Service providing system, learning device, inference device, application server, program, and control method

WO2026159904A1PCT designated stage Publication Date: 2026-07-30MITSUBISHI ELECTRIC CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
MITSUBISHI ELECTRIC CORP
Filing Date
2025-03-24
Publication Date
2026-07-30

Smart Images

  • Figure JP2025011362_30072026_PF_FP_ABST
    Figure JP2025011362_30072026_PF_FP_ABST
Patent Text Reader

Abstract

This service providing system (1) comprises: terminal devices (101) that are connected to networks (20); an application server (41) that provides a service to the terminal devices (101) over the networks (20); a plurality of network management devices (21) that respectively manage the plurality of networks (20) that serve as communication paths of the service to the terminal devices (101); and an authentication server (31) that authenticates the application server (41). When the application server (41) is authenticated by the authentication server (31), the network management devices (21) permit the application server (41) to perform network control pertaining to communication between the application server (41) and the terminal devices (101) in the networks (20) managed by the network management devices (21).
Need to check novelty before this filing date? Find Prior Art

Description

Service delivery system, learning device, inference device, application server, program, and control method

[0001] This disclosure relates to a service delivery system that utilizes a network.

[0002] Traditionally, in communication between a terminal device and an application server that provides web services to the terminal device via a network, QoS (Quality of Service) control was applied to the network to which the terminal device was connected in order to achieve the communication quality that should be applied according to the content of the service.

[0003] International Publication No. 2024 / 181091

[0004] Incidentally, communication between a terminal device and an application server typically takes place via network lines managed by multiple network operators, including public lines such as the internet. In such cases, the application server or terminal device could only access network information and control the network to which the terminal device was connected. For example, when a terminal device connects to a mobile network, QoS control defined by the application running on the terminal device, such as low latency, bandwidth allocation, and loss rate, is applied only to the mobile network to which the terminal device is connected, and cannot be configured for the internet to which the mobile network further connects, or for other networks to which the application server is connected. Service providers managing application servers have a need to centrally control the entire communication between the terminal device running the application and the application server to achieve the communication quality required by the application, in order to enhance the user experience for users of the application.

[0005] This disclosure aims to solve the aforementioned problems by providing a service provision system that performs optimal control over the network between terminal devices and application servers to achieve the communication quality required by the application.

[0006] The service provision system relating to this disclosure comprises terminal devices connected to a network, an application server that provides services to the terminal devices via the network, multiple network management devices that manage multiple networks that serve as communication paths to the terminal devices for the services, and an authentication server that authenticates the application server. When the application server is authenticated by the authentication server, the network management device authorizes the application server to control the network communication between the application server and the terminal devices on the network managed by the network management device.

[0007] Furthermore, the learning device relating to this disclosure is communicatively connected to an application server that provides services to terminal devices via a network, and includes a data acquisition unit that acquires learning data including network information indicating the state of the network, the content of the service, and a QoS profile of the communication of the service via the network, and a model generation unit that uses the learning data to generate a trained model for inferring a QoS profile of the service communication that is appropriate for the state of the network from the network information and the content of the service.

[0008] Furthermore, the inference device relating to this disclosure is connected to an application server that provides services to terminal devices via a network, and comprises a data acquisition unit that acquires network information indicating the state of the network and the content of the service, and an inference unit that uses a trained model for inferring a QoS profile from the network information to output a QoS profile of the service communication that is appropriate to the state of the network from the network information and the content of the service acquired by the data acquisition unit.

[0009] Furthermore, the application server relating to this disclosure is an application server that provides services to terminal devices via a network, and comprises a communication path identification unit that identifies the communication path to the terminal device for the service, a storage unit that stores authentication information for the application server, and a communication unit that transmits a network control request and information indicating that authentication has been performed using the authentication information to each of the multiple network management devices that manage the multiple networks that constitute the communication path.

[0010] Furthermore, the program relating to this disclosure provides an application server that provides services to terminal devices via a network with the following functions: a function to identify the communication path to the terminal device for the service; a function to obtain information indicating that the application server has been authenticated; and a function to send a network control request and information indicating that authentication has been performed to each of the multiple network management devices that manage the multiple networks that constitute the communication path.

[0011] Furthermore, the control method relating to this disclosure is a network control method in a service provision system that provides services via a network, and includes the steps of: identifying a network that serves as a communication path between a terminal device that is the recipient of the service and an application server that provides the service; authenticating the application server; and authorizing the authenticated application server to control network communication between the application server and the terminal device on the network.

[0012] According to this disclosure, it is possible to provide a service provision system that performs network control to centrally realize the communication quality required by the application for the network that serves as the communication path for data transmitted and received between terminal devices and application servers.

[0013] This is a diagram illustrating the configuration of the service provision system according to Embodiment 1. This is a functional configuration diagram of each element of the service provision system according to Embodiment 1. This is a diagram showing the contract details between stakeholders of the service provision system according to Embodiment 1. This is a diagram showing the procedure flow regarding the intermediary agreement concluded between the certification provider and the network provider according to Embodiment 1. This is a diagram showing the procedure flow regarding the user agreement concluded between the service provider and the certification provider according to Embodiment 1. This is a diagram showing the procedure flow regarding the application service agreement concluded between the user of the terminal device and the service provider according to Embodiment 1. This is a sequence diagram showing the network control by the application server when the terminal device according to Embodiment 1 runs an application. This is a sequence diagram showing the details of the token issuance process by the certification server according to Embodiment 1. This is a sequence diagram showing the details of the QoS profile determination process by the application server and the network management device according to Embodiment 1. This is a sequence diagram showing the details of the process by which the network management device according to Embodiment 1 queries the certification server for a token. This is an example of a QoS profile. This is a sequence diagram showing the details of the QoS profile setting process from the application server to the network management device according to Embodiment 1. This is a sequence diagram showing the network control by the application server when the network is changed while the terminal device according to Embodiment 1 is running an application. This is a functional configuration diagram of the cloud server according to Embodiment 2. This diagram shows the procedure flow for a cloud service contract concluded between a service provider and a cloud service provider according to Embodiment 2. This flowchart shows the learning process of the learning device according to Embodiment 2. This flowchart shows the inference process of the cloud server according to Embodiment 2. This flowchart shows the simulation process of the cloud server according to Embodiment 2. This sequence diagram shows the details of the QoS profile determination process by the application server and network management device according to Embodiment 2. This sequence diagram shows the details of the QoS profile determination process by the application server and network management device according to Embodiment 3.

[0014] The embodiments for carrying out the subject matter of this disclosure will be described with reference to the attached drawings. In each drawing, the same or corresponding parts are denoted by the same reference numerals, and redundant explanations are simplified or omitted as appropriate. However, the subject matter of this disclosure is not limited to the following embodiments, and any modification of any component of the embodiments, or any combination or omission of any component of the embodiments is possible without departing from the spirit of this disclosure.

[0015] Embodiment 1. Figure 1 is a diagram illustrating the configuration of the service provision system 1 according to this embodiment. The overview of the service provision system 1 will be described with reference to Figure 1. The service provision system 1 is a system that provides Web services to terminal devices 101 via multiple networks 20 from an application server 41 managed by a service provider 4. In Figure 1, terminal devices 101 are shown as a smartphone 101a, a drone 101b, a personal computer 101c, and a webcam 101d. The service provision system 1 includes multiple networks 20 managed by a network provider 2, a network management device 21 for managing each of the networks 20, terminal devices 101 connected to the networks 20, an application server 41 managed by a service provider 4 connected to the networks 20, and an authentication server 31 managed by an authentication provider 3 connected to the networks 20. Furthermore, it may also include a cloud server 51 managed by a cloud service provider 5 that operates in cooperation with the application server 41.

