EP1676419A1 - Procede de surveillance de messages destines a l initialisat ion de sessions d echange de flux multimedias, serveur et in stallation mettant en oeuvre ce procede - Google Patents
Procede de surveillance de messages destines a l initialisat ion de sessions d echange de flux multimedias, serveur et in stallation mettant en oeuvre ce procedeInfo
- Publication number
- EP1676419A1 EP1676419A1 EP04805244A EP04805244A EP1676419A1 EP 1676419 A1 EP1676419 A1 EP 1676419A1 EP 04805244 A EP04805244 A EP 04805244A EP 04805244 A EP04805244 A EP 04805244A EP 1676419 A1 EP1676419 A1 EP 1676419A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- initialization
- monitoring
- packet
- sip
- messages
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000012544 monitoring process Methods 0.000 title claims abstract description 65
- 238000000034 method Methods 0.000 title claims abstract description 28
- 238000009434 installation Methods 0.000 title claims abstract description 7
- 230000000977 initiatory effect Effects 0.000 title abstract 4
- 230000005540 biological transmission Effects 0.000 claims abstract description 24
- 238000012545 processing Methods 0.000 claims description 25
- 230000009897 systematic effect Effects 0.000 claims description 3
- 238000012360 testing method Methods 0.000 description 6
- 230000004044 response Effects 0.000 description 4
- 238000010586 diagram Methods 0.000 description 2
- 230000006870 function Effects 0.000 description 2
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/20—Traffic policing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/22—Traffic shaping
- H04L47/225—Determination of shaping rate, e.g. using a moving window
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/1066—Session management
- H04L65/1101—Session protocols
- H04L65/1104—Session initiation protocol [SIP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/80—Responding to QoS
Definitions
- the present invention relates to a message monitoring method intended for the initialization of multimedia stream exchange sessions, a server and an installation implementing this method. More specifically, the invention relates to a method for monitoring messages intended for the initialization of sessions for exchanging multimedia streams transmitted in packet mode via a monitoring server by a network between a transmitting terminal and at least one receiving terminal.
- Initialization means establishing, modifying or closing a session during which multimedia streams are exchanged. Thereafter, we will describe the invention based on the SIP protocol.
- the SIP protocol Session Initialization Protocol
- Session Initialization Protocol is a protocol of the Application layer of the OSI model allowing the establishment, modification or closure of a session during which multimedia streams are exchanged between a transmitting terminal and at minus a receiving terminal.
- This SIP protocol uses messages which circulate in the form of packets in a SIP network made up of specific processing servers.
- the SIP network is a network overlapping with an IP network.
- the path taken by SIP messages is therefore not necessarily the same as that taken by multimedia streams.
- the establishment of the session consists in defining, by means of the exchange of SIP messages, the type and format of the multimedia streams (for example the encoded codes used) that the terminals wish to transmit.
- SIP messages can be exchanged between terminals to agree on a new format for multimedia streams. Finally, SIP messages are exchanged again when the session is closed.
- the operator of the network on which the multimedia flows are exchanged invoices the user of the terminal having established the connection, according to the duration of the multimedia flow exchange session. If the terminal cannot establish the connection despite the exchange of SIP messages, the operator does not charge the user for this terminal. However, it is possible for a malicious user to use the SIP messages themselves as well as the bandwidth allocated by the operator for their transmission, to include data not linked to the establishment of a connection, in particular the multimedia data themselves. Indeed, the operator does not generally check the content of SIP messages.
- SIP processing servers are already known in the state of the art, which consist in limiting the transmission of SIP messages to messages containing only predefined pieces of information, adapted to services that the network operator wishes to provide to its users.
- This method however requires significant processing capacity at the level of the SIP processing servers which compare each SIP message with messages authorized by the operator. It also requires an update of the SIP processing servers each time the operator decides to modify the types of SIP messages authorized to transit on his network. This solution is effective but complex and costly to implement.
- the object of the invention is to remedy these drawbacks by providing a method for monitoring messages intended for the initialization of multimedia stream exchange sessions capable of verifying that the session initialization messages are not used for transmitting diverted information, without verifying the content of each initialization message passing through the network.
- the subject of the invention is a method for monitoring messages intended for the initialization of multimedia stream exchange sessions, these messages being transmitted in packet mode via a monitoring server by a network between a transmitting terminal and at least one receiving terminal, characterized in that it comprises the following steps: a speed value is estimated for at least one initialization packet received by the monitoring server, this value is compared to a maximum authorized speed value, - the transmission of the initialization packet is authorized only if the speed value for this initialization packet does not exceed the maximum authorized speed value. Thanks to the monitoring of the speed of SIP packets passing through the network, the invention makes it possible to detect diverted SIP packets which, containing information useless to the SIP protocol, abnormally increase their own speed. The transmission of these SIP packets is then interrupted.
