Method and module for dynamic routing modification
The method and module for dynamic routing modification in communication networks address the challenge of inserting additional functions without interruption, enhancing resilience and security by dynamically redirecting traffic through intermediate services, ensuring real-time response and optimized performance.
Patent Information
- Application Number
- FR2024006615
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-20
- Publication Date
- 2025-12-26
AI Technical Summary
Existing communication network systems lack the ability to easily and dynamically insert additional functions affecting current traffic without service interruption, necessitating improved flexibility and resilience, particularly in managing security and performance.
A method and module for dynamically modifying routing in a communication network by implementing conditional indirect communication through an intermediate service, allowing on-the-fly insertion of functions like firewalls or intrusion detection systems, with real-time monitoring and selection of suitable services based on criteria such as security and performance needs.
Enables continuous communication with enhanced resilience and security by redirecting traffic through intermediate services, ensuring real-time response to anomalies and threats, and optimizing latency and loading speed, thereby improving the quality and reliability of critical communications.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method and module for dynamic routing modification. Technical field
[0001] This disclosure falls within the field of telecommunications. More specifically, it relates to a method for dynamically modifying routing in a communication network service system, a corresponding module, device, computer program, and recording medium. Previous technique
[0002] The state of the art includes systems that use containerization technologies, such as Docker, and container orchestration technologies, such as Kubernetes.
[0003] These systems are designed to deploy applications and services on data processing agglomerations, or "clusters", by distributing them across several working environments, or "clouds".
[0004] In this context, there is a continuing need to allow for the easy, hot insertion of additional functions affecting current traffic in service systems. Summary
[0005] This disclosure improves the situation.
[0006] A method for dynamically modifying routing is proposed in a service system of a communication network, the method comprising, during a direct, active communication between a first service and a second service: a conditional implementation of an indirect communication between said services passing through an intermediate service.
[0007] The method allows for the potentially on-the-fly insertion of intermediate functions without service interruption, so that a flow routed by the system benefits from these intermediate functions. This flexibility makes it possible to maintain continuous communication between services while adding additional functionalities, thus facilitating a rapid response to various needs, such as security or performance. In particular, the method can improve the resilience and / or security of the communication network. Indeed, the conditional insertion of intermediate services makes it possible to redirect all or part of a traffic stream through security services, such as firewalls or intrusion detection systems, thereby increasing protection against cyberattacks.
[0008] According to another aspect, a dynamic routing modification module is proposed in a service system of a communication network, the module being configured for, during direct, active communication between a first service and a second service: a conditional implementation of indirect communication between said services via an intermediary service.
[0009] According to another aspect, a computer program is proposed comprising instructions for implementing all or part of a process as defined herein, in any of its embodiments, when this program is executed by a processor. According to another aspect, a non-transient, computer-readable recording medium is proposed on which such a program is recorded.
[0010] The features described in the following paragraphs may optionally be implemented independently of each other or in combination with each other:
[0011] In one example, said conditional implementation takes into account a service system management policy.
[0012] This can help with intelligent and adaptive traffic management within the communication network. For example, in a scenario where the network must prioritize critical data traffic, the management policy can automatically redirect this traffic through a verification service to ensure its integrity and speed.
[0013] In one example, said conditional implementation takes into account monitoring of traffic within the communication network.
[0014] This provides the service system with a real-time response capability to detected anomalies or attacks. For example, when a traffic anomaly is detected indicating a potential DDoS attack, the suspicious traffic can be automatically redirected to an analysis service to neutralize the threat.
[0015] In one example, the intermediate service acts as a repair service, at least partially, for traffic originating from the first service.
[0016] This helps to increase the quality and reliability of communications, particularly critical communications, by enabling real-time repair of data streams. If corrupted packets are detected in a transmission, the intermediate service can correct these packets before forwarding them to the final recipient without interrupting the transmission, thus improving the user experience.
[0017] In one example, the intermediate service is selected from a plurality of services during said conditional setup.
[0018] Choosing the most suitable service from several available options offers an advantage in terms of flexibility. For example, for a streaming service, different caching services can be used depending on the Geographic location of users to optimize latency and loading speed.
[0019] In one example, the intermediate service is selected based on at least one selection criterion from among: a required level of security, a required level of performance, a type of traffic using indirect communication, a regulatory requirement; a combination of at least two of the above criteria.
