Robust Mutual Authentication with a Key Agreement Scheme for the Session Initiation Protocol

Robust Mutual Authentication with a Key Agreement Scheme for the Session Initiation Protocol
复制标题

DOI:
10.4103/0256-4602.62780
复制
发表时间:
2010-05
影响因子:
2.4
通讯作者:
Eunjun Yoon;Yongjoo Shin;Il-Soo Jeon;K. Yoo
Eunjun Yoon;Yongjoo Shin;Il-Soo Jeon;K. Yoo
中科院分区:
计算机科学4区
文献类型:
--
作者:
Eunjun Yoon;Yongjoo Shin;Il-Soo Jeon;K. Yoo

文献摘要

被引文献

相似文献

会话初始化协议(SIP)是一种功能强大的信令协议,它控制Internet上的通信,建立、维护和终止会话。SIP支持的服务同样适用于移动的和普适计算的世界。2009年,Tsai提出了一种有效的基于随机数的SIP认证方案。然而,目前的论文表明,蔡的认证方案仍然容易受到离线密码猜测攻击,Denning-Sunday攻击和被盗验证者攻击,并且不提供完美的前向保密性。为了克服这些安全问题,我们还提出了一个新的安全和有效的认证方案的基础上的椭圆曲线离散对数问题的SIP。
Abstract The session initiation protocol (SIP) is a powerful signaling protocol that controls communication on the Internet, establishing, maintaining, and terminating the sessions. The services that are enabled by SIP are equally applicable in the world of mobile and ubiquitous computing. In 2009, Tsai proposed an efficient nonce-based authentication scheme for SIP. The current paper, however, demonstrates that Tsai’s authentication scheme is still vulnerable to offline password guessing attacks, Denning-Sacco attacks, and stolen-verifier attacks, and does not provide perfect forward secrecy. We also propose a new secure and efficient authentication scheme based on the elliptic curve discrete logarithm problem for SIP in order to overcome such security problems.