Method and device for managing communication

The method addresses the limitations of existing observability solutions in cloud-native xG networks by using an external agent to non-intrusively monitor and correlate data from encrypted protocols, enhancing network management and reducing latency.

FR3167026A3Pending Publication Date: 2026-04-03ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2024-10-02
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing communication network architectures, particularly in cloud-native xG systems, face challenges in observing and managing network functions due to the interdependence of microservices in containers, leading to performance unpredictability, increased latency, and difficulty in correlating encrypted protocols, which are not adequately addressed by current observability solutions.

Method used

A non-intrusive method using an external agent with an observation program, such as eBPF, selects and correlates data from cloud-native applications, including encrypted protocols, to provide end-to-end visibility and monitoring without modifying the software applications, leveraging context parameters and user libraries to enrich network management metrics.

Benefits of technology

Enables comprehensive, non-intrusive monitoring of cloud-native xG networks by correlating data from different software applications and protocols, improving performance management and reducing latency, while maintaining application integrity and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method and Device for Managing Communication The invention relates to a method for managing communication applied to at least one software application (MS1) of a cellular core network, said at least one software application (MS1) being deployed in a cloud computing environment, said method being implemented by an external agent (Agt) to the software application (MS1) and comprising: Associating an observation program instantiated on an environment of the at least one software application, Selecting data associated with the communication by means of a context parameter relating to the environment, from a set of data examined by means of the observation program associated with the at least one software application. Abstract Figure: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method and device for managing communication technical field

[0001] This disclosure falls within the general field of communications, the flows of which are routed in a virtualized architecture. By way of example, such an invention can be instantiated in a cloud computing context. More specifically, the invention aims to implement an end-to-end data flow observability solution, i.e., an enhanced monitoring solution, so as to enrich network management metrics without affecting the services offered from the cloud infrastructure. Prior art

[0002] Communication network architectures increasingly rely on cloud infrastructures in which network services and functions are instantiated on virtual machines and, even more commonly, in containers. Network services and functions are thus structured as microservices in a so-called cloud-native architecture. This cloud-native architecture, in which a microservice contributing to an application service or network function is instantiated in a container, enables faster service deployment, easier infrastructure scalability, and simplified enhancement, modification, or reconfiguration of an existing service or function.

[0003] In a specific case of deploying an xG system (e.g., 5G) to provide an xG service, the functions (e.g., addressing, routing, security, etc.) contributing to the implementation of this xG service are increasingly instantiated in a cloud-native architecture. These functions, also called Cloud Native Network Functions (CNFs), deployed in this type of architecture must be manageable and monitorable. This observability, which consists of collecting a set of data to deduce the state or behavior of an xG system, must be based on data specific to the cloud technologies used, as well as on data from the protocols used by the network functions of the xG system.

[0004] Prior art techniques used in these cloud-native infrastructures involve the use of observability solutions for cloud-native applications, which focus on collecting three types of data: metrics, logs, and distributed traces. These solutions can be intrusive, requiring instrumentation of the observed object (e.g., the application or infrastructure) and a modification of the code of the observed functions, or non-intrusive ones, not requiring modification of the code of the observed network functions. Furthermore, so-called traditional solutions used for managing telecommunications networks, such as traffic / port mirroring solutions that replicate application data, are also not relevant in a natively cloud-based architecture designed to enable more dynamic and denser services.

[0005] These techniques, used independently of the application or applications for which the microservices are instantiated in containers, present some limitations in the context of an xG network deployment based on these technologies.

[0006] In particular, these techniques do not specifically address the protocols used for the operation of the xG core network, including, but not limited to, the NGAP (Next Generation Application Protocol), PFCP (Packet Forwarding Control Protocol), GTP-U (User Plane GPRS Tunneling Protocol), and generically the protocols relating to NAS (Non Access Stratum) access. Even when these protocols are possibly observable, as described in document https: / / ieeexplore.ieee.org / document / !0154433, for example, this solution does not allow the observation of encrypted protocols or the correlation of observed information on each of the observed protocols, and for example, the observation of end-to-end traffic, whether that traffic is encrypted or unencrypted.

[0007] The implementation of microservices in xG system architectures can lead to increased sensitivity to performance unpredictability due to the interdependence of network functions instantiated in containers. Existing solutions can also introduce additional latency and processing overhead, which can degrade the user experience.

[0008] The high density and dynamism of services in a cloud-native xG infrastructure make manual examination of interactions within the system both time-consuming and error-prone, as well as correlation between analyses performed on different functions, difficult. Effective observability of the network, associated protocols, and a deeper understanding of interactions between protocol data is necessary to manage this complexity.