[0016] In Figure 1, five networks are illustrated as Network 20: Networks 20a, 20b, 20c, 20d, and 20e. When no distinction is made between Networks 20a, 20b, 20c, 20d, and 20e, they are simply referred to as Network 20. Networks 20a, 20b, 20c, 20d, and 20e are managed by Network Management Devices 21a, 21b, 21c, 21d, and 21e, respectively. When no distinction is made between Network Management Devices 21a, 21b, 21c, 21d, and 21e, they are simply referred to as Network Management Device 21. Furthermore, Network Management Devices 21a, 21b, 21c, 21d, and 21e are operated by Network Operators 2a, 2b, 2c, 2d, and 2e. When no distinction is made between Network Operators 2a, 2b, 2c, 2d, and 2e, they are simply referred to as Network Operator 2. Network operator 2 includes line operators that provide physical internet lines, providers that provide internet connection services, and administrators of networks they have built themselves. Network operator 2 controls the network 20 that it owns or has the authority to manage using a network management device 21. The control of the network 20 by the network management device 21 refers to activities that operate, manage, protect, and optimize the network 20, such as data routing / transfer, IP (Internet Protocol) address management of each connected server and terminal device 101, and security management such as encryption.

[0017] Terminal device 101 is a device used by user 10 (not shown in Figure 1) that can receive Web services (hereinafter simply referred to as "services") from application server 41 by connecting to network 20. Terminal device 101 includes devices that allow user 10 to use services provided by application server 41 by installing application programs (hereinafter referred to as "apps") on a smartphone 101a or personal computer 101c. Note that Web services executed on smartphone 101a or personal computer 101c may be executed using a Web browser without installing an app. In addition, terminal device 101 includes devices that allow services provided by application server 41 by dedicated programs built into devices such as drone 101b or web camera 101d.

[0018] The application server 41 is a server that provides services to the terminal device 101 via the network 20. The application server 41 is operated and managed by the service provider 4. The application server 41 may be divided into multiple servers, each for a different function. In this case, the locations where the multiple servers are installed and the networks 20 to which the multiple servers are connected may be different.

[0019] The authentication server 31 is a server that provides authentication functions managed by the authentication provider 3. The authentication server 31 has the function of mediating the authority of the authenticated application server 41 to control the network 20 managed by the contracted network provider 2. The control of the network 20 mediated by the authentication server 31 refers to the disclosure of network information indicating the state of the network 20 and QoS control related to communication between the application server 41 and the terminal device 101. Network information is information indicating the current state of the network 20, such as network traffic information and bandwidth utilization. QoS control refers to setting QoS parameters that request delay time, bandwidth, etc., from the network 20 during communication between the terminal device 101 and the application server 41.

[0020] The cloud server 51 provides the functions deployed by the service provider 4 to the application server 41 via the network 20. Note that in the service provision system 1 according to this embodiment, the cloud server 51 is not required.

[0021] Figure 2 is a functional configuration diagram of each element of the service provision system 1 according to this embodiment. Referring to Figure 2, the functional configurations of the network management device 21, authentication server 31, application server 41, and terminal device 101 will be described.

[0022] The network management device 21 comprises a communication unit 22, a control unit 23, and a storage unit 24. The network management device 21 is composed of a processor and memory, and each functional unit is realized by the processor and memory. The processor is also called a CPU (Central Processing Unit), processing unit, arithmetic unit, microprocessor, microcomputer, DSP (Digital Signal Processor), or FPGA (Field-Programmable Gate Array). The memory is composed of non-volatile or volatile semiconductor memory such as RAM, ROM, flash memory, EPROM, and EEPROM. The communication unit 22 is connected to the network 20 and manages the network 20 and communicates with the authentication server 31 and the application server 41. The control unit 23 controls the entire network management device 21. The storage unit 24 is a memory that stores network information 24a and QoS profile 24b. The QoS profile 24b is a collection of items set in QoS control, specifically a group of information that includes items such as profile name, application status, bandwidth (by direction), delay time, and jitter, along with the required setting values ​​for each. Details of the QoS profile will be described later. The network information 24a is information that indicates the status of the network 20, such as bandwidth utilization and throughput. Since this information indicates the current status of the network 20, the network management device 21 monitors the status of the network 20 and periodically updates the network information 24a.

[0023] The authentication server 31 comprises a communication unit 32, a control unit 33, and a storage unit 34. The authentication server 31 is composed of a processor and memory, and each functional unit is realized by the processor and memory. The communication unit 32 is connected to the network 20 and communicates with the network management device 21 and the application server 41, and authenticates the application server 41 to the network management device 21. The content of the communication performed by the communication unit 32 will be described later. The control unit 33 performs overall control of each function of the authentication server 31. The storage unit 34 is memory and stores authentication information for authenticating multiple application servers 41 that have concluded a usage agreement for the authentication server 31. The authentication information is, for example, a combination of ID and password.

[0024] The application server 41 comprises a communication unit 42, a control unit 43, and a storage unit 44. The application server 41 is composed of a processor and memory, and each functional unit is realized by the processor and memory. The communication unit 42 is connected to the network 20 and communicates with the network management device 21, the authentication server 31, and the terminal device 101. In addition, when the application server 41 cooperates with the cloud server 51, the communication unit 42 also communicates with the cloud server 51. The control unit 43 performs overall control of each function of the application server 41. The control unit 43 includes a communication path identification unit 43a that identifies the network 20 which is the communication path between the terminal device 101 and the application server 41. The communication path identification unit 43a can identify the communication path, for example, by performing a TCP (Transmission Control Protocol) / IP trace. The storage unit 44 is a memory that stores authentication information 44b for the authentication server 31 to authenticate the application server 41 and user information 44a for the terminal device 101. User information 44a is information for authenticating the user 10 using the terminal device 101, and is, for example, a combination of user ID and password.

[0025] The terminal device 101 consists of a processor and memory, and each functional unit is realized by the processor and memory. The communication unit 102 is connected to the network 20 and communicates with the application server 41. The control unit 103 performs overall control of each function of the terminal device 101. The storage unit 104 is memory and stores application data 104a, which is the data of the application that runs on the terminal device 101. Note that if the terminal device 101 operates using a dedicated program built into the device, such as a drone 101b or a web camera 101d, the application data 104a is the program data of the terminal device 101.

[0026] Figure 3 is a diagram showing the contractual details between the stakeholders of the service provision system 1 according to this embodiment. The stakeholders of the service provision system 1 according to this embodiment are the user 10 who uses the terminal device 101, the service provider 4 who manages the application server 41, the authentication provider 3 who manages the authentication server 31, and the network provider 2 who manages the network 20 and the network management device 21.

[0027] The certification authority 3 and the network operator 2 enter into an intermediary agreement c1 that authorizes the certified application server 41 to control the network 20. Figure 4 is a diagram showing the procedure flow for the intermediary agreement c1 concluded between the certification authority 3 and the network operator 2 according to this embodiment. Referring to Figure 4, an example of the procedure between the certification authority 3 and the network operator 2 when concluding the intermediary agreement c1 will be explained.

[0028] First, in c11, the certification authority 3 and the network operator 2 negotiate the details of the control of the network 20 authorized by the application server 41 certified by the certification authority 3, the consideration to be paid by the certification authority 3 to the network operator 2, and contract terms that define compensation and liability in the event of an accident, the contract period, etc. If both parties agree, they conclude an intermediary agreement c1.

[0029] Next, in c12, the network operator 2 registers the information of the authentication server 31 and the information necessary for mediation with the network management device 21. The information of the authentication server 31 is, for example, the address of the authentication server 31. The information necessary for mediation is, for example, the control details of the network 20 that the authentication server 31 is to mediate.

[0030] Next, in c13, the network operator 2 sends an initial registration completion notice to the authentication operator 3, informing it that the registration of contract information has been completed and that the authentication operator 3 is ready to authorize the application server 41, which it has authenticated, to control the network 20.

[0031] Next, in c14, the authentication provider 3 registers the network 20 of the network provider 2, with whom it has concluded an intermediary agreement, as a linked network with the authentication server 31.