- a method of monitoring messages transmitted in packet mode may also include one or more of the following characteristics: for each pair formed by a transmitting terminal and a receiving terminal, a transmission channel is defined, associated with a specific maximum authorized flow value; the estimation of the throughput value for the initialization packet received by the monitoring server comprises a step during which the sizes of the last initialization packets transmitted by the sending terminal to the receiving terminal are kept in memory and received by the monitoring server from a predetermined duration and a step during which the sum of the sizes of the stored initialization packets is divided by the predetermined duration; the method is implemented by the monitoring server, the latter being further dedicated to the processing of session initialization packets; - the routing of session initialization packets s is forced to the monitoring server as the first processing server crossed by these session initialization packets; the monitoring server being any one of the servers for processing session initialization packets, routing rules are defined ensuring a systematic transit of session initialization packets by this processing server; and the session initialization messages transmitted use the SIP protocol.
- the invention also relates to a message monitoring server intended for the initialization of multimedia stream exchange sessions, these messages being transmitted in packet mode via a monitoring server by a network between a transmitting terminal and at least one receiving terminal, characterized in that it comprises: means for estimating a throughput value for at least one initialization packet received by the monitoring server, - means for comparing this value with a throughput value maximum authorized, means for authorizing the transmission of the initialization packet only if the rate value for this packet does not exceed the maximum authorized rate value.
- the invention also relates to an installation for transmitting messages intended for the initialization of multimedia stream exchange sessions comprising a network and at least one monitoring server according to the invention.
- FIG. 1 shows a transmitter terminal 10 communicating with a receiver terminal 12 via a data transmission network 18.
- the terminals 10 and 12 are for example computers or telephones, and the data transmission network 18 is an IP network 18 or a switched telephone network in combination with an IP network.
- the data transmission network 18 consists of a set of routers 14, 16, linked together, the function of which is to ensure correct routing of messages between the terminals 10 and 12, through the data transmission network 18 .
- the terminals 10 and 12 exchange both initialization messages intended for the initialization of multimedia stream exchange sessions and multimedia streams.
- the initialization messages are SIP messages. These SIP messages are transmitted in packet mode, that is to say that they are transmitted in the form of a plurality of packets.
- the data transmission network 18 is also constituted by servers 20, 22 for processing specific SIP packets, interconnected in the form of a network 24 overlapping the data transmission network 18. This network 24 overlapping the transmission network 18 is called SIP network 24 in the following description because it is dedicated to the transfer of SIP messages.
- the function of the SIP processing servers 20, 22 is to ensure the correct routing of SIP packets between the terminals 10 and 12 through the SIP network 24.
- the path followed by the multimedia streams 26 depends on the IP addresses of the computers 10, 12. It is determined by the IP routers 14, 16 of the network.
- the path followed by the SIP flows 28 can depend on the IP addresses of the computers 10, 12, but also on the telephone numbers or e-mail addresses of the users of the computers 10, 12. It is determined by the SIP processing servers 20, 22 and necessarily passes through the SIP network 24.
- the SIP flows 28 are transmitted on different SIP channels and can be identified using the addresses of the computers 10, 12 between which the flows are transmitted, or addresses (for example the telephone numbers) of the users of computers 10 and 12.
- the monitoring method according to the invention is implemented by a monitoring server through which the SIP packets pass. This monitoring server is generally also dedicated to processing SIP packets.
- the monitoring method according to the invention is therefore implemented by one of the SIP processing servers 20, 22, and consists in monitoring the SIP messages transmitted in packet mode by the network 18 between the sending terminal 10 and the receiving terminal 12. For a given SIP channel, a bit rate value Dm is estimated for a SIP packet sent on this SIP channel and this bit rate value Dm is compared to a maximum authorized bit rate value Dmax.
- the transmission of the SIP packet is then authorized only if the rate value Dm for this SIP packet does not exceed the value of maximum authorized rate Dmax.
- the maximum authorized speed Dmax for a given SIP channel is previously defined and communicated by the operator to the SIP monitoring servers 20, 22 which implement the monitoring process. The operator also communicates the maximum authorized size Tmax for a package. This data is useful for SIP monitoring servers when a new SIP channel is created, and the servers have not received enough SIP packets to be able to calculate the bit rate value Dm of the new packet sent on the new SIP channel created.