[0009] The present invention aims to provide improvements over the prior art. Summary of the invention

[0010] The purpose of this disclosure is to remedy all or part of the limitations of prior art solutions, in particular those described above, by proposing a This solution enables non-intrusive observation of data related to communication protocols on an xG network, including encrypted protocols, relying on a cloud computing infrastructure, in addition to data specific to that infrastructure. The solution aims to generate distributed traces, logs, and metrics, including for encrypted protocols, to provide complete visibility into the operation of the network and the underlying infrastructure, and in particular to allow end-to-end observation of a service or application.

[0011] To this end, a method is proposed for managing instantiated communication by means of at least one software application of a cellular core network, said at least one software application being deployed in a cloud computing environment, said method being implemented by an external agent (Agt) to the software application (MSI) and comprising: - Activate an observation program instantiated on an environment of at least one software application, - Select a data associated with the communication by means of an environment-related context parameter, from a set of data examined by means of the observation program activated on at least one software application.

[0012] The management process thus makes it possible to select data and potentially propagate the context of exchanges in the form of identifiers within messages exchanged between software applications or obtained from user libraries of the software applications in order to generate traces. These traces make it possible, in particular, to observe the dependencies between incoming and outgoing communications at the level of each software application and to have end-to-end visibility of a service, an application, or a user communication by selecting only the data specific to the context for which the selection is made. The information in a library can correspond to files, functions, scripts, and routines that can be referenced and executed by the software applications to implement a specific function for a particular need or a specific context.Obtaining such data, for example in addition to communication protocol data, allows for enhanced monitoring of an application, service, or user communication, thereby enabling the resolution of problems, the anticipation of future issues, and system administration, for example, by adding, removing, or replacing system software applications. A context parameter is therefore potentially associated with these files, functions, scripts, and routines of the software application.

[0013] The management process thus makes it possible to specifically select packets, messages or datagrams from one or more protocols of a network Cellular, for example, 5G. Using an external agent, for example, composed of a core agent and a user agent, to the software application, which can be specific to trace analysis, allows the software application's capabilities to be preserved for the service for which it was deployed. This method makes it possible to obtain data transmitted over a communication interface of the software application and / or in a user library of the software application, and to select context-specific data in order to observe end-to-end communication.Current state-of-the-art solutions allow for the observation of data specific to a software application, but they do not allow for the aggregation or correlation of data potentially originating from distinct software applications based on an application and / or user context and / or an operator's routing context (for example, a network slice). The software application may be a microservice contributing to the implementation of a network function, or it may be the network function itself. The computing, transmission, or management capabilities of the software application are therefore not used to identify and select data specific to a communication context within a cellular core network.This method allows for the distribution of an observation program, for example, in one or more containers, its activation on demand, and its ability to correlate data from different software applications without degrading their performance. Furthermore, because the agent is external to the software application, it is application-agnostic and can be used with software applications from different manufacturers or vendors. In addition, since the observation program is associated with the software application's environment—that is, activated (i.e., launched or executed) within the application—it can obtain data exchanged by the application as well as data stored by the application, for example, in user libraries, thus enabling the retrieval of this data prior to encryption.For example, the program instantiation can take place in the kernel agent while the association is performed by the user agent of the external agent.

[0014] The method makes it possible to analyze selected network exchanges in order to extract relevant information and to generate metrics and logs tracking the behavior and proper functioning of the cellular network, for example of the 5G type, and its components.

[0015] There are no limits to the cellular network protocols analyzed or observed as long as the data can be effectively identified and selected by the external agent. In particular, the external agent, through the observation program, It can select data, for example, to generate monitoring data, such as telemetry data related to NGAP, PFCP and GTP-U protocols, HTTP / 2 and more generally to NAS link protocols, as well as data related to the software application library that is crucial for session management, signaling and transport of user data in a 5G network. This monitoring data can be metrics, logs or distributed traces.

[0016] According to an example, the management process can, for example, select data from an environment comprising a session management protocol of a terminal connected to the cellular network, or a signaling or data transport protocol associated with a terminal connected to the cellular network.

[0017] According to one aspect of the invention, the management process observation program is an extended Berkeley Packet Filter program.

[0018] Preferably, eBPF (extended Berkeley Packet Filter) technology can be used as an observation program. This widely used observability technology does not require modifying the source code of a software application to be observed and analyzed.

[0019] According to another aspect, the external agent of the management process is previously instantiated in the cloud computing environment which also includes the software application.

[0020] The external agent, for example consisting of a kernel agent and a user agent, can advantageously be installed in a container within the cloud computing environment. For example, in the case of a Kubemetes environment, the external agent can thus be distributed across one or more containers in a cluster, facilitating interactions with the software application also installed in the container and thereby allowing for a wider distribution of external agents within the environment. The external agent hosting the observation program is thus located close to the software application without degrading its performance. The external agent can be specific to the need, for example, to obtain context-specific data and possibly modify the data by adding a context identifier to subsequently facilitate the correlation of the different data points.