[0032] Next, in c15, the authentication provider 3 requests a connection test from the network management device 21 of the network provider 2 via the authentication server 31.

[0033] Next, in c16, when the network management device 21 of the network operator 2 receives the connection test request in c15, it returns a connection test response notifying that the connection was successful. This concludes the procedure for the mediation contract c1.

[0034] By concluding intermediary agreements c1 with multiple network operators 2, the authentication provider 3 enables the application server 41 authenticated by the authentication server 31 to control multiple networks 20.

[0035] The service provider 4 and the authentication provider 3 enter into a service agreement c2 to utilize the authentication service of the application server 41 and the control of the network 20 managed by multiple network management devices 21, for which the authentication provider 3 has entered into an intermediary agreement c1. Figure 5 is a diagram showing the procedure flow for the service agreement c2 to be concluded between the service provider 4 and the authentication provider 3 according to this embodiment. Referring to Figure 5, an example of the procedure between the service provider 4 and the authentication provider 3 when concluding a service agreement c2 will be explained.

[0036] First, in c21, the service provider 4 and the certification provider 3 negotiate regarding the content of the control of the network 20 that the application server 41 can use, the consideration paid from the service provider 4 to the certification provider 3, and the contract conditions such as compensation and liability in case of an accident, the contract period, etc. When both parties agree, they conclude a usage contract.

[0037] Next, in c22, the certification provider 3 registers the authentication information of the application server 41 managed by the service provider 4 and the content regarding the contract in the authentication server 31. The registered information is stored in the storage unit 34 of the authentication server 31. The authentication information of the application server 41 is, for example, a combination of the ID sent to the application server 41 and the initial password. The content regarding the contract is, for example, the information of the network 20 authorized for the application server 41 and the content of the control of the network 20.

[0038] Next, in c23, the certification provider 3 transmits a service start notification notifying that the application server 41 of the service provider 4 is ready to use the authentication service and the control of the network 20 together with the authentication information.

[0039] Next, in c24, the service provider 4 registers the authentication information in the storage unit 44 of the application server 41. The service provider 4 may be able to change the initial password sent from the certification provider 3 to an arbitrary password. In this case, the service provider 4 changes the initial password sent from the certification provider 3 to an arbitrary password and transmits it to the authentication server 31, and the authentication server 31 rewrites the authentication information 34a in the storage unit 34 with the changed password.

[0040] Next, in c25, the service provider 4 requests the authentication server 31 of the certification provider 3 to conduct a connection test from the application server 41.

[0041] Next, in c26, when the authentication server 31 of the certification provider 3 receives the connection test request in c25, it returns a connection test response notifying that the connection was successful. Thus, the procedure of the usage contract c2 by the service provider 4 and the certification provider 3 ends.

[0042] The user 10 of the terminal device 101 and the service provider 4 enter into an application service contract c3 for using the services provided by the application server 41. Figure 6 is a diagram showing the procedure flow for the application service contract c3 concluded between the user 10 of the terminal device 101 and the service provider 4 according to this embodiment. Referring to Figure 6, an example of the procedure between the user 10 and the service provider 4 in the application service contract c3 will be explained.

[0043] First, in c31, user 10 uses terminal device 101 to send user information to the application server 41 of service provider 4 for account creation. User information is information that the application server 41 uses to authenticate user 10, and includes information that identifies user 10, such as the email address, telephone number, and name used by user 10, as well as an arbitrary password set by user 10.

[0044] Next, in c32, the application server 41 of the service provider 4 registers the user information as user information 44a in the storage unit 44. At this time, if the application server 41 includes an email address or phone number in the user information sent from the terminal device 101, it may perform a process to confirm whether it is the email address or phone number used by user 10. In this case, the application server 41 sends a verification code to the sent email address or phone number. User 10 obtains the verification code using their own email address or phone number and sends the verification code to the application server 41 from the application or web browser on the terminal device 101. The application server 41 can confirm that it is the email address or phone number used by user 10 by verifying whether the verification code sent to the email address or phone number matches the verification code obtained from the terminal device 101.

[0045] Next, in c33, the service provider 4 sends an account creation completion notification to the terminal device 101. With this, the application service contract c3 is concluded between the user 10 of the terminal device 101 and the service provider 4.

[0046] The application server 41 has been described as authenticating user 10. Therefore, user 10 can use application services from multiple terminal devices 101 by inputting user information. Alternatively, the application server 41 may be configured to authenticate terminal devices 101. That is, the application server 41 may store device information of terminal devices 101 in the storage unit 44 instead of user information, and terminal devices 101 may transmit device information to the application server 41 to enable them to use services provided by the application server 41. Device information refers to information that identifies terminal device 101, such as the MAC address and serial code of terminal device 101.

[0047] As explained above, the authentication provider 3 enters into intermediary agreements with each of the multiple network operators 2 that manage the multiple networks 20. In addition, the service provider 4 enters into a usage agreement with the authentication provider 3. Based on these agreements, the authentication server 31 authenticates the application server 41, and the network management device 21 authorizes the authenticated application server 41 to control the network 20. As a result, the application server 41 can control the network 20, such as by setting QoS settings for the multiple networks 20 that serve as the communication path between the application server 41 and the terminal device 101, and can centrally realize communication quality according to the service across the network 20 that serves as the communication path between the application server 41 and the terminal device 101. Therefore, the application server 41 can provide a service with an improved user experience to the user 10 who has entered into an application service agreement.

[0048] Next, we will describe the specific process of the authentication of the application server 41 by the authentication server 31 based on the contract and the mediation of the application server 41's control of the network 20 managed by the network management device 21. Figure 7 is a sequence diagram showing the control of the network 20 by the application server 41 when the terminal device 101 according to this embodiment runs an application. Referring to Figure 7, we will explain the mediation of the network 20 control by the authentication server 31.

[0049] First, in step S10, the terminal device 101 executes the application. The application is executed when the user 10 operates the terminal device 101.

[0050] Next, in step S11, the terminal device 101 sends a login request to the application server 41. At this time, the terminal device 101 sends user information such as an email address, user ID, and password as information necessary for login. The user information is entered by the user 10 by operating the terminal device 101. Alternatively, the user information may be stored in the storage unit 104 of the terminal device 101 and configured to be entered automatically.

[0051] Next, in step S12, the application server 41 checks the received user information against the user information 44a stored in the storage unit 44. If the user information is correct, it permits login and sends a login completion notification to the terminal device 101. Alternatively, when permitting login, the application server 41 may redirect the terminal device 101 to a URL providing services instead of sending a login completion notification.

[0052] Next, in step S13, the communication path identification unit 43a of the application server 41 identifies a plurality of networks 20 that will be the communication path between the terminal device 101 and the application server 41. Taking the communication between the terminal device 101, which is a smartphone 101a in Figure 1, and the application server 41 as an example, the networks 20 that will be the communication path will be networks 20a, 20c, and 20d.

[0053] Next, in step S20, the application server 41 sends a token issuance request to the authentication server 31 indicating that it has been authenticated. In this embodiment, the token is information indicating that the application server 41 has been authenticated by the authentication server 31. Step S20 is the step in which the authentication server 31 authenticates the application server 41. Figure 8 is a sequence diagram showing the details of the token issuance process by the authentication server 31 according to this embodiment. Now, the token issuance process will be explained with reference to Figure 8.

[0054] First, in S21, the application server 41 sends a token issuance request to the authentication server 31 along with authentication information such as the ID and password.

[0055] Next, in S22, the authentication server 31 compares the received authentication information with the authentication information 34a in the storage unit 34 and verifies the authentication information.

[0056] Next, in S23, if authentication is successful, the authentication server 31 issues a token to the application server 41. On the other hand, if authentication fails, no token is issued, and QoS control to the network fails. This completes the token issuance process by the authentication server 31.

