Method of providing an application with access to a function of an operating system of a terminal
By establishing a communication channel between a terminal and a network entity hosting remote OS functions, the method addresses the limitations of existing terminals in accessing new services and functions, enhancing functionality and simplifying maintenance.
Patent Information
- Application Number
- FR2023014761
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-27
AI Technical Summary
Existing terminals face limitations in accessing new services and functions without requiring changes to the terminal hardware or software, and are restricted by the operating system's limitations on API access.
A method that establishes a communication channel between the terminal and a network entity hosting remote OS functions, allowing these functions to be exposed to applications as if they were locally implemented, thereby extending the terminal's functional capabilities.
This solution enables terminals to access new and advanced functions without hardware upgrades, extends the terminal's usage duration, simplifies management and maintenance, and provides cost-effective access to new services.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for providing an application with access to a function of an operating system of a terminal Technical field
[0001] The present invention relates to the field of telecommunications, and more particularly to that of value-added IP services. Previous Art
[0002] [Fig.l] represents an example of a simplified internal structure of a terminal. Such a terminal embeds different applications associated with different services and an operating system (OS) adapted to support these different applications.
[0003] Access to certain services requires the support and activation of specific functions also called primitives or API (for "Application Programming Interface" in English) in the terminal, such as prioritization functions, traffic acceleration or data encryption characteristic of the use of such services.
[0004] These specific functions are hosted in the terminal. However, there is a need to allow a user to access new services using new functions without having to change terminal.
[0005] In addition, dedicated applications may be used to access a service from a terminal. These applications may request specific processing of the functions exposed by the terminal's OS. However, access to certain functions may be limited by the OS. For example, a network socket application may be limited to searching for Wi-Fi access points for connecting a terminal to the network or prohibit IPv6 communications. Summary of the invention
[0006] The invention proposes a collaborative procedure between a terminal, a network and service platforms which makes it possible in particular to meet the need and to remedy the aforementioned drawbacks. This procedure overcomes the limitations possibly imposed by the OS, to optimize the provision and access to services from terminals connected to this network, whether or not these services are new services.
[0007] More specifically, an object of the invention relates to a method for providing an application installed on a terminal, by an operating system of said terminal, with access to a function of the operating system, said method comprising: - a step of establishing at least one communication channel with at least one entity of a network hosting for a management device of the operating system at least one function called a remote function of the operating system, said establishment step using at least one piece of information provided by the operating system management device; - a step of exposing to the application of said remote function as a function implemented locally by the operating system; and
[0008] - upon receipt of a message from the application invoking said remote function, a step of transferring the message to the network entity hosting said remote function, via the communication channel established with this network entity.
[0009] The invention proposes to emulate a function of the operating system, called a remote function, elsewhere than in a user terminal and to set up suitable mechanisms to encapsulate / transport the invocation messages of this function. This remote function is then located in an entity of a network and can be presented and be accessible to the applications of the terminal as if it were embedded in the terminal. The invention thus proposes a collaborative mechanism intended to use a communication network to allow an extension of the functions offered by an operating system of the terminal.
[0010] The functional capabilities of the user terminal are also increased by these remote functions which are provided from a communication network via one or more dedicated channels. This mechanism makes it possible to increase the duration of use of the terminal, the latter being able to access new functions or even advanced functions traditionally not supported by the terminal (for hardware constraints, costs, etc.) without it being necessary to replace it with a more recent generation terminal. In addition, the management and maintenance operations of the terminal are simplified due in particular to less frequent software updates thanks to the invention.
[0011] The invention thus presents substantial savings prospects for an ever-increasing number of users who are becoming aware of the challenges of a sustainable economy capable of taking into account the planet's limited resources while allowing access to new services.
[0012] In an alternative embodiment, before establishing a said communication channel with said network entity, the method comprises a step of authenticating the terminal with this entity.
[0013] This improves the overall security of the method for providing access to a function of the operating system.
[0014] In an alternative embodiment, the method comprises a step of receiving, from said network entity, a list of remote functions hosted by this network entity, for exposure to said application.
[0015] The terminal thus has all of the remote functions hosted by the network entity.
[0016] In an alternative embodiment, the method comprises a step of receiving from said network entity at least one marking indication intended to be applied to at least one data packet sent by the application before being transferred by the operating system to this network entity.
[0017] This step of receiving a marking indication facilitates the processing of the data packet by the network entity and possibly the identification by the operating system of the messages which are eligible for transfer to the network entity.
[0018] In an alternative embodiment, the supply method comprises:
[0019] - a step of identifying at least one data packet sent by the application intended to be transmitted via said established communication channel to said network entity; and
[0020] - a step of transferring said at least one identified packet to said network entity via said communication channel.
[0021] It is thus possible to transfer to the network entity the data packet to be processed by a remote function instead of local processing at the terminal level.
[0022] In an alternative embodiment, the method comprises a step of transferring to the application a message received from the network entity hosting the remote function invoked by the application.
[0023] The OS thus transmits the data processed by the remote function to the application. Calling a remote function is thus transparent to the application.
[0024] In an alternative embodiment, upon receipt of the message from the application invoking a function required for the service, the method comprises a prior step of verifying whether this function is hosted locally by the operating system or transferred to the network entity.
[0025] This verification step conditions the transfer of the message or the local processing of this message by a terminal.
[0026] Another object of the invention relates to a communication method implemented by a device for managing an operating system of a terminal connected to a network, said method comprising:
[0027] - a step of obtaining at least one piece of information from a network controller allowing access to at least one entity of the network, selected by said network controller for the management device to host at least one function called a remote function of said operating system;
[0028] - a step of sending to the data network controller making it possible to activate said remote function of said operating system on the selected network entity; and
[0029] - following receipt of a message from the operating system of the terminal, a step of sending information to said operating system for allow the terminal to establish a communication channel with the network entity hosting said remote function.
[0030] These preliminary communication steps allow optimal operation of the method for providing access to a remote function of the operating system.
[0031] In an alternative embodiment, the obtaining step follows a step of sending a message to the controller indicating at least one constraint to be satisfied by the network entity.
[0032] These constraints are, for example, an IP transit delay, an invocation time, a location constraint, etc.
[0033] Another object of the invention relates to a method of control by a controller of a network, comprising:
[0034] - a step of sending to a management device an operating system of a terminal connected to the network, of at least one piece of information allowing access to at least one entity of the network selected by the controller for the management device to host at least one function called a remote function of the operating system; and
[0035] - a step of activating said remote function on said network entity in using data received from the management device enabling this activation.
[0036] These preliminary control steps allow optimal operation of the method for providing access to a remote function of the operating system.
[0037] In an alternative embodiment, the selected network entity verifies at least one constraint indicated by the management device.
[0038] These constraints are, for example, an IP transit delay, an invocation time, a location constraint, etc.
[0039] Another object of the invention relates to a method for hosting at least one function called a remote function of an operating system of a terminal connected to a network, said method being implemented by a network entity, selected by a network controller to host said remote function for a device for managing the operating system, said method comprising:
[0040] - a step of establishing a communication channel with said system operating the terminal on the basis of at least one piece of information received from the terminal and provided by the management device to said terminal to enable it to establish said communication channel;
[0041] - a step of verifying that said terminal is authorized to invoke the function deported hosted by the network entity;
[0042] - following the reception via said communication channel of a message from an AP application embedded on the terminal invoking the remote function, a step of executing said remote function if said remote function is authorized for the terminal.
[0043] It is thus possible to introduce a mechanism that makes it possible to emulate a function of the operating system, called a remote function, elsewhere than in the terminal via the implementation of suitable mechanisms to encapsulate / transport the invocation messages of the application invoking this function. This remote function is located in an entity of a network and can be presented, and therefore accessible, to the applications of the user terminal as if it were embedded in the user's terminal. The invention thus proposes a collaborative mechanism intended to use an entity of a communication network as an extension of an operating system of the terminal.
[0044] In an alternative embodiment following the verification step, the hosting method comprises a step of sending to the operating system of the terminal a list of remote functions hosted by the network entity and authorized for the terminal.
[0045] It is thus possible for the terminal's operating system to access the list of remote functions hosted by the network entity.
[0046] In an alternative embodiment, if at least one remote function hosted by the network entity is authorized for the terminal, the hosting method comprises a step of storing at least one element among:
[0047] - at least one invocation parameter of the remote function included in a message invoking this remote function,
[0048] - at least one descriptive information of the communication channel; and / or
[0049] - at least one piece of information sent to the terminal following the verification step.
[0050] This storage step allows the network entity to execute the remote function on the data packet using one or more stored elements.
[0051] In an alternative embodiment, the hosting method comprises, following the reception of a data packet originating from the application embedded on the terminal via said communication channel or a data packet intended for said application, a step of executing the function transferred to said data packet using at least one element stored during the storage step.
[0052] This makes it possible to emulate a function of the operating system elsewhere than in the terminal.
[0053] Another object of the invention relates to a terminal for providing an application installed on said terminal with access to a function of an operating system belonging to said terminal, said terminal comprising:
[0054] - a module for establishing at least one communication channel with at least one entity of a network hosting for an operating system management device at least one function called a remote operating system function, said step establishment using at least one piece of information provided by the operating system management device;
[0055] - a module for exposing said remote function to the application as a function implemented locally by the operating system; and
[0056] - upon receipt of a message from the application invoking said remote function, a module to transfer the message to the network entity hosting said remote function, via the communication channel established with this network entity.
[0057] Such a terminal allows the implementation of the method of providing access to a remote function of the operating system which is the subject of the invention.
[0058] Another object of the invention relates to a device for managing an operating system of a terminal connected to a network, said management device comprising:
[0059] - a module for obtaining from a network controller at least one in training allowing access to at least one entity of the network, selected by said network controller for the management device to host at least one function called a remote function of said operating system;
[0060] - a module for sending to the data network controller enabling said activation remote function of said operating system on the selected network entity; and
[0061] - following receipt of a message from the operating system of the terminal, a module for sending information to said operating system to enable the terminal to establish a communication channel with the network entity hosting said remote function.
[0062] Such a management device allows the implementation of a communication method which is the subject of the invention.
[0063] Another object of the invention relates to a network controller comprising:
[0064] - a module for sending to a management device of an operating system of a terminal connected to the network, of at least one piece of information allowing access to at least one entity of the network selected by the controller for the management device to host at least one function called a remote function of the operating system; and
[0065] - a module for activating said function remoted on said network entity in using data received from the management device enabling this activation.
