A single round-trip SIP authentication scheme for Voice over Internet Protocol using smart card

被引:54
作者
Irshad, Azeem [1 ]
Sher, Muhammad [1 ]
Rehman, Eid [1 ]
Ch, Shehzad Ashraf [1 ]
Ul Hassan, Mahmood [1 ]
Ghani, Anwar [1 ]
机构
[1] Int Islamic Univ, Fac Basic & Appl Sci, Dept Comp Sci & Software Engn, Islamabad, Pakistan
关键词
Session initiation protocol; Authentication; Security; Voice over Internet Protocol; Smart card; SECURE AUTHENTICATION;
D O I
10.1007/s11042-013-1807-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Session Initiation Protocol (SIP) has revolutionized the way of controlling Voice over Internet Protocol (VoIP) based communication sessions over an open channel. The SIP protocol is insecure for being an open text-based protocol inherently. Different solutions have been presented in the last decade to secure the protocol. Recently, Zhang et al. authentication protocol has been proposed with a sound feature that authenticates the users without any password-verifier database using smart card. However, the scheme has a few limitations and can be made more secure and optimized regarding cost of exchanged messages, with a few modifications. Our proposed key-agreement protocol makes a use of two server secrets for robustness and is also capable of authenticating the involved parties in a single round-trip of exchanged messages. The server can now authenticate the user on the request message received, rather than the response received upon sending the challenge message, saving another round-trip of exchanged messages and hence escapes a possible denial of service attack.
引用
收藏
页码:3967 / 3984
页数:18
相关论文
共 42 条
[1]  
[Anonymous], SIMPLE PASSWORD BASE
[2]  
[Anonymous], 1825 RFC
[3]  
[Anonymous], 4253 RFC
[4]  
[Anonymous], 2009, INT J NETW SECUR
[5]  
[Anonymous], INT J NETW SECUR
[6]  
[Anonymous], P INC IMS IDC
[7]  
[Anonymous], SIP SECURIT IN PRESS
[8]  
[Anonymous], 2016, HDB APPL CRYPTOGRAPH
[9]  
[Anonymous], CFL2001002 PRINC U D
[10]  
[Anonymous], 1998, RFC 2401