Method for managing a connection between a first terminal and a second terminal via a communication network
Patent Information
- Application Number
- PCT/EP2026/054298
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-18
- Filing Date
- 2026-02-17
- Publication Date
- 2026-08-27
Smart Images

Figure EP2026054298_27082026_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Method for managing a connection between a first terminal and a second terminal via a communication network
[0003] technical field
[0004] The invention lies in the field of communication networks, and more particularly in that of IP networks (from the English "Internet Protocol").
[0005] Previous art
[0006] With the massive use of communication means, the improvement of transmission rates, the proliferation of applications and services, and the multiplication and sophistication of the underlying technological building blocks (such as those supported by terminals, intermediate networks, data centers, etc.), it has become common for additional data to be generated in correlation with application data packets (typically inserted into application data packets) routed via a communication network, generally without the knowledge of the users or the application that originated this application data.Such additional data - which can also be described as ancillary data in that it is not necessary for the provision of the service or specific to the application or the user - can for example be used for statistical purposes, monitoring and quality assurance of packet routing (as is the case for example with techniques such as "In-band OAM" or "In-situ Telemetry"), or for the provision of complementary services (for example a functional chaining of the type "Service Function Chaining (SFC)").
[0007] In many cases, although associated with an application data package generated by an application, this ancillary data is not part of the data necessary for the application's operation. In some cases, it can be used to optimize data routing through intermediate networks. However, it is likely to disclose information that falls under a user's privacy, or at the very least, circumvent certain application measures implemented specifically to protect access to data that a user might wish to keep private. As an example of such an application measure, an application might encrypt the application data it generates to prevent an entity within an intermediate communication network from accessing and exploiting it in plaintext.An application can also modulate the application data it transmits to prevent such an entity from identifying the application associated with those data packets through profiling techniques or the use of templates (or "traffic patterns"). However, these application measures can be rendered less effective, or even completely ineffective, if the operating system of the communication terminal running the application enriches (by default) the application data packets with unencrypted ancillary data (for example, via IPv4 options, IPv6 extensions, TCP options, UDP options, or application headers) that discloses, for example, the user's identity, their practices, or the nature of the application.In general, supplementary data is also likely to be inserted during the routing of application data by equipment on a communication network, or even by the receiving terminal itself (typically a remote server), before, for example, sending a response to a request received from the application. Information disclosed by a remote terminal can facilitate the correlation of exchanged packets and thus reveal information characteristic of the application or even the user. It should be noted that several remote terminals can be involved in the same communication (for example, for a broadcast service or, more generally, point-to-multipoint communications). Similarly, the applications involved can be of various types (bidirectional, unidirectional, point-to-point, point-to-multipoint, etc.).) or even rely on different modes of transport (a single connection, a multiple connection established via multiple paths, multiple connections per path, etc.).
[0008] Such ancillary data can be used by a remote terminal for traceability or profiling purposes, or by an entity in the communication network located on one of the paths used by application data to extract sensitive data and share it with a dedicated service platform for uses that may not be consented to by the user.
[0009] Therefore, there is a need for a solution that allows for better control of the insertion of ancillary data within all or part of data packets correlated with application data exchanged during the operation of an application. Summary of the invention
[0010] The present invention describes a solution to overcome certain drawbacks of the prior art. In one aspect, the present invention relates to a method for managing a connection between a first terminal and a second terminal via a communication network. Such a method, implemented by said first terminal, comprises at least one exchange, with said second terminal, of at least one message including at least one parameter representing a request to activate or deactivate a process for controlling the insertion of supplementary data within at least one data packet correlated with application data generated in connection with an application executed within said first or second terminal.
[0011] In this way, mechanisms are proposed for exchanging information between two remote terminals, so that these terminals can, for example, agree on a common policy for controlling the insertion of ancillary data, or at the very least, so that at least one of these terminals is aware of the other terminal's ability to implement such a control policy. This technique thus makes it possible, for example, to extend an ancillary data insertion control policy configured on a first terminal to a second remote terminal with which application data is exchanged, in order to ensure consistency or synchronization in the management of such ancillary data both locally and remotely, thereby giving a user greater control over their data.