[0021] According to another aspect of the management process, the dataset being examined is encrypted and the observation program is adapted to select data from the encrypted dataset.

[0022] The management process can advantageously select encrypted data, particularly by leveraging access to user libraries, thus relieving the agent of the need to hold encryption keys since the data is obtained from the libraries before encryption and / or after decryption. Another option for Selecting encrypted data involves scrutinizing encrypted traffic at the software application interfaces using a decryption key associated with the key used to encrypt the data.

[0023] According to another aspect of the management process, the context parameter is configured by the external agent based on information relating to an application and / or a user and / or routing information present in a message relating to the environment of said software application.

[0024] The management process may advantageously include configuring the context parameter based on information it has determined from the activated program. Thus, if the objective is to have an end-to-end view of an application, a user communication, or the routing of a message, the external agent can configure the context parameter based on information transmitted in a communication protocol. For example, it can identify information such as the PID (process identifier), Thread ID (thread identifier), Socket ID (socket identifier), and transport layer information (IP address pair and port number pair).From one or more of these identifiers, and other potentially usable information, a context parameter can be generated and possibly propagated in messages, for example, in specific fields of the protocols implemented in the network. For HTTP / 2, standardized fields called "headers" are used, for example. For other 5G protocols (particularly PFCP and NGAP), the context parameter is propagated in standardized fields called "Information Elements" (IE), allowing an entity to then correlate different messages and information based on this context parameter. Specifically, the context parameter can consist of information relating to an application.

[0025] According to another aspect, the management process may further include the generation of a control message established from the selected data and issued to an observability entity.

[0026] In order to monitor end-to-end communication or a service, the external agent can generate a control message that it transmits to a tracing or observability entity, enabling the latter to be specifically informed of events related to the communication or service based on information selected from different protocols and various software applications. The control message can thus be specific to trace analysis and include data selected by an agent for use by an analysis and / or correlation entity.

[0027] According to another aspect, the environment includes a communication interface for at least one software application and / or a library associated with the software application.

[0028] The messages exchanged on a communication interface alone may not be sufficient to observe an application or end-to-end communication. In particular, when communication protocols are encrypted, it is advantageous to be able to obtain information from user libraries and thus access data before or after encryption. If only the exchanged messages were used, the external agent would, for example, need to possess a decryption key associated with the encryption key used to encrypt the message, which is difficult to envision. Even if possible, this solution poses a security problem related to the dissemination of such decryption keys. Obtaining data from libraries can also enrich the analysis of end-to-end communication.

[0029] According to another aspect, the management process further includes a selection of at least one second data associated with the communication by means of a context parameter relating to an environment of at least one second software application, from a set of data examined by means of the activation program associated with at least one second software application.

[0030] The method may advantageously include the selection of multiple data possibly associated with distinct software applications and obtained from communication protocols on distinct communication interfaces and / or libraries. Thus, it becomes possible to select and correlate distinct data from different protocols and different software applications, but sharing the same context (user, application, network slice), allowing end-to-end traffic observation by selecting data from software applications contributing to the routing and processing of data sharing this context.

[0031] According to another aspect of the management process, the software application of the management process is a microservice of a piece of equipment in the cellular network core.

[0032] The software application may correspond to a component of a network function, such as a microservice, or to the network function itself. The software application may thus correspond to any function or component of a function instantiated in software form and interfacing with other components using a cellular network protocol.

[0033] According to another aspect of the management process, the selected data is transmitted to a cellular network management entity communicating with the external agent for aggregation and use for the management of the cellular core network.

[0034] The selection of data specific to a user or application or operator context can advantageously be transmitted, for example via a specific protocol or by inserting it into an existing protocol, to an observability entity which will be able to aggregate the data specific to the context and thus use it to administer, control and possibly modify the cellular communication network.

[0035] According to another aspect of the management process, the context parameter is extracted from a header or data of a communication protocol of the cellular core network.

[0036] In particular, where the environment includes a communication interface, the context parameter can be extracted from a communication protocol carried on the communication interface. This can be information from the protocol header or information from a data field of the protocol.

[0037] According to another aspect, the management process further includes a selection of data representative of a consumption of a resource of the software application and of the hosting entity in which the software application is instantiated in the cloud computing environment.

[0038] Data relating to protocols specific to a cellular network may not be sufficient to identify a malfunction in a computing environment used to deploy a cellular core network. Selecting data relating to the operation of the software application, regardless of the service to which it contributes, and to the entity hosting the software application, for example, a container, can complement the selected protocol-specific data, particularly to improve the understanding of a cause of malfunction in a cellular network. Data representative of the hosting entity includes, in particular, data specific to the virtual machines hosting the containers, as well as the physical server hosting the virtual machine hosting the containers. Indeed, hosting-specific data can be used to analyze an anomaly, both reactively and / or proactively.

