Method for managing a connection of a terminal, method for accessing a communication service, management device and terminal
By verifying the correspondence of identifiers from signaling and media streams, the method strengthens communication security against impersonation attacks, ensuring secure terminal connections in real-time services.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ORANGE SA
- Filing Date
- 2025-11-06
- Publication Date
- 2026-05-15
AI Technical Summary
Existing communication services, such as video conferencing, are vulnerable to impersonation attacks due to advancements in generative artificial intelligence that can simulate voices and faces, making it difficult to authenticate users and terminals securely.
A method for managing terminal connections to communication services that involves receiving and verifying two identifiers, one from signaling and one from a media stream, ensuring their correspondence or consistency, and rejecting connections if they do not match, using encryption and timestamp verification to enhance security.
This approach significantly enhances communication security by preventing unauthorized access, even when using pre-recorded media, and is applicable to real-time services like video conferencing, VoIP, and other multimedia exchanges.
Smart Images

Figure EP2025082152_15052026_PF_FP_ABST
Abstract
Description
Description Title: Method for managing a terminal connection, method for accessing a communication service, management device and terminal Scope of the invention
[0001] This invention relates to the field of telecommunications.
[0002] More specifically, the invention relates to a mechanism for securing communication. Previous art
[0003] Technical developments in network equipment and audio and video compression solutions, and more recently the development of remote working methods, have contributed to developing and standardizing the use of video conferencing applications such as Teams, Zoom, etc.
[0004] Like many communication solutions, these applications have benefited from the development of security solutions common to many digital services, such as dual user and terminal identification, user identification via PKI (public key infrastructure) keys or via biometric data.
[0005] These solutions enhance the protection of communication methods which are, by nature, "normally" already secure due to the transmission of unique characteristics of the interlocutors, including their voice and, where applicable, their face, gestures, etc.
[0006] Thus, even if a person can connect to a video conferencing service with the credentials of a third party, they are usually quickly unmasked as soon as their interlocutors notice that their voice and face do not match those of the person impersonated.
[0007] This situation, however, is increasingly being challenged by recent developments in generative artificial intelligence, which notably allows for the simulation of a person's voice and / or face, and the application of lip-syncing to a given text. Numerous instances have already occurred where these advancements have been exploited by malicious actors to perpetrate all sorts of scams using communication methods perceived as secure by their users. Object and summary of the invention
[0008] The invention remedies these drawbacks in particular by proposing a method for managing a terminal connection to a communication service, via at least one network, said method being implemented by a management device and comprising:
[0009] - a stage of receiving, from said terminal, a first identifier contained in a signal of said connection;
[0010] - in the absence of a match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection, a step of rejecting the connection of said terminal.
[0011] By "correspondence" we mean here that the identifiers are either identical or consistent with each other, that is to say that the association (or coupling) of these two identifiers is previously established, typically it is recognized as valid by the management system.
[0012] The pairing of two identifiers is, for example, recorded in a lookup table, a database, or a list accessible by the management system. Note that the first and second identifiers can be exclusively linked to each other, or conversely, a first and second identifier can be linked to several second and first identifiers.
[0013] The invention advantageously allows for the verification of the identity of participants in a service based on two identifiers transmitted respectively by the signaling and the media stream associated with a connection to the service in question. It also offers the possibility of securing access to the communication service in a simple and effective manner. The invention applies particularly, but not exclusively, to real-time communication services during which multimedia streams are exchanged, such as a video conferencing service.
[0014] Indeed, a malicious person gaining unauthorized access must be able, in order to circumvent the invention, to: - identify and retrieve the first identifier, - to be aware that a second identifier must be inserted into the media stream, - know the second identifier (is it the first identifier or a distinct identifier?) and / or ensure that the first and second identifiers match each other; - and finally, if necessary, know how to properly insert the first identifier into the signaling and / or the second identifier into the media stream (in which packet, according to which protocol and at what frequency, etc.).