[0057] Returning to Figure 7, the application server 41 performs the QoS profile determination process S30 on the network management device 21, which manages the network 20 that serves as the communication path. Figure 9 is a sequence diagram showing the details of the QoS profile determination process S30 performed by the application server 41 and the network management device 21 according to this embodiment. Now, the QoS profile determination process S30 will be explained with reference to Figure 9.

[0058] First, in step S31, the application server 41 sends a QoS profile acquisition request to the network management device 21 along with the token issued by the authentication server 31. At this time, the application server 41 may also request network information from the network management device 21.

[0059] Next, the network management device 21, having received the token and QoS profile acquisition request, queries the authentication server for the token in step S40. Figure 10 is a sequence diagram showing the details of the process by which the network management device 21 queries the authentication server 31 for the token according to this embodiment. As shown in Figure 10, in step S41, the network management device 21 sends the token query request received from the application server 41 to the authentication server 31. Next, in step S42, the authentication server 31 verifies the validity of the token. Next, in step S43, the authentication server 31 sends the result to the network management device 21. The token query process in step S40 is the process by which the network management device 21 verifies the validity of the token. Alternatively, the network management device 21 may verify the validity of the token instead of the token query process in step S40. For example, the authentication server 31 may sign the token when issuing it in step S20. The network management device 21 can verify the validity of the token by verifying the signature. In this case, the authentication server 31 already holds the private key used to create the signature, and the network management device 21 already holds the public key corresponding to the private key.

[0060] If the token query is successful and the token is valid, in step S32, the network management device 21 reads the QoS profile 24b from the storage unit 24. Figure 11 shows an example of a QoS profile. The network management device 21 stores a QoS profile as shown in Figure 11 as QoS profile 24b in the storage unit 24. QoS profile 24b defines the items that the network management device 21 can set for communication on the network 20. At this time, the network management device 21 may read only the QoS profiles from the QoS profiles 24b stored in the storage unit 24 that it allows the application server 41 to set. Also, in S32, if the application server 41 requests network information, the network management device 21 also reads the network information 24a from the storage unit 24. On the other hand, if the token is invalid, step S32 is not executed.

[0061] Next, in step S33, the network management device 21 sends the QoS profile to the application server 41 as a response to the QoS profile acquisition request. If the application server 41 also requests network information, the network management device 21 also sends the network information 24a to the application server 41. On the other hand, if the token is invalid, the network management device 21 sends a token invalidation message in step S33.

[0062] Next, if the token is valid, in step S34, the application server 41, having received the QoS profile from the network management device 21, determines a QoS profile suitable for the service to be provided to the terminal device 101. Specifically, the application server 41 selects a profile name suitable for the service from the received QoS profile. In the example in Figure 11, "No" is selected. Alternatively, the application server 41 may set values ​​for each item in the received QoS profile. At this time, if the application server 41 has obtained network information, it may determine the QoS profile based on the network information. On the other hand, if the application server 41 receives a message indicating that the token is invalid in step S33, step S34 is not executed. This concludes the QoS profile determination process in step S30.

[0063] Returning to Figure 7, the application server 41 performs a QoS profile setting process S50 to set the determined QoS profile to the network management device 21, which manages the network 20 that serves as the communication path. The QoS profile setting process S50 is a step in this embodiment in which the network management device 21 authorizes the authenticated application server 41 to perform network control regarding communication between the application server 41 and the terminal device 101 on the network 20. On the other hand, if the token becomes invalid in step S40, which was performed in step S30, the QoS profile setting process S50 is not performed. Figure 12 is a sequence diagram showing the details of the QoS profile setting process S50 from the application server 41 to the network management device 21 according to this embodiment. Now, the QoS profile setting process S50 will be explained with reference to Figure 12.

[0064] First, in step S51, the application server 41 sends a QoS profile setting request to the network management device 21, along with the token issued by the authentication server 31 and the QoS profile determined in step S30.

[0065] Next, the network management device 21, having received the token, QoS profile, and QoS profile configuration request, queries the authentication server for the token in step S40. The token querying process is the same as the process shown in Figure 10 above, so its explanation is omitted.

[0066] If the token query is successful, in step S52, the network management device 21 configures the network 20 to apply the QoS profile received from the application server 41. On the other hand, if the token is invalid, the QoS profile configuration in S52 is not performed.

[0067] Next, in step S53, the network management device 21 sends a QoS profile setting response to the application server 41 indicating that the QoS profile setting is complete. On the other hand, if the token is invalid, it sends a token invalidation message in step S53. This completes the QoS profile setting process in step S50.

[0068] The QoS profile determination process in step S30 and the QoS profile setting process in step S50 are performed on the network management device 21 that manages the multiple networks 20 that form the communication path between the terminal device 101 and the application server 41, as identified by the communication path identification unit 43a of the application server 41 in step S13. Taking the communication between the terminal device 101, a smartphone 101a, and the application server 41 in Figure 1 as an example, the application server 41 performs the QoS profile determination process in step S30 and the QoS profile setting process in step S50 on each of the network management devices 21a, 21c, and 21d.

[0069] Returning to Figure 7, in step S14, the application server 41 sends a QoS control completion notification to the terminal device 101, informing it that the QoS settings for the network 20, which serves as the communication path, have been completed. The completion notification includes information on whether QoS control is possible for each network subject to QoS control.

[0070] Next, in step S15, the application launched on the terminal device 101 performs a service change after confirming that the QoS settings have been completed. A service change is the act of changing the service in accordance with the QoS control of the network 20. For example, if the service is a video viewing service, and the communication bandwidth is improved by QoS control, the application changes its settings to improve the quality of the video received from the application server 41. Also, for example, if the service is a location information service, and the communication latency is improved by QoS control, the application changes its settings to increase the update frequency of the location information obtained from the application server 41.

[0071] Next, in step S16, the application launched on the terminal device 101 returns a QoS control notification response to the application server 41, which is a response to the QoS control completion notification in S14.

[0072] Next, in step S17, the application launched on the terminal device 101 requests the application server 41 for the service data necessary for the service.

[0073] Next, in step S18, the application server 41 provides services via the network 20 in response to the application's request. The processes in steps S17 and S18 are executed as needed until the application is terminated.

[0074] The communication between the terminal device 101 and the application server 41 in steps S17 and S18 is performed using the QoS control set in step S50. This ensures that the communication between the application on the terminal device 101 and the application server 41 is of appropriate quality according to the service content, allowing the application user 10 to enjoy a service with an improved user experience. This concludes the explanation of the cooperation between the application server 41, the authentication server 31, and the network management device 21 when the terminal device 101 runs the application.

[0075] Through the above process, the application server 41 can request the network management device 21, which manages multiple networks 20 that serve as communication paths with the terminal device 101, to acquire network information and perform QoS control after being authenticated by the authentication server 31. As a result, the application server 41 can obtain a unified network connection environment without having to be aware of multiple network operators 2. Therefore, the user 10 using the terminal device 101 can enjoy a service with improved user experience due to unified communication quality.

[0076] <Modification> As a modification of this embodiment, we will now describe network control when the network 20 to which the terminal device 101 is connected changes while the application is running. If the terminal device 101 is a device that is easily movable, such as a smartphone 101a or a drone 101b, the network 20 to which the terminal device 101 is connected may change while the application is running on the terminal device 101 due to movement. In such a case, the communication path between the terminal device 101 and the application server 41 also changes. Therefore, in a service targeting a terminal device 101 that is intended to be moved, it is desirable for the application server 41 to detect changes in the communication path and, if a change has occurred, perform network control on the network 20 which is the changed communication path.

[0077] Figure 13 is a sequence diagram showing the control of the network 20 by the application server 41 when the network is changed while the terminal device 101 according to this embodiment is running an application. A modified example of this embodiment will be described with reference to Figure 13. Note that in Figure 13, the same processes as in Figures 7 to 10 and 12 are denoted by the same reference numerals and their descriptions are omitted.

[0078] First, step S60 shows the state of the terminal device 101 in Figure 13. The terminal device 101 has completed the process in Figure 7 and the application is running on the terminal device 101.

