Method for controlling an insertion of ancillary data within at least one packet of data correlated to application data
Patent Information
- Application Number
- PCT/EP2026/054290
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-18
- Filing Date
- 2026-02-17
- Publication Date
- 2026-08-27
Smart Images

Figure EP2026054290_27082026_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Method for controlling the insertion of supplementary data within at least one data packet correlated with application data
[0003] technical field
[0004] The invention lies in the field of communication networks, and more particularly in that of IP networks (from the English "Internet Protocol").
[0005] Previous art
[0006] With the massive use of communication means, the improvement of transmission rates, the proliferation of applications and services, and the multiplication and sophistication of the underlying technological building blocks (such as those supported by terminals, intermediate networks, data centers, etc.), it has become common for additional data to be generated in correlation with application data packets (typically inserted into application data packets) routed via a communication network, generally without the knowledge of the users or the application that originated this application data.Such additional data - which can also be described as ancillary data in that it is not necessary for the provision of the service or specific to the application or the user - can for example be used for statistical purposes, monitoring and quality assurance of packet routing (as is the case for example with techniques such as "In-band OAM" or "In-situ Telemetry"), or for the provision of complementary services (for example a functional chaining of the type "Service Function Chaining (SFC)").
[0007] In many cases, although associated with an application data package generated by an application, this ancillary data is not part of the data necessary for the application's operation. In some cases, it can be used to optimize data routing through intermediate networks. However, it is likely to disclose information that falls under a user's privacy, or at the very least, circumvent certain application measures implemented specifically to protect access to data that a user might wish to keep private. As an example of such an application measure, an application might encrypt the application data it generates to prevent an entity within an intermediate communication network from accessing and exploiting it in plaintext.An application can also modulate the application data it transmits to prevent such an entity from identifying the application associated with those data packets through profiling techniques or the use of templates (or "traffic patterns"). However, these application measures can be rendered less effective, or even completely ineffective, if the operating system of the communication terminal running the application enriches (by default) the application data packets with unencrypted ancillary data (for example, via IPv4 options, IPv6 extensions, TCP options, UDP options, or application headers) that discloses, for example, the user's identity, their practices, or the nature of the application.In general, supplementary data is also likely to be inserted during the routing of application data by equipment on a communication network, or even by the receiving terminal itself (typically a remote server), before, for example, sending a response to a request received from the application. Information disclosed by a remote terminal can facilitate the correlation of exchanged packets and thus reveal information characteristic of the application or even the user. It should be noted that several remote terminals can be involved in the same communication (for example, for a broadcast service or, more generally, point-to-multipoint communications). Similarly, the applications involved can be of various types (bidirectional, unidirectional, point-to-point, point-to-multipoint, etc.).) or even rely on different modes of transport (a single connection, a multiple connection established via multiple paths, multiple connections per path, etc.).
[0008] Such ancillary data can be used by a remote terminal for traceability or profiling purposes, or by an entity in the communication network located on one of the paths used by application data to extract sensitive data and share it with a dedicated service platform for uses that may not be consented to by the user.
[0009] Therefore, there is a need for a solution that allows for better control of the insertion of ancillary data within all or part of the data packets correlated with application data exchanged during the operation of an application. Summary of the invention
[0010] The present invention describes a solution to overcome certain drawbacks of the prior art. In one aspect, the present invention relates to a method for controlling the insertion of supplementary data within at least one data packet correlated with application data generated by an application running on a communication terminal. Such a method comprises, prior to transmitting said at least one data packet to at least one remote terminal via a communication network, the processing of said at least one data packet by an operating system of said communication terminal, according to a supplementary data insertion control policy.
[0011] In this way, the user of an application has the possibility, by configuring a policy for controlling the insertion of ancillary data, to regain control over the ancillary data that may be inserted locally, that is to say within his communication terminal itself, in a data packet correlated with application data (for example a packet including said application data, or a packet not intended for the routing of such application data but nevertheless linked to this application data, such as a data packet intended for the out-of-band routing of data linked to said application data) before its transmission on a communication network.More specifically, such a control policy includes a set of rules that determine, at multiple levels (construction of data packets, selection of data packet output interfaces, control perimeter, redirection, fully or partially local remote processing, etc.) a level of tolerance regarding how ancillary data should be managed in relation to application data generated by an application.
[0012] In a particular embodiment, the processing of said at least one data packet includes a particular construction or modification of said at least one data packet, at the level of at least one layer of a protocol stack used for said transmission via said communication network.
[0013] In this way, the present technique makes it possible, in particular, to control the insertion of ancillary data that may be carried out during the encapsulation of application data or related data in order to prepare them for transmission over the communication network. More specifically, the proposed technique allows for fine-grained control over the authorization or, conversely, the prohibition of inserting ancillary data into data packets correlated with application data.
[0014] According to a particular characteristic, said processing takes the form of a prohibition on inserting ancillary data or a deletion of at least one ancillary data for at least one protocol associated with at least one target layer of said layer stack, identified in said control policy.
[0015] In this way, the present technique allows the implementation of control of the insertion of application data protocol by protocol, offering a great deal of configuration latitude for the user.
[0016] According to another particular characteristic, said processing takes the form of a prohibition on inserting additional data or a deletion of at least one additional piece of data for any protocol associated with at least one target layer of said layer stack, identified in said control policy.
[0017] In this way, the present technique allows the implementation of control of the insertion of application data at the global level of one or more layers, independently of the particular protocols actually used within these layers.
