作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (13): 119-121,124. doi: 10.3969/j.issn.1000-3428.2011.13.038

• 安全技术 • 上一篇    下一篇

一种增强的ZRTP认证机制

肖鸿飞,刘长江   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:2011-01-25 出版日期:2011-07-05 发布日期:2011-07-05
  • 作者简介:肖鸿飞(1984-),男,硕士研究生,主研方向:网络安全;刘长江,高级工程师

Enhanced Authentication Mechanism of ZRTP

XIAO Hong-fei, LIU Chang-jiang   

  1. Enhanced Authentication Mechanism of ZRTP
  • Received:2011-01-25 Online:2011-07-05 Published:2011-07-05

摘要: ZRTP本身的认证机制在一些特殊的情况下无法抵抗中间人攻击。为此,基于简单密钥协商协议(SAKA)提出一种NSAKA算法,改进ZRTP的认证机制,使用RFC4474中的SIP身份认证模型来安全传输用户预共享的秘密口令。通过分析表明,该方案可以提高ZRTP抵抗中间人攻击的能力,并弥补SAKA算法原有的安全缺陷。

关键词: SRTP协议, ZRTP协议, 中间人攻击, SIP身份认证, 简单认证密钥协商协议

Abstract: The original authentication mechanism of Zimmermann RTP(ZRTP) is vulnerable to the Man In The Middle(MITM) attack in certain conditions, although it is a light-weighted and efficient key agreement protocol. This paper introduces a new algorithm named NSAKA to enhance the original mechanism, which is based on the basic concept of Simple Authentication Key Agreement(SAKA). The Session Initiation Protocol(SIP) identity authentication model of RFC4474 is also employed to securely transmit the users’ pre-shared secret password. The scheme can effectively enhance the ability to resist against the MITM attack of ZRTP and remedy the primary vulnerabilities of SAKA.

Key words: Secure RTP(SRTP), Zimmermann RTP(ZRTP), Man In The Middle(MITM) attack, Session Initiation Protocol(SIP) identity authentication, Simple Authentication Key Agreement(SAKA) protocol

中图分类号: