Session Initiation Protocol is currently receiving much attention and seems to be the most promising candidate as signaling protocol for the current and future IP telephony services, also becoming a real competitor to plain old telephone service. For the, realization of such a scenario, there is the obvious need to provide a certain level of quality and security, comparable to that provided, by the traditional telephone systems. While the problem of QoS mostly refers to the network layer, the problem of security is strictly related to the signaling mechanisms and the service provisioning model. For this reason, at present, a very hot topic in the SIP and IP telephony standardization track is security support. In this work, the security model used by SIP is described, and the different open issues are highlighted. We focus, in particular, on the problem of authentication providing a short tutorial on the solution under standardization. The architecture of a possible commercial IP telephony service including user authentication is also described. Finally, we focus on performance issues. By means of a real testbed implementation, we provide an experimental performance analysis of the SIP security mechanisms, based on our open source Java implementation of a SIP. proxy server. The performance of the server has been compared with and without security support, under various scenarios.

SIP security issues: the SIP authentication procedure and its processing load / S., Salsano; Veltri, Luca; D., Papalilo. - In: IEEE NETWORK. - ISSN 0890-8044. - 16:6(2002), pp. 38-44. [10.1109/MNET.2002.1081764]

SIP security issues: the SIP authentication procedure and its processing load

VELTRI, Luca;
2002-01-01

Abstract

Session Initiation Protocol is currently receiving much attention and seems to be the most promising candidate as signaling protocol for the current and future IP telephony services, also becoming a real competitor to plain old telephone service. For the, realization of such a scenario, there is the obvious need to provide a certain level of quality and security, comparable to that provided, by the traditional telephone systems. While the problem of QoS mostly refers to the network layer, the problem of security is strictly related to the signaling mechanisms and the service provisioning model. For this reason, at present, a very hot topic in the SIP and IP telephony standardization track is security support. In this work, the security model used by SIP is described, and the different open issues are highlighted. We focus, in particular, on the problem of authentication providing a short tutorial on the solution under standardization. The architecture of a possible commercial IP telephony service including user authentication is also described. Finally, we focus on performance issues. By means of a real testbed implementation, we provide an experimental performance analysis of the SIP security mechanisms, based on our open source Java implementation of a SIP. proxy server. The performance of the server has been compared with and without security support, under various scenarios.
2002
SIP security issues: the SIP authentication procedure and its processing load / S., Salsano; Veltri, Luca; D., Papalilo. - In: IEEE NETWORK. - ISSN 0890-8044. - 16:6(2002), pp. 38-44. [10.1109/MNET.2002.1081764]
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11381/2298295
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 160
  • ???jsp.display-item.citation.isi??? 96
social impact