[0066] Such a network controller allows the implementation of a control method which is the subject of the invention.
[0067] Another object of the invention relates to a network entity for hosting at least one function called a remote function of an operating system of a terminal connected to said network, said entity being selected by a network controller to host said remote function for a system management device. operating, said network entity comprising:
[0068] - a module for establishing a communication channel with said system operating the terminal on the basis of at least one piece of information received from the terminal and provided by the management device to said terminal to enable it to establish said communication channel;
[0069] - a module for verifying that said terminal is authorized to invoke the function deported hosted by the network entity;
[0070] - following the reception via said communication channel of a message from an AP embedded application on the terminal invoking the remote function, a module for executing said remote function if said remote function is authorized for the terminal.
[0071] Such a network entity allows the implementation of a method for hosting at least one remote function which is the subject of the invention.
[0072] Another object of the invention relates to a computer program comprising program code instructions for executing the steps of a method for providing access to a function of an operating system of a terminal.
[0073] Another subject of the invention relates to a computer-readable recording medium on which is recorded a computer program comprising program code instructions for executing the steps of a method for providing access to a function of an operating system of a terminal, when said program is executed by a processor. Description of the figures
[0074] Other characteristics and advantages of the invention will appear during the reading of the detailed description which follows for the understanding of which reference will be made to the appended drawings in which:
[0075] [Fig.l] illustrates an example of a simplified internal structure of a terminal according to the prior art;
[0076] [Fig.2] illustrates a communication system for providing access to a remote function of an operating system;
[0077] [Fig.3] illustrates steps of a method for providing access to the remote function implemented by all or part of the communication architecture of [Fig.2] as well as steps of a method for hosting said remote function;
[0078] [Fig.4] illustrates a terminal which implements the provisioning method illustrated by [Fig.3] ;
[0079] [Fig.5] illustrates a network entity used for implementing the hosting method illustrated by [Fig.3];
[0080] [Fig.6] illustrates steps of a communication method implemented by any or part of the communication architecture of [Fig.2] as well as steps of a control method;
[0081] [Fig.7] illustrates a management device for implementing the communication method illustrated by [Fig.6];
[0082] [Fig.8] illustrates a network controller for implementing the control method illustrated by [Fig.6].
[0083] Description of embodiments
[0084] [Fig.2] illustrates a SYS communication system enabling the implementation of a method for providing an application with access to a remote (“remote”) function of an operating system (i.e. an OS) installed on a user terminal. This provision method is also called herein the NECTARINE procedure (for “NEtwork-Coordinated Terminal Access to Remote, INtelligent and Emulated OS APIs”).
[0085] The SYS communication system illustrated by [Fig.2] includes in particular the following elements:
[0086] - a Terminal terminal;
[0087] - a NEAT network entity and a network controller Controller located in a network Network; and
[0088] - an OVI (OS Vendor Infrastructure) management device for operating systems.
[0089] The terminal Terminal is adapted to be controlled by a user who wishes to access services. As already explained, this terminal comprises an operating system OS, managed by the OVI management device, and one or more APP applications, only one of which is represented here.
[0090] The terminal Terminal can be a user equipment or UE (for “User Equipment” in English), a service instance, a CPE (for “Customer Promises Equipment”), etc. This terminal can be mobile or fixed.
[0091] Only one terminal is shown in [Fig.2]. However, the SYS communication system is adapted to manage multiple terminals.
[0092] The terminal Terminal is connected to a single network Network according to [Fig.2]. This network is a communication network. It can be, for example, a 5G mobile network, a WLAN (for “Wireless Local Area Network”) wireless network or a fixed network. In another embodiment, the terminal can be connected to several Network networks. These networks can be of the same nature or of a different nature.
[0093] In addition, the Network may support a plurality of network slices.
[0094] A physical network can be organized into several distinct networks which can be considered as many operating domains (for example, a communication network can be broken down into an access network, a collection network, a network heart and a transit network).
[0095] Each of these domains can support network slices whose engineering and operation are characteristic of the domain (for example, a slice deployed on a 5G mobile core network will use traffic processing and operation functions characteristic of a 5G mobile core network). Thus, each domain can use technologies deployed in this domain for the realization of the network slices. For example, slices in a mobile network (5G) can be based on the implementation of slices in the following different domains: Radio Access Network (RAN), Core Network (CN) and Transport Network (TN).
[0096] The NEAT network entity (for “NW_EMULATED_API_TERMINAL” in English) is adapted, that is to say configured, to host one or more functions of the terminal operating system OS but which are not present locally in the terminal OS. Such functions are, for example, prioritization functions, traffic acceleration or encryption of data characteristic of the use of services. These functions are then called remote functions. A single NEAT network entity is represented here. Alternatively, the Network network can integrate several NEAT network entities. Each NEAT network entity is capable of hosting one or more remote functions. Remote functions can be common to several NEAT network entities. No assumption is made as to the network which hosts a NEAT entity.
[0097] The Network Controller has the ability to activate one or more remote function(s) on a NEAT network entity.
[0098] The OVI management device illustrated by [Fig.2] is responsible for distributing software updates of the terminals' OS, security patches, etc. This OVI device is associated with a supplier of the terminal or the OS of this terminal (called "OS Vendor" in English). Several terminal models can be managed by the same OVI device. The organic and functional structure of an OVI is internal and characteristic of the organization of the manufacturer of the user terminal or the supplier of the OS. The OVI management device can be composed of one or more front-end servers and one or more "back-end" servers. The front-end servers are adapted to manage communication channels established with the terminals whose OS are managed by the OVI management device. Furthermore, the management of connections with the terminals can be distributed.For example, the management of the TLS (Transport Layer Security) connection termination function can be separate from the management of the application termination function. These managements can use resources located in different places. This distribution of functions is not visible to the terminals. In the case where the application termination is not at the front of the terminals, the IP address and the source port number of a . Messages received from a terminal must be communicated to the application endpoint using mechanisms such as HOST_ID described in IETF RFC 7974, edited by B. Williams et al. and entitled "An Experimental TCP Option for Host Identification", October 2016.
[0099] The OVI management device is external to a terminal. However, it can be reached by this terminal using a domain name, an IP address, etc. Other information (for example, a security certificate) such as that necessary to establish security associations ("Secure Association" in English) between a terminal and a front-end server of the OVI management device can be configured in the user terminal. The reachability information of an OVI is called here OVI_FRONTAL_CONTACT_TERMINAL (OFCT). This information is typically configured in the terminal before its commercialization. However, other dynamic configuration modes can be considered (for example "OMA Device Management").
[0100] In the example of [Fig.2], the communication system SYS comprises only one OVI management device. Alternatively, the communication system SYS comprises several OVI management devices. Different terminals can then be managed by different OVI management devices.
[0101] The OVI management device is directly connected to the Network. Alternatively, the OVI management device is connected to the Network via one or more intermediate networks (e.g., transit network).
[0102] [Fig.6] illustrates the steps of a communication method implemented by the OVI management device illustrated in [Fig.2]. This communication method allows the activation of the NECTARINE procedure.
[0103] Initially, the OVI management device dynamically negotiates with the Network, for example according to the CPNP protocol (for “Connectivity Provisioning Negotiation Protocol”), as described in the IETF RFC 8921 document, edited by M. Boucadair et al. entitled “Dynamic Service Negotiation: The Connectivity Provisioning Negotiation Protocol (CPNP)”, October 2020.
[0104] This negotiation includes the transmission by the OVI management device of a “Subscribe()” message to the network controller Controller. This “Subscribe()” message includes TOVI identification information, called OVI_ID. This identifier is unique. The subscription message may also include instructions for placing network entities to expose the remote functions (for example, to optimize an invocation time or an IP transit delay).
[0105] In response to this "Subscribe()" message, the network controller returns to the OVI at least one IP address (and possibly a port number) to invoke the remote function. This IP address is coded in a "NTW_API_Locator (NAL)" field. The The message also contains an authentication identifier (ADN for "Authentication Domain Name" in English) called "NTW_API_ADN (NAA)". The information exchanged during the negotiation / subscription procedure is recorded by the network controller and the OVI. The network controller uses a table "OVI_NECTARINE_SUBSCRIBERS" for this purpose (which notably records the identifier of each of the OVIs that have subscribed to the service), while the OVI records the NAL, NAA information, as well as the network identifier (noted NWID) in a table called: "ACTIVE_NW_NECTARINE".
[0106] API_PACKAGES software modules (denoted here “S AV Package Locator (SPL) and “SAV Package ADN (SPA)”) are then communicated to the network controller Controller to be installed in all or part of the selected NEAT network entities to expose the remote functions. The network may decide to install these modules in certain regions, for example depending on the operator's coverage. These software modules may be updated by the OVI during the lifetime of the NECTARINE service as subscribed to by the OVI. It should be noted that a security procedure may be necessary because software updates are likely to generate traffic that may constitute a potential attack vector.
[0107] The network controller selects the NEAT network entities which will expose the remote functions for this OVI according to, for example, constraints indicated by the OVI (such as an IP transit delay, an invocation time, a location constraint, etc.).
[0108] One or more NEAT entities may be activated for a single OVI. For example, activation may depend on the geographic distribution of the terminals associated with that OVI.
[0109] A single NEAT entity can expose remote functions which correspond to distinct OVIs.
[0110] The information used to install the API_PACKAGES modules (“SAV Package Locator (SPL) and “SAV Package ADN (SPA)”) is typically different from the NAL / NAA information intended to be presented to the terminals, since it corresponds to two distinct uses (access to functions deported by the terminals and installation of software modules).
[0111] We now assume that the terminal indicates to the network controller Controller its ability to implement the NECTARINE procedure. To do this, an information element, called NECTARINE_CAPABLE, is inserted into a message for establishing a connection with the network controller sent by the terminal. Such a step has the advantage of allowing the configuration of network filters to prepare the establishment of secure channels with a NEAT entity, the activation on demand of new NEAT entities for dimensioning purposes, etc.
[0112] When the user terminal is connected to the network, it sends a message to the OVI using the preconfigured OFCT information.
[0113] This message can be formed using an HTTP PUT, POST or GET primitive.
[0114] The message indicates the identity of the communication network to which it is connected (NWID). This identifier is for example a “Network Access Identifier” as described in the IETF RFC 7542 document edited by A. DeKok entitled “The Network Access Identifier”, May 2015, or an “Access Network Domain Name” identifier as described in the IETF RFC 5986 document, edited by M. Thomson et al. and entitled “Discovering the Local Location Information Server (LIS)”, September 2010.
[0115] If the terminal is eligible for the NECTARINE service, then the OVI returns to the operating system information called OVI_SUPPLIED_NECTARINE_INFO (OSNI). This information includes in particular here an IP address of the NEAT network entity, an OVI_ID identifier of the OVI management device, authentication information such as NAA information, NAL information (for "NTW_API_Locator" in English), as well as an authentication token (or "token" in English) called here Token.
[0116] The OVI determines whether a terminal is eligible for the NECTARINE service by taking into account, for example, the terminal model, the value-added services provided by the network to which said terminal is connected, the software or hardware limitations of the terminal, etc.
[0117] Other parameters may be communicated such as a filter on the remote functions, at least one particular service identifier, one or more data network names or "Data Network Names" in English (DNN), etc. The invocation by the terminal of the remote functions is then conditioned by these filters. For example, if a DNN has been returned, then only connections involving this DNN are eligible for the NECTARINE service.
[0118] Alternatively, the NECTARINE_ENABLE parameter may be omitted. The presence of the NAL and NAA information is then an implicit indication of the implementation of the NECTARINE service for this communication network.
[0119] Once the OSNI information has been retrieved by the terminal, the latter can establish at least one secure channel (ReqCanai message and RepCanai message) with the NEAT network entity which hosts the remote function(s), as described later with reference to [Fig.3]. The OSNI information is used to establish this secure channel.
[0120] In a variant, the remote functions can be supported by several NEAT entities of the network. A secure channel is established with each of these NEAT entities.
[0121] The NEAT network entity performs authentication of the user terminal and validation of the OVI_ID and Token information.
[0122] If the terminal is authorized to use the NECTARINE service, then said NEAT entity returns a list of remote functions (API, typically) that can be exposed by the terminal's OS to applications as local functions. An argument "Type=Local / Remote" can be used by the terminal (more precisely the OS) to distinguish local functions (Type=Local) from emulated functions (i.e. accessible via the network) (Type=Remote). The functions in such a list correspond to the authorization of the terminal and its applications to invoke them. Furthermore, the number of functions hosted by a NEAT entity can change over time: thus, the addition of a new function that a terminal authenticated by the NEAT entity is authorized to invoke could trigger a new verification procedure.Similarly, in the event of withdrawal of a remote function, this withdrawal could be the subject of a notification sent by the NEAT entity to all the terminals that it serves and which are authorized to invoke said function. This notification could also include an indication for contacting another NEAT entity which continues to host said remote function.
[0123] If the authorization to use the NECTARINE service or the authentication of the terminal fails, then the NEAT entity rejects the request for access to the NECTARINE service for this terminal.
[0124] Otherwise, if the authorization is validated, the terminal (its OS more specifically) exposes to the applications the remote functions received from a NEAT entity in the same way as it exposes functions that it implements locally. If necessary, the user terminal applies the filters mentioned above to control the exposure of these primitives to the applications.
[0125] [Fig.3] illustrates steps of a method for providing access to a remote function F'j implemented by all or part of the elements of the SYS communication system illustrated in [Fig.2], following activation of the NECTARINE procedure by the method of [Fig.6].
[0126] As mentioned previously, in an authentication step, the terminal OS sends a ReqAuth request for authentication to the NEAT network entity. In return, the NEAT network entity transmits a RepAuth response validating or not this authentication.
[0127] In a step of establishing a communication channel, the OS of the terminal sends a Reqcanai request to the NEAT network entity. This ReqCanai request comprises at least the OSNI information. In response to the ReqCanai request, the NEAT network entity sends a RepCanai response to the terminal comprising the identification data of the communication channel. In a preferred embodiment, the RepCanai response further comprises elements for securing said channel and the establishment of this canal.
[0128] The terminal OS can expose, here, local functions F;, with i ranging from 1 to n, n being a non-zero natural integer. These local functions F; are directly hosted by VOS. The terminal OS can also expose remote functions F'j, with j ranging from 1 to m, m being a non-zero natural integer. These remote functions F'j are hosted by the NEAT entity (or by several NEAT entities).
[0129] To discover the remote functions F'j hosted by the NEAT entity, the OS transmits, in the embodiment described here, a ReqList request to said NEAT entity in order to acquire a list of the remote functions F'j hosted by said entity. In a RepList response, the NEAT network entity provides the terminal with this list List. Alternatively, the NEAT entity can spontaneously send the list List to the OS, without explicit request from the latter.
[0130] In a particular embodiment, each remote function F'j present in the list List corresponds to an associated marking indication IMj. Such a marking indication IMj is used by the OS to mark data packets intended to be processed by said remote function Fj hosted by the NEAT entity. This marking indication IMj is, in a particular embodiment, provided by the NEAT network entity with the list List.
[0131] Following the obtaining of the list of the remote functions, in a function exposure step, the OS exposes to the application APP the set of functions F;, with i ranging from 1 to n hosted locally by the OS and the set of functions Fj, with j ranging from 1 to m hosted by the entity NEAT. According to the invention, the local and remote functions Fi and F'j of the OS are exposed to the application APP by the OS in an identical or similar manner so that the application APP is not able to distinguish the functions which are hosted locally by the OS from the functions hosted by the entity NEAT.