[0015] All of these conditions contribute to increasing the security of communication services, and this at any time during the connection, the process can be implemented at the beginning of the connection and / or during the duration of the connection to the communication service, or on a recurring or ad hoc basis upon detection of a particular event.
[0016] The invention can be applied in different contexts, in which it may be relevant to consider the identity of the two identifiers or their consistency.
[0017] For example, the management system can consider the consistency between two identifiers in a context where the same terminal can be shared among several users (such as a teleconferencing device in a meeting room or from any other public or semi-public terminal). In such a case, the first identifier can correspond to that of the terminal used and the second identifier to the user of that terminal (or vice versa). The correspondence between the two identifiers ensures that the user associated with the second identifier is authorized to use the terminal associated with the first identifier (for example, there may be a match if the shared terminal associated with the first identifier is linked to the department of the user associated with the second identifier, or if the shared terminal associated with the first identifier is on the same site as the one where the user associated with the second identifier works).The correspondence between these two identifiers is, for example, recorded in a database listing all the. authorized user ID and terminal ID pairs or, conversely, user ID and terminal ID pairs that are not authorized or indicated as inconsistent with the connection management device.
[0018] Alternatively, the first and second identifiers can also correspond to each other according to a specific encoding algorithm allowing the second identifier to be obtained from the first (or vice versa).
[0019] Such an embodiment, in which one focuses on identifiers that are consistent with each other (and not just identical), advantageously strengthens the security of communication services for which the invention is implemented by multiplying the protections against fraudulent access to such a service.
[0020] In a particular embodiment, the connection signaling conforms to the SIP protocol, Session Initiation Protocol.
[0021] This embodiment allows for simple implementation of the invention within existing communication services: the SIP session initialization protocol is widely used by Voice over IP services as well as for many other applications such as video conferencing, instant messaging, virtual reality, and even online video games. It is thus possible to ensure the security of a large number of communication services at a lower cost.
[0022] In one particular embodiment, the second identifier is transmitted in a payload of the media stream.
[0023] This embodiment advantageously simplifies the implementation of the invention within existing communication services by reusing data packets already used in communication, such as communication services using RTP (Real-time Transport Protocol), RDP (Remote Desktop Protocol), or SRTP (Secure Real-time Transport Protocol) protocols.
[0024] Furthermore, by using the payload as a means of authentication, the invention allows for a connection security that is more complex to detect and therefore to bypass than if the identifier were sent in a dedicated data packet and potentially easier to identify and intercept.
[0025] In a particular embodiment, the first identifier and the second identifier are taken from an identifier relating to the terminal and / or an identifier relating to the user of the terminal.
[0026] The first and second identifiers can therefore be identifiers of the same nature (identical or consistent) or identifiers of different natures.
[0027] For example, the first identifier could be a terminal identifier and the second identifier a user identifier, or vice versa. This implementation advantageously strengthens the security of a connection by using identifiers of different types, which are more difficult for a malicious third party to retrieve than two identifiers of the same type (for example, two user identifiers or two terminal identifiers).
[0028] This implementation also offers stronger security, for example, when a user connects from a device they have not used in a particular way. Under such a scenario, it is possible to trigger a third-party verification process, allowing, for example, detection of whether someone has managed to impersonate the user associated with the second identifier or whether someone has gained access to a device associated with the first identifier, such as a meeting room phone or a shared company computer.
[0029] In a particular embodiment, the connection management process includes a step of decrypting the first and second identifiers received using a public key from a trusted authority before analyzing their correspondence.
[0030] This implementation method increases communication security by multiplying security techniques. It requires anyone wishing to bypass the security process to know in advance the private key used to generate the first and second identifiers.
[0031] In a particular embodiment, said at least one media stream further includes timestamp information, and the connection is rejected if the timestamp information is inconsistent with timestamp information expected by the management system.
