会话启动协议
计算机科学
网络电话
认证(法律)
重放攻击
计算机安全
会话(web分析)
计算机网络
SIP中继
身份验证协议
方案(数学)
安全性分析
协议(科学)
互联网
服务器
万维网
病理
数学分析
替代医学
医学
数学
作者
Yuting Feng,F. Xiong,Wenchao Huang,Yan Xiong
标识
DOI:10.1109/bigcom53800.2021.00005
摘要
The Internet Engineering Task Force (IETF) proposed the Session Initiation Protocol (SIP) as the IP-based telephony protocol. With the widespread application of the Voice over IP (VoIP) on Internet, Security problems of SIP have received a lot of attention of researchers and the authentication mechanism in SIP is becoming increasingly important. Many studies reveal that the initial version of SIP specification suffers malicious attacks. To improve the security of the authentication mechanism in SIP, amendments and supplements are expressed over years. Researches on the previous specification have been carried out and some attacks are found, such as replay attack, online dictionary attack, man in the middle attack, etc. However, there is currently a lack of security analysis to the fresh security mechanisms of SIP. In this paper, we accommodate such a requirement by analyzing the security properties of SIP Digest Access Authentication Scheme adopting a formal protocol analysis tool SPAN. The authentication scheme is modeled in the validator according to two practical scenarios. With the two back-ends of SPAN, the two models of authentication scheme are verified both as safe. This result confirms that the supplemented version of SIP authentication mechanism is more reliable.
科研通智能强力驱动
Strongly Powered by AbleSci AI