[0018] In a particular embodiment, said at least one data package subject to said processing is selected according to at least one selection criterion defined for said application in said control policy.
[0019] In this way, the present technique offers the possibility of precisely selecting the data packets that should be subject to the control of insertion of ancillary data, by allowing the identification of target data packets to be processed according to one or more given criteria (or filters).
[0020] According to a particular characteristic, the selection criterion in question belongs to the group including, for example:
[0021] a selection of all data packets from the same application session; a selection of all data packets from the same application flow;
[0022] a selection of data packages associated with application data of a predetermined nature;
[0023] A selection of specific data packets. In this way, it is possible to select particular data packets to be processed based on numerous and varied criteria, which allow, for example, selecting only the data packets in an audio stream, only the data packets associated with keyframes in a video stream, only the data packets associated with a particular identifier, etc. A multitude of filters and filter combinations are thus available to a user or application, allowing them to very precisely target the data packets for which an insertion check of supplementary data must be performed.
[0024] In a particular embodiment, said control method includes the implementation of a procedure for discovering the capacity of at least one network entity to implement a process for controlling the insertion of supplementary data within said at least one data packet.
[0025] In this way, the communication terminal is able to access information on the capabilities of its network environment to support at least certain actions enabling the control of the insertion of ancillary data into application data packets.
[0026] In a particular embodiment, the processing of said at least one data packet includes a selection of at least one output interface of the communication terminal for the transmission of said data packet via said communication network.
[0027] In this way, the application and / or its user have the possibility of favoring communication channels, and therefore paths, which are known to offer guarantees in terms of control of the insertion of ancillary data when routing data packets to the remote terminals for which they are intended.
[0028] In a particular embodiment, said control process includes transmitting said at least one data packet to a third-party network entity for implementation by said third-party network entity of at least a part of said processing.
[0029] In this way, a dedicated third-party network entity can be used as a support entity for implementing at least part of the control over the insertion of ancillary data within data packets correlated with application data, particularly when the operating system of the communication terminal is unable to implement a control policy across the entire desired scope. Thus, the application can benefit from remote processing of data packets when certain ancillary data insertion control operations cannot be performed locally. The information required to contact the third-party network entity may have been pre-configured at the communication terminal level or discovered via the previously mentioned discovery procedure.
[0030] According to a particular characteristic, said transmission to a third-party network entity is implemented by said application, by source routing techniques or by establishing a tunnel to said third-party network entity.
[0031] In this way, a direct communication channel between the application and the dedicated third-party network entity can be established, making it possible to constrain the routing of application data on a determined secure path for the implementation of the remote processing of at least part of the control of insertion of ancillary data.
[0032] According to a particular feature, the said discovery procedure is based on an exchange of messages according to a dynamic DHCP host configuration protocol.
[0033] In this way, a known and widely used protocol is cleverly adapted to inform a communication terminal of the capabilities of its network environment to support at least some insertion control operations of ancillary data in data packets correlated with application data.
[0034] In a particular embodiment, the control process includes, prior to said processing, obtaining, by said application, at least one piece of information representative of the capacity of said operating system to implement said control of an insertion of supplementary data.
[0035] In this way, an application has the possibility to verify that the procedure for controlling the insertion of ancillary data is supported by the operating system of the communication terminal on which it is executed, and on what scope, before any implementation.
[0036] In a particular embodiment, the control process includes, prior to said processing, the configuration of said ancillary data insertion control policy for said application, via an application programming interface made available by said operating system. In this way, an application running on the communication terminal has a simple and secure means, via the methods exposed by such an application programming interface, to obtain, on the one hand, information on the operating system's ability to apply ancillary data insertion control policy and on its current configuration regarding ancillary data management, and on the other hand, to modify the configuration of this control policy, for example, according to a user's choice.
[0037] In a particular embodiment, said communication network is an IP network (“Internet Protocol” in English).
[0038] In this way, the process finds a wide application, because it is implemented within a very widespread type of network, and in connection with a well-known and widely used TCP / IP protocol stack.
[0039] In another aspect, the present technique also relates to a device for controlling the insertion of ancillary data within at least one data packet correlated with application data generated by an application running on a communication terminal. Such a device comprises at least one processor configured to control, prior to the transmission of said at least one data packet to at least one remote terminal via a communication network, the processing of said at least one data packet by an operating system of said communication terminal, according to an ancillary data insertion control policy.
[0040] Such an electronic device can, of course, exhibit the various characteristics relating to the control method according to the invention, which can be combined or considered separately. Thus, the characteristics and advantages of this control device are the same as those of the method for controlling the insertion of supplementary data within at least one data packet correlated with application data generated by an application running within a communication terminal, and are not described in further detail.
[0041] According to yet another aspect, the present technique relates to a network entity supporting the control of ancillary data insertion within at least one data packet correlated with application data generated by an application running within a communication terminal. Such a network entity comprises at least one processor configured to receive said data packet and to implement, according to an ancillary data insertion control policy, the processing of said at least one data packet before its transmission to at least one remote terminal.
[0042] From yet another perspective, the present technique relates to a system for controlling the insertion of supplementary data within at least one data packet correlated to application data generated by an application running on a communication terminal. Such a system comprises:
[0043] a control device for the insertion of said ancillary data, implemented within said communication terminal, said control device comprising at least one processor configured to initiate, prior to the transmission of said at least one data packet to at least one remote terminal via a communication network, at least part of the processing of said at least one data packet by an operating system of said communication terminal, according to an ancillary data insertion control policy;
[0044] a supporting network entity comprising at least one processor configured to receive said data packet and to implement, according to said ancillary data insertion control policy, at least one other part of the processing of said at least one data packet before said transmission of said at least one data packet to said at least one remote terminal.
[0045] According to another aspect, the proposed invention also relates to a computer program product downloadable from a communication network and / or stored on a computer-readable medium and / or executable by a microprocessor, comprising program code instructions for the execution of at least one process as described above in any of its embodiments, when this process is executed on a processor.
[0046] The proposed invention also relates to a computer-readable recording medium on which is recorded a computer program comprising program code instructions for executing the steps of a process as described above, in any of its embodiments.
[0047] Such a recording medium can be any entity or device capable of storing the program. For example, the medium may include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a USB flash drive or a hard drive.
[0048] On the other hand, such a recording medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means, so that the computer program it contains can be executed remotely. The program according to the invention can, in particular, be uploaded to a network, for example, the Internet.
[0049] The different embodiments mentioned above can be combined with each other for the implementation of the invention.
[0050] Figures
[0051] Other features and advantages of the invention will become more apparent upon reading the following description of a particular embodiment, given by way of simple illustrative and non-limiting example, and the accompanying drawings, among which:
[0052] [Fig 1] schematically illustrates an example of an environment for the implementation of this technique, in a particular embodiment;
[0053] [Fig 2] schematically illustrates an example of processing of ancillary data associated with the encapsulation of application data, in a particular embodiment of the proposed technique;
[0054] [Fig 3] illustrates an example of the formalism of a new attribute of a dynamic host configuration protocol of the DHCP type, dedicated to the announcement by a communication network of the support of a control process for the insertion of ancillary data, in a particular embodiment of the invention;
[0055] [Fig 4] illustrates an example of an exchange of messages between a communication terminal and a communication network, for the discovery of the capabilities of said network to support a process of controlling the insertion of ancillary data, in a particular embodiment of the invention;
[0056] [Fig 5] describes a simplified architecture of a control device for the insertion of ancillary data within at least one data packet correlated with application data generated by an application executed within a communication terminal, in a particular embodiment of the proposed technique; [Fig 6] describes a simplified network entity architecture supporting the control of the insertion of ancillary data within at least one data packet correlated with application data generated by an application executed within a communication terminal, in a particular embodiment of the proposed technique.
[0057] Detailed description of the invention
[0058] An example of an environment in which this technique is implemented is described in relation to Figure 1. The operation of a communication terminal (CT) is governed by at least one operating system (OS) installed on the terminal, enabling it to run one or more applications. Such a CT can take the form of a computer, tablet, smartphone, connected device, customer premises equipment (CPE), proxy, or more generally, any software instance capable of establishing or receiving communications. The operating system (OS) and at least some of the applications installed on the terminal can exchange application data with other remote terminals (other communication terminals, servers, etc.).) reachable by the communication terminal via at least one RC communication network, such as the Internet. Thus, as part of its operation, an application (APP) running on the communication terminal (TC) exchanges application data (DA) via the RC network with another terminal, for example a remote server (SRV), to provide a service to a user.
[0059] Application data (AD) refers to data intrinsically associated with the operation of the application. Such data includes, for example, payload data (or payload), i.e., data sent or received by an application in the course of using the service provided by the application, as well as data intended to ensure the operation of the application, such as signaling data used, for example, to establish a connection with a remote terminal, manage user authentication for said application, etc.
[0060] Such DA application data is to be distinguished from so-called DX ancillary data within the framework of this technique, which relates to additional data that may be inserted into data packets correlated with said DA application data.By "data packets correlated with said application data", we mean here for example data packets including application data DA (in other words application data packets, which can also be described as "in-band" or "In-Packet" packets, i.e. packets "in the band" or included in the application data packet), but also data packets which do not include application data DA but which nevertheless have a link with this application data DA (i.e. which are correlated with this application data DA), and which are for example intended to be transmitted out-of-band ("out-of-band" or also "Dedicated-Packet" in English), i.e. in a channel separate from that used for the transmission of application data packets (typically in a dedicated data packet in the context of IP communications, distinct from the application data packet but correlated to the latter).The concepts of in-band (or "In-Packet") and "out-of-band" (or "Dedicated-Packet") for IP communications are explained in more detail in the IETF document by C. Plgnatoro et al. entitled "Guidelines for Characterizing "O AM" draft-ietf-opsawg-oam-characterization-04", November 2024.
[0061] Such ancillary data is not intrinsically linked to the operation of the application. However, in some cases, it may be related to optimizing the paths taken by application data (AD). In other words, the absence of such ancillary data (AD) generally does not impair the operation of the application (APP). As discussed in relation to prior art, this ancillary data (AD) is often inserted into data packets without the user's knowledge, typically includes information that a knowledgeable user might legitimately not want exposed, and is susceptible to being used for purposes not consented to by the user.
[0062] The invention applies independently of the protocols used for the exchange of application data as well as the method of managing a communication.
