There is a trend towards voice-over-IP systems based on the session initiation protocol (SIP), which is a protocol for session management in general. However, as signalling data is transferred using the Internet, systems face security problems. Thus, at least authentication of the participants and confidentiality of signalling data have to be ensured as basic mechanism. In this work, we propose a mechanism for assuring the identity of a group of users fulfilling the same role (e.g., employees of a customer call centre). Using our concept enables using only one certificate for the whole group for signing and encrypting messages according to the SIP standard. Our mechanism works transparently for users as we provide a special proxy server for this purpose, which significantly reduces administration efforts and resource needs on the participating nodes. Furthermore, such a proxy server can be used for transparently validating and decrypting SIP messages as well. This reduces efforts on the terminals, resulting in an improved resource-usage, e.g., on a personal digital assistant. We provide an implementation of the concept based on the NIST SIP proxy server.
[1]
Jon Peterson,et al.
Session Initiation Protocol (SIP) Authenticated Identity Body (AIB) Format
,
2004,
RFC.
[2]
Mark Handley,et al.
SIP: Session Initiation Protocol
,
1999,
RFC.
[3]
Thomas Froment.
Authorization Policies for Preventing SPIT
,
2007
.
[4]
Eric Rescorla,et al.
The Transport Layer Security (TLS) Protocol Version 1.1
,
2006,
RFC.
[5]
Saverio Niccolini.
SIP Extensions for SPIT identification
,
2007
.
[6]
Mats Näslund,et al.
The Secure Real-time Transport Protocol (SRTP)
,
2004,
RFC.
[7]
Butler W. Lampson,et al.
SPKI Certificate Theory
,
1999,
RFC.
[8]
Eric Allman,et al.
DomainKeys Identified Mail (DKIM) Signatures
,
2007,
RFC.
[9]
Henning Schulzrinne,et al.
Session Initiation Protocol (SIP): Locating SIP Servers
,
2002,
RFC.
[10]
David Schwartz.
SPAM for Internet Telephony (SPIT) Prevention using the Security Assertion Markup Language (SAML)
,
2006
.
[11]
Robert Sparks,et al.
Internet Media Type message/sipfrag
,
2002,
RFC.