- the values of the maximum authorized speed Dmax and the maximum authorized size Tmax depend on the channel of the SIP messages, that is to say the terminals sending the SIP messages.
- SIP processing servers on the network are necessarily SIP monitoring servers. Also, it must be ensured that among all the processing servers through which a SIP packet passes, at least one of these SIP processing servers is a SIP monitoring server.
- the invention can be implemented by a single SIP monitoring server as the first processing server through which the SIP packets pass. One can then use in the routers 14, 16 a software device such as a firewall, to force the routing of the SIP packets to this first SIP processing server.
- the invention can be implemented by a SIP monitoring server which is any of the SIP processing servers of the SIP network.
- the monitoring method represented in FIG. 2 comprises a first step 30 of reception of an SIP packet by the SIP monitoring server 20 , 22.
- the SIP monitoring server 20, 22 identifies the SIP channel relating to the received packet. This identification is possible thanks to the addresses of the sender and receiver of the received SIP packet.
- the SIP monitoring server 20, 22 tests whether the received SIP packet relates to a newly created SIP channel or to a SIP channel in use.
- the SIP monitoring server checks whether the size T of the received packet is less than the maximum size Tmax authorized for a packet.
- the size T of the received packet is less than the authorized size Tmax, we pass to a step 40 of transmission of the packet received by the SIP monitoring server. Otherwise, we go to a test step 42 during which the monitoring server tests whether the received SIP packet corresponds to a SIP request or to a SIP response. If the received packet corresponds to a request, we go to a step 44 during which the SIP monitoring server 20, 22 does not transmit this request to the recipient but deletes it and sends an error response to the packet sender . If the received packet corresponds to a response, we go to a step 46 during which the SIP monitoring server does not transmit the response to the recipient and sends a “cancellation” type message to the recipient.
- step 34 finds that the received packet corresponds to a SIP channel in use, we go to a step 48 for updating the List_Demiers_Paquets list relating to the SIP channel of the received packet.
- This update consists in adding to this list the information concerning the last packet received and in deleting from this list the information concerning the packets received for longer than the duration D of storage.
- the SIP monitoring server estimates the average rate Dm of the packets relating to the SIP channel of the last packet received. This average throughput is estimated by dividing the sum of the sizes of the packets stored in the List_Last_Packages list by the duration D of storage.
- the SIP monitoring server checks whether the average speed Dm is less than the maximum authorized speed Dmax. If the average flow Dm is less than the maximum authorized flow Dmax, we go to step 40. If the average flow Dm is greater than the maximum authorized flow Dmax, we go to step 42.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Multimedia (AREA)
- Business, Economics & Management (AREA)
- General Business, Economics & Management (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0312346A FR2861520A1 (fr) | 2003-10-22 | 2003-10-22 | Procede de surveillance de messages destines a l'initialisation de sessions d'echange de flux multimedias, serveur et installation mettant en oeuvre ce procede |
| PCT/FR2004/002680 WO2005041528A1 (fr) | 2003-10-22 | 2004-10-20 | Procede de surveillance de messages destines a l'initialisation de sessions d'echange de flux multimedias, serveur et installation mettant en oeuvre ce procede |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1676419A1 true EP1676419A1 (fr) | 2006-07-05 |
Family
ID=34400700
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP04805244A Withdrawn EP1676419A1 (fr) | 2003-10-22 | 2004-10-20 | Procede de surveillance de messages destines a l initialisat ion de sessions d echange de flux multimedias, serveur et in stallation mettant en oeuvre ce procede |
Country Status (5)
| Country | Link |
|---|---|
| EP (1) | EP1676419A1 (fr) |
| JP (1) | JP4592705B2 (fr) |
| CN (1) | CN1898934B (fr) |
| FR (1) | FR2861520A1 (fr) |
| WO (1) | WO2005041528A1 (fr) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103209396B (zh) * | 2013-03-27 | 2016-01-13 | 东莞宇龙通信科技有限公司 | 一种调整彩信数据量上限的方法及使用该方法的移动终端 |
| CN112769636B (zh) * | 2020-12-16 | 2022-06-14 | 咪咕数字传媒有限公司 | 视频短信链路监测方法、装置、电子设备及存储介质 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| GB9711788D0 (en) * | 1997-06-06 | 1997-08-06 | Northern Telecom Ltd | Method and interface for connecting communication traffic between narrowband and broadband networks |