[0063] In the context of communication between an application (APP) and a remote terminal (SRV), such DX ancillary data can be inserted into a data packet correlated with application data (i.e., transmitted within the application data packet itself or out of band, in a dedicated packet) at different levels:
[0064] firstly, at the NI level of the communication terminal TC itself, before transmission of application data DA generated by the application APP or out-of-band data related to this application data to a remote terminal SRV; secondly, at the N2 level of an intermediate communication network equipment RC used to route the data packets;
[0065] Thirdly, at the N3 level of the remote SRV terminal, for example before transmission of application data or out-of-band data related to this application data to the APP application running on the TC communication terminal, for example in response to a request issued by this APP application.
[0066] The technique described below relates more specifically to the control of ancillary data that may be inserted at the first NI level, that is, at the level of the communication terminal itself, before the transmission of a data packet correlated with the application data generated by the APP to a remote terminal, for example, a remote SRV server. More generally, the proposed technique relates to all actions that may be implemented, or at least initiated, at the local level of the communication terminal, in order to control the insertion of ancillary data within application data packets or within data packets linked to application data intended, for example, for out-of-band transmission.
[0067] In this context, a method for controlling the insertion of ancillary data within at least one data packet correlated with application data generated by an application running on a communication terminal is proposed, based on a general principle of the proposed technique. This method involves the processing, by the communication terminal's operating system, of at least one such data packet according to an ancillary data insertion control policy. The operating system's processing may include, for example, an operation to prevent the insertion of ancillary data, an operation to redirect the packet to another entity responsible for preventing the insertion of ancillary data, and so on.
[0068] More specifically, the ancillary data insertion control policy includes a set of rules that constrain how data frames used to carry application data, or out-of-band data correlated with that application data, over a communication network—and therefore the associated data packets—can be generated or modified. This allows, for example, defining within which framework and at which level of a protocol stack ancillary data insertion is permitted or, conversely, denied. As described later, an ancillary data insertion control policy may also include rules for determining, at the device level where it is implemented, how data packets should be transmitted over the communication network (for example, through redirection rules, network interface selection, etc.).Such a control policy has, for example, been previously configured at the level of the communication terminal (by a user, an operator, or any other actor), and can in particular be associated with one or more applications running on this terminal.
[0069] In a particular embodiment, the processing of data packets thus includes the implementation, by the operating system of the communication terminal, of a particular construction or modification of at least one of said data packets used for the transmission of application data or related out-of-band data (or at least at least a part of such data) via the communication network, at the level of at least one layer of a protocol stack used for said transmission.
[0070] It is worth recalling at this point that within many current communication networks, particularly IP networks, the implementation of data transmission between two remote entities—in this case, data transmission between a client application at the communication terminal and a server application at a remote server—relies on a principle of encapsulation according to a suite of protocols organized in layers (hence the notion of a "protocol stack"). The OSI model (from the English "Open Systems Interconnection") thus defines, for example, seven layers (layer 7: application, layer 6: presentation, layer 5: session, layer 4: transport, layer 3: network, layer 2: data link, layer 1: physical), each responsible—through the implementation of its associated protocols—for specific functionalities to ensure data transmission over the communication network.
[0071] Figure 2 schematically illustrates how data, for example application data (DA), is successively encapsulated by different software libraries of the communication terminal's operating system, according to protocols specific to each layer, until a data frame (TD) is obtained for transmission over the communication network, within a data packet. At each layer (four in number: C1, C2, C3, and C4 in the example of Figure 4), an E_PC header and possibly a T_PC postamble (where i is the layer number), defined according to a protocol used at the layer in question, are added to the Protocol Data Unit (PDU) of the immediately preceding layer.For example, at layer 3, an E_PC3 header and a T_PC3 postamble according to the protocol used associated with this layer C3 are added respectively to the head and tail of the data generated as output from the immediately preceding layer C4.
[0072] In a particular embodiment of this technique, the rules defined in the ancillary data insertion control policy allow the insertion of ancillary data at the communication terminal level, in all or part of a data frame, to be authorized or denied with a desired level of granularity. Thus, in relation to Figure 2, it is possible, for example, to prohibit 21 any ancillary data insertion for a particular PC3 protocol associated with layer C3 (in the illustrated example, the insertion of DX ancillary data in the E_PC3 header is denied), but to accept 22 the insertion of ancillary data at layer C2 regardless of the protocol implemented at that layer C2 (in the illustrated example, the insertion of DX ancillary data in the T_PC2 postamble is authorized).
[0073] Such control of the insertion of DX ancillary data can be implemented: either by the operating system software libraries associated with each layer, at the very time of the construction of the data package, by blocking any insertion of ancillary data that would not be authorized with regard to the control policy;
[0074] either through a dedicated software component of the operating system, configured to inspect the TD data frame once it has been generated by the aforementioned software libraries, but before its transmission over the network, in order to remove any additional data that would not be authorized under the control policy.
[0075] In this context, the rules defined in the policy for controlling the insertion of supplementary data can act at different levels.
[0076] For example, in a particular embodiment, a rule prohibiting the insertion of ancillary data at the general level of one or more layers can be defined. Thus, it is possible, for example, to define a rule according to which no insertion of ancillary data is allowed in connection with the transport layer of a TCP / IP model, regardless of the IP version used (IPv4 or IPv6) or the transport protocol (for example TCP "Transmission Control Protocol", UDP "User Datagram Protocol", SCTP "Stream Control Transmission Protocol", QUIC, etc.) actually used.