[0039] The different aspects of the management process that have just been described can be implemented independently of each other or in combination with each other.

[0040] The invention further relates to a device for managing instantiated communication by means of at least one software application of a cellular network core, said at least one software application being deployed in a cloud computing environment, said device comprising a processor coupled to a memory in which program instructions are stored for execution by the processor to activate an observation program. instantiated on an environment of at least one software application, and select a data associated with the communication by means of a context parameter relating to the environment, from a set of data examined by means of the observation program activated on at least one software application.

[0041] According to one aspect, the management device is further adapted to send to an observability entity a message developed from the selected data.

[0042] According to another aspect, the device is adapted to configure the context parameter to be added to a message transmitted to a software application.

[0043] This management device is adapted to implement in all its modes of embodiment the management process which has just been described.

[0044] The invention also relates to a computer program product comprising a set of program code instructions which, when executed by at least one processor, configure said at least one processor to implement the management process according to any one of the implementation modes of this disclosure.

[0045] The invention also relates to a computer-readable recording medium on which is recorded a set of program code instructions which, when executed by at least one processor, configure said at least one processor to implement the management process according to any one of the implementation modes of this disclosure. Brief description of the drawings

[0046] The invention will be better understood upon reading the following description, given by way of non-limiting example, and made with reference to the figures which represent: - [Fig. 1] Fig. 1 illustrates a schematic representation of a 5G communication network (also called a system) deployed in a Kubemetes-type cloud computing environment according to a particular embodiment, - [Fig.2] Fig.2 illustrates a schematic representation of a 5G communication network (also called a system) deployed in a Kubemetes-type cloud computing environment according to another specific embodiment, - [Fig.3] [Fig.3] illustrates a representation of a selection device according to an example, - [Fig.4] [Fig.4] illustrates the main steps of a management process applied to a communication interface of a software application, according to a particular embodiment of the proposed technique.

[0047] In these figures, identical reference numerals from one figure to another designate identical or analogous elements. For clarity, the elements shown are not to scale unless otherwise stated. Description of the implementation methods

[0048] More generally, it should be noted that the implementation and realization methods considered above have been described as non-limiting examples, and that other variants are therefore conceivable.

[0049] In the following description, embodiments relating to the deployment of a 5G type cellular network or system are presented, but these embodiments are completely transposable to communication networks of different types.

[0050] Reference is first made to [Fig. 1], which presents a Kubemetes-type cloud infrastructure from which a 5G cellular network is deployed. This 5G cellular network is instantiated by a set of MSI, MS2, MS3, MS4, MS5, and MS6 microservices implemented in a container cluster comprising, in this embodiment, two containers identified by the execution environments Env Exec Cont 1 of the first container and Env Exec Cont 2 of the second container, sharing the same operating system. The cluster could comprise a single container or multiple containers without any limit on the number.

[0051] This environment thus includes a centralized CTRL controller for the cluster responsible for discovering the microservices involved in instantiating the network functions of the 5G cellular network and for collecting metadata relating to these network functions. The network functions of the 5G cellular network are the network functions that enable the proper functioning of the network, including the AMF (Access and Mobility Management Function), SMF (Session Management Function), UPF (User Plane Function), and PCF (Policy Control Function). This CTRL controller interacts with the API serv function, for APIserver, which represents a cluster management interface and a server responsible for the interaction between the cluster and entities external to the cluster.

[0052] The system thus consists of a centralized CTRL controller and an external Agt agent (comprising a Kernel agent and a Util (user) agent). The centralized CTRL controller is responsible for discovering the MSI, MS2, and MS3 software applications and collecting their metadata. For discovery, the CTRL controller collects metadata related to the deployment environment, including information related to component names, the IP addresses of network interfaces INT1, ..., INT4, details on the communication protocols used, and information on LIB1 libraries (or other libraries related to the MS2 and MS3 applications (not shown in [Fig. 1]) used for encryption or encoding / decoding of network messages, as well as information about replica sets that manage multiple instances of the same application. This metadata is essential for correctly configuring distributed Agt agents and for ensuring accurate and detailed monitoring of M1, MS2, and MS3 network functions.

[0053] The operation of the 5G cellular network relies on the microservices MSI, MS2, MS3, MS4, MS5, and MS6. A network function is characterized by the instantiation of one or more microservices and the interaction of these microservices through communication interfaces on which communication protocols are activated. Thus, for example, the PCF network function is instantiated from the MSI microservice associated with a communication interface INT1. This PCF interacts, for example, with an SMF function, represented by a set of MS2 and MS3 microservices, using an HTTP / 2 protocol whose streams are carried on the INT1 interface. By activating an observation program on the INT1 interface, on which data is exchanged between an MSI software application and another MS2 software application, it is thus possible to identify and process data specific to the HTTP / 2 protocol.This identification is based on a selection of the different data conveyed on the communication interfaces, and in particular in the example given, on the INT1 interface.

[0054] The centralized controller CTRL transmits the discovered information to the external Agt agent. To this end, the management process relies on communication between the external agent and the centralized controller, based on declarative and persistent APIs. For example, in the case of a Kubemetes environment, communication between the centralized controller CTRL and the external Agt agent can be based on the Kubemetes API. In this case, this API is extended to include Custom Resources (CRs), allowing the storage and transmission of the information discovered by the controller CTRL in a declarative manner, as key-value data. This management process ensures the robustness and resilience of the solution.For example, if a component of the solution (whether it be the centralized controller or the external agent) restarts, the data necessary to ensure the proper functioning of the solution will be persisted in a Kubernetes-native way, without requiring an additional database.

[0055] The external Agt agent uses the information transmitted by the controller to generate distributed metrics, logs and traces relating to the 5G system.

[0056] The environment shown in [Fig. 1] thus comprises an external agent Agt structured in two elements, namely a Util Agent, for user agent, and a Kernel Agent. The Util Agent listens for information transmitted by the CTRL controller and attaches an observation program, such as a program eBPF, network interfaces, and libraries discovered by the CTRL controller. Attachment can correspond to an instantiation of the observation protocol in the Kernel Agent and its association with the discovered communication interface or a library used by the MSI software application, for example. The Util Agent is also responsible for processing events filtered by the Kernel Agent and reporting telemetry data in three forms: Prometheus-style labeled metrics, JSON-style logs, and distributed traces according to the OpenTelemetry specification. The Kernel Agent's purpose is to instantiate the observation protocol, such as eBPF, which is executed for each network packet or datagram carried within an environment, for example, on a communication interface or a library to which the observation protocol has been associated.Thus, packet filtering is performed to select only those protocol packets specific to the implementation of a cellular core network, for example, a 5G network, and corresponding to a particular context. This context could be related to an application, a service, one or more users, or an infrastructure deployment context, such as a network slice or a virtual private network. The information identifying the context in the observed protocols can correspond to a source IP address, a destination IP address, a port number, data from the observed protocol's data field, a combination of these, or any other information from the observed protocol that identifies the context. The fields used to identify and potentially propagate the context of the traces can therefore be the HTTP headers for HTTP / 2 exchanges.For 3GPP protocols (such as NGAP and PFCP), tracing information can be Information Elements (IEs). These IEs are used to exchange information via the protocols standardized by 3GPP. Several types of IEs already exist (such as those for User Equipment Identifiers (UEs), SUPI (Subscription Permanent Identifier), IMSI (International Mobile Subscriber Identity), slice identifiers, such as SD (Service Differentiator) and SST (Slice / Service Type), or QoS Flow Identifiers (QFI), 5QI (5G QoS Identifier), etc.), or a component of these indicators). It is also possible to use context information to be specified for each observed protocol and transmitted in a field to be defined within the observed protocols.

[0057] Thus, only packets using the NGAP, PFCP, GTP-U, and HTTP / 2 protocols for a specific context or used on a NAS interface are selected. This list of protocols is not exhaustive and may evolve over time, depending on the protocols used and listened for by the external agent composed of the Kernel Agent and the Utility Agent. It should be noted that the agent is called external because it is external to the MSI, ..., MS6 software applications and allows obtaining data from core network protocols without penalizing the provision of a service by the software application being listened to through one or more INT1,...,INT8 interfaces of these software applications.

[0058] The external agent includes a selection device, an example of which is shown in [Fig. 3]. The architecture of a Sel device adapted to implement the management process in a computer environment, according to a particular embodiment.

[0059] The Sel device includes a data processing module comprising a storage space 201, for example a memory (MEM), a processing unit 202, equipped for example with a microprocessor (PROC), and controlled by a computer program (PGR) 203 whose instructions are configured to implement the management process as described in relation to [Fig.3].

[0060] At initialization, the code instructions of the computer program 203 are, for example, loaded into memory 201 before being executed by the processor of the processing unit 202. The microprocessor of the processing unit 202 implements, according to the instructions of the computer program 203, the steps of the management process described below with reference to [Fig.4].

[0061] To this end, in addition to the memory 301 and the processor 302, the device includes communication means Comm 204, enabling it to exchange messages with other devices. These communication means include, for example, a wired communication bus. The communication means 204 allow the Sel device, in particular, to exchange data with the CTRL controller and entities in the computing environment, such as the Stock TD-CS entity and the interfaces of software applications. The Sel device includes an Inst 205 acquisition module configured to instantiate the observation program in the external agent. The program can be pre-configured or loaded into the external agent, or it can be loaded when the activation program for a software application needs to be instantiated.

