摘要
目前,会话初始协议(SIP)大部分认证机制只提供了服务器到客户端的认证,HTTP摘要认证便是其中的一种。分析了这种机制容易遭受服务器伪装攻击和密码窃取攻击的缺陷,提出了一种弥补这些缺陷的安全认证机制。试验表明该算法具备较高的效率。
At present, most of the session initial protocol (SIP) authentication schemes only provide client-to-server authentication. And HTrP digest authentication is one of them. The weakness of this scheme in server spoofing and password guessing attacks was analyzed, and a more secure strategy was proposed which avoided these shortcomings. The experimental result illustrates that this proposed algorithm is effective.
出处
《计算机应用》
CSCD
北大核心
2007年第3期616-618,623,共4页
journal of Computer Applications
基金
河南省科技攻关项目(0524220019)
洛阳市科技攻关项目(50225)
关键词
会话初始协议
认证
HTTP摘要
安全
Session Initial Protocol (SIP)
authentication
HTTP digest
security