Publication | Closed Access
Using SIP identity to prevent man-in-the-middle attacks on ZRTP
10
Citations
2
References
2008
Year
Unknown Venue
Mobile SecurityEngineeringInformation SecurityInformation ForensicsFormal VerificationHardware SecuritySecure CommunicationInternet Of ThingsSecure ProtocolAuthentication ProtocolLightweight Authentication MechanismData PrivacySip IdentityKey Agreement ProtocolComputer ScienceMobile ComputingData SecurityCryptographyProtocol ExtensionsVoip Session
In this paper we present an architecture and associated protocol extensions for securing the media stream of a VoIP session. We make use of ZRTP which is a key agreement protocol that allows two parties to agree upon a secret session key over the media path. Because ZRTP is based on the popular Diffie-Hellmann key exchange mechanism it is inherently vulnerable to man-in-the-middle (MITM) attacks. Although ZRTP offers a mechanism for the prevention of MITM attacks, a sophisticated attacker might be able to launch a successful attack in certain scenarios. We describe an approach that provides authentic cryptographic parameters for ZRTP without sacrificing the independence from a user-level Public Key Infrastructure (PKI). We propose to use the mechanisms provided by RFC 4474 (SIP Identity) to ensure the identity of the parties involved in an ZRTP key exchange.
| Year | Citations | |
|---|---|---|
Page 1
Page 1