[0012] According to a particular characteristic, said at least one message further includes at least one parameter representing a desired control perimeter for the implementation, by the receiving terminal of said at least one message among said first terminal or said second terminal, of said control process of an insertion of supplementary data.
[0013] In this way, the first terminal can inform the second remote terminal of a perimeter within which it wants an insertion control for additional data to be performed. Such a desired perimeter could, for example, correspond to a control perimeter already implemented at the first terminal.
[0014] According to a particular characteristic, said at least one parameter representing a control perimeter belongs to the group comprising: a parameter representing a request for control of insertion of ancillary data at the level of at least one layer of a protocol stack used for the transmission of said at least one data packet via said communication network;
[0015] a parameter representative of a request for control of insertion of ancillary data at the level of at least one protocol of said protocol stack used for the transmission of said at least one data packet via said communication network;
[0016] a parameter representing a request for control of insertion of ancillary data at the level of at least one data packet determined according to at least one criterion defined for said application;
[0017] a parameter representative of a request for out-of-band insertion control of ancillary data correlated to said application data.
[0018] In this way, the present technique makes it possible, in particular, to control the insertion of ancillary data that may be performed during out-of-band data generation or during the encapsulation of application or related data carried out during its transmission over the communication network. More specifically, the proposed technique allows for granular control over the insertion of ancillary data into data packets correlated with application data. Such control can be implemented at a very precise level of granularity, for example at the level of a target protocol, or at a more global level, for example at the level of a target layer independent of the protocol used.In a complementary or alternative manner, this technique also allows, where appropriate, the definition of the data packets which must be subject to the control of insertion of ancillary data (for example, only the data packets of an audio stream, only the data packets associated with keyframes of a video stream, only the data packets associated with a particular identifier, etc.).
[0019] In a particular embodiment, said at least one parameter representing a control perimeter includes a parameter representing a request to select a route using at least one autonomous system capable of implementing a process for controlling the insertion of supplementary data within said at least one data packet, for the routing of said at least one data packet via said communication network.
[0020] In this way, the first terminal can request the second terminal to use specific routes for the routing of data packets via the communication network, including routes that meet precise criteria in terms of controlling the insertion of ancillary data within data packets, typically criteria defined within the framework of an ancillary data insertion control policy possibly already implemented locally within the first terminal and / or the second terminal.
[0021] According to a particular characteristic, said at least one parameter representing a control perimeter includes a parameter representing at least one routing direction of said at least one data packet in relation to which a control process for an insertion of supplementary data is requested from among:
[0022] a first direction, corresponding to a routing from the first terminal to the second terminal;
[0023] a second direction, corresponding to a routing from the second terminal to the first terminal;
[0024] both the said first direction and the said second direction.
[0025] In this way, the present technique also allows the first terminal to inform the second terminal of a direction in which a control of the insertion of ancillary data must be carried out.
[0026] In a particular embodiment, said method includes a recording, in a data structure associated with said first terminal, for said connection, of at least one parameter negotiated with said second terminal in relation to said request to activate or deactivate said process of controlling ancillary data insertion.
[0027] In this way, the parameters negotiated between two terminals for the control of ancillary data within a connection are stored within each terminal.
[0028] In a particular embodiment, at least one of said at least one message further includes a request to establish a connection with said second terminal.
[0029] In this way, a request to activate a procedure for controlling the insertion of supplementary data at the level of a remote terminal can be made simultaneously with the request to establish a connection with that terminal.
[0030] In a particular embodiment, said method further includes at least one exchange of at least one message comprising at least one parameter representing an activation or deactivation confirmation, at the level of said first terminal or said second terminal, of said ancillary data insertion control process.
[0031] In this way, the two terminals can inform each other of the proper implementation of the instructions for a policy controlling the insertion of ancillary data within them.
[0032] In another respect, the present technique also relates to a method for managing a connection between a first terminal and a second terminal via a communication network, implemented by said second terminal. Such a method includes receiving, from said first terminal, at least one message comprising at least one parameter representing a request to activate or deactivate, at said second terminal, a process for controlling the insertion of supplementary data within at least one data packet correlated with application data generated in connection with an application executed within said first terminal or said second terminal.