[0062] The Sel device further includes an Assoc 206 module adapted to activate (or associate) the program instantiated on the communication interface and / or a library of the software application for which a selection of protocol data is to be implemented.

[0063] The Sel device further includes a Select 207 module adapted to select data associated with the communication by means of a context parameter, possibly configured by another software application, relating to the environment, i.e. the communication interface and / or a library, associated with the software application, from among a set of data examined by means of the observation program associated with at least one software application. In the case where a packet passes through several software applications, a first software application can thus configure a context parameter to be added to the transmitted data, this context parameter then being used by the external agents of the other software applications, to select only the data including this context parameter, or a value of context parameter, if several context parameters are present.

[0064] The environment shown in [Fig. 1] further includes an Infra Export module, or infrastructure data export module, distributed in the Env Exec Cont 1 and Env Exec Cont 2 containers of the cluster, which communicates with the operating system to retrieve resource consumption data from the MS1,...,MS6 software applications and the infrastructure hosting these software applications. This Infra Export module then transmits this data to the Stock TD-CDS entity.

[0065] The Infra Export module as the external agent, software applications and interfaces and the CTRL controller are positioned in a GEN TD-G telemetry data generation entity.

[0066] This entity transmits telemetry data to a Stock TD-CS entity responsible for collecting and storing the generated telemetry data. This Stock TD-CS entity comprises three servers, Metr, Joum, and Trac, responsible respectively for storing, exposing, and correlating the generated telemetry data, and for recording the data in logs made available for visualization and analysis. In particular, the Trac server is responsible for aggregating and correlating the various data observed by external agents on different software applications that share the same contextual information, i.e., specific to the same application, the same service, a user or group of users (company, residence, customers with the same contract), or the same network segment.This Trac entity can thus obtain data from various external agents regarding communication interfaces and / or software application libraries, this data being transmitted over various protocols (NGAP, PFCP, HTTP / 2, etc.). Context data can be propagated to the Trac entity using a control protocol, for example, or by transmitting data from the observed protocol, including context information such as those mentioned above (UE ID, Slice ID, QoS ID). Based on the collected data sharing the same context, the Trac entity can analyze and resolve potential malfunctions or audit a service related to that context.

[0067] This data, including data collected by the Trac entity, is then analyzed and made available to an administrator by means of a Proc TD- entity The P component handles data processing, analysis, and anomaly detection. It comprises two modules: Anomal for anomaly analysis and Int for interface, such as a GUI, allowing a system administrator and / or operator to view the data. Specifically, 5G protocol data collected by the external agent is gathered, processed, and logged to identify potential malfunctions in one or more core cellular network protocols.

[0068] The Proc TD-P entity may further include other advanced processing modules, including in particular the forecasting of future trends and the proactive identification of operational irregularities, enabling more appropriate and faster decision-making in the face of unforeseen events. Data on cellular core network protocols can be used to improve forecasting techniques, particularly through the use of models and possibly artificial intelligence techniques.

[0069] Figure 2 illustrates a schematic representation of a network (also called A 5G communication system deployed in a Kubemetes-type cloud computing environment is shown in a different, specific embodiment. This representation differs from that of [Fig. 1] in that the external agent used to select data associated with a communication based on contextual information, and thus to monitor end-to-end communication, is instantiated within a specific external agent. Therefore, an external agent can be instantiated to perform protocol data analysis of a 5G system, and a specific external agent can also be instantiated to select context-specific data from a software application environment, including, in particular, communication interfaces between software applications and user libraries associated with those applications.This external agent is particularly well-suited for determining contextual information for the various observed protocols, and for communicating selected data from the different protocols and software applications of the 5G system to a Trac observability entity, either through a specific control protocol or by relaying the selected data via the observed protocols. The characteristics of the entities and exchanges specific to the 5G system in [Fig. 1] are also valid for the 5G system in [Fig. 2].

[0070] Reference is then made to [Fig.4] which illustrates the main steps of a management process applied to a communication interface and a library of a software application, according to a particular embodiment of the proposed technique.

[0071] This embodiment is, for example, instantiated in a computer environment such as that described in [Fig. 1]. The entities described in [Fig. 1] will be used to describe the management process of [Fig. 4].

[0072] During a discovery step 100 Dec, the CTRL controller, through an analysis of the software applications deployed in the environment, discovers a software application, represented by a microservice contributing to a cloud-native network function (CNF). In a particular case, the software application may correspond to the CNF. This discovery can be initiated by the CTRL controller, which can probe the IT environment and its constituent clusters at regular intervals, or the software applications can register with the CTRL controller, or the CTRL controller can be configured with information relating to the software applications.Regardless of the discovery mode used, the CTRL controller obtains information about the software application, including the IP address used by the application to communicate or a loopback address, its name, its communication interfaces, the identification of the server hosting it, and possibly the identification of the cellular core network function it supports or contributes to. This discovery step is optional, as the IT environment may be stable for a period of time and not require prior discovery. This discovery step can be repeated at various intervals to maintain the CTRL controller's up-to-date knowledge of the IT environment.