[0077] More specifically, the proposed technique also allows for the definition of one or more rules prohibiting the insertion of additional data at the level of a particular protocol within a given layer (physical, network, transport, application, etc.). For example, it is possible to define a rule whereby no additional data is allowed during encapsulation using the UDP transport protocol.Implementing such a rule results, for example, in disabling the use of any "options" available in the headers and / or postambles of data packets defined according to these protocols. (In this case, either the operating system does not insert any data into these fields when constructing the packets, and therefore the data packets to be transmitted over the communication network, or the operating system of the communication terminal and / or a dedicated third-party network entity requesting this service performs a process to remove all data present in these fields.) For example, terminals participating in a QUIC connection can negotiate the disabling of UDP options for all or part of the exchanged data. Other protocols, such as TCP, HTTP, SIP, WebRTC, etc., also operate in this way.can of course also be subject to the scope of the control of insertion of ancillary data.
[0078] In a particular embodiment, using an alternative or complementary approach, the proposed technique also allows, within the framework of the control policy, the configuration of rules that define whether the insertion control of ancillary data should be performed for all application or related data of the same application, or even for all applications. More specifically, provided that the operating system supports these different modes, it is possible to specify that the insertion control of ancillary data should be performed, for example, for all data packets emitted during the same application session, or conversely, to perform this control only for all data packets of a targeted data flow of an application session, or even only for certain clearly identified packets (for example, those associated with application data of a predetermined nature, or bearing a particular identifier or marking).For example, if the application in question is a video conferencing application, it is possible to define rules according to which the insertion of ancillary data is allowed in the packets of the audio application data stream, but not in the packets of the video application data stream. More precisely, it is also possible, with regard to the control performed at the video application data stream level, to configure a rule prohibiting the insertion of application data only within the data packets associated with the transmission of keyframes of that video stream.
[0079] Alternatively or in addition, one or more rules prohibiting the insertion of ancillary data at the level of out-of-band data correlated with application data can also be defined. In this way, the insertion of ancillary data can be controlled not only at the level of the communication channel used to carry application data, but also at the level of other communication channels that might be used to carry out-of-band data. Such a channel could rely on application data packet mirroring, a dedicated ICMP (Internet Control Message Protocol) packet, etc.In the case of an ICMP packet, correlation with the application data packet can, for example, be achieved by inserting into the ICMP packet a digest (or "hash" in English) of said data packet, the characteristic information of the connection (source IP address, source port number, destination IP address, destination port number, transport protocol), or a combination of the two.
[0080] Alternatively or in addition, in other specific embodiments of this technique, the ancillary data insertion control policy includes rules that allow action to be taken, at the communication terminal level, regarding how data packets are transmitted. These rules include, for example, redirection rules, network interface selection rules, or other types of rules, which aim in particular to prioritize communication channels that offer guarantees in terms of ancillary data insertion control management when routing application data packets to their intended remote terminals.
[0081] In this context, support for a process controlling the insertion of ancillary data by a communication network can be announced to the communication terminal by various means. In one particular embodiment, a protocol of the type Dynamic Host Configuration Protocol (DHCP) type is used.
[0082] This can be used, for example, by implementing a new DHCPv6 option illustrated in relation to Figure 3. This option, called OPTION_V6_HASH in the figure, allows for the announcement of various pieces of information specifying the scope of support for an ancillary data insertion control process by a communication network, via various parameters specifying, for example, a supported mode 31 and scope 32. Mode 31 defines, for example, the data packets that can be subject to such control (e.g., only specific identified packets, all packets associated with a particular flow, all packets associated with the same application session, etc.), while scope 32 defines, for example, at which level of at least one OSI layer or at least one specific protocol the ancillary data insertion control process can be implemented by the network in question.Of course, these example parameters are given purely for illustrative purposes and are not limiting; other parameters may be considered within the framework of this technique, including parameters including connection information to a particular channel to be used to constrain the routing of packets (for example, a tunnel).
[0083] An example of message exchange between a communication terminal and a network for implementing this advertisement and discovery mechanism is illustrated in relation to Figure 4, in a particular embodiment. Such a DHCP session typically includes:
[0084] a SOL discovery message (from the English "Solicit") issued by the TC communication terminal acting as a CLT-DHCPv6 DHCP client to the RC network of which at least one entity is able to act as an SRV-DHCPv6 DHCP server;
[0085] in response to the SOL discovery message, at least one ADV (Advertise) message issued by at least one DHCP server on the RC network, typically including an offer of an IP address to the TC client;
[0086] following the selection of an offer by the TC client, the issuance by this client, to the RC network, of a REQ (from the English "Request") requesting the assignment of an IP address by the DHCP server whose offer was selected;
[0087] In response to this request, the selected DHCP server issues a REP (Reply) confirming the assignment of the IP address to the TC client. As illustrated in Figure 4, the OPTION_V6_HASH option and its parameters can be transmitted to the communication terminal via the ADV advertisement and REP response messages described above, thus allowing the TC communication terminal to learn about the network's capabilities regarding its support for the ancillary data insertion control process.
[0088] In order for the TC communication terminal to become aware of the capabilities of the RC network, including in cases where the connection of the TC communication terminal to the RC communication network is not direct, but is established via one or more intermediate gateway-type equipment (“Gateway” or “Customer Premises Equipment” CPE in English), the discovery procedure described above is recursive.
[0089] The selection of a network interface for transmitting application data packets or data packets related to such application data can then be performed by the communication terminal, based on the results of the discovery procedure and the applicable control policy, and more specifically, the identified capabilities to support the ancillary data insertion control process for the various communication networks to which the communication terminal is connected. The network interface can be determined in such a way as to select a network capable of applying ancillary data insertion control policy operating within a scope similar or identical to the control scope already implemented locally on the communication terminal. One or more networks can be chosen for the same communication.
[0090] The discovery procedure described above can also be used, alternatively or in addition, to identify a dedicated third-party network entity capable of acting as a support entity to implement all or part of the control over the insertion of ancillary data within data packets correlated with application data. Such at least partially remote implementation of data packet processing proves useful, for example, when it is determined that the communication terminal's operating system is unable to implement the ancillary data insertion control policy across the entire desired scope, or to manage a situation in which intermediate entities insert ancillary data but do not collaborate with the communication terminal for the insertion of this ancillary data.The entity discovered by the terminal may be an entity hosted by a network other than the network that provides connectivity to the terminal. In these particular embodiments of the control method according to this technique, application or related data packets are thus transmitted to the dedicated third-party network entity so that it can perform appropriate processing of these packets, for example, to complete or finalize processing initiated locally at the communication terminal or to remove data inserted by intermediate entities.Such remote processing may include one or more of the operations described above in relation to the implementation of a control policy, such as, for example, data cleansing operations aimed at removing any extraneous data that may have been inserted at the level of at least one target protocol and / or at least one target layer of a protocol stack during a data encapsulation process. Depending on a particular characteristic, the transmission of data packets from the communication terminal to the dedicated third-party network entity for implementing the remote processing may, for example, be based on connection information obtained during the discovery procedure, and rely in particular on source routing techniques or the establishment of a tunnel to said third-party network entity.Once the remote processing is complete, the processed data packets are transmitted to the recipient terminal(s) as part of the operation of the application that generated them. Depending on various specific embodiments, this transmission can be implemented directly by the third-party network entity that performed the remote processing, or via the communication terminal on which the application is executed (in which case the third-party network entity sends the processed packets to the communication terminal so that it can carry out this transmission itself).
[0091] The preceding examples are, of course, given for illustrative purposes only and are not exhaustive; other types of rules (for example, based on time ranges or resource availability) can also be considered within the framework of this technique. Combining several rules is also possible.
[0092] Thus, the proposed technique offers great flexibility in implementing a policy for controlling the insertion of ancillary data at the local level (at least in part) of a communication terminal. In a particular embodiment, the configuration of the policy for controlling the insertion of ancillary data is carried out by means of an application programming interface (or API) made available by the operating system of the communication terminal.
[0093] More specifically, such an application programming interface exposes, for example, methods of type (GET) or (SET) allowing an application running on a communication terminal not only to obtain, among other things, information on the ability of the operating system of the communication terminal or of a communication network to support the control process that is the subject of this technique and on what scope, but also to set configuration choices for the policy control of insertion of ancillary data with regard to the application in question.
[0094] Through such an application programming interface, as previously presented, the insertion of supplementary data can be controlled at different levels of granularity, for example:
[0095] at the global level of at least one layer of a multilayered data transmission model, such as an OSI or TCP / IP model;
[0096] at the level of at least one particular protocol associated with a layer of such a multi-layered model (at the level of the UDP, TCP, HTTP, SIP, WebRTC protocol, etc.);
[0097] for all application or related data packets of the same application session, whatever they may be, or on the contrary at the level of sessions, data streams, particular data frames identified according to one or more given criteria (based on an identifier, a type of stream, a particular nature of certain data frames, etc.);
[0098] etc.
[0099] Such an application programming interface can also expose information about the ability of the communication networks to which the communication terminal is connected to support an ancillary data insertion control process when routing data packets within them.
[0100] The various rules introduced previously can obviously be combined, allowing for very precise and customized configuration of ancillary data management related to an application or group of applications. The set of rules defining an ancillary data insertion control policy associated with an application can be referred to as a "profile." Such a profile may have been generated by the application vendor and / or customized by a user, for example, using a graphical profile management interface provided by the application or the operating system.
[0101] We describe below some examples of methods that can be exposed by an application programming interface, in a particular embodiment. In the proposed names of these methods, the term "HASH" refers to the mechanism for controlling the insertion of ancillary data that is the subject of this technique, called "Host-based control of Side Channels" in English.
[0102] GET_HASH_SUPPORT: This method allows an application to check whether the operating system of the communication terminal on which it is installed permits (HASH_SUPPORT set to "True") or not (HASH_SUPPORT set to "False") the insertion of supplementary data into its associated application data packets. Depending on the implemented embodiment, this attribute can be global (i.e., have the same value for all applications running on the communication terminal) or specific to the application in question. More specifically, in a particular embodiment, the operating system can control which applications are eligible for the service; such control might, for example, be defined based on a policy of the operating system vendor, available resources on the communication terminal, etc.
[0103] SET_HASH_ENABLE: This method allows an application to indicate—when available, i.e., when HASH_SUPPORT is set to "true" for that application—whether it wants the supplementary data insertion control mechanism enabled or disabled for itself. Thus, a HASH_ENABLE attribute set to "true" via this method indicates that the application invoking the API requests the activation of the supplementary data insertion control procedure for some or all of the application data packages. Conversely, a HASH_ENABLE attribute set to "false" indicates that the application invoking the API requests the deactivation of the procedure for all data packages associated with that application.
[0104] SET_HASH_SCOPE(value1, value2, ...): This method allows an application to specify at which level(s) (e.g., layer, protocol, etc.) it wants to prohibit the insertion of extraneous data. Such levels are chosen, for example, from a set of levels exposed by the operating system, this set having been previously obtained by the application through a call to a corresponding GET_HASH_SCOPE method also exposed by the API. The SET_HASH_SCOPE method thus allows an application to define the scope of prohibition (and therefore, by contrast, of authorization) for the insertion of extraneous data. A value of "ALL" passed as a parameter to such a method can therefore mean that the application in question requests that no extraneous data be inserted into the data packets associated with it.Such a method can also accept as parameters one or more values representing a layer of the OSI model, for example, the value "IP" to indicate that all Layer 3 channels (the IP layer of the OSI model) can be controlled by the application, or the value "Transport" to indicate that all Layer 4 channels (the Transport layer of the OSI model) can be controlled by the application. Alternatively, such a method can also accept as parameters one or more values representing a protocol, such as "UDP", "TCP", "HTTP", "SIP", "WebRTC", etc.
[0105] Thus, for example, passing the values "UDP" and "SIP" as parameters when calling such a SET_HASH_SCOPE method allows us to indicate that any insertion of additional data is prohibited during the encapsulation of application data implemented at the level of the "UDP" or "SIP" protocols.
[0106] SET_HASH_MODE(value): This method allows an application to specify a control mode, for example, a level of granularity (in terms of data units) at which it wants to prevent the insertion of additional data. Such modes are chosen, for example, from a set of modes exposed by the operating system, this set having been previously obtained by the application through a call to a corresponding GET_HASH_MODE method also exposed by the API.The SET_HASH_MODE method thus allows an application to define a mode of prohibition (and therefore, by contrast, of authorization) of insertion of ancillary data, such a mode being able for example to have the value "PKT" for a prohibition determined packet by packet, the value "STREAM" for a prohibition on all packets of a channel (or "stream" in English) of a given application flow (for example a QUIC "stream"), the value "FLOW" for a prohibition on all packets of a given application session, the value "ALL" for a complete prohibition at all levels, etc.
[0107] GET_HASH_FORWARDING: This method allows an application to check whether the operating system of the communication terminal on which it is installed supports (HASH_FORWARDING set to "true" (or equivalently to "True")) or not (HASH_FORWARDING set to "false" (or equivalently to "False")) the procedure for selecting network interfaces to route packets according to application instructions (in particular, to prioritize the selection of a network capable of applying ancillary data insertion control policy that conforms to the desired policy and, for example, is already implemented locally on the communication terminal). By using a corresponding SET_HASH_FORWARDING method, the application can also specify whether or not it wants such interface selection to be implemented, when this functionality is supported at the level of the communication terminal's operating system.
[0108] The examples of methods and associated parameters described above are, of course, purely illustrative and not exhaustive; other methods and parameters may be considered for implementing an application programming interface according to this technique. In specific embodiments where at least part of the processing of application data packets is offloaded to a dedicated third-party network entity, the application programming interface may be implemented in a distributed manner, with all or part of said methods being, for example, implemented and exposed at the level of said third-party network entity.
[0109] In another respect, the proposed technique also relates to a device for controlling the insertion of supplementary data within at least one data packet correlated with application data generated by an application running on a communication terminal. Such an electronic device is capable of performing the process described above in any of its embodiments. More specifically, such a device according to the present technique comprises at least one processor configured to control, prior to the transmission of said at least one data packet to at least one remote terminal via a communication network, the processing of said at least one data packet by an operating system of said communication terminal, according to a policy for controlling the insertion of supplementary data.
[0110] Figure 5 schematically and simply represents the structure of such an electronic device in a particular embodiment. According to the proposed technique, the device comprises, for example, a memory 51 consisting of a buffer memory M, a processing unit 52, equipped, for example, with a microprocessor pP, and controlled by the computer program Pg 53, implementing steps of the method for controlling the insertion of supplementary data according to at least one embodiment of the invention.
[0111] At initialization, the code instructions of computer program 53 are loaded into the buffer before being executed by the processor of processing unit 52. Processing unit 52 receives, for example, configuration data for an ancillary data insertion control policy as input E. Such configuration data can be processed, in particular, using a dedicated application programming interface.
[0112] The microprocessor of the processing unit 52 then carries out the following steps of the control process, according to the instructions of the computer program 53. More specifically, the processing unit 52 implements a processing of at least one data packet of data correlated with application data according to at least one of the embodiments previously described, so as to deliver at output S of the processing unit 52 data packets processed in accordance with the established control policy, in terms of construction and / or routing of said packets.
[0113] In another aspect, the proposed technique also relates to a network entity supporting the control of ancillary data insertion within at least one data packet correlated with application data generated by an application running on a communication terminal. More specifically, such a network entity according to the present technique comprises at least one processor configured to receive said data packet and, based on an ancillary data insertion control policy, to process said at least one data packet before transmitting said at least one data packet to at least one remote terminal.
[0114] Figure 6 schematically and in a simplified manner represents the structure of such a network entity in a particular embodiment. The network entity, according to the proposed technique, comprises, for example, a memory 61 consisting of a buffer memory M, a processing unit 62, equipped, for example, with a microprocessor pP, and controlled by the computer program Pg 63, implementing support operations for controlling the insertion of additional data, as previously described.