[0079] Next, in step S61, the terminal device 101 moves, and the network 20 to which it connects is changed. Note that the change in the network 20 to which the terminal device 101 connects in step S61 is not limited to when the terminal device 101 moves, but also occurs when the user 10 changes the network 20 to which it connects. Alternatively, the terminal device 101 may change the network 20 to which it connects if the previously connected network 20 becomes unreachable for some reason.

[0080] Next, in step S62, the application server 41's communication path identification unit 43a detects that the communication path between the terminal device 101 and the application server 41 has been changed and identifies the changed communication path. The detection of the communication path change and identification of the changed communication path by the communication path identification unit 43a in step S62 may be performed by the communication path identification unit 43a periodically performing a process to identify the communication path. Alternatively, when the destination network 20 of the terminal device 101 is changed, the terminal device 101 may send a notification of the communication path change to the application server 41, and the communication path identification unit 43a may detect the change.

[0081] From this point onward, the process is the same as in Figure 7 from S20 onward, so the explanation will be simplified. In other words, the application server 41 receives a token from the authentication server 31 indicating that it has been authenticated, and uses the token to perform network control on the network management device 21. With the above process, even if the communication path between the terminal device 101 and the application server 41 is changed, the application server 41 can perform network control on the network 20 that becomes the communication path, regarding communication between the application server 41 and the terminal device 101, and a unified network line environment can be obtained without being aware of the network operator 2.

[0082] In this embodiment, authentication of the application server 41 in the authentication server 31 is assumed to use OAuth 2.0, but other authentication methods such as OIDC (OpenID® Connect), OIDC-CIBA (OpenID® Connect Client-Initiated Backchannel Authentication), blockchain, etc. may also be used. The authentication information 44b stored in the storage unit 44 of the application server 41 and the authentication information 34a stored in the storage unit 34 of the authentication server will be the necessary information depending on the authentication method, such as a certificate or public key.

[0083] Furthermore, in this embodiment, when the application server 41 accepts a login from the terminal device 101, the application server 41 holds user information 44a and determines whether or not login is permitted. However, the application server 41 may be configured to have an external authentication server perform the authentication of the terminal device 101.

[0084] As described above, the service provision system 1 according to this embodiment comprises a terminal device 101 connected to a network 20, an application server 41 that provides services to the terminal device 101 via the network 20, a plurality of network management devices 21 that manage a plurality of networks 20 which serve as communication paths to the terminal device 101 for the services, and an authentication server 31 that authenticates the application server 41. When the application server 41 is authenticated by the authentication server 31, the network management device 21 authorizes the application server 41 to perform network control regarding communication between the application server 41 and the terminal device 101 in the network 20 managed by the network management device 21.

[0085] As a result, the application server 41 can perform unified network control over multiple networks 20 that serve as communication paths between the application server 41 and the terminal device 101, without having to be aware of multiple network operators 2.

[0086] Furthermore, the authentication server 31 authenticates the application server 41 based on an intermediary agreement c1 concluded with multiple network management devices 21, which mediates the authorization of network control to the application server 41 authenticated by the authentication server 31, and a user agreement c2 concluded with the application server 41, which provides authentication services and allows the application server 41 to use network control over the networks 20 managed by the multiple network management devices 21 that have entered into the intermediary agreement c1. As a result, the service provider 4 that manages the application server 41 can perform centralized network control over the multiple networks 20 that serve as communication paths between the application server 41 and the terminal device 101 without having to contract with multiple network providers 2.

[0087] Furthermore, when the authentication server 31 authenticates the application server 41, it issues a token to the application server 41. The application server 41 then transmits the token issued by the authentication server 31 to the network management device 21. The network management device 21 verifies the validity of the token, and if the token is valid, it authorizes the application server 41 to control the network. In this way, when the application server 41 transmits the token issued by the authentication server 31 to the network management device 21, the network management device 21 knows that the application server 41 has been authenticated by the authentication server 31. Therefore, the network management device 21 can authorize the authenticated application server 41 to control the network 20.

[0088] Furthermore, when the application server 41 is authenticated by the authentication server 31, the network management device 21 authorizes the application server 41 to access network information indicating the status of the network 20 managed by the network management device 21. This allows the application server 41 to obtain information about the network 20 managed by the network management device 21.

[0089] Furthermore, when the application server 41 is authenticated by the authentication server 31, the network control authorized by the network management device 21 to the application server 41 is the QoS control of network 20. This allows the application server 41 to perform unified QoS control over multiple networks 20 that serve as communication paths between the application server 41 and the terminal device 101, without having to be aware of multiple network operators 2.

[0090] Furthermore, when the application server 41 is authenticated by the authentication server 31, the network management device 21 authorizes the application server 41 to access network information indicating the status of the network 20 managed by the network management device 21. The application server 41 then uses the network information to determine the QoS profile of the network 20 and sends a request to the network management device 21 to set the QoS profile. This enables the application server 41 to perform QoS control appropriate to the status of the network 20 indicated by the network information.

[0091] The application server 41 according to this embodiment is an application server 41 that provides services to a terminal device 101 via a network 20, and comprises a communication path identification unit 43a that identifies the communication path to the terminal device 101 of the service, a storage unit 44 that stores authentication information 44b of the application server 41, and a communication unit 42 that transmits a control request for the network 20 and information indicating that it has been authenticated by the authentication information 44b to each of the multiple network management devices 21 that each manage the multiple networks 20 that serve as the communication path. With this configuration, the application server 41 can indicate to the network management device 21 that it has been authenticated and can receive authorization from the network management device 21 to control the network 20.

[0092] Furthermore, when the communication path identification unit 43a detects a change in the service's communication path, it identifies the changed communication path for the service, and the communication unit 42 of the application server 41 sends a control request for the network 20 and information indicating that it has been authenticated by authentication information to each of the multiple network management devices 21 that manage the multiple networks 20 that become the changed communication path. As a result, even if the communication path between the application server 41 and the terminal device 101 changes, the application server 41 can obtain authorization to control the network 20 that becomes the changed communication path.

[0093] The application server 41 program according to this embodiment implements the following functions: a function to identify the communication path to the service terminal device 101; a function to acquire information indicating that the application server 41 has been authenticated; and a function to send a control request for the network 20 and information indicating that it has been authenticated to each of the multiple network management devices 21 that manage each of the multiple networks 20 that serve as the communication path. Through these functions, the application server 41 can indicate to the network management devices 21 that it has been authenticated and can receive authorization from the network management devices 21 to control the network 20.

[0094] The method for controlling the network 20 in the service provision system 1 according to this embodiment includes the steps of: identifying the network 20 which is the communication path between the terminal device 101, which is the recipient of the service, and the application server 41 that provides the service; authenticating the application server 41 in the step of S20; and authorizing the authenticated application server 41 to control the network regarding communication between the application server 41 and the terminal device 101 on the network 20. With this control method, the application server 41 can indicate to the network management device 21 that it has been authenticated and can receive authorization from the network management device 21 to control the network 20.

[0095] Embodiment 2. Next, Embodiment 2 will be described. In this embodiment, the application server 41 cooperates with the cloud server 51 to determine the QoS profile. The cloud server 51 has a learning function and an inference function for inferring the QoS profile from network information and service content. In this embodiment, the configuration of the service provision system 1 and the functional configuration of each element of the service provision system 1 are the same as in Embodiment 1, so their description will be omitted.

[0096] Figure 14 is a functional configuration diagram of the cloud server 51 according to this embodiment. The cloud server 51 includes a communication unit 52 that connects to the network 20 and performs communication, a data acquisition unit 55 that acquires data necessary for determining the QoS profile from the application server 41 via the communication unit 52, a model generation unit 56 that performs learning using a learning algorithm, a trained model storage unit 54 that stores the generated trained model, and an inference unit 53 that performs QoS profile inference using the trained model. The data acquisition unit 55 and the model generation unit 56 function as learning devices that perform learning to infer the QoS profile from network information and service content. The data acquisition unit 55 and the inference unit 53 function as inference devices that infer the QoS profile using the trained model. In this embodiment, the inference unit 53 may output the QoS profile by performing a simulation without using the trained model.

[0097] The data acquisition unit 55 acquires network information of the network 20, the content of services provided to the terminal device 101, and a QoS profile, which is the content of QoS control for communication between the application server 41 and the terminal device 101 on the network 20, from the application server 41 via the communication unit 52 as training data. Network information includes, for example, information indicating the state of the network 20, such as network traffic information and bandwidth utilization. The content of services is the content of services that the application server 41 provides to the terminal device 101 via the network 20, such as voice calls, video viewing, or location information services. The content of services used as training data may also be information indicating a class corresponding to the content of the service. Information indicating a class indicates, for example, which class a service belongs to when it is classified based on whether it requires real-time performance or whether it has high priority. The data acquisition unit 55 also acquires information regarding the communication quality between the application server 41 and the terminal device 101, which will be used in the reward calculation described later, via the communication unit 52.

[0098] The model generation unit 56 learns the QoS profile of service communication suitable for the network state based on the learning data that is a combination of the network information acquired by the data acquisition unit 55, the content of the service, and the QoS profile. That is, a learned model for inferring an optimal QoS profile from the network information and the content of the service is generated.

[0099] The learning algorithm used by the model generation unit 56 can be a known algorithm such as supervised learning, unsupervised learning, reinforcement learning, etc. As an example, the case of applying reinforcement learning will be described. In reinforcement learning, an agent (acting entity) in a certain environment observes the current state (parameters of the environment) and determines the action to be taken. The action of the agent dynamically changes the environment, and the agent is given a reward according to the change of the environment. The agent repeats this and learns an action policy that can obtain the most rewards through a series of actions. As typical methods of reinforcement learning, Q-learning and TD-learning are known. For example, in the case of Q-learning, the general update formula of the action value function Q(s, a) is represented by Equation (1).

[0100]

[0101] In Equation (1), s t , t , t , t ,

[0102] , represents the state of the environment at time t, and a t represents the action at time t*. The action a t changes the state to s t+1 . r t+1 represents the reward obtained by the change of the state, γ represents the discount rate, and α represents the learning coefficient. Note that γ is in the range of 0 < γ ≤ 1, and α is in the range of 0 < α ≤ 1. The QoS control for the communication between the application server 41 and the terminal device 101 in the network 20 becomes the action a t , the network information and the content of the service become the state s t , and the best action a t in the state s t at time t is learned.

[0102] The update formula, represented by equation 1, increases the action value Q of action a if the action value Q of action a with the highest Q value at time t+1 is greater than the action value Q of action a performed at time t, and decreases the action value Q if the opposite is true. In other words, the action value function Q(s, a) is updated so that the action value Q of action a at time t approaches the best action value at time t+1. As a result, the best action value in a given environment is sequentially propagated to the action values ​​in previous environments.

[0103] As described above, when a trained model is generated by reinforcement learning, the model generation unit 56 includes a reward calculation unit 56a and a function update unit 56b.

[0104] The reward calculation unit 56a calculates the reward r based on the information regarding the communication quality between the application server 41 and the terminal device 101 acquired by the data acquisition unit 55. The information regarding communication quality includes, for example, whether the delay time and jitter set in the QoS profile were met, and the percentage of packet loss. If the delay time and jitter were met in the QoS profile, or if the percentage of packet loss was below a threshold, the reward r is increased by 1. On the other hand, if the delay time and jitter were not met in the QoS profile, or if the percentage of packet loss was above a threshold, the reward r is decreased by 1. The application on the terminal device 101 may also be configured to accept a communication quality evaluation of the service by the user 10 and send it to the application server 41. The application server 41 sends the communication quality evaluation to the communication unit 52. The reward calculation unit 56a increases the reward r if the communication quality evaluation is high, and decreases the reward r if the communication quality evaluation is low.

[0105] The function update unit 56b updates the function for determining the optimal QoS profile according to the reward calculated by the reward calculation unit 56a, and outputs it to the trained model storage unit 54. For example, in the case of Q learning, the action value function Q(s) represented by equation 1 is used. t , a t This function is used to calculate the QoS profile.

[0106] The learning process described above is repeated. The trained model memory unit 54 stores the action-value function Q(s) updated by the function update unit 56b. t , a t ), that is, it memorizes the trained model.

[0107] In order for the application server 41 to use the learning device and inference device on the cloud server 51, the service provider 4 and the cloud service provider 5 that provides the cloud service enter into a cloud service agreement c4. Figure 15 is a diagram showing the procedure flow for the cloud service agreement c4 that is concluded between the service provider 4 and the cloud service provider 5 according to this embodiment. An example of the contents of the cloud service agreement c4 will be explained with reference to Figure 15.

[0108] First, in c41, service provider 4 enters into a contract to use the cloud server 51 managed by cloud service provider 5.

[0109] Next, in c42, service provider 4 deploys the necessary learning / inference functions, simulator functions, etc., to the cloud server 51 managed by cloud service provider 5, making them available. The learning / inference functions and simulator functions provided by the cloud server 51 are implemented by service provider 4 using resources provided by cloud service provider 5. Alternatively, cloud service provider 5 may provide the learning / inference functions and simulator functions, and service provider 4 may configure input / output information, etc., so that they can be used from the application server 41.

[0110] Next, in c43, the cloud service provider 5 starts the service of the function deployed by the service provider 4.

[0111] Next, in c44, the cloud service provider 5 notifies the service provider 4 that it has started the cloud service.

[0112] Next, in c45, the cloud service provider 5 requests a connection test between the application server 41 and the cloud server 51 managed by the cloud service provider 5.

[0113] Next, at c45, the cloud server 51 managed by the cloud service provider 5 returns a response to the connection test request. With this, the cloud service contract between service provider 4 and cloud service provider 5 is concluded.

[0114] Through a cloud service agreement between service provider 4 and cloud service provider 5, application server 41 can use the learning device, inference device, and simulator functions implemented on cloud server 51 via the network 20. Furthermore, if cloud service provider 5 provides learning and inference functions, cloud service provider 5 may contract with multiple service providers 4 and perform learning to infer the optimal QoS profile from network information obtained from multiple application servers 41 and the content of the services.

[0115] Figure 16 is a flowchart showing the learning process of the learning device according to this embodiment. Using Figure 16, the process by which the learning device of the cloud server 51 learns the optimal QoS profile from network information and service content will be explained.

[0116] In step a1, the model generation unit 56 acquires the network information, service details, and QoS profile acquired by the data acquisition unit 55 as training data.

[0117] In step a2, the model generation unit 56 acquires information on communication quality acquired by the data acquisition unit 55 and a communication quality evaluation as information to be used for reward calculation.

[0118] In step a3, the model generation unit 56 calculates the reward based on the communication quality information and the communication quality evaluation. Specifically, the reward calculation unit 56a increases the reward if the delay time and jitter are within the limits set in the QoS profile, or if the packet loss rate is below a threshold (step a4), and decreases the reward if the delay time and jitter are not within the limits set in the QoS profile, or if the packet loss rate is above a threshold (step a5). Furthermore, the reward calculation unit 56a increases the reward if the communication quality evaluation is high (step a4), and decreases the reward if the communication quality evaluation is low (step a5). Note that the information used by the reward calculation unit 56a to increase or decrease the reward may be either the communication quality information or the communication quality evaluation, or only one of them.

[0119] In step a6, the function update unit 56b updates the action value function Q(s) represented by the number 1 stored in the trained model memory unit, based on the reward calculated by the reward calculation unit 56a, the network information, the service content, and the QoS profile. t , a t ) Update.