[0132] It is now assumed that the OS receives a “Call_F;” message from the APP application invoking the function F;. Upon receipt of this “Call_F;” message, the OS determines that the invoked function F; is hosted locally. It then executes the function F; on the “Call_F;” message in a manner known per se. If a response is required for this “Call_F;” message, the OS transmits an associated Rep_Call_Fi response to the APP application.
[0133] It is now assumed that the OS receives a “Call_F'j” message from the APP application invoking the function F'j. Upon receipt of this “Call_F'j” message, the OS determines that the invoked function F'j is deported. The OS relays the received message to the NEAT network entity via the pre-established communication channel as described above. The NEAT network entity then executes the invoked function F'j on the received message. If a response is required for the “Call_F'j” message, after execution of the function F'j by the NEAT entity, the latter sends a Rep_Call_F'j to the terminal's OS via the communication channel. The Rep_Call_F'j response is communicated by the OS to the APP application.
[0134] The NEAT entity records locally, for example in a table, the information retrieved in the call of the function “Call_F'j”, the communication channel and, where appropriate, the information returned to the terminal in response to the call of the function “Call_F'j”. The information thus recorded in the table can be used subsequently by the NEAT entity when processing of data packets is necessary following the call of the function F'j. The terminal can also use the marking information IMj to mark the data packets sent for processing by the function F'j in order to facilitate the identification of an entry in the table to be used for this processing.
[0135] It should be noted that calling a function by transmitting the message "Call_Fi" or "Call_F'j" is not necessarily associated with the exchange of data. For example, a function may be a function for discovering external addresses, configuring classification rules, etc.
[0136] In an alternative embodiment, there are several NEAT entities with which the terminal is likely to communicate to activate and operate remote functions. Therefore, the discovery step via the ReqList request consists of discovering these NEAT entities and the functions that they host. The list List thus constituted comprises a set of remote functions F'kj where k represents the kth NEAT entity hosting the jth remote function F'j.
[0137] It will also be noted that the step of exposing the remote function(s) F'j and, where appropriate, the local functions F;, can be done before or after the step of establishing the communication channel between the terminal Terminal and the network entity NEAT.
[0138] [Fig.4] illustrates the terminal Terminal for implementing the method of providing [Fig.3].
[0139] This terminal includes:
[0140] - at least one input / output interface E / STerm;
[0141] - a MemTeim storage memory;
[0142] - a ProcTerm processor.
[0143] The at least one input / output interface E / STerm is adapted to allow the terminal to receive and transmit messages, for example with the Network.
[0144] The MemTerm storage memory is adapted to store data such as data associated with the APP application.
[0145] The ProcTerm processor is adapted to implement the steps of the provisioning method as described above.
[0146] [Fig.3] also illustrates steps of a method for hosting a remote function implemented by the NEAT network entity. This NEAT network entity is selected by a network controller to host the remote function for the OVI management device. This hosting method comprises the step of establishing the communication channel (Reqcanai message and Repcanai message) with the operating system OS of the terminal. This establishment step is carried out on the basis of at least one piece of information received from the terminal and provided by the OVI management device to said terminal to enable it to establish the communication channel.
[0147] The hosting method also comprises a verification step according to which the terminal is authorized to invoke the remote function hosted by the NEAT network entity.
[0148] Following this verification step, the hosting method comprises a step of sending to the operating system the list of remote functions hosted by the network entity and that the terminal is authorized to invoke (ReqList message and Reptist message) - If there is at least one remote function hosted by the NEAT network entity and that the terminal is authorized to invoke, the hosting method comprises a step of storing at least one element from among:
[0149] - at least one invocation parameter of the remote function included in a message invoking this remote function;
[0150] - at least one descriptive information of the communication channel; and / or
[0151] - at least one piece of information sent to the terminal following the verification step.
[0152] Following receipt via the communication channel of the message “Call_F'j” invoking the remote function, the hosting method comprises a step of executing said remote function.
[0153] Following the reception of a data packet from the APP application embedded in the terminal via said communication channel or a data packet intended for said APP application, the hosting method comprises a step of executing the remote function on said data packet using at least one element stored during the storage step.
[0154] [Fig.5] illustrates the NEAT network entity for hosting and executing remote functions.
[0155] This NEAT network entity includes:
[0156] - an input / output interface E / SNEAt;
[0157] - a MemNEAT storage memory;
[0158] - a ProcNEAT processor.
[0159] The E / Sneat input / output interface is adapted to allow the Neat entity to communicate with the terminal operating system.
[0160] The MemNEAT storage memory is suitable for storing data such as those characteristic of one or more remote functions.
[0161] The ProcNEAT processor is adapted to implement the steps of the hosting method as described above.
[0162] [Fig.7] illustrates the OVI management device for implementing the method of communication illustrated by [Fig.6].
[0163] This OVI management device includes:
[0164] - an input / output interface E / SOvi;
[0165] - a storage memory Mem0Vi;
[0166] - a ProcOVi processor.
[0167] The input / output interface E / SOvi is adapted to allow the OVI management device to receive and transmit messages, for example with the operating system OS and the controller Controller.
[0168] The MemTerm storage memory is adapted to store data such as OSNI data i.e. OVI_ID, NAL, NAA information, and the Token.