[0115] At initialization, the code instructions of computer program 63 are loaded into the buffer before being executed by the processor of processing unit 62. Processing unit 62 receives as input E, for example, at least one data packet to be processed, and configuration data for an additional data insertion control policy to be applied to said at least one packet. Such configuration data can, in particular, be populated using an application programming interface of the same type as previously described, but implemented at the level of said supporting network entity (according to a distributed variant of this application programming interface).
[0116] The microprocessor of the processing unit 62 then carries out the following steps of the support process, according to the instructions of the computer program 63. More specifically, the processing unit 62 implements a processing of at least one packet of data correlated with application data according to at least one of the embodiments previously described, so as to deliver at output S of the processing unit 62 packets of data processed in accordance with the established control policy, in terms of construction and / or routing of said packets.
[0117] From another perspective, the proposed technique also relates to a control system for inserting supplementary data, including:
[0118] at least one control device for the insertion of said ancillary data as already described in relation to Figure 5, implemented within a communication terminal, for the implementation of at least part of a processing of at least one data packet correlated with application data generated by an application executed within the communication terminal, according to an ancillary data insertion control policy (such part of the processing may, where appropriate, when the operating system is not able to apply the rules defined in the control policy, be limited to the simple transmission of the data packets to be processed to a supporting network entity);
[0119] at least one supporting network entity as already described in relation to Figure 6, comprising at least one processor configured to receive said at least one data packet and to implement, according to said ancillary data insertion control policy, at least one other part of the processing of said at least one data packet before its transmission to at least one remote terminal for which it is intended.
Claims
Tl DEMANDS 1. Method for controlling the insertion of supplementary data (DX) within at least one data packet correlated with application data (DA) generated by an application (APP) executed within a communication terminal (TC), said method being characterized in that it comprises, prior to the transmission of said at least one data packet to at least one remote terminal (SRV) via a communication network (RC), the processing of said at least one data packet by an operating system (OS) of said communication terminal, according to a supplementary data insertion control policy.
2. Control method according to claim 1, characterized in that the processing of said at least one data packet comprises a particular construction or modification of said at least one data packet, at the level of at least one layer of a protocol stack used for said transmission via said communication network.
3. Control method according to claim 2, characterized in that said processing takes the form of a prohibition on inserting additional data or a deletion of at least one additional data item for at least one protocol associated with at least one target layer of said layer stack, identified in said control policy.
4. Control method according to claim 2, characterized in that said processing takes the form of a prohibition on inserting additional data or a deletion of at least one additional data item for any protocol associated with at least one target layer of said layer stack, identified in said control policy.
5. A control method according to any one of the preceding claims, characterized in that said at least one data packet subject to said processing is selected according to at least one selection criterion defined for said application in said control policy.
6. A control method according to claim 5, characterized in that said selection criterion belongs to the group comprising: a selection of all data packets from the same application session; a selection of all data packets from the same application flow; a selection of data packages associated with application data of a predetermined nature; a selection of predetermined data packets.
7. A control method according to any one of the preceding claims, characterized in that it comprises the implementation of a procedure for discovering the capacity of at least one network entity to implement a process for controlling the insertion of supplementary data within said at least one data packet.
8. Control method according to any one of the preceding claims, characterized in that the processing of said at least one data packet comprises a selection of at least one output interface of the communication terminal for the transmission of said data packet via said communication network.
9. Control method according to any one of the preceding claims, characterized in that it comprises a transmission of said at least one data packet to a third-party network entity for implementation by said third-party network entity of at least a part of said processing.
10. Control method according to claim 9, characterized in that said transmission to a third-party network entity is implemented by said application, by source routing techniques or by establishing a tunnel to said third-party network entity.
11. A control method according to claim 7, characterized in that said discovery procedure is based on an exchange of messages according to a dynamic DHCP host configuration protocol.
12. A control method according to any one of the preceding claims, characterized in that it comprises, prior to said processing, a step of obtaining, by said application, at least one piece of information representative of the ability of said operating system to implement said control of an insertion of ancillary data.
13. Control method according to any one of the preceding claims, characterized in that it comprises, prior to said processing, the configuration of said ancillary data insertion control policy for said application, via an application programming interface made available by said operating system.
14. Control device for the insertion of ancillary data within at least one data packet correlated with application data generated by an application executed within a communication terminal, said device being characterized in that it comprises at least one processor configured to control, prior to the transmission of said at least one data packet to at least one remote terminal via a communication network, the implementation of processing of said at least one data packet by an operating system of said communication terminal, according to an ancillary data insertion control policy.
15. Network entity supporting the control of an insertion of ancillary data within at least one data packet correlated with application data generated by an application executed within a communication terminal, said network entity being characterized in that it includes at least one processor configured to receive said data packet and to implement, according to an ancillary data insertion control policy, a processing of said at least one data packet before a transmission of said at least one data packet to at least one remote terminal.
16. Control system for the insertion of ancillary data within at least one data packet correlated with application data generated by an application executed within a communication terminal, said system being characterized in that it comprises: a control device for the insertion of said ancillary data, implemented within said communication terminal, said control device comprising at least one processor configured to initiate, prior to the transmission of said at least one data packet to at least one remote terminal via a communication network, at least part of a processing of said at least one data packet by an operating system of said communication terminal, according to an ancillary data insertion control policy; a supporting network entity comprising at least one processor configured to receive said data packet and to implement, according to said ancillary data insertion control policy, at least one other part of the processing of said at least one data packet before said transmission of said at least one data packet to said at least one remote terminal.