[0020] At least one (for example each) selection criterion can be aligned with a specific operational need and can, for example, take into account the aforementioned management policy and / or the aforementioned monitoring, thus allowing for increased flexibility and responsiveness.
[0021] In one example, the above process (or module) is implemented by a WASM (WebAssembly) module.
[0022] The WebAssembly format inherently ensures high performance and cross-platform compatibility, facilitating the deployment and execution of the intermediate function independently of the hardware and software support used at the server and terminal levels concerned.
[0023] In one example, the above process (or module) is implemented in a container environment.
[0024] This facilitates the integration and management of intermediate functions in microservices architectures, thus helping to provide improved scalability and portability.
[0025] In an example, in which the intermediate service is dynamically deployed during said conditional setup.
[0026] Such an approach can help improve the responsiveness of the service system by enabling the instantaneous (or near-instantaneous) deployment of new intermediate functions. For example, during an urgent security update, a new filtering service can be hot-deployed to immediately protect the network against a new vulnerability.
[0027] In one example, the above process includes (or the above module is configured to) when establishing indirect communication, an abandonment of direct communication.
[0028] This can help increase system security (towards maximum security) by ensuring that all traffic passes through the intermediate function without exception. For example, for financial transactions, direct communication may be abandoned in favor of communication via an authenticity verification service to prevent fraud.
[0029] In one example, the above process includes (or the above module is configured to), after the establishment of indirect communication, a conditional abandonment of indirect communication.
[0030] Planning to restore direct communication when security or performance conditions permit is a possible option to help optimize the resources of the service system.
[0031] In one example, the above process includes (or the above module is configured to) an application of an authentication and / or filtering overlay to indirect communication.
[0032] Such mechanisms contribute to strengthening the security of communications. For example, it may be stipulated in a corporate network that all communications passing through a given intermediate service are authenticated and filtered to prevent unauthorized access and data exfiltration. Brief description of the drawings
[0033] Other features, details and advantages will become apparent from reading the detailed description below and from analyzing the accompanying drawings, in which: Fig. 1
[0034] [Fig.1] shows an algorithm and a functional organization of a service system in an example of an embodiment. Fig. 2
[0035] [Fig.2] shows an architecture of a control plane of a service system in an example embodiment. Fig. 3 and Fig. 4
[0036] [Fig.3] and [Fig.4] show two examples of setting up indirect communication between two services in implementation examples. Description of the implementation methods
[0037] In the description that follows, identical reference numerals designate identical elements or elements having similar functions.
[0038] This disclosure relates to a technique for assisting a service system deployed in a communication network.
[0039] It should be noted at the outset that the term "service" is used in this document in a general way to encompass a service per se, one or more microservices, or even a complete application. "Application" is understood to mean a set of software functionalities or macro-functions that meet a specific need. An application may consist of a or several services or microservices that work together to provide overall functionality. It's important to note that the distinction between a "service" and a "microservice" is primarily based on the scale and functional breakdown of an application's software architecture. A service is a self-contained functional unit that can cover a broad range of features and can either form part of a larger application or be used by multiple applications. A microservice is smaller and is typically responsible for a specific feature of an application.
[0040] One aspect of the technique proposed in this document is a method for dynamically modifying routing in a service system of a communication network.
[0041] Another aspect of the proposed technique is a dynamic routing modification module in a service system of a communication network.
[0042] Any suitable hardware and / or software may be used for the practical implementation of said module and / or services. By way of example, a Packet Gateway (PGW) is an example of network equipment providing a data routing service including security functions. Generally, although aspects of the proposed technique may be described in this document as a process, device, module, system, procedure, or method, it should be noted that the proposed technique may also cover computer memory that can be connected to a processor possibly connected to a communication interface, the memory storing instructions which, when executed by such a processor, enable the implementation of the processes, devices, modules, systems, procedures, or methods described in this document.
[0043] Some terms specific to service systems and communication networks are now clarified for a better understanding of the proposed technique.
[0044] The term "service system" refers, in the context of this document, to a physical and / or software medium that enables communication and the sharing of resources and services within a communication network. This system may refer to a communication infrastructure or one or more of its sub-components, including data processing and storage systems, servers and networks, data centers, cloud systems, telecommunications equipment, etc. This system may also refer to a communication infrastructure within a specific organization, such as an internal network of computers and servers, or to a broader infrastructure, such as a network of telecommunications or a cloud. The proposed technique is applicable to any type of service system and any type of network architecture.
