李锋, 唐宝民. Security Analysis of SIP in NGI[J]. 2007, (9): 1-6.DOI:
Security Analysis of SIP in NGI
摘要
本文在介绍SIP安全威胁模型的基础上
对SIP应用中存在的安全问题
分为两个方面(SIP会话过程及注册认证过程)详细探讨了SIP的安全及解决现状。并针对SIP认证过程
从理论研究的角度给出了一种安全性可得到保证的、清晰的认证机制。从而
既可以对SIP的安全有一个整体上的把握
对安全问题中的认证机制
也有一个微观上的清晰把握。
Abstract
In this paper
SIP security threats model is introduced
then the security issues in the application of SIP is studied. There are two aspects (SIP conversation process and the registration process) show a detailed study of the safety in SIP. For the certification process
I proposed a clear authentication mechanism
which safety can be assured from the theoretical study. Thus
the security issues in SIP can be not only an overall but also a micro clear grasp.