[0032] Inconsistent timestamp information refers to timestamp information that is significantly different (i.e., greater than a given threshold) from a known timestamp information held by the connection management device. For example, if the timestamp information contained in the media stream received by the connection management device indicates a time H1, and the connection management device receives this media stream at a time H2, such that H2-H1 is greater than the transit time R of the media stream from the terminal to the management device.
[0033] Using timestamp information makes it advantageous to secure the communication service not only during its initialization, i.e. during the connection between the user and the communication service, but also over time, i.e. throughout the entire duration of the connection to the communication service.
[0034] This embodiment thus makes it advantageous to guard against cases where a pre-recorded video segment is used to simulate communication when the connection to the communication service has previously been secured by means of the invention or any other method of securing a connection to a communication service known to a person skilled in the art.
[0035] In another aspect, the invention also relates to a method for accessing a communication service via at least one network, implemented by a terminal and comprising: - a step of sending to a device, a first identifier in a signal of a connection to the communication service and a second identifier, corresponding to the first identifier, in a media stream of the communication service supported by the connection; and - a step of accessing the service via the connection.
[0036] The invention also relates to a device for managing a connection from a terminal to a communication service via at least one network, comprising: - a receiving module configured to receive, from said terminal, a first identifier contained in a signal of said connection; and - a rejection module configured to reject the connection of said terminal if there is no match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection.
[0037] The invention also relates to a terminal configured to access a communication service via at least one network, said terminal comprising: - a sending module configured to send a first identifier in a signal of a connection associated with the service and a second identifier, corresponding to the first identifier, in a media stream supported by the connection, and - an access module configured to access the service via the connection.
[0038] The invention also relates to a system comprising: - a terminal according to the invention, configured to access a communication service via at least one network; - a management device according to the invention, configured to manage a connection of the terminal to the communication service via said at least one network.
[0039] For example, the management device can be integrated within a session controller of said at least one network, an application server managing the service in a network, or a service platform.
[0040] The invention also relates to computer programs, comprising program code instructions for implementing processes according to any of the particular embodiments described above, when these programs are executed by a processor.
[0041] Such instructions can be stored permanently in a non-transient memory medium of terminals implementing the method of managing a connection or the method of accessing a communication service according to the invention.
[0042] This program can use any programming language, and be in the form of source code, object code, or code somewhere between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0043] The invention also relates to a computer-readable information or recording medium on which computer programs such as mentioned above.
[0044] The recording medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM (Read Only Memory), for example a CD ROM (Compact Disc Read-Only Memory) or a microelectronic circuit ROM, or a magnetic recording means, for example a mobile medium, a hard disk drive or an SSD (Solid State-Drive).
[0045] On the other hand, the recording medium can be a transmissible medium, such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means, so that the computer program(s) it contains can be executed remotely. The programs according to the invention can, in particular, be uploaded to a network, for example, an Internet-type network.
[0046] Alternatively, the recording medium may be an integrated circuit in which one of the programs is incorporated, the circuit being adapted to execute or to be used in the execution of a method for managing a connection according to or a method for accessing a communication service according to the invention.
[0047] Furthermore, in other embodiments, it is possible to consider that the processes, devices and system according to the invention present in combination all or part of the aforementioned characteristics. Brief description of the figures
[0048] Other features and advantages of the present invention will become apparent from the description given below, with reference to the attached figures which illustrate an example of an embodiment without any limiting character.
[0049] Figure [Fig. 1] represents, in its environment, a system according to the invention, in a particular embodiment,
[0050] Figure [Fig. 2] schematically represents the hardware architecture of a connection management device according to one embodiment of the invention,
[0051] Figure [Fig. 3] schematically represents the hardware architecture of a terminal connecting to a communication service according to one embodiment of the invention,
[0052] Figure [Fig. 4] describes the steps of the processes for managing a connection and accessing a communication service according to one embodiment. Description of the invention
[0053] Description of a system conforming to the invention
[0054] Figure [Fig. 1] represents, in its environment, a SYS system according to the invention, in a particular embodiment, said system being configured to implement the methods of managing a connection and accessing a communication service according to the invention.