[0045] A service system comprises a set of resources that can be reserved for the operation of one or more services. This set of resources may include resources of various types, including computation time at the level of one or more processors, locations in one or more memories, or usage slots, expressed for example in time and / or frequency, of one or more communication channels.
[0046] A service system can be extended across multiple sites and benefit from the efficiency of a multi-site architecture. Such architectures are well established and enhance robustness and resource management across the entire service system. Distributed architectures at Tedge represent a further development that is particularly relevant for telecommunications systems such as Cloud-RANs, where they are currently being deployed.
[0047] Cloud computing environments rely on one or more service systems as defined above.
[0048] In cloud computing environments, the basic hosting unit is often called a "container". These containers are lightweight software units that encapsulate code and all its dependencies, thus allowing a service to run reliably from one computing environment to another.
[0049] For managing these containers, a solution called Kubernetes, K8S, is frequently used. Kubernetes is a system that facilitates the deployment, scaling, and management of containerized services.
[0050] In the Kubernetes architecture, containers are grouped into "pods," which constitute the basic unit representing a service deployment. Several pods can be grouped into a "node," which symbolizes a server. The definition of "node" in the Kubernetes architecture corresponds to that of "node" in the NUMA system. These nodes are then grouped into "clusters," which are sets of servers that work together and can be perceived as a single system.
[0051] In the context of Kubernetes, a cluster consists of a group of "Masters" and Nodes. Masters are the components of the Kubernetes cluster that provide the control interface or control plane for the cluster, and that manage pod scheduling, failure detection and handling, and the deployment of new application versions. Nodes, on the other hand, are the servers that run the applications and provide the runtime environment for the containers.
[0052] To manage network communications between containers of an application deployed on a Kubernetes cluster, auxiliary containers, known as "sidecar proxies," are attached to each primary container of the application. The sidecar proxies are responsible for intercepting and managing network communications. Each sidecar proxy acts as an intermediary between the primary container to which it is attached and the rest of the network. To enhance security, sidecar proxies can include features such as request and response validation, permission and identity management, and monitoring.
[0053] ISTIO is an example of an open source service mesh, commonly used by networking and security operators for running distributed microservices-based applications, and which provides a uniform way to connect, manage and secure these microservices using sidecar proxies.
[0054] ISTIOD is a central driver for ISTIO, which serves as a control point for configuring sidecar proxies. It is suitable for managing routing rules, communication and operations management policies between services, and service configurations. ISTIOD intervenes in event detection by applying a management policy and observing communications between microservices.
[0055] KIALI is a visualization tool for ISTIO that allows for the visual identification of anomalies or unusual behavior patterns in communications between microservices. KIALI thus facilitates the detection of events related to potential security problems.
[0056] JAEGER is a distributed traceability system that collects information on communications between microservices to enable detailed analysis of latency, performance, and errors. JAEGER thus facilitates the detection of events related to performance problems or failures.
[0057] The proposed technique is particularly suited to microservices architectures, such as containers and virtual network functions. These are commonly used in telecommunications systems and cloud-based computing environments.
[0058] It is present refers to [Fig.1], which represents a possible example of algorithm and functional organization allowing the implementation of the proposed technique at the level of a service system in a communication network.
[0059] According to a first possible branch of the algorithm, it is planned to include: a module 1 for defining and updating a management policy, a module 2 for deploying the management policy, a module 3 for modifying routing for traffic affected by the management policy and / or by monitoring, a module 4 for updating topology information, and a module 5 for updating routing information.
[0060] Module 1, which defines and updates the management policy, is configured to establish and / or revise a traffic management policy within the network. This policy may relate to optimizing one or more needs, for example, security, performance, or availability. Module 1 can define rules that determine how other modules should manage and direct traffic. Module 1 can further stipulate that a given rule be applied differently by entity (for example, a service, a client, a macro-function) or group of entities, for example, according to the respective criticality levels of the entity or group of entities concerned.
[0061] The management policy deployment module 2 is configured to deploy the policy established or updated by module 1 in the network so that it is applied in real time.
