A secure and lightweight scheme for media keying in the session initiation protocol (SIP): work in progress

  • Authors:
  • Vijay K. Gurbani;Vladimir Kolesnikov

  • Affiliations:
  • Acatel-Lucent, Bell Labs, Naperville, IL;Alcatel-Lucent, Bell Labs, Murray Hill, NJ

  • Venue:
  • Principles, Systems and Applications of IP Telecommunications
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Exchanging keys to encrypt media streams in the Session Initiation Protocol (SIP) has proved challenging. The challenge has been to devise a key transmission protocol that preserves the features of SIP while minimizing key exposure to unintended parties and eliminating voice clipping. We first briefly survey the two IETF SIP media keying protocols -- SDES and DTLS-SRTP -- and evaluate them against a core feature set. We then introduce a novel simple and lightweight scheme to significantly increase the security of SDES SIP keying with minimal overhead costs. Our proposed key exchange involves only one symmetric key operation by sender and receiver and is secure against the Man-in-the-middle attack unless the attacker is able to intercept both the SIP signaling and media plane traffic. Our key exchange scheme is much simpler than DTLS-SRTP; in fact, compared to SDES, it includes only one additional simple step. At the same time, it provides significantly better security than SDES and is only slightly weaker than the non-PKI version of DTLS-SRTP.