S-Sip: Secure Session Initiation Protocol

25 Pages Posted: 17 Aug 2022

See all articles by Osama Younes

Osama Younes

Menoufia University

Umar Albalawi

University of Tabuk

Abstract

The Session Initiation Protocol (SIP) is widely used for multimedia communication as a signaling protocol for managing, establishing, maintaining, and terminating multimedia sessions among participants. However, SIP is exposed to a variety of security threats. To overcome the security flaws of SIP, it needs to support a number of security services: authentication, confidentiality, and integrity. Few solutions have been introduced in the literature to secure SIP, which can support these security services. Most of them are based on internet security standards and have many drawbacks. This work introduces a new protocol for securing SIP called secure-SIP (S-SIP). S-SIP consists of two protocols: the SIP authentication (A-SIP) protocol and the key management and protection (KP-SIP) protocol. A-SIP is a novel mutual authentication protocol. KP‐SIP is used to secure SIP signaling messages and exchange session keys among entities. It provides different security services for SIP: integrity, confidentiality, and key management. A-SIP is based on the secure remote password (SRP) protocol, which is one of standard password-based authentication protocols supported by the transport layer security (TLS) standard. However, A-SIP is more secure and efficient than SRP because it covers its security flaws and weaknesses, which are illustrated and proven in this work. Through comprehensive informal and formal security analyses, we demonstrate that S-SIP is secure and can address SIP vulnerabilities. In addition, the proposed protocols are compared with many related protocols in terms of security and performance. It is found that the proposed protocols are more secure and have better performance.

Keywords: SIP security, authentication protocols, SRP analysis

Suggested Citation

Younes, Osama and Albalawi, Umar, S-Sip: Secure Session Initiation Protocol. Available at SSRN: https://ssrn.com/abstract=4192646 or http://dx.doi.org/10.2139/ssrn.4192646

Osama Younes (Contact Author)

Menoufia University ( email )

Gamal Abd El-Nasir,
Shebeen El-Kom
Egypt

Umar Albalawi

University of Tabuk ( email )

P.O. Box 741
Tabuk, 71491
Saudi Arabia

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
65
Abstract Views
424
Rank
916,100
PlumX Metrics