[0169] The ProcTerm processor is adapted to implement the steps of the communication method as described above.
[0170] [Fig.6] also illustrates steps of a method of control by the network controller Controller. This method comprises a step of sending to the OVI management device the NAL / NAA information allowing access to the NEAT network entity to host the remote function F'j of the OS operating system. The method also comprises a step of activating the remote function F'j on the NEAT network entity using the SPA / SPL data received from the OVI management device allowing this activation.
[0171] [Fig.8] illustrates the network controller Controller for implementing the control method of [Fig.6].
[0172] This network controller includes:
[0173] - an E / SCont input / output interface;
[0174] - a MemCont storage memory;
[0175] - a ProcConf processor
[0176] The input / output interface E / SCont is adapted to allow the controller Controller to receive and transmit messages, for example with the management device OVI and the network entity NEAT.
[0177] The MemCont storage memory is suitable for storing data such as SPA and SPL data.
[0178] The ProcCont processor is adapted to implement the steps of the control method as described above.
[0179] The invention thus allows specific processing of a call for access to a function deported by an OS of a terminal:
[0180] - the application uses the information relayed by the terminal. This use is identical to that of a local function call. The application generates a data packet that uses a marking relayed by the OS;
[0181] - the OS intercepts the application data and associates it with a channel then sends if need in a secure communication channel (e.g. an IPsec tunnel) established with the relevant NEAT entity. The OS optionally marks them before sending them to the appropriate secure communication channel;
[0182] - the NEAT network entity executes the corresponding function then sends the packet, especially when this packet is a data packet. Note that calling a function is not necessarily associated with the exchange of data. For example, a function for discovering external addresses, configuring classification rules, etc. In another example, the NEAT network entity can set up a URSP table (for "UE Route Selection Policy") remote in the network to associate an application flow with a network slice, when this network has several slices.
[0183] Packets sent to the terminal that pass through the NEAT network entity are routed after associated processing using the ad hoc network slice.
Claims
Claims
1. Method for providing an application (APP) installed on a terminal (Terminal), by an operating system (OS) of said terminal (Terminal), with access to a function of the operating system, said method comprising: - a step of establishing at least one communication channel with at least one entity (NEAT) of a network (Network) hosting for a management device of the operating system (OVI) at least one function called a remote function (F'j) of the operating system (OS), said establishment step using at least one piece of information (OSNI) provided by the management device of the operating system (OVI); - a step of exposing (Expo_F'j) to the application (APP) said remote function (F'j) as a function implemented locally by the operating system (OS);and - upon receipt of a message (Call_F'j) from the application invoking said remote function (F'j), a step of transferring the message (Call_F'j) to the entity (NEAT) of the network hosting said remote function (F'j), via the communication channel established with this entity (NEAT) of the network.;
2. A method of providing according to claim 1 further comprising, before establishing a said communication channel with said entity (NEAT) of the network, a step of authenticating the terminal (Terminal) with this entity (NEAT).
3. A method of providing according to claim 1 or 2 further comprising a step of receiving, from said entity (NEAT) of the network, a list (List) of remote functions hosted by this entity (NEAT) of the network, for exposure to said application (APP).
4. A method of providing according to any one of claims 1 to 3 comprising a step of receiving from said entity (NEAT) of the network at least one marking indication (IMj) intended to be applied to at least one data packet (Pack) sent by the application (APP) before being transferred by the operating system (OS) to this entity (NEAT) of the network.
5. A method of providing according to any one of claims 1 to 4 comprising: - a step of identifying at least one data packet (Pack) sent by the application (APP) intended to be transmitted via said established communication channel to said entity (NEAT) of the network; and - a step of transferring said at least one identified packet (Pack IMj) to said entity (NEAT) of the network via said communication channel.
6. A method of providing according to any one of claims 1 to 5 comprising a step of transferring to the application (APP) a received message (Rep_Call_F'j) from the entity (NEAT) of the network hosting the remote function (F'j) invoked by the application (APP).
7. Method of providing according to any one of claims 1 to 6 comprising, on receipt of the message (Call_F; ;Call_F'j) coming from the application (APP) invoking a required function (F; ; F'j), a prior step of verifying whether this function is hosted locally (F;) by the operating system (OS) or remote (F'j) on the entity (NEAT) of the network.
8. Communication method implemented by a management device (OVI) of an operating system (OS) of a terminal (Terminal) connected to a network (Network), said method comprising: - a step of obtaining, from a network controller, at least one piece of information (NAL / NAA) allowing access to at least one entity (NEAT) of the network, selected by said network controller for the management device (OVI) to host at least one function called a remote function (F'j) of said operating system; - a step of sending to the data network controller (SPA, SPL) allowing activation of said remote function of said operating system (OS) on the selected network entity (NEAT);and - following receipt of a message from the operating system (OS) of the terminal (Terminal), a step of sending to said operating system (OS) information (OSNI) to enable the terminal (Terminal) to establish a communication channel with the entity (NEAT) of the network hosting said remote function (F'j).;
9. Communication method according to claim 8 in which the obtaining step follows a step of sending a message to the controller indicating at least one constraint to be satisfied by the entity (NEAT) of the network.
10. Method of control by a controller (Controller) of a network, comprising: - a step of sending to a management device (OVI) of an operating system (OS) of a terminal (Terminal) connected to the network, at least one piece of information (NAL / NAA) allowing access to at least one entity (NEAT) of the network selected by the controller for the management device (OVI) for hosting at least one function called remote function (F'j) of the operating system (OS); and - a step of activating said remote function (F'j) on said entity (NEAT) of the network using data (SPA, SPL) received from the management device (OVI) allowing this activation.
11. Control method according to claim 10 in which said selected network entity (NEAT) verifies at least one constraint indicated by the management device (OVI).
12. Method for hosting at least one function called a remote function (F'j) of an operating system (OS) of a terminal (Terminal) connected to a network (Network), said method being implemented by an entity (NEAT) of the network, selected by a controller (Controller) of the network to host said remote function (F'j) for a management device (OVI) of the operating system (OS), said method comprising: - a step of establishing a communication channel with said operating system (OS) of the terminal (Terminal) on the basis of at least one piece of information received from the terminal (Terminal) and provided by the management device (OVI) to said terminal (Terminal) to enable it to establish said communication channel; - a step of verifying that said terminal (Terminal) is authorized to invoke the remote function (F'j) hosted by the entity (NEAT) of the network;- following receipt via said communication channel of a message (Call_F'j) from an application (APP) embedded on the terminal (Terminal) invoking the remote function (F'j), a step of executing said remote function (F'j) if said remote function (F'j) is authorized for the terminal (Terminal).;
13. Hosting method according to claim 12 comprising, following the verification step, a step of sending to the operating system (OS) of the terminal (Terminal) a list (List) of remote functions hosted by the entity (NEAT) of the network and authorized for the terminal (Terminal).
14. Hosting method according to claim 12 or 13 comprising if at least one remote function (F'j) hosted by the entity (NEAT) of the network is authorized for the terminal (Terminal), a step of storing at least one element among: - at least one invocation parameter of the remote function (F'j) included in a message invoking this remote function, - at least one descriptive information of the communication channel; and / or - at least one information sent to the terminal (Terminal) following the verification step.
15. Hosting method according to claim 14 comprising, following the reception of a data packet (Packet) originating from the application (APP) embedded on the terminal (Terminal) via said communication channel or a data packet (Data) intended for said application (APP), a step of executing the remote function (F'j) on said data packet (Packet) using at least one element stored during the storage step.
16. Terminal for providing an application (APP) installed on said terminal (Terminal) with access to a function of an operating system belonging to said terminal, said terminal comprising: - a module for establishing at least one communication channel with at least one entity (NEAT) of a network (Network) hosting for an operating system management device (OVI) at least one function called a remote function (F'j) of the operating system (OS), said establishment step using at least one piece of information (OSNI) provided by the operating system management device (OVI); - a module for exposing (Expo_F'j) to the application (APP) said remote function (F'j) as a function implemented locally by the operating system (OS);and - upon receipt of a message (Call_F'j) from the application invoking said remote function (F'j), a module for transferring the message (Call_F'j) to the entity (NEAT) of the network hosting said remote function (F'j), via the communication channel established with this entity (NEAT) of the network.;
17. Device for managing an operating system (OS) of a terminal (Terminal) connected to a network (Network), said management device (OVI) comprising: - a module for obtaining, from a network controller, at least one piece of information (NAL / NAA) allowing access to at least one entity (NEAT) of the network, selected by said network controller for the management device (OVI) to host at least one function called a remote function (F'j) of said operating system; - a module for sending data to the network controller (SPA, SPL)
18.
19. enabling said remote function (F'j) of said operating system (OS) to be activated on the selected network entity (NEAT); and - following receipt of a message from the operating system (OS) of the terminal (Terminal), a module for sending information (OSNI) to said operating system (OS) to enable the terminal (Terminal) to establish a communication channel with the network entity (NEAT) hosting said remote function (F'j). Controller of a network, said controller (Controller) comprising: - a module for sending to a management device (OVI) of an operating system (OS) of a terminal (Terminal) connected to the network, at least one piece of information (NAL / NAA) allowing access to at least one entity (NEAT) of the network selected by the controller for the management device (OVI) to host at least one function called a remote function (F'j) of the operating system (OS); and - a module for activating said remote function (F'j) on said entity (NEAT) of the network using data (SPA / SPL) received from the management device (OVI) allowing this activation. Entity of a network (Network) for hosting at least one function called a remote function (F'j) of an operating system (OS) of a terminal (Terminal) connected to said network (Network), said entity (NEAT) being selected by a controller (Controller) of the network to host said remote function (F'j) for a management device (OVI) of the operating system (OS), said network entity (NEAT) comprising: - a module for establishing a communication channel with said operating system (OS) of the terminal (Terminal) on the basis of at least one piece of information received from the terminal (Terminal) and provided by the management device (OVI) to said terminal (Terminal) to enable it to establish said communication channel; - a verification module that said terminal (Terminal) is authorized to invoke the remote function (F'j) hosted by the entity (NEAT) of the network; - following receipt via said communication channel of a message (Call_F'j) from an application (APP) embedded on the terminal (Terminal) invoking the remote function (F'j), a module for executing said remote function (F'j) if said remote function (F'j) is authorized for the terminal (Terminal).
Citation Information
Patent Citations
Task computing
US20050246726A1
Object-oriented multicast networking system
WO1995017066A1