[0073] During an optional step 101 Inst, an external agent composed of a Core agent and a User agent is instantiated in a container within a cluster of the computing environment. This instantiation can occur during the initial installation of a software application in the corresponding container, or upon an administrator's action to initiate the process of analyzing a cellular core network protocol on one or more interfaces and / or a user library of an already installed software application. The Inst instantiation can also be linked to the deployment of a new container, for example, if each container in the infrastructure environment requires such an agent.

[0074] During step 102 Assoc, an observation program is associated with a communication interface of a software application. In one example, this is the software application discovered during step 100. To facilitate the description of the process in [Fig. 2], the software application is considered to be the MSI application corresponding to a microservice of a cellular core function, and the microservice is considered here to contribute to a UPF function. The process would be identical if the microservice were the UPF function itself or if the network function were another core function. This function contributes to the user plane and / or the control plane of the cellular core network. The association involves, alternatively, instantiating the observation program within the external agent's Core agent and associating the program with an environment, such as a communication interface and / or a user library, of the MSI application via the external agent's user agent. The observation program analyzes all packets or datagrams passing through the interface and performs filtering to extract packets or datagrams relevant to a specific protocol and context within the cellular core network of the MSI microservice. Depending on the function considered by the method, the analyzed protocols may vary.A non-exhaustive list of cellular core network protocols includes, among others, NGAP, PFCP and GTP-U protocols, HTTP / 2 and the protocols of a NAS interface of a cellular core network.

[0075] Filtering can be performed, on the one hand, based on the headers of the packets exchanged on the interface, and in particular a field indicating the protocol in a header of a transport protocol used to convey the data of the protocol to be identified by the external agent, and on the other hand, based on context information uniquely encoded in the observed protocols or encoded distinctly in the different observed protocols, as previously described. One advantage of using an external agent is that it does not impact the service provided by the software application by modifying it, for example, by adding an observation function that impacts the service provided by that application. Using the eBPF program as an observation program offers high-performance monitoring with minimal impact on cellular network performance, which is essential for maintaining a high-quality user experience.Furthermore, distributing the observation program at the container level allows for efficient management of observability in large-scale cellular network environments. Moreover, network traffic monitoring is performed without modifying the MSI application, which is crucial for production environments where access to source code may be restricted or where modifications may be risky. The solution is therefore agnostic to vendor-provided software applications and can be deployed with any software application.

[0076] During a Select 1 step, the associated observation program analyzes the packets or datagrams carried on the communication interface or obtained from the MS user library and selects the packets or datagrams associated with a core cellular network protocol to which the MSI software application contributes and which also correspond to a specific context. Thus, the program selects the data of the aforementioned protocols. The context is identified by a UE, QoS, or slice identifier, for example, potentially enabling processing and improved core network management for data specific to a particular context. Thus, it is possible to determine if a slice is operating satisfactorily, if a user's data is being correctly routed, or if traffic sharing the same quality of service has routing characteristics that verify this quality of service. The protocol in question can be either a control or session management protocol for a terminal connected to the cellular network, or a signaling or data transport protocol associated with a terminal. The data associated with a selected communication can correspond to all the protocol data, or only a part (header, payload data, context information).

[0077] During a Select 2 step, a second data point and possibly other context-specific data points are further selected from the same software application or from a different software application. The second selected data point may be obtained from the same protocol or from a different protocol than the one corresponding to Select 1. This selection of multiple data points during Select 1 and Select 2 steps thus makes it possible to aggregate and correlate different data points from the same context selected from a communication interface or a software application library of a cellular system.

[0078] Certain network exchanges between software applications of a cellular system, such as 5G (for example, those based on the HTTP / 2 protocol), must be encrypted and are further encoded dynamically, for example, when adaptive compression techniques are used to minimize the size of the transmitted data. These techniques often involve encoding information according to schemes that vary depending on the data, making interpretation difficult without detailed analysis. For this purpose, the management process, and more specifically the selection of data, is advantageously applied to a user library of a software application within a core cellular system.This method allows monitoring of calls from the software application to the user library used for encoding and decoding and / or encrypting and decrypting network communications, and efficiently capturing events related to the execution of critical functionalities without directly interfering with the data flow. A significant advantage of this method lies in its ability to observe encrypted and / or encoded communications dynamically. Specifically, this management method allows observation of calls to the primitives provided by the user library for encoding and decoding and / or encrypting and decrypting communications, with access to the inputs and outputs of these functions. These include relevant information about network exchanges before their encoding / encryption or after their decoding / decryption, respectively. This observation of the libraries within a software application environment proves sufficient or complementary to observations of communication interfaces, enriching the selected data and thus improving knowledge of the data specific to a particular context.

