作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (11): 140-142. doi: 10.3969/j.issn.1000-3428.2008.11.050

• 安全技术 • 上一篇    下一篇

基于SIP协议的网络电话安全方案及实现

刘 刚1,覃 嘉1,廖 伟2,刘 强3,吕玉琴1   

  1. (1. 北京邮电大学电子工程学院,北京100876;2. 北京邮电大学理学院,北京100876;3. 重庆工学院数理学院,重庆 400050 )
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-06-05 发布日期:2008-06-05

Security Mechanism and Realization for SIP-based Network Telephone

LIU Gang1, QIN Jia1, LIAO Wei2, LIU Qiang3, LV Yu-qin1   

  1. (1. School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876; 2. School of Sciences, Beijing University of Posts and Telecommunications, Beijing 100876; 3. School of Sciences, Chongqing Institute of Technology, Chongqing 400050)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-06-05 Published:2008-06-05

摘要: 以基于身份的非对称加密技术为核心,引入身份证书和更具灵活性的XML格式属性证书,解决用户身份认证、私钥分发和安全实现增值服务问题。与话者在通话时,利用证书向PKDC进行身份认证,获取私钥,用于加密传输会话密钥。在信令协商过程中,CPL服务器通过验证用户的属性证书提取用户属性,更加便捷地实现增值服务。

关键词: XML语言, 属性证书, 私钥分发中心

Abstract: To solve the problems of authentication of user identity, private-key distribution and secure realization of increment service, a new scheme is proposed by taking the public-key algorithm based on identity as the core. The identity certificate and the flexible XML attribute certificate are used in the new scheme. Participants use their identity certificates to authenticate themselves to PKDC, and obtain the private-key, which are used to encrypt and transmit the session key. And in the process of signaling negotiation, the increment service is realized expediently by CPL server authenticating the user attribute certificate and picking up the user attribute.

Key words: XML, attribute certificate, private-key distribution center

中图分类号: