Title :
An End-to-End Security Solution for SCTP
Author :
Lindskog, Stefan ; Brunstrom, Anna
Author_Institution :
Centre for Quantifiable Quality of Service in Commun. Syst., Norwegian Univ. of Sci. & Technol., Trondheim
Abstract :
The stream control transmission protocol (SCTP) is a fairly new transport protocol that was initially designed for carrying signaling traffic in IP networks. SCTP offers a reliable end-to-end (E2E) transport. Compared to TCP, SCTP provides a much richer set of transport features such as message oriented transfer, multistreaming to handle head- of-line blocking, and multihoming for enhanced failover. These are all very attractive features, but at the same time proven hard and complex to secure for E2E transports. All existing security solutions have limitations. In this paper, a survey of existing solutions is first given. Then, an alternative solution is proposed. The proposed solution uses the new authenticated chunks for SCTP for integrity protection, TLS for key exchange and authentication, and symmetric encryption implemented at the socket layer for confidentiality protection. A qualitative comparison of the described E2E security solutions is also given.
Keywords :
IP networks; cryptography; data integrity; message authentication; telecommunication network reliability; telecommunication security; telecommunication signalling; telecommunication traffic; transport protocols; IP network; authentication; confidentiality protection; integrity protection; key exchange; reliable end-to-end security; stream control transmission protocol; symmetric encryption; telecommunication signaling traffic; transport protocol; Authentication; Communication system traffic control; Cryptography; IP networks; Protection; Security; Signal design; Sockets; TCPIP; Transport protocols; SCTP; end-to-end security; protocol design; qualitative comparison; security differentiation;
Conference_Titel :
Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
Conference_Location :
Barcelona
Print_ISBN :
978-0-7695-3102-1
DOI :
10.1109/ARES.2008.37