• DocumentCode
    3589477
  • Title

    Cryptanalysis and improvement of a SIP authentication scheme

  • Author

    Jun Zheng ; Dongyun Wang

  • Author_Institution
    Sch. of Comput. Sci. & Technol., Beijing Inst. of Technol., Beijing, China
  • fYear
    2014
  • Firstpage
    199
  • Lastpage
    203
  • Abstract
    SIP (Session Initial Protocol) has been a very popular protocol for VoIP. However, the authentication of this protocol just derives from HTTP digest authentication, which has been demonstrated insecure in the open network. Recently, Arshad et al. proposed an improved mutual authentication scheme based on ECC and claimed that it´s secure enough. In this paper, however, we point out that their protocol still could not resist offline password guessing attacks. Furthermore, we propose an ECC-based mutual authentication and key agreement scheme to overcome such a security problem. Also, an analysis of it is provided to indicate that compared to Arshad et al.´s scheme, this scheme reduces twice hash operation and is more secure with reasonable computation cost.
  • Keywords
    Internet telephony; cryptography; signalling protocols; HTTP digest authentication; SIP authentication scheme; Session Initial Protocol; VoIP; cryptanalysis; open network; Authentication; Elliptic curve cryptography; Protocols; Resists; Servers; Zinc; ECC; Key Agreement; Mutual Authentication; Password Guessing Attacks; Session Initial Protocol;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology and Electronic Commerce (ICITEC), 2014 2nd International Conference on
  • Print_ISBN
    978-1-4799-5298-4
  • Type

    conf

  • DOI
    10.1109/ICITEC.2014.7105601
  • Filename
    7105601