跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.75) 您好!臺灣時間:2026/08/20 11:50
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:莊智強
研究生(外文):Chuang, Chihchiang
論文名稱:結合SIP與三向金鑰協議交換協定之安全多媒體通訊技術
論文名稱(外文):Integrating SIP with Three-way Key and Agreement Exchange Protocol for Secure Multimedia Communications
指導教授:江為國江為國引用關係
指導教授(外文):Chiang, Weikuo
口試委員:李新林陳裕賢柯仁松
口試委員(外文):Lee, SinglingChen, YuhshyanKo, Renson
口試日期:2012-07-27
學位類別:碩士
校院名稱:國立中正大學
系所名稱:資訊工程研究所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2012
畢業學年度:100
語文別:英文
論文頁數:49
中文關鍵詞:議程初始協定網際網路安全金鑰交換協定
外文關鍵詞:Session initiation protocolNetwork securityKey exchange protocol
相關次數:
  • 被引用被引用:0
  • 點閱點閱:445
  • 評分評分:
  • 下載下載:7
  • 收藏至我的研究室書目清單書目收藏:1
自從IP網路上出現了許多種攻擊,網路安全就成了一個重要的議題,而金鑰交換協定是個可以利用私密的通話金鑰進行加密以保障兩點之間通訊的密碼學機制。本篇論文特別針對兩個客戶端分別註冊在不同的伺服器上之四方金鑰交換協定進行討論;對於註冊在不同網域的使用者,彼此雙方的溝通都須先通過各自的proxy server;另一方面,為了支援合法監聽(Lawful interception),設計是以server能參與計算或是能取得金鑰為主軸,同時也必須設計讓整個流程能保持三向交握(three-way handshake),以便與SIP的會話建立流程相結合。本篇論文提出結合SIP與三向金鑰交換協議之協定(TW-KEAP),稱為SIP+TW-KEAP。依據RFC 4568定義的SDES (Session Description Protocol Security Descriptions for Media Streams),在SIP訊息中,利用SDP內新增的”crypto”欄位夾帶金鑰資訊,可以在SIP建立session時的流程中同時讓雙方交換金鑰,不需要額外的訊息交換。本篇論文以GNU oSIP library和crypto++ library實作整個協定,透過佇列排隊理論對實驗數據做分析比較,觀察出SIP+TW-KEAP相較於SIP結合其他的金鑰交換協定,有著較佳的效率;並且在不同的無線網路環境中,我們也透過無線傳輸延遲模型和能源消耗模型對實驗數據做分析比較,其結果也顯示SIP+TW-KEAP不僅有較少的無線傳輸延遲,也較為省電。
Network security has become an important issue since various attacks are appearing in the IP network, and the key exchange protocol is one of the most important cryptography mechanisms to protect end-to-end communication by the secret session key encryption. In this paper, we focus on the four-party key exchange protocol in an environment in which two clients are registered under two distinct servers, and both registered parties have to communicate through their corresponding server respectively. We integrate SIP with the three-way key exchange and agreement protocol (TW-KEAP), denoted by SIP+TW-KEAP. The SIP+TW-KEAP uses an attribute (a=crypto) of SDP in the SIP message body to carry key parameters without exchanging any extra message according to RFC 4568 SDES (Session description protocol security descriptions for media streams). It makes two communication parties have a secret session key to protect their subsequent communications on an efficient way, and intends servers to involve with the key exchange procedure to derive the session key for the lawful interception support. In addition, we utilize GNU oSIP library and crypto++ library to implement the proposed scheme. The SIP+TW-KEAP has not only the shortest total service time based on the experimental results but also the shortest queuing delay, wireless transmission delay, and energy consumption from numerical analysis, as compared with the current alternative.
