said router equipment, a first signaling message, comprising at least one resolution key, called alias, selected by said receiving terminal as a function of said content service identifier; - receive, from said router equipment, a second signaling request message, comprising at least one multicast group address, called authorized multicast address, of at least one multicast group associated with the broadcasting by said content service of at least one multicast stream that said receiving terminal is authorized to access - transmit, to said router equipment, a second signaling message representing a request for subscription from said terminal to at least one multicast group associated with at least one of said at least one authorized multicast address.
18. Computer program product downloadable from a network communication and / or stored on a computer-readable medium and / or executable by a microprocessor, characterized in that it comprises program code instructions for executing a method according to any one of claims 1 to 14, when executed by a computer.
Citation Information
Patent Citations
Determination method of router geographic position
CN105119827A
Method and apparatus for enhancing multicast group membership protocol(s)
US10944582B2
System and method for multicast communications using real time transport protocol (RTP)
US7221660B1