[0033] In this way, mechanisms are proposed for exchanging information between two remote terminals, so that these terminals can, for example, agree on a common policy for controlling the insertion of ancillary data, or at the very least, so that at least one of these terminals is aware of the other terminal's ability to implement such a control policy. This technique thus makes it possible, for example, to extend an ancillary data insertion control policy configured on a first terminal to a second remote terminal with which application data is exchanged, in order to ensure consistency or synchronization in the management of such ancillary data both locally and remotely, thereby giving a user greater control over their data.
[0034] In a particular embodiment, said method includes a recording, in a data structure associated with said second terminal, for said connection, of at least one parameter negotiated with said first terminal in relation to said request to activate or deactivate said process of controlling ancillary data insertion.
[0035] In this way, the parameters negotiated between two terminals for the control of ancillary data within a connection are stored within each terminal. In a particular embodiment, said method includes, when said request includes at least one parameter representing a request to activate said process of controlling the insertion of ancillary data within said at least one data packet, the processing of said at least one data packet by an operating system of said second communication terminal, according to an ancillary data insertion control policy.
[0036] In this way, the second terminal effectively puts into practice a processing of data packets in accordance with a desired policy for controlling the insertion of ancillary data, following the receipt of a request in this regard from the first terminal.
[0037] In yet another respect, the present technique relates to a device for managing a connection between a first terminal and a second terminal via a communication network. This device is implemented, for example, at the first terminal and includes at least one processor configured to exchange, with the second terminal, at least one message comprising at least one parameter representing a request to activate or deactivate a process for controlling the insertion of ancillary data within at least one data packet correlated with application data generated in connection with an application executed within the first or second terminal.
[0038] Such an electronic device can, of course, exhibit the various characteristics relating to the connection management method according to the invention, which can be combined or considered separately. Thus, the characteristics and advantages of this management device are the same as those of the connection management method between a first terminal and a second terminal via a communication network, and are not described in further detail.
[0039] According to another aspect, the proposed invention also relates to a computer program product downloadable from a communication network and / or stored on a computer-readable medium and / or executable by a microprocessor, comprising program code instructions for the execution of at least one process as described above in any of its embodiments, when this process is executed on a computer.
[0040] The proposed invention also relates to a computer-readable recording medium on which is recorded a computer program comprising program code instructions for executing the steps of a process as described above, in any of its embodiments.
[0041] Such a recording medium can be any entity or device capable of storing the program. For example, the medium may include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a USB flash drive or a hard drive.
[0042] On the other hand, such a recording medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means, so that the computer program it contains can be executed remotely. The program according to the invention can, in particular, be uploaded to a network, for example, the Internet.
[0043] The different embodiments mentioned above can be combined with each other for the implementation of the invention.
[0044] Figures
[0045] Other features and advantages of the invention will become more apparent upon reading the following description of a particular embodiment, given by way of simple illustrative and non-limiting example, and the accompanying drawings, among which:
[0046] [Fig 1] schematically illustrates an example of an environment for the implementation of this technique, in a particular embodiment;
[0047] [Fig 2] illustrates schematically, in the form of a sequence diagram, examples of message exchange between a first terminal and a second terminal within the framework of managing the connection between these two terminals, in a particular embodiment of the proposed technique;
[0048] [Fig 3] describes a simplified architecture of a device for managing a connection between a first terminal and a second terminal, in a particular embodiment of the proposed technique.
[0049] Detailed description of the invention
[0050] An example of an environment in which this technique is implemented is described in relation to Figure 1. The operation of a communication terminal (TC) is governed by at least one operating system (OS) installed on the terminal, enabling it to run one or more applications. Such a TC can take the form of a computer, tablet, smartphone, connected device, customer premises equipment (CPE), proxy server, or more generally, any software instance capable of establishing or receiving communications. The operating system (OS) and at least some of the applications installed on the terminal can exchange application data with other remote terminals (other communication terminals, servers, etc.).) reachable by the communication terminal via at least one RC communication network, such as the Internet. Thus, as part of its operation, an application (APP) running on the communication terminal (TC) exchanges application data (DA) via the RC network with another terminal, for example a remote server (SRV), to provide a service to a user.
[0051] Application data (AD) refers to data intrinsically associated with the operation of the application. Such data includes, for example, payload data (or payload), i.e., data sent or received by an application in the course of using the service provided by the application, as well as data intended to ensure the operation of the application, such as signaling data used, for example, to establish a connection with a remote terminal, manage user authentication for said application, etc.
[0052] Such DA application data is to be distinguished from data, referred to as DX annexes in the context of this technique, which relates to additional data that may be inserted into data packages correlated with said DA application data.By "data packets correlated with said application data", we mean here for example data packets including DA application data (which can be described as "in-band" or "In-Packet" packets, i.e., packets "in the band" or included in the application data packet), but also data packets which do not include DA application data but which nevertheless have a link with this DA application data (i.e., which are correlated with this DA application data), and which are intended to be transmitted out-of-band ("out-of-band" or also "Dedicated-Packet" in English), i.e. in a channel separate from that used for the transmission of DA application data packets (typically in a dedicated data packet in the context of IP communications, distinct from the application data packet but correlated to the latter).The concepts of in-band (or "In-Packet") and "out-of-band" (or "Dedicated-Packet") for IP communications are explained in more detail in the IETF document by C. Plgnatoro et al. entitled Guidelines for Characterizing "OAM" draft-ietf-opsawg-oam-characterization-04, November 2024.
[0053] Such ancillary data is not intrinsically linked to the operation of the application. However, in some cases, it may be related to optimizing the paths taken by application data (AD). In other words, the absence of such ancillary data (AD) generally does not impair the operation of the application (APP). As discussed in relation to prior art, this ancillary data (AD) is often inserted into data packets without the user's knowledge, typically includes information that a knowledgeable user might legitimately not want exposed, and is susceptible to being used for purposes not consented to by the user.
[0054] The invention applies independently of the protocols used for the exchange of application data as well as the method of managing a communication.
[0055] In the context of communication between an application (APP) and a remote terminal (SRV), such DX ancillary data can be inserted into a data packet correlated with application data (i.e., transmitted within the application data packet itself or out-of-band, in a dedicated packet) at different levels:
[0056] firstly, at the NI level of the TC communication terminal itself, before transmission of DA application data generated by the APP application or out-of-band data related to this application data to a remote SRV terminal;
[0057] secondly, at level N2 of an intermediate RC communication network equipment used to route data packets;
[0058] Thirdly, at the N3 level of the remote SRV terminal, for example before transmission of application data or out-of-band data related to this application data to the APP application running on the TC communication terminal, for example in response to a request issued by this APP application.
[0059] The technique described below relates more particularly to the control of ancillary data that may be inserted at the third level N3, i.e. at the level of the remote terminal SRV with which the communication terminal TC exchanges application data in the context of the execution of the application APP.
[0060] More generally, the proposed technique describes mechanisms for exchanging information between two remote terminals - a first terminal (for example, the TC communication terminal or the SRV remote terminal in Figure 1) and a second terminal (respectively, for example, the SRV remote terminal or the TC communication terminal in Figure 1) - so that these two terminals can, for example, agree on a common policy for controlling the insertion of ancillary data, or at the very least, so that at least one of these terminals is aware of the other terminal's ability to implement such a control policy.
[0061] More specifically, an ancillary data insertion control policy includes a set of rules that constrain how data frames used to carry application data, or out-of-band data correlated with that application data, over a communication network—and therefore the associated data packets—can be generated or modified. This allows, for example, defining within which framework and at which level of a protocol stack an ancillary data insertion is permitted or, conversely, denied. As described later, an ancillary data insertion control policy may also include rules for determining, at the device level where it is implemented, how data packets should be transmitted over the communication network (for example, through redirection rules, network interface selection, etc.).Such a control policy has, for example, been previously configured at the level of a terminal (by a user, an operator, or any other actor), and can in particular be associated with one or more applications running on that terminal.
[0062] In this context, a method for managing a connection between a first terminal and a second terminal, via a communication network (for example, an IP network such as the Internet), is proposed, according to a first aspect. The terms "first terminal" and "second terminal" used in this document are intended solely to distinguish between these two terminals and do not imply any hierarchical relationship between them.According to the general principle of the proposed technique, such a process, presented in relation to Figure 2, is for example implemented at the level of the first terminal T1, and it includes at least one exchange, with the second terminal T2, of at least one message including at least one parameter representing a request to activate or deactivate a control process for the insertion of supplementary data DX within at least one packet of data correlated with application data DA generated in relation to an application APP executed within said first terminal T1 or said second terminal T2.
[0063] By "exchange" we mean here the transmission by the first terminal of at least one message to the second terminal and / or the reception at the level of the first terminal of at least one message from the second terminal.
[0064] In the specific embodiment illustrated in Figure 2, the first terminal T1 transmits, for example, to the second terminal T2 a message M1 that includes at least one parameter representing a request to activate, at the level of the second terminal T2, a process for controlling the insertion of supplementary data DX within at least one data packet correlated with application data DA generated in relation to an application APP executed within the first terminal T1. According to a particular feature, the message M1 (or a subsequent message to the message M1) further includes at least one parameter representing a desired control scope for the implementation, by the second terminal, of the process for controlling the insertion of supplementary data. Examples of such parameters are described later in this document.
[0065] Such a request Ml aims for example to extend to the second terminal T2 a policy of controlling the insertion of ancillary data which the first terminal Tl already implements or plans to implement.
[0066] Upon receipt of the Ml request, the second terminal T2 checks whether it is able, at its level, to implement a policy for controlling the insertion of ancillary data on the scope desired by the first terminal Tl.
[0067] In the event of a successful verification, in other words, when the second terminal determines that it is capable of implementing a process for controlling the insertion of ancillary data within the scope desired by the first terminal T1, and possibly after considering other complementary criteria (for example, verification by the second terminal that implementing such a process does not compromise other functionalities of that terminal), the second terminal can decide to apply a control process conforming to the request M1 of the first terminal. The second terminal T2 then sends, in a specific embodiment, a message M2 to the first terminal T1, confirming that it has indeed activated the process for controlling the insertion of ancillary data.
[0068] In the event of an inconclusive verification, in other words when the second terminal determines that it is unable to implement a process for controlling the insertion of ancillary data on the scope desired by the first terminal Tl, the second terminal sends, in a particular embodiment, a message M2' to the first terminal to inform it of this situation.
[0069] The reception of such a message M2' by the first terminal T1 allows it, for example, to send a new request to the second terminal T2, in the form of a message of the same type as the message M1, but with a request for data insertion control on a different, for example more restricted, perimeter than that initially defined in the message M1.
[0070] According to a particular characteristic, message M2' (or another subsequent message transmitted from the second terminal to the first terminal) includes at least one parameter representing a request to activate, at the level of the first terminal T1, a control process for the insertion of supplementary data over a perimeter other than that initially defined in message M1. Similar to what has already been described in relation to message M1, this other perimeter is defined, for example, by the additional transmission, in message M2' or a message subsequent to message M2', of at least one parameter representing a desired control perimeter for the implementation, by the first terminal, of the control process for the insertion of supplementary data.
[0071] Such an M2' request aims, for example, to ask the first terminal T1 to implement a policy for controlling the insertion of ancillary data that is consistent with the one that the second terminal T2 already implements or has the capacity to implement. Similar to the verification operation already described at the level of the second terminal T2, the first terminal T1 can also, in a particular embodiment, upon receiving such an M2' message, verify that it is indeed capable of implementing a policy for controlling the insertion of ancillary data within the scope desired by the second terminal T2.Several cycles of message exchanges of the type M1, M2 and / or M2' as described above can be implemented within the framework of this technique, initiated by either of the first terminal T1 or the second terminal T2, for example, until these two terminals have agreed on a policy for controlling the insertion of ancillary data to be implemented on both sides. Furthermore, these cycles can occur at any phase of a connection (during the establishment of a connection or when it is already established, typically when a new channel ("stream") or sub-session ("subflow") is added to a connection).
[0072] In one particular embodiment, the message exchanges implemented within the framework of this technique thus provide a synchronization (or negotiation) mechanism enabling remote terminals (the first terminal T1 and the second terminal T2 in the example described here) to agree—when possible—on a common ancillary data insertion control policy that each can implement independently. The parameters negotiated during these exchanges (for example, the parameters defining a common ancillary data insertion control policy to be implemented, in other words, parameters representing the scope of control to be applied) are stored, for each terminal, in a data structure (typically a database) associated with that terminal. According to a particular characteristic, these negotiated parameters are associated with a current connection established between the remote terminals.Thus, each terminal is aware of the policy for controlling the insertion of additional data that it must apply for a given connection.
[0073] In a particular embodiment of the proposed technique, the message exchanges described above are implemented, for example, during the establishment of a connection between the two terminals T1 and T2. According to a particular characteristic, one of the messages comprising at least one parameter representing a request to activate or deactivate a process for controlling the insertion of supplementary data (typically the first message of this type sent or received by the first activation terminal) includes a request to establish a connection with the second terminal.
[0074] We now describe examples of parameters representative of a control perimeter that can be transmitted from one terminal to another as part of a request to activate a control process for the insertion of ancillary data within at least one data packet correlated with application data.
[0075] For illustrative purposes only and not as a limitation, such parameters include, for example:
[0076] a parameter representing a request for control of insertion of ancillary data at the level of at least one layer of a protocol stack used for the transmission of at least one data packet correlated with application data via the communication network;
[0077] a parameter representative of a request for control of insertion of ancillary data at the level of at least one protocol of said protocol stack used for the transmission of at least one data packet correlated with application data on the communication network;
[0078] a parameter representative of a request for control of insertion of ancillary data at the level of at least one data package correlated with application data, determined according to at least one criterion defined for said application;
[0079] a parameter representative of a request for out-of-band insertion control of ancillary data correlated to said application data.
[0080] These parameters, which define rules that one terminal wants to be applied by another terminal as part of the implementation of a policy for controlling the insertion of ancillary data, thus offer the possibility of acting at different levels.
[0081] For example, in a particular embodiment, a rule prohibiting the insertion of ancillary data at the general level of one or more layers can be defined. Thus, it is possible, for example, to define a rule according to which no insertion of ancillary data is allowed in connection with the transport layer of a TCP / IP model, regardless of the IP version used (IPv4 or IPv6) or the transport protocol (for example, TCP "Transmission Control Protocol", UDP "User Datagram Protocol", SCTP "Stream Control Transmission Protocol", QUIC) actually used.
[0082] More specifically, the proposed technique also allows for the definition of one or more rules prohibiting the insertion of additional data at the level of a particular protocol within a given layer (physical, network, transport, application, etc.). For example, it is possible to define a rule whereby no additional data is allowed during encapsulation using the UDP transport protocol.Implementing such a rule results, for example, in disabling the use of any "options" available in the headers and / or trailers of data frames defined according to these protocols (in this case, either the operating system does not insert any data into these fields when constructing the data frame to be transmitted over the communication network, or the operating system removes all data present in these fields). For example, terminals participating in a QUIC connection can negotiate the disabling of UDP options for all or part of the exchanged data. Other protocols, such as TCP, HTTP, SIP, WebRTC, etc., can also be subject to the control of ancillary data insertion.
[0083] In a particular embodiment, according to an alternative or complementary approach, the proposed technique also allows, within the framework of the control policy, the configuration of rules that define whether or not the ancillary data insertion control should be performed for all application data. More specifically, it is thus possible, provided that the operating system of the terminal receiving the activation request supports these different modes, to specify that the ancillary data insertion control should be performed, for example, for all data packets sent during the same application session, or conversely, to perform this control only for all data packets of a targeted data stream of an application session, or even only for certain clearly identified packets (using, for example, a packet identifier).For example, if the application in question is a video conferencing application, it is possible to define rules according to which the insertion of ancillary data is allowed in the audio application data stream, but not in the video application data stream. More precisely, it is also possible, with regard to the control performed at the video application data stream level, to configure a rule prohibiting the insertion of application data only within the data packets associated with the transmission of keyframes of that video stream.
[0084] Alternatively or in addition, one or more rules prohibiting the insertion of ancillary data at the level of out-of-band data correlated with application data can also be defined. In this way, the insertion of ancillary data can be controlled not only at the level of the communication channel used to carry application data, but also at the level of other communication channels that might be used to carry out-of-band data. Such a channel could rely on application data packet mirroring, a dedicated ICMP (Internet Control Message Protocol) packet, etc.In the case of an ICMP packet, correlation with the application data packet can, for example, be achieved by inserting into the ICMP packet a digest (or "hash" in English) of said data packet, the characteristic information of the connection (source IP address, source port number, destination IP address, destination port number, transport protocol), or a combination of the two.
[0085] Alternatively or in addition, in other specific embodiments of this technique, the parameters representing a control perimeter define rules to be implemented at the recipient terminal to govern how data packets related to application data are transmitted. These rules include, for example, redirection rules, network interface selection rules, or other types of rules, which aim in particular to prioritize communication channels that offer guarantees in terms of managing the insertion of ancillary data when routing data packets to their intended remote recipients.Thus, the parameters representing a control perimeter may include at least one parameter representing a request to select a route using at least one autonomous system capable of implementing a process for controlling the insertion of supplementary data within at least one data packet, for the routing of such data packets via said communication network.
[0086] In one embodiment, the procedure is implemented via one or more "proxies" (relays).
[0087] In a particular embodiment, the parameters representing a control perimeter also include a parameter representing at least one direction of data packet routing, in relation to which the implementation of a process for controlling the insertion of supplementary data is requested. Thus, with reference to the example illustrated in Figure 2, it can be specified via such a parameter that the control is requested:
[0088] only for data packets routed from the first terminal to the second terminal (in a first direction);
[0089] only for data packets routed from the second terminal to the first terminal (in a second direction);
[0090] both for data packets routed from the first terminal to the second terminal and for data packets routed from the second terminal to the first terminal (according to said first and second directions).
[0091] The preceding examples are, of course, given for illustrative purposes only and are not exhaustive. Other types of rules (based on time ranges, resource availability, etc.) can also be considered within the framework of this technique and integrated as parameters representing a desired control perimeter for the implementation, by a recipient terminal, of the process of controlling the insertion of supplementary data. The combination of several rules can also be considered.
[0092] In another respect, the proposed technique also relates to a device for managing a connection between a first terminal and a second terminal via a communication network. Such an electronic device, implemented at the first terminal (or, respectively, the second terminal), is capable of carrying out the process described above in any of its embodiments. More specifically, such a device according to the present technique comprises at least one processor configured to exchange, with said second terminal (or, said first terminal), at least one message including at least one parameter representing a request to activate or deactivate a process for controlling the insertion of supplementary data within at least one data packet correlated with application data generated in connection with an application executed within said first or second terminal.
[0093] Figure 3 schematically and simply represents the structure of such an electronic device in a particular embodiment. The device, according to the proposed technique, comprises, for example, a memory 31 consisting of a buffer memory M, a processing unit 32, equipped, for example, with a microprocessor pP, and controlled by the computer program Pg 33, implementing steps of the process for managing a connection between a first terminal and a second terminal according to at least one embodiment of the invention.
[0094] At initialization, the code instructions of computer program 33 are loaded into the buffer memory before being executed by the processor of the processing unit 32.
[0095] When the terminal in which the electronic device is implemented, referred to as the first terminal, requests the activation or deactivation of a control process for the insertion of ancillary data at another terminal, referred to as the second terminal, the processing unit 32 receives, as input E, for example, data relating to an ancillary data insertion control policy that the first terminal wishes the second terminal to apply, within the context of a connection between these two terminals. Such configuration data, which defines a desired scope for the implementation of a control policy, can notably be enhanced by means of a dedicated application programming interface made available to a user or an application at the first terminal.The microprocessor of the processing unit 32 then carries out the steps of the connection management process, according to the instructions of the computer program 33. More specifically, the processing unit 32 constructs and emits, for example, at least one message at output S intended for the second terminal, including at least one parameter representing a request to activate or deactivate a process for controlling the insertion of supplementary data on the desired perimeter, according to at least one of the embodiments described previously.
[0096] When the terminal in which the electronic device is implemented, referred to as the first terminal, receives a request from another terminal, referred to as the second terminal, to activate or deactivate a process for controlling the insertion of supplementary data, the processing unit 32 receives, for example, at least one message as input E from the second terminal, containing at least one parameter representing a request to activate or deactivate a process for controlling the insertion of supplementary data. The microprocessor of the processing unit 32 then performs the steps of the connection management process, according to the instructions of the computer program 33.More specifically, processing unit 32 determines a requested control perimeter, based on the information contained in the message, and assesses whether the first terminal is capable of applying a policy to control the insertion of ancillary data across this entire perimeter. Depending on the results of this analysis, processing unit 32, for example, outputs a message S to the second terminal, informing it whether or not the first terminal is capable of implementing a process to control the insertion of ancillary data within the requested perimeter. If it is determined that the first terminal is capable of implementing it within the requested perimeter, processing unit 32 activates the process to control the insertion of ancillary data at the first terminal.
Claims
DEMANDS 1. Method for managing a connection between a first terminal and a second terminal via a communication network (CR), said method being implemented by said first terminal, said method being characterized in that it comprises at least one exchange, with said second terminal, of at least one message comprising at least one parameter representing a request to activate or deactivate a control process for the insertion of supplementary data (DX) within at least one packet of data correlated with application data (DA) generated in relation to an application (APP) executed within said first terminal or said second terminal.
2. Method according to claim 1, characterized in that said at least one message further comprises at least one parameter representing a desired control perimeter for the implementation, by the receiving terminal of said at least one message from said first terminal or said second terminal, of said control process of an insertion of supplementary data.
3. A method according to claim 2, characterized in that said at least one parameter representative of a control perimeter belongs to the group comprising: a parameter representative of a request for control of insertion of ancillary data at the level of at least one layer of a protocol stack used for the transmission of said at least one data packet via said communication network; a parameter representative of a request for control of insertion of ancillary data at the level of at least one protocol of said protocol stack used for the transmission of said at least one data packet via said communication network; a parameter representing a request for control of insertion of ancillary data at the level of at least one data packet determined according to at least one criterion defined for said application; a parameter representing a request for control of out-of-band insertion of ancillary data correlated to said application data.
4. Method according to claim 2, characterized in that said at least one parameter representing a control perimeter includes a parameter representing a request for selection of a route using at least one autonomous system capable of implementing a process for controlling the insertion of ancillary data within said at least one data packet, for the routing of said at least one data packet via said communication network.
5. A method according to claim 2, characterized in that said at least one parameter representing a control perimeter comprises a parameter representing at least one routing direction of said at least one data packet in relation to which a control process for an insertion of supplementary data is requested from among: a first direction, corresponding to a routing from the first terminal to the second terminal; a second direction, corresponding to a routing from the second terminal to the first terminal; both the said first direction and the said second direction.
6. A method according to any one of the preceding claims, characterized in that it comprises a recording, in a data structure associated with said first terminal, for said connection, of at least one parameter negotiated with said second terminal in relation to said request for activation or deactivation of said control process of ancillary data insertion.
7. A method according to any one of the preceding claims, characterized in that at least one of said at least one message further comprises a request to establish a connection with said second terminal.
8. A method according to any one of the preceding claims, characterized in that it further comprises at least one exchange of at least one message comprising at least one parameter representing an activation or deactivation confirmation, at the level of said first terminal or said second terminal, of said ancillary data insertion control process.
9. Method for managing a connection between a first terminal and a second terminal via a communication network, said method being implemented by said second terminal, said method being characterized in that it comprises a reception, from said first terminal, of at least one message comprising at least one parameter representing a request for activation or deactivation, at the level of said second terminal, of a process for controlling the insertion of ancillary data within at least one packet of data correlated with application data generated in relation to an application executed within said first terminal or said second terminal.
10. Method according to claim 9, characterized in that it comprises a record, in a data structure associated with said second terminal, for said connection, of at least one parameter negotiated with said first terminal in relation to said request for activation or deactivation of said control process of ancillary data insertion.
11. Method according to claim 9 or 10, characterized in that it comprises, when said request includes at least one parameter representative of a request to activate said process of controlling the insertion of supplementary data within said at least one data packet, the processing of said at least one data packet by an operating system of said second communication terminal, according to a policy for controlling the insertion of supplementary data.
12. Device for managing a connection between a first terminal and a second terminal via a communication network, said device being characterized in that it is implemented at the level of said first terminal and in that it includes at least one processor configured to exchange, with said second terminal, at least one message including at least one parameter representing a request to activate or deactivate a process for controlling the insertion of ancillary data within at least one data packet correlated with application data generated in relation to an application executed within said first terminal or said second terminal.
13. Product computer program downloadable from a communication network and / or stored on a computer-readable medium and / or executable by a microprocessor, characterized in that it includes program code instructions for the execution of a method according to any one of claims 1 to 8 or a method according to any one of claims 9 to 11, when executed by a computer.