Abstract (Chinese)
Abstract (English)
Contents
Introduction
Related Works
2.1. Session Initiation Protocol
2.2. SDP Security Description for Media Streams
2.3. Four-party Key Exchange Protocols
2.3.1. KTAP
2.3.2. KAAP
2.3.3. IMSKAAP
2.3.4. BaoPKAE
2.3.5. TW-KEAP
Integrating SIP with TW-KEAP
Security analysis
Performance analysis
5.1 Experimental Results
5.2 Queuing Delay
5.3 Wireless Transmission Delay
5.4 Energy Consumption
Conclusions
References

[1]F. Andreasen, M. Baugher, D. Wing, “Session description protocol (SDP) security descriptions for media streams,” IETF RFC 4568, July 2006.
[2]S.M. Bellovin, M. Merritt, “Encrypted key exchange: password-based protocols secure against dictionary attacks,” Proceedings of IEEE Symposium on Research in Security and Privacy, pp. 72–84, May 1992.
[3]M. Bellare, D. Pointcheval, P. Rogaway, “Authenticated key exchange secure against dictionary attacks,” Advances in Cryptology EUROCRYPT'00, pp. 139–155, 2000.
[4]V. Boyko, P. MacKenzie, S. Patel, “Provably secure password-authenticated key exchange using Diffie-Hellman,” Advances in Cryptology EUROCRYPT'00, pp. 156–171, 2000.
[5]M. Baugher, D. McGrew, M. Naslund, E. Carrara, K. Norrman, “The secure real-time transport protocol (SRTP),” IETF RFC 3711, March 2004.
[6]H. Bao, F. Xu, X. Huang, “Authentication key exchange protocol for IMS network,” Power and Energy Engineering Conference (APPEEC) 2010, Asia-Pacific, pp. 1–4, March 2010.
[7]U. Bernhard, E. Jugl, J. Mueckenheim, H. Pampel, M. Soellner, “Intelligent management of radio resources in UMTS access networks,” Bell Labs Technical Journal, vol. 7, no. 3, pp. 109–126, 2003.
[8]S.C. Borst, A. Buvaneswari, L.M. Drabeck, M.J. Flanagan, J.M. Graybeal, G.K. Hampel, M. Haner, W.M. MacDonald, P.A. Polakos, G. Rittenhouse, I. Saniee, A. Weiss, P.A. Whiting, “Dynamic optimization in future cellular networks,” Bell Labs Technical Journal, vol. 10, no. 2, pp. 99–119, 2005.
[9]N. Balasubramanian, A. Balasubramanian, and A. Venkataramani, “Energy Consumption in Mobile Phones: A Measurement Study and Implications for Network Applications,” IMC, 2009.
[10]C.-Y. Chen, T.-Y. Wu, Y.-M. Huang, H.-C. Chao. “An efficient end-to-end security mechanism for IP multimedia subsystem,” Computer Communications, Secure Multi- Mode Systems and their Applications for Pervasive Computing, vol. 31, no. 18, pp. 4259–4268, Dec. 2008.
[11]Wei-Kuo Chiang, Jian-Hao Chen, “TW-KEAP: an efficient four-party key exchange protocol for end-to-end communications,” Proceedings of the 4th International Conference on Security of Information and Networks (SIN 2011), Sydney, NSW, Australia, November 14 – 19, 2011.
[12]S. Das, E. Lee, K. Basu, and S. Sen, “Performance Optimization of VoIP Calls over Wireless Links Using H.323 Protocol,” IEEE Trans. Computers, vol. 52, no. 6, pp. 742-752, June 2003.
[13]W. Diffie, M. Hellman, “New directions in cryptography,” IEEE Transactions on Information Theory, vol. 22, no. 6, pp.644–654, Nov. 1976.
[14]L.M. Feeney and M. Nilsson, “Investigating the energy consumption of wireless network interface in an ad hoc networking environment,” IEEE INFOCOM, pp. 1548–1557, 2001.
[15]H. Fathi, S. S. Chakraborty, R. Prasad, “Optimization of SIP session setup delay for VoIP in 3G wireless networks,” IEEE Trans. Mobile Computing, vol. 5, no. 9, Sep. 2006.