[0062] The routing modification module 3 is configured to enforce the management policy by modifying, as appropriate, one or more routes that traffic must follow through the network. This can include activating security features based on various triggers such as changes in traffic volume, specific user-defined priorities, or quality of service criteria (e.g., predefined ones). For example, a sudden increase in traffic volume or a request for a high service priority can conditionally activate firewalls or intrusion detection systems to proactively enhance security within the network. The conditional activation of these security features therefore does not require prior detection of a specific event.By "specific event," we mean incidents such as a detected intrusion attempt, a security alert generated by a monitoring system, or a reported hardware failure. Thus, triggers can include scenarios such as: an increase in bandwidth demand due to a planned event (e.g., a live stream), a network reconfiguration to optimize performance during peak hours, the application of enhanced security policies for critical network segments, or adjusting routing to maintain quality of service during updates or maintenance of certain parts of the network.
[0063] Module 4, the topology information update module, is configured to maintain and update the network map. This updating contributes to optimized routing and efficient distribution of system service resources. The Module 4 can be configured to update topology information according to a schedule differentiated by service, flow, or client, based on the criticality of the service, flow, or client in question. In addition to the conditional routing modification implemented by Module 3, Module 4 can be configured to implement a conditional update of network entry points to strengthen corresponding network access.
[0064] Routing information update module 5 is configured to ensure that information on traffic routes and / or paths within the network is continuously updated, thereby helping to increase responsiveness to any adjustments in management policy, updates to the new network architecture including, for example, service removals and / or new deployments, or the implementation of cleanup operations for the purpose of optimizing service system resources. For example, responsiveness can be immediate or near-immediate.
[0065] Modules 1 to 5 interact in a cycle materialized on [Fig.1] by arrows b, c, d, e and g.
[0066] Arrow b represents the transfer of the traffic management policy defined or updated by Module 1 to Module 2. This arrow symbolizes the transmission of complete directives and rules that must be deployed in the network. This includes all changes to traffic management, security, and performance, as well as specifications on how the policy should be applied according to different criticality levels of the entities concerned.
[0067] Arrow c transmits the deployment instructions for the management policy from module 2 to module 3. This includes specific directives on the routing changes needed to apply the management policy in the network, including the conditional activation of security functions or other measures without the presence of a specific trigger.
[0068] Arrow d carries information relating to routing changes made by module 3 to module 4. It allows communication of adjustments or new route configurations which require an update in the network map so that module 4 can update and optimize the network topology accordingly.
[0069] Arrow e carries the updated topology information from module 4 to module 5. It serves to inform the routing information update module of the latest changes to the network topology, thus allowing these changes to be reflected in the current traffic routes to maintain network efficiency.
[0070] Arrow g represents the feedback from module 5 to module 1. This feedback includes data on the current routing efficiency and any other indicators This relevant feedback could influence future traffic management policy. It allows Module 1 to reassess and refine the existing policy to better meet the network's evolving needs.
[0071] The first branch of the algorithm in [Fig.1] allows a functionality to be added dynamically to a pre-existing flow; it can be applied in various usage contexts.
[0072] For example, for the purpose of dynamically managing network capacity, it allows the use of a traffic management policy to automatically adjust network routing and capacity. This is done by implementing intermediate functions based on fluctuating demand, thus ensuring optimal performance without human intervention.
[0073] For example, for the purpose of proactively responding to a vulnerability, it allows security functions, such as firewalls or intrusion detection systems, to be conditionally activated based on a continuously revised security policy to counter emerging threats before an attack occurs.
[0074] For example, with the aim of improving (e.g. optimizing) the user experience for critical applications, it allows for routing adjustment by implementing intermediate functions to help improve the quality of service for latency-sensitive applications, such as VoIP or video streaming services, by reducing delays and limiting (e.g. avoiding) network congestion.
[0075] In a second possible branch of the algorithm, and in addition to modules 1, 3, 4 and 5 described above, a traffic monitoring module II is planned, and Module III for deploying an intermediate service.
[0076] It may also be provided, prior to the implementation of module III, for an additional module for the provisional implementation of an infrastructure supporting said intermediate service, in order to strengthen the responsiveness of the algorithm.
[0077] The traffic monitoring module II is configured to continuously monitor network traffic, i.e., regularly and without interruption, with inspection frequencies and methods that can vary depending on specific network needs and / or specific service system management objectives. For example, certain types of traffic or network segments (e.g., more critical ones) may be scheduled for more intensive monitoring. This monitoring may include, for example, one or more of the following monitoring methods: exhaustive inspection of each data packet originating from the first service, or of each packet circulating between the first and second services, a random inspection of data packets originating from the first service, or of packets circulating between the first and second services, periodic inspection of data packets originating from the first service, or of packets circulating between the first and second services, at regular intervals; collection of network performance metrics such as traffic volume, error rate, or latency, coupled with analysis of these metrics over a sufficiently long period to identify unusual trends or sudden jumps or drops in traffic volume that could indicate security or performance issues; the use of anomaly detection algorithms that evaluate data continuously collected by proxies to identify suspicious behavior as deviations from behaviors ("normal") as defined by the management policy; suspicious behavior could, for example, refer to a sequence of requests that does not correspond to a normal usage profile or a high rate of errors or abnormal responses detected by the proxies, monitoring based on specific events, or predefined triggers, such as security alerts, network configuration changes, or cyberattack signatures by applying the management policy. These monitoring methods are complementary and can potentially be used together.
[0078] An example of an attack detection algorithm that can be implemented by a WASM module might include detecting a user associated with a given traffic, then implementing one or more filtering rules based on user authentication, and finally analyzing the frames of the given traffic. Such an algorithm makes it possible to analyze the given traffic according to several criteria reflecting a specific attack signature, for example, a traffic origin, a traffic destination, a traffic destination port, a variation in traffic rate, etc.
[0079] It can, for example, use advanced sensors and algorithms to collect metrics or indicators to evaluate in real time traffic patterns in terms of, for example, security, performance of deployed services, resource utilization rates and / or energy consumption, detect deviations from a standard that could indicate security risks and / or failures, and / or generate alerts based on the deviations detected.
[0080] The intermediate service deployment module III is configured to react to alerts generated by module II by rapidly deploying one or more intermediate services to inspect, filter, and / or modify traffic in order to manage detected threats. This module allows specific action to be taken on data flows deemed risky without disrupting the entire network. For example, it can It is expected that module III will deploy the intermediate service on specifically identified and / or selected cloud resources, for example, one or more pods, nodes or clusters.
[0081] Modules 1, II, III, 3, 4 and 5 interact in a cycle materialized on [Fig.1] by arrows a', b', d, e and g, which represents an implementation of a countermeasure to an attack detection based on a control plan of the service system.
[0082] Arrow a' represents the transfer of the traffic management policy defined or updated by Module 1 to Module IL. This arrow, like arrow b described previously, symbolizes the transmission of complete directives and rules that must be deployed in the network. This includes directives relating to traffic monitoring by Module II and may, in particular, include values (used, for example, as thresholds) or standards as references against which to compare the collected metrics or indicators relating to current traffic.
[0083] Arrow b' represents the transmission of security alerts and notifications of abnormal or undesirable behavior detected by Module II to Module III. These alerts trigger the deployment of intermediate services to address or mitigate identified risks, as well as routing modifications by Module 3 to direct all or part of the traffic affected by these identified risks to these intermediate services.
[0084] Arrows d, e and g perform the same functions as those previously described with respect to the first branch, namely the transfer of routing update information, topology and feedback to enable continuous management and / or reassessment of the management policy.
[0085] The second branch of the algorithm in [Fig.1] allows for interception and so-called "strong" processing of a pre-existing stream; it can be applied in various usage contexts.
[0086] For example, for the purpose of rapid detection and intervention in the event of a cyberattack, it makes it possible to detect an intrusion attempt or malicious traffic in real time and to automatically deploy security functions (for example by encrypting the data involved and / or protecting and / or isolating the application concerned) to inspect and neutralize the attack before it reaches critical assets.
[0087] For example, for the purpose of managing traffic anomalies in networks involving connected objects, it allows specifically monitoring of connected objects to detect abnormal behaviors that could indicate a compromised connected object, and, if necessary, to intervene immediately (or almost immediately) to secure the data and connected objects concerned.
[0088] For example, for the purpose of dynamically controlling applications in a hybrid cloud environment, it allows, in the event of detection of an abnormally high or suspicious workload in the cloud, to automatically isolate the application concerned and redirect traffic to more secure resources for further examination, thus ensuring the continuity and security of operations.