[0055] In the embodiment described here, the SYS system comprises at least one user terminal Tl and a management device DG, conforming to the invention and connected to a network R, for example a Wifi network or a fiber network.
[0056] The terminal Tl is, for example, a user's mobile terminal such as a smartphone or tablet, a computer, or any other connected terminal known to a person skilled in the art.
[0057] Terminal Tl is configured to establish a connection with a communication service (SC) not shown in the figure, in order to allow its user to access that service. In the example considered here, the communication service (SC) is a video conferencing service based on the Session Initiation Protocol (SIP) and the Session Description Protocol (SDP), both well-known and defined respectively in RFC 3261, "SIP: Session Initiation Protocol," June 2002, and RFC 4566, "SDP: Session Description Protocol," July 2006, published by the 1TETF. Alternatively, however, it could also be a Voice over IP (VoIP) service or any other communication service, known to those skilled in the art, that relies on other protocols.
[0058] According to the invention, the DG management device is configured to manage a connection from terminal Tl to the SC communication service.
[0059] This could be, for example, a network session controller (or SBC, Session Border Controller), such as a network element ensuring the security of telephony infrastructure, a firewall, an application server, or a platform. service, etc.
[0060] The communication service can be hosted on a terminal associated with the DG management device or on a third-party device not represented as a service platform or server.
[0061] The terminal Tl, the management device DG, and the platform managed by the communication service SC communicate with each other via the network R, which is, for example, a mobile telephone network or a fixed network (copper or fiber). It may consist of one or more (sub)networks such as, for example, Wi-Fi networks or mobile networks, possibly operated by the same operator or by different operators.
[0062] According to the invention, the DG management device is equipped with: - of an MRC receiver module, and - of an MRJ rejection module.
[0063] The Tl terminal is equipped with: - of an ME sending module, - of an MA access module.
[0064] Figure 2 presents the simplified structure of the Tl terminal, configured to implement the process of accessing a communication service in a particular embodiment.
[0065] In this embodiment, the terminal Tl includes an ER1 sending and receiving module adapted to receive and transmit calls and information.
[0066] Furthermore, in the particular embodiment of the invention described herein, the steps executed by the terminal Tl, within the framework of implementing the connection management method of the present invention, are implemented by means of instructions in a computer program PG1. To this end, the terminal Tl has the classic architecture of a computer and includes, in particular, a memory MEM1, a processing unit UTR1, equipped, for example, with a processor PROC1, and controlled by the computer program PG1 stored in memory MEM1. The memory MEM1 is a storage medium within the meaning of the invention. The computer program PG1 includes instructions for implementing the steps of the method for accessing a communication service according to the invention, which are described later with reference to figure [Fig. 4],
[0067] The PG1 program thus defines functional modules of the Tl terminal which include: - the ME sending module, which is configured to send a first identifier ID1 in a signal of a connection associated with the service and a second identifier ID2, corresponding to the first identifier, in a media stream associated with the connection, - the MA access module, which is configured to access the service via said connection.
[0068] The ID1 and ID2 identifiers may contain identification information relating to the terminal Tl (for example, terminal identification number, data relating to an organization or department or service of an organization, physical location data of the terminal, a universal unique identifier, etc.) or relating to a user associated with the terminal (for example, name, surname, affiliation of the user to an organization or department or service of an organization, access rights of the user to services or terminals, etc.).
[0069] Note that the terminal Tl, via its identifiers, can be associated with a group of terminals, for example a group of terminals linked to a given location or to a given organization (or sub-organization) such as a company or a particular department of a company.
[0070] In the example considered here, ID1 and ID2 are chosen from among these identifiers, and ID1 corresponds to the terminal identification number and ID2 to the user pseudonym associated with the terminal user Tl with the SC communication service. ID1 and ID2 are consistent and therefore correspond to each other.
