|国家预印本平台
首页|基于数字证书认证的SIP安全机制

基于数字证书认证的SIP安全机制

SIP security mechanism based on digital certificate authentication

中文摘要英文摘要

计算机网络技术的发展,使得基于分组交换技术的IP数据网络逐渐取代基于电路交换技术的传统电话网在通信领域的核心地位。尽管IP数据网络的便捷性和高效性给多媒体业务的迅速发展带来了益处,但其具有的开放性所带来的安全性问题仍不容忽视。文章对VOIP主流信令交换协议SIP的网络实体进行了介绍,详细分析了SIP协议可能面临的各种攻击和威胁模型,针对现有的安全机制存在的漏洞或者局限性进行改进,在应用层上提出了一种基于数字证书认证的SIP协议安全机制,进一步提升SIP协议的安全可靠性。

With the development of computer network technology, the IP data network based on packet switching gradually replaces the core status of traditional telephone network based on circuit exchange in the field of communication. Although the convenience and efficiency of IP network have brought benefits to the rapid development of multimedia services, the security problems caused by its openness cannot be ignored. This paper introduces the network entities of VOIP mainstream signaling exchange protocol-SIP, and various attack and threat models that the SIP protocol could face have been analyzed in detail. Aiming at improving the security of SIP protocol, this essay gives a possible way to decrease the vulnerabilities or reduce limitations of the existing SIP protocol security mechanism. Furthermore,in the application layer,a SIP protocol security mechanism based on digital certificate authentication is proposed in this paper to further enhance the security and reliability of SIP protocol.

徐严、卞佳丽

通信

计算机网络SIP协议安全数字证书认证

omputer NetworkSIP Protocolsecuritydigital certificateauthentication

徐严,卞佳丽.基于数字证书认证的SIP安全机制[EB/OL].(2017-11-30)[2025-08-19].http://www.paper.edu.cn/releasepaper/content/201711-246.点此复制

评论