Device for managing a terminal connection

By verifying the consistency of identifiers in signaling and media streams, the method enhances communication service security by rejecting unauthorized connections, effectively preventing impersonation attacks in video conferencing and similar real-time services.

FR3168306A3Pending Publication Date: 2026-05-08ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Utility models
Current Assignee / Owner
ORANGE SA
Filing Date
2024-11-07
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing communication services, particularly video conferencing, are vulnerable to impersonation attacks due to advancements in generative artificial intelligence that can simulate voices and faces, making it difficult to authenticate users effectively.

Method used

A method for managing terminal connections to communication services by verifying the consistency of two identifiers, one in the signaling and one in the media stream, using a management device that rejects connections if these identifiers do not match, enhancing security through encryption and timestamp verification.

Benefits of technology

This approach significantly strengthens communication security by ensuring that only authorized users can access services, even when faced with sophisticated impersonation attempts, by requiring multiple conditions to be met for unauthorized access to succeed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Connection Management Device for a Terminal The connection management device for a terminal (T1) to a communication service via at least one network comprises: - a receiving module configured to receive, from said terminal (T1), a first identifier (ID1) contained in a signal of said connection; - a rejecting module configured to reject the connection of said terminal if there is no match between the first identifier (ID1) and a second identifier (ID2) contained in at least one media stream of the communication service supported by the connection. Figure for the abbreviation: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Device for managing a terminal connection. Field of the invention

[0001] This invention relates to the field of telecommunications.

[0002] More specifically, the invention relates to a mechanism for securing a communication. Previous art

[0003] Technical developments in network equipment and audio and video compression solutions, and more recently the development of remote working methods, have contributed to developing and standardizing the use of video conferencing applications such as Teams, Zoom, etc.

[0004] Like many communication solutions, these applications have benefited from the development of security solutions common to many digital services, such as dual user and terminal identification, user identification via PKI (public key infrastructure) keys or via biometric data.

[0005] These solutions increase the protection of communication methods which are by nature, "normally" already secure due to the transmission of unique characteristics of the interlocutors, in particular their voice and, where applicable, their face, their gestures, etc.

[0006] Thus, even if a person can connect to a video conferencing service with the credentials of a third party, they are usually quickly unmasked as soon as their interlocutors notice that their voice and face do not match those of the person impersonated.

[0007] This situation, however, is being challenged by recent developments in generative artificial intelligence, which notably make it possible to simulate a person's voice and / or face and apply lip-syncing to a given text. Numerous instances have already occurred in which these developments have been exploited by malicious individuals to perpetrate all sorts of scams using communication methods perceived as secure by their users.

[0008] Object and summary of the invention

[0009] The invention notably remedies these drawbacks by proposing a method for managing a connection of a terminal to a communication service, via at least one network, said method being implemented by a management device and comprising:

[0010] - a step of receiving, from said terminal, a first identifier contained in a signal of said connection;

[0011] - in the absence of a match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection, a step of rejecting the connection of said terminal.

[0012] By "correspondence", we mean here that the identifiers are either identical or consistent with each other, that is to say that the association (or coupling) of these two identifiers is previously established, typically it is recognized as valid by the management system.

[0013] The pairing of two identifiers is, for example, recorded in a lookup table, a database, or a list accessible by the management system. Note that the first and second identifiers may be exclusively linked to each other, or conversely, a first, or respectively a second, identifier may be linked to several second, or respectively first, identifiers.

[0014] The invention advantageously allows for the verification of the identity of participants in a service based on two identifiers transmitted respectively by the signaling and the media stream associated with a connection to the service in question. It also offers the possibility of securing access to the communication service in a simple and effective manner. The invention is particularly, but not exclusively, applicable to real-time communication services during which multimedia streams are exchanged, such as a video conferencing service.

[0015] Indeed, a malicious person gaining unauthorized access must be able, in order to circumvent the invention, to: - identify and retrieve the first identifier, - be aware that a second identifier must be inserted into the media stream, - know the second identifier (is it the first identifier or a distinct identifier?) and / or ensure that the first and second identifiers match each other; - and finally, if necessary, know how to properly insert the first identifier into the signaling and / or the second identifier into the media stream (in which packet, according to which protocol and at what frequency, etc.).

[0016] All of these conditions contribute to increasing the security of communication services, and this at any time during the connection, the process being able to be implemented at the beginning of the connection and / or during the duration of the connection to the service communication, either recurrently or occasionally upon detection of a particular event.

[0017] The invention can be applied in different contexts, in which it may prove relevant to consider the identity of the two identifiers or their consistency.

[0018] For example, the management system may consider the consistency between two identifiers in a context where the same terminal can be shared between several users (such as a teleconferencing device in a meeting room or from any other public or semi-public terminal). In such a case, the first identifier may correspond to that of the terminal used and the second identifier to the user of said terminal (or vice versa). The correspondence between the two identifiers ensures that the user associated with the second identifier is authorized to use the terminal associated with the first identifier (for example, there may be a correspondence if the shared terminal associated with the first identifier is linked to the department of the user associated with the second identifier, or if the shared terminal associated with the first identifier is on the same site as the one where the user associated with the second identifier works).The correspondence between these two identifiers is, for example, recorded in a database listing all authorized user ID and terminal ID pairs, or conversely, user ID and terminal ID pairs that are not authorized or indicated as inconsistent with the connection management system.

[0019] Alternatively, the first and second identifiers can also correspond to each other according to a specific encoding algorithm allowing the second identifier to be obtained from the first (or vice versa).

[0020] Such an embodiment in which one focuses on identifiers that are consistent with each other (and not just identical) advantageously makes it possible to strengthen the security of communication services for which the invention is implemented by multiplying the protections opposing fraudulent access to such a service.

[0021] In a particular embodiment, the connection signaling conforms to the SIP protocol, Session Initiation Protocol.

[0022] This embodiment allows for simple implementation of the invention within existing communication services: the SIP session initialization protocol is widely used by Voice over IP services as well as for many other applications such as video conferencing, instant messaging, virtual reality, and even online video games. It is thus possible to ensure the security of a large number of communication services at a lower cost.

[0023] In a particular embodiment, the second identifier is transmitted in a payload of the media stream.

[0024] This embodiment advantageously simplifies the implementation of the invention within existing communication services by reusing data packets already used in the context of communication, such as communication services using RTP (Real-time Transport Protocol), RDP (Remote Desktop Protocol), or SRTP (Secure Real-time Transport Protocol) protocols.

[0025] Furthermore, by using the payload as a means of authentication, the invention allows for a connection security that is more complex to detect and therefore to circumvent than if the identifier were sent in a dedicated data packet and potentially easier to identify and intercept.

[0026] In a particular embodiment, the first identifier and the second identifier are taken from an identifier relating to the terminal and / or an identifier relating to the user of the terminal.

[0027] The first and second identifiers can thus be identifiers of the same nature (identical or consistent) or identifiers of different natures.

[0028] For example, the first identifier may be a terminal identifier and the second identifier a user identifier, or vice versa. This embodiment advantageously strengthens the security of a connection by using identifiers of different types, which are more difficult for a malicious third party to retrieve than two identifiers of the same type (for example, two user identifiers or two terminal identifiers).

[0029] This embodiment also offers stronger security, for example when a connection is established by a user from a terminal that is not in their usual use. Under such a scenario, it is then possible to trigger a third-party verification process, allowing, for example, the detection of whether someone has managed to impersonate the user associated with the second identifier or whether someone has gained access to a terminal associated with the first identifier, such as a meeting room telephone or a shared company computer.

[0030] In a particular embodiment, the connection management process includes a step of decrypting the first and second identifiers received using a public key from a trusted authority before analyzing their correspondence.

[0031] This embodiment increases communication security by multiplying the security techniques. It requires that a person wishing to circumvent the security process must know in advance the private key used to generate the first and second identifiers.

[0032] In a particular embodiment, said at least one media stream further includes timestamp information and the connection is rejected if the timestamp information is inconsistent with timestamp information expected by the management device.

[0033] Inconsistent timestamp information is defined here as timestamp information that is too far off (i.e., greater than a given threshold) from timestamp information known to the connection management device. For example, if the timestamp information contained in the media stream received by the connection management device indicates a time H1, and the connection management device receives this media stream at a time H2, such that H2-H1 is greater than the transit time of the media stream through the network R from the terminal to the management device.

[0034] Using timestamp information advantageously secures the communication service not only during its initialization, i.e. during the connection between the user and the communication service, but also over time, i.e. throughout the entire duration of the connection to the communication service.

[0035] This embodiment thus advantageously makes it possible to guard against cases where a pre-recorded video segment is used to simulate communication when the connection to the communication service has previously been secured by means of the invention or by any other method of securing a connection to a communication service known to a person skilled in the art.

[0036] According to another aspect, the invention also relates to a method of accessing a communication service via at least one network, implemented by a terminal and comprising: - a step of sending to a device, a first identifier in a signal of a connection to the communication service and a second identifier, corresponding to the first identifier, in a media stream of the communication service supported by the connection; and - a step of accessing the service via the connection.

[0037] The invention also relates to a device for managing a connection of a terminal to a communication service via at least one network, comprising: - a receiving module configured to receive, from said terminal, a first identifier contained in a signal of said connection; and - a rejecting module configured to, in the absence of a match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection, reject the connection of said terminal.

[0038] The invention also relates to a terminal configured to access a communication service via at least one network, said terminal comprising: - a sending module configured to send a first identifier in a signal of a connection associated with the service and a second identifier, corresponding to the first identifier, in a media stream supported by the connection, and - an access module configured to access the service via the connection.

[0039] The invention also relates to a system comprising: - a terminal according to the invention, configured to access a communication service via at least one network; - a management device according to the invention, configured to manage a connection of the terminal to the communication service via said at least one network.

[0040] For example, the management device can be integrated within a session controller of said at least one network, an application server managing the service in a network or a service platform.

[0041] The invention finally relates to computer programs, comprising program code instructions for implementing the processes according to any of the particular embodiments described above, when these programs are executed by a processor.

[0042] Such instructions can be stored permanently in a non-transient memory medium of terminals implementing the method of managing a connection or the method of accessing a communication service according to the invention.

[0043] This program may use any programming language, and be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0044] The invention also relates to a computer-readable information or recording medium on which computer programs as mentioned above are recorded.

[0045] The recording medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM (Read Only Memory), for example a CD ROM (Compact Disc Read-Only Memory) or a microelectronic circuit ROM, or a magnetic recording means, for example a mobile medium, a hard disk or an SSD (Solid State-Drive).

[0046] On the other hand, the recording medium can be a transmissible medium, such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means, so that the computer program(s) it contains can be executed remotely. The programs according to the invention can, in particular, be downloaded onto a network, for example, an Internet-type network.

[0047] Alternatively, the recording medium may be an integrated circuit in which one of the programs is incorporated, the circuit being adapted to execute or to be used in the execution of a method for managing a connection according to or a method for accessing a communication service according to the invention.

[0048] Furthermore, it can be envisaged, in other embodiments, that the processes, devices and system according to the invention present in combination all or part of the aforementioned characteristics. Brief description of the figures

[0049] Other features and advantages of the present invention will become apparent from the description given below, with reference to the attached figures which illustrate an example of an embodiment without any limiting character.

[0050] Figure [Fig. 1] represents, in its environment, a system according to the invention, in a particular embodiment,

[0051] Figure [Fig.2] schematically represents the hardware architecture of a connection management device according to one embodiment of the invention,

[0052] Figure [Fig.3] schematically represents the hardware architecture of a terminal connecting to a communication service according to one embodiment of the invention,

[0053] Figure [Fig.4] describes the steps of the processes for managing a connection and accessing a communication service according to one embodiment.

[0054] Description of the invention Description of a system conforming to the invention

[0055] Figure [Fig.1] represents, in its environment, a SYS system according to the invention, in a particular embodiment, said system being configured to implement the methods of managing a connection and access to a communication service according to the invention.

[0056] In the embodiment described here, the SYS system comprises at least one user terminal Tl and a management device DG, conforming to the invention and connected to a network R, for example a Wifi network or a fiber network.

[0057] Terminal Tl is, for example, a user's mobile terminal such as a smartphone or tablet, a computer or any other connected terminal known to a person skilled in the art.

[0058] Terminal Tl is configured to establish a connection with a communication service SC not shown in the figure, in order to allow its user to access the service in question. In the example considered here, the communication service SC is a video conferencing service based on the SIP session initiation protocol and the SDP protocol, known per se and as defined respectively in RFC 3261 entitled "SIP: Session Initiation Protocol", June 2002, and RFC 4566 entitled "SDP: Session Description Protocol", July 2006, published by the IETF. However, alternatively, it could also be a Voice over IP (Internet Protocol) service or any other communication service, known to a person skilled in the art and based on other protocols.

[0059] According to the invention, the DG management device is configured to manage a connection of the terminal Tl to the communication service SC.

[0060] This may be, for example, a network session controller (or SBC, Session Border Controller), such as, for example, a network element ensuring the security of telephony infrastructures, a firewall, an application server or a service platform, etc.

[0061] The communication service can be hosted on a terminal associated with the DG management device or on a third-party device not represented as a service platform or server.

[0062] The terminal Tl, the management device DG, and the platform managed by the communication service SC communicate with each other via the network R, which is, for example, a mobile telephone network or a fixed network (copper or fiber). It may be composed of one or more (sub-)networks such as, for example, Wi-Fi networks or mobile networks operated, where applicable, by the same operator or by different operators.

[0063] In accordance with the invention, the DG management device is equipped with: - of an MRC receiver module, and - of an MRJ rejection module.

[0064] The Tl terminal is equipped with: - a ME sending module, - an MA access module.

[0065] Figure 2 presents the simplified structure of the terminal Tl, configured to implement the process of accessing a communication service in a particular embodiment.

[0066] In this embodiment, the terminal Tl includes a sending and receiving module ER1 adapted to receive and send calls and information.

[0067] Furthermore, in the particular embodiment of the invention described herein, the steps executed by the terminal Tl, within the framework of implementing the connection management method of the present invention, are implemented by means of instructions from a computer program PG1. For this purpose, the terminal Tl has the classic architecture of a computer and includes, in particular, a memory MEM1, a processing unit UTR1, equipped, for example, with a processor PROC1, and controlled by the computer program PG1 stored in memory MEM1. The memory MEM1 is a medium of registration within the meaning of the invention. The computer program PG1 includes instructions for implementing the steps of the method of accessing a communication service according to the invention, which are described later with reference to the figure [Fig.4].

[0068] The PG1 program thus defines functional modules of the terminal Tl which include: - the ME sending module, which is configured to send a first identifier ID1 in a signal of a connection associated with the service and a second identifier ID2, corresponding to the first identifier, in a media stream associated with the connection, - the MA access module, which is configured to access the service via said connection.

[0069] The ID1 and ID2 identifiers may contain identification information relating to the terminal Tl (for example, terminal identification number, data relating to an organization or a department or service of an organization, physical location data of the terminal, a universal unique identifier, etc.) or relating to a user associated with the terminal (for example, name, surname, affiliation of the user to an organization or a department or a service of an organization, the user's access rights to services or terminals, etc.).

[0070] It is noted that the terminal Tl, via its identifiers, can be associated with a group of terminals for example a group of terminals linked to a given location or to a given organisation (or sub-organisation) such as for example a company or a particular department of a company.

[0071] In the example considered here, the identifiers ID1 and ID2 are chosen from among these identifiers, and ID1 corresponds to the identification number of the terminal and ID2 to the user pseudonym associated with the user of terminal Tl with the communication service SC. ID1 and ID2 are consistent and therefore correspond to each other.

[0072] Alternatively, the invention can be implemented with identical ID1 and ID2 identifiers.

[0073] It is assumed here that these identifiers in question were communicated to him prior to the connection with the SC communication service, for example during his registration with said SC communication service or by a third-party service.

[0074] Figure 3 presents the simplified structure of the DG management device configured to implement the connection management process in a particular embodiment.

[0075] In this embodiment, the DG device comprises an ER sending and receiving module adapted to receive and transmit calls and information. Furthermore, in the particular embodiment of the invention described herein, the The steps executed by the DG device, within the framework of implementing the connection management method of the present invention, are implemented by means of instructions in a computer program PG. For this purpose, the DG device has the classic architecture of a computer and includes, in particular, a memory memory (MEM), a processing unit (TU), equipped, for example, with a processor (PROC), and controlled by the computer program PG stored in the MEM memory. The MEM memory is a storage medium within the meaning of the invention. The computer program PG includes instructions for implementing the steps of the connection management method according to the invention, as described later with reference to Figure [Fig. 4].

[0076] The PG program defines functional modules of the connection management device which include in particular: - the MRC receiving module, which is configured to receive, from the Tl terminal, a first identifier contained in a connection signal. - the MRJ rejection module, which is configured to reject the connection from the TL terminal if there is no match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection.

[0077] Description of the main steps in the processes for managing a connection and accessing a communication service.