[0089] It is present refers to [Fig. 2], which represents a possible example of a control plane architecture enabling the implementation of the proposed technique in a communication network at the level of a service system. Generally, a suitable control plane includes at least a manager, an orchestrator, and a service mesh (in this case, ISTIO in the illustrated example).
[0090] In the service system, any network traffic is successively routed to a plurality of services according to the principle of a service chaining.
[0091] In [Fig.2], an example of network traffic is symbolized as being first routed to a first service 10 and then to a second service 12.
[0092] Sidecar proxies 11, 13 are configured respectively for each service 10, 12. These proxies route traffic through the service system. Thus, in the example considered, incoming traffic is first directed to the proxy 11 of the first service 10, then routed, by this proxy 11, in the form of a communication 100, to the proxy 13 of the second service 12.
[0093] The proxies are managed centrally by an ISTIOD 20 module, which itself can use, at least as a decision-making aid, a KIALI 21 module and / or a JAEGER 22 module. The KIALI 21 module allows visualization of the impact and extent of a detected event (for example, an attack) on the entire service system, thus facilitating rapid decision-making regarding routing and / or topology modifications. The JAEGER 22 module allows tracing the request path through the different microservices, which makes it easy to analyze the impact of recent routing and / or topology changes on the operation of the service system and to identify potential points of failure or bottlenecks, thus facilitating decision-making regarding corrective actions.
[0094] The ISTIOD module 20 is interfaced with a service system orchestrator 40 and / or a service system manager (not shown) via a dedicated module or plugin 30, the implementation and / or updating of which is, for example, carried out by the management policy deployment module 2. For example, module 30 could be a WebAssembly (WASM) module. WebAssembly is a binary format and a low-level language designed to run in web browsers. It allows the execution of complex and high-performance web applications, offering an alternative to traditional programming languages such as JavaScript. WebAssembly is also used outside of web browsers, particularly in the terminal environment. It allows applications and software to run securely and portablely on various types of devices, such as smartphones, tablets, desktops, servers, and more. WebAssembly offers high performance and cross-platform compatibility, making it an attractive choice for terminal application development.
[0095] Traffic data passing through proxies 11, 13 can thus be analyzed by module 30 to detect attack signatures, such as traffic anomalies, suspicious access patterns, or malware signatures. Module 30 can be configured to react to specific criteria applicable to a given traffic stream, or to all traffic associated with a given client, service, criticality level, etc., or to all traffic within the service system. Examples of specific criteria include throughput thresholds, request types, or user behavior.
[0096] When an event (such as a potential attack) is detected by module 30, it may be expected that the orchestrator 40 and / or the service system manager will be instructed to dynamically modify the routing to isolate or redirect traffic to specialized services, such as a "clinic" service, for further cleaning and / or inspection of the traffic. This may include redirection through secure paths or services that provide additional cleaning and / or authentication functions. For example, establishing a secure path to an intermediate service may involve an exchange of TLS certificates.
[0097] The intermediate service can be implemented by a service provider. It can also be designed to notify the service provider, and more generally any relevant entity—for example, a certificate authority or any other relevant entity in the control plane, clients of one or more applications affected by the detected event, etc.—of an indicative alert about the detected event. After analyzing the alert and / or the traffic redirected to the intermediate service, the service provider can select one or more appropriate functions from a library of functions that the intermediate service can perform. The intermediate function can be provided, for example, as ad hoc WASM code, which can optionally be generated on the fly by the service provider, or as a cloud resource, such as a pod, hosting such code.
[0098] Fig. 3 illustrates an example of setting up indirect communication between the first service 10 and the second service 12 via an intermediate service 14 acting as a partial repair service for the traffic initially diverted from the first service to the second service.
[0099] In the example of [Fig.3], the initial direct communication 100 between the respective proxies 11, 13 of the first and second services remains active for part of the traffic initially routed from the first service to the second service via said direct communication (for example, traffic considered not indicative of an attack), while the remaining part of the traffic (for example, traffic considered indicative of a potential attack) is diverted to the intermediate service 14.
[0100] Indirect communication includes: an initial communication 200 between the proxy 11 of the first service and the proxy of the intermediate service 14 followed by an internal communication 300 within intermediate service 14 to a so-called "clinical" module ensuring an inspection and / or repair function for the traffic received by intermediate service 14 and of a second 400 communication between the proxy of the intermediate service and the proxy 13 of the second service.