[0120] The learning device of the cloud server 51 repeatedly performs steps a1 to a6 above each time it acquires training data, and generates the action value function Q(s t , a t The model is stored as a trained model in the trained model storage unit 54. In this way, the model generation unit 56 learns the QoS profile using network information, service content, and QoS profile, and by calculating a reward using information on communication quality and communication quality evaluation.

[0121] Next, the inference unit 53 of the cloud server 51 will be described. The inference unit 53 uses the trained model stored in the trained model storage unit 54 to infer the optimal QoS profile. That is, by inputting network information and service details into the trained model, it is possible to infer a QoS profile suitable for the network state and the service.

[0122] In this embodiment, it has been described that the inference unit 53 outputs a QoS profile using a trained model learned by the model generation unit 56 of the cloud server 51. However, the model generation unit 56 and the inference unit 53 may be provided by different devices. For example, the application server 41 may acquire the trained model generated by the model generation unit 56 in the trained model storage unit 54 of the cloud server 51, and the application server 41 may output a QoS profile using the trained model.

[0123] Next, the process by which the inference unit 53 obtains the optimal QoS profile using the trained model will be explained. Figure 17 is a flowchart showing the optimal QoS profile inference process by the cloud server 51 according to this embodiment. Note that the optimal QoS profile inference process in Figure 17 corresponds to step S62 of the QoS profile determination process S30_2 in this embodiment, which will be described later.

[0124] First, in step b1, the inference unit 53 obtains network information and service details from the data acquisition unit 55.

[0125] In step b2, the inference unit 53 retrieves a trained model from the trained model storage unit 54, inputs network information and service details into the retrieved trained model, and outputs a QoS profile.

[0126] In step b3, the inference unit 53 transmits the QoS profile obtained by the trained model to the application server 41 via the communication unit 52. This completes the inference process on the cloud server 51.

[0127] In this embodiment, we have described the case where reinforcement learning is applied to the learning algorithm used by the model generation unit 56, but this is not the only possible case. In addition to reinforcement learning, supervised learning, unsupervised learning, or semi-supervised learning can also be applied to the learning algorithm.

[0128] Furthermore, the learning algorithm used in the model generation unit 56 may be deep learning, which learns to extract the features themselves, or machine learning may be performed according to other known methods, such as neural networks, genetic programming, inductive logic programming, or support vector machines.

[0129] Furthermore, the inference unit 53 may obtain the optimal QoS profile through simulation without using a pre-trained model. Figure 18 is a flowchart showing the QoS profile determination simulation process of the cloud server 51 according to this embodiment. Note that the QoS profile determination simulation process in Figure 18 corresponds to step S63 of the QoS profile determination process S30_2 in this embodiment, which will be described later.

[0130] First, in step b'1, the inference unit 53 obtains network information and service details from the data acquisition unit 55.

[0131] In step b'2, the inference unit 53 simulates communication in the service using the network state included in the network information. Based on the simulation results, it outputs the QoS profile for the case where the communication quality is highest.

[0132] In step b'3, the inference unit 53 transmits the QoS profile obtained from the simulation to the application server 41 via the communication unit 52. This completes the simulation process on the cloud server 51.

[0133] The process by which the application server 41 cooperates with the inference unit 53 of the cloud server 51 to obtain the optimal QoS profile will be explained. Figure 19 is a sequence diagram showing the details of the QoS profile determination process S30_2 by the application server 41 and the network management device 21 according to this embodiment. The QoS profile determination process S30_2 shown in Figure 19 is a process that replaces the QoS profile determination process S30 in the sequence diagram showing the control of the network 20 by the application server 41 when the terminal device 101 according to Embodiment 1 in Figure 7 executes an application. In Figure 19, processes that are the same as the QoS profile determination process S30 in Embodiment 1 are denoted by the same reference numerals, and the explanation is simplified.

[0134] First, in step S31, the application server 41 sends a QoS profile acquisition request to the network management device 21 along with the token issued by the authentication server 31.

[0135] Next, the network management device 21, having received the token and QoS profile acquisition request, queries the authentication server for the token in step S40. The process S40 in which the network management device 21 queries the authentication server 31 for the token is the same as in Figure 10 of Embodiment 1, so its explanation is omitted.

[0136] If the token query is successful, in step S32, the network management device 21 reads the QoS profile 24b and network information 24a from the storage unit 24.

[0137] Next, in step S33, the network management device 21 sends the QoS profile 24b and network information 24a to the application server 41 as a response to the QoS profile acquisition request.

[0138] Next, in step S60, the application server 41 determines a method for obtaining a QoS profile suitable for the service to be provided to the terminal device 101. The method of acquisition refers to inference using a trained model or output from a simulation. For example, if the application server 41 determines that the network 20, which is the communication path between the terminal device 101 and the application server 41, has been sufficiently trained by the learning device of the cloud server 51, it selects inference using a trained model. On the other hand, if the application server 41 determines that the network 20, which is the communication path between the terminal device 101 and the application server 41, has not been sufficiently trained, it selects output from a simulation. The application server 41 determines that the learning device has not been sufficiently trained when determining a QoS profile for the network management device 21, which manages the network 20 that has been used infrequently in communication between the application server 41 and the terminal device 101, either in the initial stages when the application server 41 has started providing the service or up to that point.

[0139] Next, in step S61, the application server 41 sends an optimal QoS profile acquisition request to the cloud server 51, along with the acquisition method, network information, and service details. The service details may be registered in advance with the cloud server 51.

[0140] Next, if the cloud server 51 receives a request to acquire an optimal QoS profile, and the acquisition method is inference using a trained model, it performs the optimal QoS profile inference process in step S62. On the other hand, if the acquisition method is output from a simulation, the cloud server 51 performs the QoS profile determination simulation process in step S63.

[0141] Next, in step S64, the cloud server 51 sends the QoS profile determined by the optimal QoS profile inference process in step S62 or the QoS profile determination simulation process in step S63 to the application server 41. This completes the QoS profile determination process in step S30_2.

[0142] In this embodiment, the application server 41 determines a QoS profile suitable for the network information and service content by inference or simulation using a trained model in cooperation with the cloud server 51. In inference using a trained model, the application server 41 can obtain a QoS profile that ensures the communication quality necessary to improve the user experience by using a trained model that has learned the network information, service content, and QoS control content. Furthermore, if the learning by the learning device is insufficient, the application server 41 can obtain a QoS profile suitable for the network information and service content by determining the QoS profile through simulation processing by the cloud server 51.

[0143] In this embodiment, the learning device for learning QoS profiles and the inference device for inferring QoS profiles are located on a cloud server 51, which is a separate device from the application server 41. However, the learning device for learning QoS profiles and the inference device for inferring QoS profiles may be configured as an integral part of the application server 41.

[0144] Furthermore, in this embodiment, the inference unit 53 of the cloud server 51 can determine the QoS profile through optimal QoS profile inference processing and QoS profile determination simulation processing. However, the inference unit 53 may be configured to execute only one of the optimal QoS profile inference processing or the QoS profile determination simulation processing.

[0145] As described above, the learning device according to this embodiment is communicatively connected to an application server 41 that provides services to a terminal device 101 via a network 20, and includes a data acquisition unit 55 that acquires learning data including network information indicating the state of the network 20, the content of the service, and the QoS profile of the communication via the network 20 related to the service, and a model generation unit 56 that uses the learning data to generate a trained model for inferring a QoS profile of the service communication suitable for the network state from the network information and the content of the service. With this configuration, the learning device can obtain a trained model for inferring a QoS profile suitable for the network state from the network information and the content of the service.

[0146] Furthermore, the inference device according to this embodiment is connected to an application server 41 that provides services to a terminal device 101 via a network 20, and includes a data acquisition unit 55 that acquires network information indicating the state of the network 20 and the content of services, and an inference unit 53 that uses a trained model for inferring a QoS profile from the network information to output a QoS profile of service communication that is suitable for the network state from the network information and the content of services acquired by the data acquisition unit 55. With this configuration, the inference device can acquire a QoS profile suitable for the network state from the network information and the content of services.