[16]J. Floroiu and D. Sisalem, “A comparative analysis of the security aspects of the multimedia key exchange protocols,” in Proc. 1st International Conf. Principles, Syst. Appl. IP Telecommun. (IPTComm). ACM, July 2009.
[17]H.-F. Huang, “A simple three-party password-based key exchange protocol,” International Journal of Communication Systems, vol. 22, no. 7, pp. 857–862, July 2009.
[18]M. Handley, V. Jacobson, C. Perkins, “SDP: session description protocol,” IETF RFC 4566, July 2006.
[19]H. Holma and A. Toskala, “LTE for UMTS - OFDMA and SC-FDMA Based Radio Access,” Wiley, 1 edition, June 2, 2009.
[20]J. Katz, R. Ostrovsky, M. Yung, “Efficient password-authenticated key exchange using human-memorable passwords,” Advances in Cryptology EUROCRYPT '01, pp. 475–494, 2001.
[21]L. Kleinrock, “Queuing systems,” vol. 1: Theory. Wiley, 1975.
[22]T.-F. Lee, J.-L. Liu, M.-J. Sung, S.-B. Yang, C.-M. Chen, “Communication-efficient three-party protocols for authentication and key agreement,” Computers & Mathematics with Applications, vol. 58, no. 4, pp. 641–648, Aug. 2009.
[23]R. Lu, Z. Cao, “Simple three-party key exchange protocol,” Computers & Security, vol. 26, no. 1, pp. 94–97, Feb. 2007.
[24]C. Lv, M. Ma, H. Li, J. Ma, “An efficient three-party authenticated key exchange protocol with one-time key,” INFOCOM IEEE Conference on Computer Communications Workshops, pp. 1–5, March 2010.
[25]J. Lorchat and T. Noel, "Power performance comparison of heterogeneous wireless network interfaces," Vehicular Technology Conference, vol. 4, Oct. 2003.
[26]A. Munir, A. Gordon-Ross, “SIP-based IMS signaling analysis for WiMax-3G interworking architectures,” IEEE Transactions on Mobile Computing, vol. 9, no. 5, pp. 733–750, May 2010.
[27]J. Rosenberg, H. Schulzrinne, G. Camarillo, J. Peterson, R. Sparks, M. Handley, E. Schooler, “SIP: session initiation protocol,” RFC 3261 IETF, June 2002.
[28]H. Schulzrinne, S. Casner, R. Frederick, V. Jacobson, “RTP: a transport protocol for real-time applications,” IETF RFC 3550, July 2003.
[29]M. Ulvan, A. Ulvan, and R. Bestak, “IMS Signalling in LTE-based Femtocell Network,” The Fourth International Conference on Mobile Ubiquitous Computing, Systems, Services and Technologies, pp. 157-163, 2010.
[30]Y. Xiao, "Throughput and delay limits of IEEE 802.11," IEEE Communications Letters, vol. 6, no.8, Aug. 2002.
[31]H.-T. Yeh, H.-M. Sun, “Password authenticated key exchange protocols among diverse network domains,” Computers & Electrical Engineering, vol. 31, no. 3, pp. 175–189, May 2005.
[32]3GPP. 3rd Generation Partnership Project; Technical Specification Group Services and Systems Aspects, "Lawful interception architecture and functions," Technical Specification 3G TS 33.107, version 11.0.0, Sept. 2011.
[33]3GPP. 3rd Generation Partnership Project, Technical Specification Group Services and Systems Aspects; “IP multimedia subsystem (IMS),” Stage 2. Technical Specification 3G TS 23.228, version 10.3.1, Jan. 2011.
[34]Crypto++® Library 5.6.1, http://www.cryptopp.com/
[35]ETSI, European Telecommunications Standards Institute, “Handover interface and service-specific details (SSD) for IP delivery; Part 6: Service-specific details for PSTN/ISDN services,” ETSI TS 102 232-6, ver. 2.3.1, March 2008.
[36]The GNU oSIP Library, http://www.gnu.org/software/osip/

QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top