[0078] Figure [Fig. 4] describes the steps of the methods for managing a connection and accessing a communication service according to the invention in a particular embodiment in which the methods are implemented respectively by the management device DG and the terminal TL

[0079] In 200a, the terminal Tl sends the IDL identifier to the management device DG

[0080] This ID1 identifier is inserted by Tl into the signaling of the connection of terminal Tl to the communication service SC.

[0081] In the embodiment described here, the connection signaling conforms to the Session Initiation Protocol (SIP), and the ID1 identifier is contained in a proprietary field, such as, for example, of type x-pki_identity, which contains the encrypted ID1 identifier. However, the identifier may be contained in other fields of the SDP description protocol.

[0082] Alternatively, the connection signaling corresponds to a protocol other than SIP, such as H323, MGCP, IAX, etc. The identifier is inserted into the signaling exchanged in accordance with this protocol.

[0083] Following step 200a, in 200b, terminal Tl sends a second identifier ID2 to the management device DG. According to the invention, this identifier ID2 is sent by terminal Tl in a media stream, for example in the payload (or payload in English) of a media stream according to the RTP protocol (for example as defined by RFC 3550), to a predetermined location LocID2 by the terminal Tl in the context of the communication service SC and received by the connection management device DG.

[0084] Alternatively, the ID2 identifier is sent within a header field of the RTP packets.

[0085] For this purpose, a request to reserve resources dedicated to the identifier ID2 is produced upstream by the RTP protocol.

[0086] Alternatively, the terminal Tl can send a media stream according to an RDP (Remote Desktop Protocol), SRTP (Secure Real-time Transport Protocol) protocol as defined in RTP 3711, or any other real-time communication protocol known to the person skilled in the art.

[0087] The ID2 identifier can be sent once or several times in the media stream (for example at the beginning of connection to the service or recurrently, at a predetermined frequency, etc.).

[0088] Furthermore, the sending of the ID2 identifier in the media stream and the way in which it is sent in the media stream (in which content packet, at what frequency, etc.) are defined by the communication service and communicated upstream to the terminal Tl according to pre-established modalities (for example when the user registers for the communication service, when installing a client allowing connection to the communication service, etc.).

[0089] The ID2 identifier corresponds to the ID1 identifier (these identifiers may be identical or consistent).

[0090] In this embodiment, the ID2 identifier is further associated with a timestamp dT corresponding to the time at which the content packet in which the ID2 identifier is contained is formed. This timestamp data can also be encrypted.

[0091] To obtain this timestamp data (possibly encrypted), the terminal Tl can use an internal clock or make a request to an unrepresented third-party application server capable of providing a reference time. The third-party application server then sends the reference time, possibly encrypted (using a token if necessary to encrypt it), to the terminal Tl (a public key enabling decryption of the time data dT is then sent to the device DG). The terminal Tl then adds this time data dT, possibly encrypted, to the content data. It then sends the encrypted data to the device DG in accordance with the invention.

[0092] According to other embodiments, the ID2 identifier is not associated with such temporal data.

[0093] According to this embodiment, the identifiers ID1 and ID2 are further encrypted using an encryption solution. The terminal Tl can use a private key for this purpose, according to this embodiment.

[0094] This private key can be provided by a third party (communication operator, security service, trusted third party, etc.) to the terminal Tl by means of a PKI key, a smart card or contactless, etc., in a way known to the person skilled in the art and not detailed here.

[0095] The payload encryption uses the usual encryption mechanisms with a private key known to a person skilled in the art.

[0096] According to other embodiments, the ID1 and / or ID2 identifiers are not encrypted.

[0097] In E201a, the DG management device receives from terminal Tl the SIP signaling which contains the identifier ID1.

[0098] E201b, the DG management device receives the RTP stream from terminal Tl. The management device is configured to examine whether an ID2 identifier is contained in the RTP stream (located in LocID2 according to the example).

[0099] If the DG management device does not find the ID2 identifier in the RTP stream, the DG management device breaks the call.

[0100] In this embodiment, the identifiers ID1 and ID2 being encrypted using a private key by the terminal Tl, steps E201a and E201b further include a decryption operation, by DG device, of the identifiers using a public key received within a digital certificate and coming from a certification authority, (according to other embodiments, other decryption means associated with other solutions used by the terminal Tl to encrypt the identifiers ID1 and ID2 are used).

[0101] According to other embodiments, this decryption operation is performed only if one or the other of the identifiers ID1, ID2 is encrypted. Finally, the decryption operation is not performed if neither of the identifiers is encrypted.

