期刊文献+

一种基于HTTP摘要认证的SIP安全机制 被引量:23

Security mechanism of SIP based on HTTP digest authentication
在线阅读 下载PDF
导出
摘要 会话初始化协议(SIP)基于Client/Server结构,由于受到SIP自身特点及应用环境的影响,目前SIP常用的安全机制大都只提供Server对Client的认证,且大都没有提供会话密钥协商的机制,容易受到服务器伪装攻击。在分析了SIP面临的安全威胁以及SIP安全机制的现状后,通过对SIP协议的扩展,设计和实现了一种基于HT-TP摘要认证的SIP安全机制。该机制能实现双向身份认证和密钥协商功能,使SIP认证和加密更为灵活。 SIP is based on the Client/Server structure. Most current security muehanisms used in SIP only provide the authentication to client from the server because of the SIP's characteristic and application environment, and most of them do not provide the key negotiation mechanism. There fore the affaek of impersonating usually happens. This paper analyzes the security threats faced with by SIP and the actuality of SIP security mechanism. And authors design and implement a SIP security mechanism based on HTTP Digest Authentication by extending the SIP. This mechanism provides the functions of bidirectional identity authentication and key negotiation, and makes SIP authentication and Eneryption more flexible.
出处 《重庆邮电学院学报(自然科学版)》 2005年第6期749-751,共3页 Journal of Chongqing University of Posts and Telecommunications(Natural Sciences Edition)
关键词 HTTP摘要认证 会话初始化协议 安全机制 密钥协商 HTTP digest authentication SIP security mechanism key negotiation
  • 相关文献

参考文献11

二级参考文献43

  • 1[1]ITU-T Recommendation H.323. Packet-based Multimedia Communication Systems. 1999-09
  • 2[2]ITU-T Recommendation H.235(Version 2).Security and Encryption for H-Series(H.323 and other H.245-based)Multimedia Terminals.2000-11
  • 3[3]Rosenberg J,Schulzrinne H.SIP:Session Initiation Protocol. RFC 3261, 2002-06
  • 4[4]Housley R,Ford W,Polk W,et al.Internet X.509 Public Key Infrastructure Certificate and CRL. Profile. RFC 2459,1999-01
  • 5[6]Baugher M,McGrew D.The Secure Real-time Transport Protocol. draft-ietf-avt-srtp-05.txt,2002-06
  • 6TSANG Simon,MOYER Stan,Marples Dave.Internet Draft"draft-tsang-sip-appliances-do-00 "[Z].Internet Engineering Task Force(IETF),May, 2001.
  • 7RFC2617-1999. Internet Draft "HTTP Authentication: Basic and Digest Access Authentication[S].
  • 8IETF RFC3261-2002. SIP: Session Initiation Protocol[S].
  • 9IETF RFC3428-2002. Session Initiation Protocol (SIP) Extension for Instant Messaging[S].
  • 10ONZALO Camarillo.SIP Demystified[M]. McGraw-Hill Companies,Inc, 2002.

共引文献37

同被引文献108

引证文献23

二级引证文献45

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部