Secure signaling in next generation networks with NSIS

  • Authors:
  • Roland Bless;Martin Röhricht

  • Affiliations:
  • Institute of Telematics, Universität Karlsruhe, Karlsruhe, Germany;Institute of Telematics, Universität Karlsruhe, Karlsruhe, Germany

  • Venue:
  • ICC'09 Proceedings of the 2009 IEEE international conference on Communications
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

The IETF working group Next Steps in Signaling (NSIS) develops signaling protocols for Quality-of-Service (QoS) reservations or dynamic NAT and firewall (NAT/FW) configuration. QoS signaling allows for on-demand resource reservations in order to provide guaranteed quality-of-service for real-time oriented services in IP-based next generation networks whereas NAT/FW signaling allows for establishing pinholes in firewalls or bindings in NAT devices. QoS signaling must be secured to allow for a reliable accounting and NAT/FW configuration is a sensitive operation per se. This paper presents an approach that provides an integrity protection of NSLP signaling messages by extending an NSLP Session Authorization Object. A worked example for secure QoS signaling in a Kerberos-secured domain is given.