[0079] During an optional step 105 Select 3, the associated observation program analyzes and selects representative data from the consumption of a resource of the MSI software application and / or the container, particularly in the Env Exec Cont 1 environment, in which the MSI software application is instantiated. This collection and selection of data, and in particular metrics relating to the hosting infrastructure, thus complements the data selection of the core cellular network protocols and consequently improves their processing and problem resolution. This selection is also performed non-intrusively and is particularly advantageous because it enriches the selected data without degrading the operation of the MSI microservice.

[0080] The data selected, in accordance with the Select 1 operation and possibly Select 2 and Select 3, in the Gen TD-G entity of [Fig.1], can be transmitted during a 106 Trans step and stored in the Stock TD-CS entity.

[0081] In particular, the data selected during Select 1 and possibly Select 2 steps are transmitted to a Trac observation entity of Stock TD-CS. The transmission may consist of transmitting the data as selected, using the protocols from which the data were selected, possibly adding context information specific to these various protocols (NGAP, PFCP, HTTP / 2, etc.), or using a specific control protocol. This control protocol conveys the selected data and its association with the context from which the data from these protocols was selected. The protocol may include all the protocol data or a portion of the protocol data, including the selected data.

[0082] The management process thus makes it possible to generate distributed traces related to the observation of exchanges between software applications (i.e., microservices) and user libraries. These distributed traces make it possible to follow the path of data through the cellular network and potentially to identify bottlenecks and diagnose performance problems.

[0083] The Trac entity can then format, aggregate, correlate this data, select and detect anomalies and malfunctions itself or through the Proc TD-P entity.

[0084] In step 107, the Proc-TD P entity, notably through the Anomal entity, analyzes the selected and transmitted data to detect malfunctions or normal operation of the protocols used for implementing the cellular core network. The infrastructure data that may also be selected can enrich the analysis and improve the detection of anomalies and malfunctions, either reactively or proactively. Thus, the selected data can be used to monitor and analyze the performance of cellular network functions, such as the 5G network, including traffic management, quality of service (QoS), and anomaly detection. This is particularly important for telecommunications operators seeking to optimize the user experience and maintain high network availability.

[0085] The management process is thus advantageously used to monitor the operation of microservices for a specific context in cloud environments, such as platforms as a service (PaaS) or infrastructures as a service (laaS).

[0086] Thus, by selecting data relating to cellular network protocols specific to a context and possibly to the infrastructure, it is possible to monitor network traffic and, by detecting anomalies, the method can help identify suspicious behavior that could indicate attempted cyberattacks or security vulnerabilities. The method can be used to ensure proactive anomaly detection, analyze root causes, and improve network resilience. The embodiments have been described in relation to protocols and interfaces of a 5G system, but these embodiments are transferable to any communication system of a generation prior to or subsequent to the 5G system, or by adopting its characteristics.

Claims

Demands

1. Method of managing an instantiated communication by means of at least one software application (MSI) of a cellular core network, said at least one software application (MSI) being deployed in a cloud computing environment, said method being implemented by an agent external (Agt) to the software application (MSI) and comprising: - Activating (Assoc) an observation program instantiated on an environment of the at least one software application, - Selecting a data associated with the communication by means of a context parameter relating to the environment, from a set of data examined by means of the observation program activated on the at least one software application.

2. Management method, according to claim 1, wherein the observation program is an extended Berkeley Packet Filter program.

3. Management method, according to any one of claims 1 or 2, wherein the external agent (Agt) is previously instantiated in the cloud computing environment further comprising the software application.

4. A management method, according to any one of the preceding claims, wherein the dataset being examined is encrypted and the observation program is adapted to select a data point from the encrypted dataset.

5. A management method, according to any one of the preceding claims, wherein the context parameter is configured by the external agent based on information relating to an application and / or a user and / or routing information present in a message relating to the environment of said software application.

6. A management method, according to any one of the preceding claims, wherein the environment includes a communication interface for at least one software application and / or a library associated with the software application.

7. A management method, according to any one of the preceding claims, further comprising selecting at least one second piece of data associated with the communication by means of a context parameter

8.

9.

10.

11. relating to an environment of at least one second software application, among a set of data examined using the activation program associated with at least one second software application. A management method, according to one of the preceding claims, in which the selected data is transmitted to a cellular network observability entity (Trac) communicating with the external agent for the purpose of its aggregation with other data associated with the communication and its use for the management of the cellular core network. Management method, according to claim 8, wherein the selected data is transmitted in a control message issued to the observability entity. A management method, according to one of the preceding claims, wherein the software application is a microservice of a cellular core network device. A management method, according to any one of the preceding claims, wherein the context parameter is extracted from a header or data of a cellular core network communication protocol.