[0101] The implementation of indirect communication can be carried out in two stages. First, the initial 200 communication and the second 400 communication can be prepared; that is, the corresponding routes can be defined at the control plane level of the service system without being immediately used to carry any traffic. Then, in a second stage, the prepared routes can be activated; that is, used to direct traffic from proxy 11 of the first service to the proxy of the intermediate service 14, and then from the proxy of the intermediate service 14 to the proxy 13 of the second service. Route activation can be performed according to a weighting setting.For example, before activation, a weight of 1 can be assigned to the route corresponding to the direct communication 100, while a weight of 0 can be assigned to the route corresponding to the first communication 200, so that all traffic handled by the first service is directly routed to the second service. Activating indirect communication can involve assigning a weight "x", such as 1 > x > 0, to the route corresponding to the first communication 200 and a concurrent assignment of a weight "1-x" to the route corresponding to the direct communication 100. Thus, depending on the chosen value of "x", all or part of the traffic handled by the first service is directly routed to the intermediate service.
[0102] Fig. 4 illustrates another example of setting up indirect communication between the first service 10 and the second service 12 via an intermediate service 14.
[0103] In the example in [Fig.4], direct communication 100 is deactivated and replaced by: the first communication 200 between proxy 11 of the first service and proxy 15 of the intermediate service 14 the second communication 300 between proxy 15 of the intermediate service and proxy 13 of the second service. Industrial application
[0104] These technical solutions may be applicable to operators and companies wishing to strengthen the security of their applications and services operating in container-based and microservices environments.
[0105] In particular, they can be adapted, at least in certain embodiments, for the management of service systems within cloud computing environments, whether private or hybrid, combining private and public elements.
[0106] They can, at least in certain embodiments, contribute to the protection of databases, whose access points often constitute vulnerabilities (and sometimes even play a key role in this protection). Although these databases are located in highly secure locations, access to them is frequently via infrastructures shared between private and public domains, which can present risks.
[0107] These solutions can in particular be adapted, at least in certain embodiments, to various cluster configurations, whether located on a single site or distributed over several sites and managed by different actors, as in the case of Cloud-RAN configurations.
[0108] Application examples may relate to a wide variety of systems and infrastructures, for example clusters operated by multiple actors, distributed over different geographical areas, and extended over several data centers, or a main cluster with replicas distributed over several data centers, or even multi-actor and multi-area clusters connecting satellites to terrestrial data centers.
[0109] This disclosure is not limited to the examples described above, which are merely examples, but encompasses all the variations that a person skilled in the art may consider in the context of the protection sought.
Claims
Demands
1. A method for dynamically modifying routing in a service system of a communication network, the method comprising, during a direct, active communication between a first service and a second service: a conditional implementation of an indirect communication between said services passing through an intermediate service.
2. A method according to claim 1, wherein said conditional implementation takes into account a service system management policy.
3. A method according to any one of the preceding claims, wherein said conditional implementation takes into account monitoring of traffic within the communication network.
4. A method according to any one of the preceding claims, wherein the intermediate service acts as a repair service at least partially for traffic originating from the first service.
5. A method according to any one of the preceding claims, wherein the intermediate service is selected from a plurality of services during said conditional setup.
6. A method according to the preceding claim, wherein the intermediate service is selected based on at least one selection criterion from among: a required level of security, a required level of performance, a type of traffic using indirect communication, a regulatory requirement, a combination of at least two of the above criteria.
7. A method according to any one of the preceding claims, implemented by a WASM (WebAssembly) module.
8. A method according to any one of the preceding claims, implemented in a container environment.
9. A method according to any one of the preceding claims, wherein the intermediate service is dynamically deployed during said conditional setup.
10. A method according to any one of the preceding claims, comprising, when establishing indirect communication, abandoning direct communication.
11. A method according to any one of the preceding claims, comprising, after the implementation of indirect communication, a conditional abandonment of indirect communication.
12. A method according to any one of the preceding claims, comprising applying an authentication and / or filtering overlay to indirect communication.
13. Dynamic routing modification module in a service system of a communication network, the module being configured to, during direct, active communication between a first service and a second service: a conditional setting up of indirect communication between said services passing through an intermediate service.
Citation Information
Patent Citations
Cloud native software-defined network architecture for multiple clusters
EP4160409A1
Method for implementing a service in a service chain and electronic device associated thereto
US20240129135A1