-
2003
- 2003-10-22 FR FR0312346A patent/FR2861520A1/fr active Pending
-
2004
- 2004-10-20 EP EP04805244A patent/EP1676419A1/fr not_active Withdrawn
- 2004-10-20 CN CN200480038425.6A patent/CN1898934B/zh not_active Expired - Fee Related
- 2004-10-20 JP JP2006536118A patent/JP4592705B2/ja not_active Expired - Fee Related
- 2004-10-20 WO PCT/FR2004/002680 patent/WO2005041528A1/fr not_active Ceased
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2005041528A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| FR2861520A1 (fr) | 2005-04-29 |
| CN1898934A (zh) | 2007-01-17 |
| JP4592705B2 (ja) | 2010-12-08 |
| WO2005041528A1 (fr) | 2005-05-06 |
| CN1898934B (zh) | 2012-09-05 |
| JP2007509556A (ja) | 2007-04-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9191377B2 (en) | Method for network communication past encryption devices | |
| FR2805112A1 (fr) | Procede et unite de controle de flux d'une connexion tcp sur un reseau a debit controle | |
| FR2954029A1 (fr) | Procede de transmission de paquets d'un flux de donnees bidirectionnel passager, dispositif gestionnaire, produit programme d'ordinateur et moyen de stockage correspondants | |
| EP2087698B1 (fr) | Procédé d'etablissement d'une connexion securisöe, equipement CFM et produit programme d'ordinateur correspondants | |
| FR2836315A1 (fr) | Correlation des requetes en qualite de service au sein d'un systeme de controle d'un reseau de donnees | |
| EP2460322A1 (fr) | Procede et systeme pour la selection automatique de media de transmission | |
| Tyagi | Tcp/ip protocol suite | |
| EP1676419A1 (fr) | Procede de surveillance de messages destines a l initialisat ion de sessions d echange de flux multimedias, serveur et in stallation mettant en oeuvre ce procede | |
| EP3808060B1 (fr) | Traitement de messages dans un réseau de voix sur ip | |
| WO2011157704A2 (fr) | Système et méthode de gestion de flux sécurisés entre plusieurs sites distants | |
| EP3963842A1 (fr) | Procedes et dispositifs de mesure de reputation dans un reseau de communication | |
| FR3160837A1 (fr) | Procédé et dispositif de détection et d’identification d’algorithmes cryptographiques dans un réseau de communication. | |
| US8806020B1 (en) | Peer-to-peer communication session monitoring | |
| FR2832889A1 (fr) | Controle d'admission a un reseau de donnees pour l'assurance de la qualite de service | |
| EP2476225B1 (fr) | Procede et systeme pour le controle de l'acheminement d'un flux de donnees d'une classe de service a travers un reseau maille et chiffre | |
| EP1432210A1 (fr) | Dispositif de contrôle de traitements associés a des flux au sein d'un reseau de communications | |
| US20070086352A1 (en) | Method of monitoring multimedia stream exchange session initialization messages and a server and an installation for carrying out said method | |
| EP2047653B1 (fr) | Transmission de flux de donnees en fragmentation des messages | |
| WO2023078993A1 (fr) | Procédé de gestion d'une retransmission de données échangées sur un chemin établi entre un premier équipement de communication et un deuxième équipement de communication au moyen d'une valeur d'un paramètre de performance intermédiaire | |
| WO2023078995A2 (fr) | Procédé de vérification de la fiabilité d'une première valeur d'un paramètre de contrôle de flux relatif à une connexion destinée à être établie entre un premier équipement de communication et un deuxième équipement de communication reliés par un chemin comprenant au moins un nœud intermédiaire au moyen d'une valeur d'un paramètre de performance intermédiaire déterminée par le nœud intermédiaire | |
| FR2960372A1 (fr) | Procede de gestion d'un flux de donnees utiles passager, produit programme d'ordinateur, moyen de stockage et dispositif gestionnaire correspondants | |
| FR2876524A1 (fr) | Procede et dispositif de transfert de flux d'informations dans un reseau de telecommunication a permutation d'etiquettes | |
| FR3013553A1 (fr) | Procede de transmission de paquets dans un reseau et reseau dans lequel est mis en œuvre ledit procede. | |
| FR2904905A1 (fr) | Procedes et systemes d'emission et de reception d'un flux de donnees en fonction de contraintes de qualite de service | |
| FR2835989A1 (fr) | Controle d'admission a un reseau de donnees pour l'assurance de la qualite de service |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20060512 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PL PT RO SE SI SK TR |
|
| 17Q | First examination report despatched |
Effective date: 20060803 |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: AVELINE, SOPHIE Inventor name: TUFFIN, STEPHANE Inventor name: NGUYEN, KIM-ANH-VU |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20060803 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| INTG | Intention to grant announced |
Effective date: 20130524 |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20131005 |