[0071] Alternatively, the invention can be implemented with identical ID1 and ID2 identifiers.
[0072] It is assumed here that these identifiers in question were communicated to him prior to the connection with the SC communication service, for example during his registration with said SC communication service or by a third-party service.
[0073] Figure 3 presents the simplified structure of the DG management device configured to implement the connection management process in a mode particular implementation.
[0074] In this embodiment, the DG device includes a send and receive module ER adapted to receive and transmit calls and information. Furthermore, in the particular embodiment of the invention described herein, the steps performed by the DG device, within the framework of implementing the connection management method of the present invention, are implemented by means of instructions in a computer program PG. For this purpose, the DG device has the classic architecture of a computer and includes, in particular, a memory memory (MEM), a processing unit (TU), equipped, for example, with a processor (PROC), and controlled by the computer program PG stored in memory memory. The memory memory (MEM) is a storage medium within the meaning of the invention. The computer program PG includes instructions for implementing the steps of the connection management method according to the invention, as described later with reference to Figure [Fig. 4].
[0075] The PG program defines functional modules of the connection management system which include in particular: - the MRC receiving module, which is configured to receive, from the Tl terminal, a first identifier contained in a connection signal. - the MRJ rejection module, which is configured to reject the connection from the TL terminal if there is no match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection.
[0076] Description of the main steps in the processes of managing a connection and accessing a communication service.
[0077] Figure [Fig. 4] describes the steps of the methods for managing a connection and accessing a communication service according to the invention in a particular embodiment in which the methods are implemented respectively by the management device DG and the terminal TL
[0078] In 200a, the terminal Tl sends the ID1 identifier to the DG management device.
[0079] This ID1 identifier is inserted by Tl into the signaling of the connection of the terminal Tl to the SC communication service.
[0080] In the embodiment described here, connection signaling conforms to the Session Initiation Protocol (SIP), and the ID1 identifier is contained in a proprietary field, such as x-pki_identity, which contains the encrypted ID1 identifier. However, the identifier can also be contained in other fields of the SDP description protocol.
[0081] Alternatively, the connection signaling corresponds to a protocol other than SIP, such as H323, MGCP, IAX, etc. The identifier is inserted into the signaling exchanged in accordance with this protocol.
[0082] Following step 200a, in 200b, the terminal Tl sends a second ID2 identifier to the management device DG. According to the invention, this ID2 identifier is sent by the terminal Tl in a media stream, for example in the payload of a media stream according to the RTP protocol (for example as defined by RFC 3550), to a predetermined location LocID2 by the terminal Tl in the context of the communication service SC and received by the connection management device DG.
[0083] Alternatively, the ID2 identifier is sent within a header field of the RTP packets.
[0084] For this purpose, a request to reserve resources dedicated to the ID2 identifier is generated upstream by the RTP protocol.
[0085] Alternatively, the Tl terminal can send a media stream using an RDP (Remote Desktop Protocol), SRTP (Secure Real-time Transport Protocol) protocol as defined in RTP 3711, or any other real-time communication protocol known to the person skilled in the art.
[0086] The ID2 identifier can be sent once or several times in the media stream (for example at the beginning of connection to the service or recurrently, at a predetermined frequency, etc.).
[0087] Furthermore, the sending of the ID2 identifier in the media stream and the method of sending it (in which content packet, at what frequency, etc.) are defined by the communication service and communicated upstream to the terminal Tl according to pre-established procedures (for example, upon user registration to the communication service, during the installation of a client enabling...). connect to the communication service, etc).
[0088] The ID2 identifier corresponds to the ID1 identifier (these identifiers may be identical or consistent).
[0089] In this embodiment, the ID2 identifier is further associated with a timestamp dT corresponding to the time at which the content packet containing the ID2 identifier is formed. This timestamp data can also be encrypted.
