Marcel Lehner
Home Resume Publications Picture Gallery Downloads Contact
 

Security of SIP communication systems by means of Kerberos

 
The Internet offers a wide range of new possibilities and services to our daily life, making it easier and more comfortable. As the market for hardware- and software products shows, there is a strong tendency to multimedia and
communication products. To meet the markets demand, company's started developing multimedia products, amongst them protocols and applications allowing telephony via the Internet. This applications allow to dispatch audio information over an IP based network infrastructure using a special protocol.

The fusion of traditional wire telephony and IP based telephony offers new opportunities for both, applications and services. The implementation of voice communication over package oriented networks is based on standards developed by the International Telecommunication Union. In 1999 the Internet Engineering Task Force published a new signaling protocol, which is becoming more and more popular due to it's simplicity and better compatibility over the protocol developed by the International Telecommunication Union. This new protocol is called Session Initiation Protocol (SIP) and is the the next large step in the division of language and video transmission over IP networks.

Due to it's high compatibility to other protocols, SIP should ease the process of developing applications for voice over IP services and make it an overall less expensive procedure. Because IP telephony is quickly gaining popularity and is already used extensively, security mechanisms are required to ensure data integrity and authenticity. SIP already uses different applications i.e. IPsec, adding transaction security and data integrity to the protocol. However, the many published drafts and proposals show, that the protocol is not final yet and still needs improvements.

At some point, when it comes to data integrity and authentication, implementing Kerberos could be such an improvement. Kerberos has been developed by the Massachusetts Institute of Technology and has been used for many years to securely authenticate users within an insecure network. Good scaling bareness, high security and extensive use are some of the advantages Kerberos is bringing along with, making it a perfect candidate for interaction with SIP.

Bachelor-Thesis, University of Applied Science Hagenberg (June 2004)


Back to publications
Marcel Corner © by Marcel Lehner Marcel Corner