Analysis of token and ticket based mechanisms for current VoIP security issues and enhancement proposal

  • Authors:
  • Patrick Battistello;Cyril Delétré

  • Affiliations:
  • Orange Labs, Lannion Cedex, France;Orange Labs, Lannion Cedex, France

  • Venue:
  • CMS'10 Proceedings of the 11th IFIP TC 6/TC 11 international conference on Communications and Multimedia Security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

These last few years, the security of VoIP architectures has become a sensitive issue with many vulnerability announcements. This article first aims to distinguish the threats and the applicable protection mechanisms depending on the underlying VoIP architecture. We then investigate the properties of a specific class of existing call establishment mechanisms based on tokens or tickets. In the last section, an enhancement to these mechanisms is proposed which lifts some of the previously seen limitations, especially the DoS risks, the token storage constraint or the transport impact of large tickets.