[0090] To obtain this timestamp data (possibly encrypted), the terminal Tl can use an internal clock or request a reference time from an unrepresented third-party application server capable of providing a reference time. The third-party application server then sends the reference time, possibly encrypted (using a token if necessary for encryption), to the terminal Tl. A public key enabling decryption of the time data dT is then sent to the device DG. The terminal Tl then adds this time data dT, possibly encrypted, to the content data. It then sends the encrypted data to the device DG in accordance with the invention.
[0091] According to other embodiments, the ID2 identifier is not associated with such temporal data.
[0092] According to this embodiment, the identifiers ID1 and ID2 are further encrypted using an encryption solution. Terminal Tl can use a private key for this purpose, according to this embodiment.
[0093] This private key can be provided by a third party (communication operator, security service, trusted third party, etc.) to the Tl terminal by means of a PKI key, a smart card or contactless, etc., in a way known to the person skilled in the art and not detailed here.
[0094] Payload encryption uses standard encryption mechanisms with a private key known to a person skilled in the art.
[0095] According to other embodiments, the ID1 and / or ID2 identifiers are not encrypted.
[0096] In E201a, the DG management system receives from terminal Tl the SIP signaling that contains the identifier ID1.
[0097] E201b, the DG management device receives the RTP stream from terminal Tl. The management device is configured to check if an ID2 identifier is contained in the RTP stream (located in LocID2 as shown in the example).
[0098] If the DG management device does not find the ID2 identifier in the RTP stream, the DG management device breaks the call.
[0099] In this embodiment, the identifiers ID1 and ID2 are encrypted using a private key by the terminal Tl, steps E201a and E201b further include a decryption operation, by DG device, of the identifiers using a public key received within a digital certificate and from a certification authority, (according to other embodiments, other decryption means associated with other solutions used by the terminal Tl to encrypt the identifiers ID1 and ID2 are used).
[0100] In other embodiments, this decryption operation is performed only if one or the other of the identifiers ID1, ID2 is encrypted. Finally, the decryption operation is not performed if neither identifier is encrypted.
[0101] In E202, the DG management system checks the correspondence of the ID1 and ID2 information. Depending on the case, the notion of correspondence means that the ID1 and ID2 data are identical or consistent with each other.
[0102] In this embodiment, the verification of the correspondence between ID1 and ID2 is performed several times during the connection of terminal Tl to the communication service. In this case, terminal Tl is pre-configured to send the second identifier in the media stream several times according to a pre-established procedure.
[0103] According to another embodiment, the verification of the correspondence of the ID1 and ID2 information is carried out only once, for example at the time of the connection of the terminal Tl to the communication service SC.
[0104] Consistency means that the data contained in ID1 and ID2 are not identical, but that the association of this data is indicated as being authorized by the DG management system. The information specifying that the association of these The data that is authorized is contained in the memory of the DG device, in a file or in a database accessible to the DG management device. It may result from a prior configuration of the management device or be entered via a third-party document sent to the DG management device or made accessible on an unrepresented third-party device corresponding to a server or a database.
[0105] Example 1: ID1 contains user data (name, surname, identification number, etc.) and ID2 contains the same data. The DG management system determines that the data in ID1 corresponds to the data in ID2 because they are identical. Otherwise, it concludes that the data does not match.
[0106] Example 2: ID1 contains data relating to the terminal Tl, such as a unique identifier, and ID2 contains data relating to a user (name, surname, identification number, etc.). The DG connection management system verifies that the user designated in ID2 is authorized to use the terminal Tl designated in ID1 and infers that the data in ID1 corresponds to the data in ID2. This verification is performed, for example, by consulting lookup tables or a database indicating the users authorized to use the terminal Tl or the terminals that the user identified by ID2 is authorized to use. Otherwise, it infers that the data does not match.
[0107] In the embodiment described here, the connection management device DG also compares the time data dT, contained in the media stream, to time data provided by an internal clock or by an unrepresented third-party device such as an application server capable of providing a time or reference time.
