DocumentCode
1578387
Title
Mutual Authentication for SIP: A Semantic Meaning for the SIP Opaque Values
Author
Guillet, Thomas ; Serhrouchni, Ahmed ; Badra, Mohamad
Author_Institution
Dept. Comput. Sci. & Networks, Inst. TELECOM Paris, Paris
fYear
2008
Firstpage
1
Lastpage
6
Abstract
The session initiation protocol (SIP) is rapidly becoming the dominant signalling protocol for calls over the Internet. It has quickly made large inroads into the voice over IP (VoIP) market. SIP is an application-layer control operating on top of a transport protocol and allows to create, modify, and terminate sessions with one or more participants. With security considerations, these operations require authentication from participating end-points, confidentiality, data integrity, and protection against internal and external attacks. For authentication, SIP relies on HTTP Digest by default; the client is authenticated to the SIP proxy server. In order to have mutual authentication between client and server, SIP could be implemented over TLS (transport layer security) when TCP is supported by SIP architecture network. In this paper, we propose a mutual authentication mechanism within HTTP Digest since this later is implemented by default in all SIP environments. It consists in providing meaning and semantic to some of the parameters\´ values generated by the participating end-points during SIP session establishment, especially to the "nonce" values. Our solution is backward-compatible with today implementations. Without being in opposition to security protocols like TLS, this approach helps in reducing DoS (denial of service) attacks, detects server identity spoofing and ensures basic mutual authentication with comparison to HTTP digest.
Keywords
Internet; Internet telephony; security of data; signalling protocols; transport protocols; HTTP Digest; Internet; SIP opaque values; SIP proxy server; VoIP; data integrity; denial of service attacks; external attacks. protection; internal attacks. protection; mutual authentication; semantic meaning; session initiation protocol; signalling protocol; transport layer security; transport protocol; voice over IP; Authentication; Computer crime; Data security; IP networks; Internet telephony; Network servers; Protection; Telecommunications; Transport protocols; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
New Technologies, Mobility and Security, 2008. NTMS '08.
Conference_Location
Tangier
Print_ISBN
978-1-42443547-0
Type
conf
DOI
10.1109/NTMS.2008.ECP.69
Filename
4689123
Link To Document