[0147] Embodiment 3. Next, Embodiment 3 will be described. In this embodiment, the range of network control authorized by the network management device 21 to the application server 41 increases or decreases depending on the state of the network 20. In this embodiment, the configuration of the service provision system 1, network management device 21, authentication server 31, application server 41, and terminal device 101 is the same as in Embodiment 1, so a description will be omitted.

[0148] In this embodiment, the authentication provider 3 and the network provider 2 enter into an intermediary agreement c1 in which the content of the control of the network 20 authorized to the authenticated application server 41 changes dynamically according to the state of the network 20.

[0149] Based on the intermediary agreement c1, the network management device 21 selects a QoS profile to authorize the application server 41 according to the state of the network 20. Figure 20 is a sequence diagram showing the details of the QoS profile determination process S30_3 by the application server 41 and the network management device 21 according to this embodiment. The QoS profile determination process S30_3 shown in Figure 20 is a process that replaces the QoS profile determination process S30 in the sequence diagram showing the control of the network 20 by the application server 41 when the terminal device 101 according to Embodiment 1 in Figure 7 executes an application. In Figure 20, processes identical to the QoS profile determination process S30 in Embodiment 1 are denoted by the same reference numerals to simplify the explanation.

[0150] First, in step S31, the application server 41 sends a QoS profile acquisition request to the network management device 21 along with the token issued by the authentication server 31.

[0151] Next, the network management device 21, having received the token and QoS profile acquisition request, queries the authentication server for the token in step S40. The process S40 in which the network management device 21 queries the authentication server 31 for the token is the same as in Figure 10 of Embodiment 1, so its explanation is omitted.

[0152] If the token query is successful, in step S32, the network management device 21 reads the QoS profile 24b and network information 24a from the storage unit 24.

[0153] Next, in step S70, the network management device 21 selects items to authorize the application server 41 from the QoS profile 24b according to the state of the network 20 indicated by the network information 24a. For example, if the bandwidth utilization rate included in the network information 24a is higher than a threshold, the network management device 21 omits the item in the QoS profile that sets whether or not to guarantee bandwidth. Also, for example, if the throughput included in the network information 24a is higher than a threshold, the network management device 21 prevents the allowable delay time from being set to 100 ms or less.

[0154] Next, in step S71, the network management device 21 sends a limited QoS profile to the application server 41 as a response to the QoS profile acquisition request, as selected in S70.

[0155] Next, in step S34, the application server 41, having received the QoS profile from the network management device 21, determines a QoS profile suitable for the service to be provided to the terminal device 101. At this time, in order to determine a QoS profile suitable for the service from the limited QoS profiles according to the state of the network 20 in step S71, the application server 41 controls the network 20 within the scope based on the intermediary contract c1. This concludes the QoS profile determination process in step S30_3.

[0156] As described above, the network management device 21 of the service provision system 1 according to this embodiment dynamically changes the content of the network control authorized to the application server 41 when the application server 41 is authenticated by the authentication server 31. As a result, the network management device 21 can efficiently allocate the resources of the network 20 to the application server 41 in accordance with the state of the network 20.

[0157] The configurations shown in the above embodiments are merely examples of the content of the present invention, and can be combined with other known technologies. It is also possible to omit or modify parts of the configuration without departing from the spirit of the present invention.

[0158] According to this disclosure, it is possible to provide a service provision system that performs network control to centrally realize the communication quality required by the application for the network that serves as the communication path for data transmitted and received between terminal devices and application servers.

[0159] 1 Service provision system, 2 Network operator, 3 Authentication operator, 4 Service operator, 5 Cloud service operator, 10 User, 17 Boundary router, 20 Network, 21 Network management device, 22 Communication unit, 23 Control unit, 24 Storage unit, 24a Network information, 24b QoS profile, 31 Authentication server, 32 Communication unit, 33 Control unit, 34 Storage unit, 34a Authentication information, 41 Application server, 42 Communication unit, 43 Control unit, 43a Communication path identification unit, 44 Storage unit, 44a User information, 44b Authentication information, 51 Cloud server, 52 Communication unit, 53 Inference unit, 54 Trained model storage unit, 55 Data acquisition unit, 56 Model generation unit, 56a Reward calculation unit, 56b Function update unit, 101 Terminal device, 102 Communication unit, 103 Control unit, 104 Storage unit, 104a Application data.

Claims

1. A service provision system comprising: a terminal device connected to a network; an application server that provides services to the terminal device via the network; a plurality of network management devices that manage a plurality of networks that serve as communication paths to the terminal device for the services; and an authentication server that authenticates the application server, wherein the network management device authorizes the application server to perform network control regarding communication between the application server and the terminal device on the network managed by the network management device when the application server is authenticated by the authentication server.

2. The service provision system according to claim 1, characterized in that the authentication server authenticates the application server based on an intermediary agreement concluded with a plurality of network management devices, which mediates the authorization of the network control to the application server authenticated by the authentication server, and a usage agreement concluded with the application server, which allows the application server to use the network control for the network managed by the plurality of network management devices that have entered into the intermediary agreement.

3. The service provision system according to claim 1 or 2, wherein the authentication server issues a token to the application server when it authenticates the application server, the application server transmits the token issued by the authentication server to the network management device, and the network management device verifies the validity of the token and, if the token is valid, authorizes the application server to control the network.

4. The service provision system according to any one of claims 1 to 3, wherein the network management device authorizes the application server to access network information indicating the state of the network managed by the network management device when the application server is authenticated by the authentication server.

5. The service provision system according to any one of claims 1 to 4, wherein the network control authorized by the network management device to the application server when the application server is authenticated by the authentication server is the QoS control of the network.

6. The service provision system according to claim 5, wherein the network management device authorizes the application server to access network information indicating the state of the network managed by the network management device when the application server is authenticated by the authentication server, and the application server determines the QoS profile of the network using the network information and sends a request to the network management device to set the QoS profile.

7. A learning device comprising: a data acquisition unit that is communicatively connected to an application server that provides services to terminal devices via a network, and acquires training data including network information indicating the state of the network, the content of the service, and a QoS profile of communication via the network relating to the service; and a model generation unit that uses the training data to generate a trained model for inferring the QoS profile of communication for the service that is suitable for the state of the network from the network information and the content of the service.

8. An inference device comprising: a data acquisition unit that is communicatively connected to an application server that provides services to terminal devices via a network, and acquires network information indicating the state of the network and the content of the service; and an inference unit that uses a trained model for inferring a QoS profile from the network information to output a QoS profile of the service communication that is suitable for the state of the network, based on the network information and the content of the service acquired by the data acquisition unit.

9. An application server that provides services to terminal devices via a network, comprising: a communication path identification unit that identifies the communication path of the service to the terminal device; a storage unit that stores authentication information of the application server; and a communication unit that transmits a network control request and information indicating that authentication has been performed using the authentication information to each of a plurality of network management devices that manage each of the plurality of networks that constitute the communication path.

10. The application server according to claim 9, wherein the communication path identification unit, when it detects a change in the communication path of the service, identifies the changed communication path of the service, and the communication unit transmits a network control request and information indicating that it has been authenticated by the authentication information to each of the multiple network management devices that manage each of the multiple networks that become the changed communication path.

11. A program for implementing the following functions in an application server that provides services to terminal devices via a network: a function to identify the communication path of the service to the terminal device; a function to obtain information indicating that the application server has been authenticated; and a function to send a network control request and the authentication information to each of the multiple network management devices that manage the multiple networks that constitute the communication path.

12. A method for controlling a network in a service provision system that provides services via a network, comprising: identifying the network which is the communication path between a terminal device that is the recipient of the service and an application server that provides the service; authenticating the application server; and authorizing the authenticated application server to control the network regarding communication between the application server and the terminal device on the network.

13. The service provision system according to claim 1 or 2, wherein the network management device dynamically changes the content of the network control authorized to the application server when the application server is authenticated by the authentication server.