[0108] If the time data dT differs from a predetermined threshold, then the connection management device DG determines that the ID1 and ID2 data do not match, regardless of their content. This verification prevents the media stream from being a live stream, instead of content recorded at a different date and / or time than the terminal Tl's connection to the communication service SC.
[0109] In E203, if ID1 and ID2 match, the management device establishes the connection of terminal Tl to the SC communication service. Similarly, since the process can be implemented throughout the connection of terminal Tl to the communication service, the management device maintains the connection of terminal Tl to the communication service if ID1 and ID2 match and the timestamp data corresponds to that expected by the management device.
[0110] If the ID1 and ID2 data do not match, the connection management process rejects or breaks the connection.
[0111] In this embodiment we have described the case where the identifier ID1 is transmitted to the management device by being contained in a field of the SDP session description protocol.
[0112] According to another embodiment, the ID1 identifier can be transmitted to the DG management device in a field of the SIP description protocol, for example the "Call-Info" field or in a custom or proprietary field.
[0113] According to another embodiment, the ID1 identifier corresponds to a functional identifier natively contained in the signaling of the connection of the terminal Tl to the communication service SC (for example, in the case of a SIP protocol, the "From" or "contact" field etc) and, in this case, the ID1 identifier is transmitted to the management device DG via this field.
[0114] It should be noted that if the ID1 identifier corresponds to the content of a functional field according to the SIP protocol and is transmitted to the management device via this functional field, the content of the field is encrypted only if this does not disrupt the connection according to the protocol.
Claims
Demands
1. A method for managing a connection from a terminal (Tl) to a communication service, via at least one network (R), said method being implemented by a management device (DG) and comprising: - a reception step, from said terminal (Tl), of a first identifier (ID1) contained in a signal of said connection, - in the absence of a match between the first identifier (ID1) and a second identifier (ID2) contained in at least one media stream of the communication service supported by the connection, a step of rejecting the connection of said terminal.
2. A method of managing a connection according to claim 1 wherein the connection signaling conforms to the SIP protocol, Session Initiation Protocol.
3. A method for managing a connection according to any of the preceding claims in which the second identifier (ID2) is transmitted in a payload of the media stream.
4. A method for managing a connection according to any one of the preceding claims in which the first identifier and the second identifier are taken from an identifier relating to the terminal and / or an identifier relating to the user of the terminal.
5. A method for managing a connection according to any of the preceding claims comprising a step of decrypting the first and second identifiers (ID1, ID2) received using a public key from a trusted authority before analyzing their correspondence.
6. A method of managing a connection according to any one of the preceding claims, wherein said at least one media stream further includes timestamp information and wherein said connection is rejected if said timestamp information is inconsistent with timestamp information expected by said management device.
7. A method for accessing a communication service via at least one network, implemented by a terminal and comprising: - a step of sending to a device, a first identifier (ID1) in a signal of a connection to the communication service and a second identifier (ID2), corresponding to the first identifier, in a media stream of the communication service supported by the connection; and - a step of accessing the service via said connection.
8. Device for managing a connection of a terminal (Tl) to a communication service via at least one network, comprising: - a receiving module configured to receive, from said terminal (Tl), a first identifier (ID1) contained in a signal of said connection; - a rejection module configured to, in the absence of a match between the first identifier (ID1) and a second identifier (ID2) contained in at least one media stream of the communication service supported by the connection, reject the connection of said terminal.
9. Terminal (Tl) configured to access a communication service via at least one network, said terminal comprising: - a sending module configured to send a first identifier (ID1) contained in a connection signal and a second identifier (ID2), corresponding to the first identifier, contained in a media stream of the communication service supported by the connection, - an access module configured to access the service via said connection.
10. System (SYS) comprising: - a terminal according to claim 9 configured to access a communication service via at least one network; and - a management device according to claim 8 configured to manage a connection of said terminal to said communication service via said at least one network.
11. System according to claim 10 wherein the management device is integrated within a session controller of said at least one network, or of an application server managing the service in a network or service platform.