[0102] In E202, the DG management device checks the correspondence of the ID1 and ID2 information. Depending on the case, the notion of correspondence means that the ID1 and ID2 data are identical or consistent with each other.

[0103] In this embodiment, the verification of the correspondence between the ID1 and ID2 information is performed several times during the connection of terminal Tl to the communication service. In this case, terminal Tl is pre-configured to send the second identifier in the media stream several times according to a pre-established procedure.

[0104] According to another embodiment, the verification of the correspondence of the ID1 and ID2 information is carried out only once, for example at the time of the connection of the terminal Tl to the communication service SC.

[0105] Consistency means that the data contained in ID1 and ID2 are not identical, but that the association of this data is indicated as being authorized by the DG management device. The information specifying that the association of this data is authorized is contained in the memory of the DG device, in a file, or in a database accessible to the DG management device. It may result from a prior configuration of the management device or be provided via a third-party document sent to the DG management device or made accessible on an unrepresented third-party device corresponding to a server or a database.

[0106] Example 1: ID1 contains data relating to a user (surname, first name, identification number, etc.) and ID2 contains the same data. The DG management system determines that the data in ID1 corresponds to the data in ID2 because they are identical. Otherwise, it concludes that the data do not match.

[0107] Example 2: ID1 contains data relating to terminal Tl, such as a unique identifier, and ID2 contains data relating to a user (name, surname, identification number, etc.). The DG connection management device verifies that the user designated in ID2 is authorized to use the terminal Tl designated in ID1 and infers that the data in ID1 corresponds to the data in ID2. This verification is performed, for example, by consulting lookup tables or a database indicating the users authorized to use terminal Tl or the terminals that the user identified by ID2 is authorized to use. Otherwise, it infers that the data do not match.

[0108] In the embodiment described here, the connection management device DG also compares the time data dT, contained in the media stream, to time data provided by an internal clock or by an unrepresented third-party device such as, for example, an application server capable of providing a time or reference time.

[0109] If the time data dT exhibits a deviation exceeding a predetermined threshold, then the connection management device DG determines that the ID1 and ID2 data do not match, regardless of the content of said data. This verification prevents the scenario where the media stream does not correspond to a direct stream, but to content recorded at a date and / or time different from the connection of terminal Tl to the communication service SC.

[0110] In E203, if the ID1 and ID2 data match, the management device establishes the connection of terminal Tl to the communication service SC. Similarly, since the process can be implemented throughout the connection of terminal Tl to the communication service, the management device maintains the connection of terminal Tl to the communication service in the case where the ID1 and ID2 data match each other and the timestamp data matches that expected by the management device.

[0111] If the ID1 and ID2 data do not match, the connection management process rejects or breaks the connection.

[0112] In this embodiment we have described the case where the identifier ID1 is transmitted to the management device by being contained in a field of the SDP session description protocol.

[0113] According to another embodiment, the ID1 identifier can be transmitted to the DG management device in a field of the SIP description protocol, for example the "Call-Info" field or in a custom or proprietary field.

[0114] According to another embodiment, the ID1 identifier corresponds to a functional identifier natively contained in the signaling of the connection of the terminal Tl to the communication service SC (for example, in the case of a SIP protocol, the "From" or "contact" field etc) and, in this case, the ID1 identifier is transmitted to the management device DG via this field.

[0115] It should be noted that if the ID1 identifier corresponds to the content of a functional field according to the SIP protocol and is transmitted to the management device via this functional field, the content of the field is encrypted only if this does not disrupt the connection according to the protocol.

Claims

Demands

1. Device for managing a connection of a terminal (Tl) to a communication service via at least one network, comprising: - a receiving module configured to receive, from said terminal (Tl), a first identifier (ID1) contained in a signal of said connection; - a rejecting module configured to, in the absence of a match between the first identifier (ID1) and a second identifier (ID2) contained in at least one media stream of the communication service supported by the connection, reject the connection of said terminal.

2. Connection management device according to claim 1 wherein the connection signaling conforms to the SIP protocol, Session Initiation Protocol.

3. Connection management device according to any one of the preceding claims wherein the second identifier (ID2) is transmitted in a media stream payload.

4. Connection management device according to any one of the preceding claims wherein the first identifier and the second identifier are taken from an identifier relating to the terminal and / or an identifier relating to the user of the terminal.