期刊文献+

基于AKA的IMS接入认证机制 被引量:1

AKA-Based IMS Access Authentication Mechanism
下载PDF
导出
摘要 IP多媒体子系统(IMS)作为3G网络的核心控制平台,其安全问题正面临着严峻的挑战。IMS的接入认证机制的实现作为整个IMS安全方案实施的第一步,是保证IMS系统安全的关键。基于认证和密钥协商(AKA)的IMS接入认证机制是由因特网工程任务组(IETF)制定,并被3GPP采用,广泛应用于3G无线网络的鉴权机制。此机制基于"提问/回答"模式实现对用户的认证和会话密钥的分发,由携带AKA参数的SIP消息在用户设备(UE)和IMS网络认证实体之间进行交互,按照AKA机制进行传输和协商,从而实现用户和网络之间的双向认证,并协商出后续通信所需的安全性密钥对。 IP Multimedia Subsystem (IMS) has been accepted as the core control platform of the 3G network. Its security problems are facing severe challenges now. The implementation of IMS access authentication mechanism, which is considered to be the first step of the whole IMS security plan, is the key to the IMS system security access. The Authentication and Key Agreement (AKA)-based IMS access authentication mechanism is developed by the Internet Engineering Task Force (IETF) organization and adopted by the 3GPP organization, and is widely used in 3G wireless network authentication mechanism. It is based on the "challenge/response" mode to achieve the bidirectional authentication and session key distribution. The Session Initiation Protocol (SIP) messages, which are carried with AKA parameters, are transmitted through the User Equipment (UE) and IMS core functional entities according to the AKA mechanism for consultation, thus realizing the two-way authentication between user and network, as well as the security key pair for later communications.
机构地区 北京邮电大学
出处 《中兴通讯技术》 2007年第6期42-47,共6页 ZTE Technology Journal
关键词 IP多媒体子系统 认证和密钥协商 会话初始协议 接入认证机制 IMS AKA SIP access authentication mechanism
  • 相关文献

参考文献8

  • 1.Security architecture(Release7)[].GPP TSvG.2006
  • 2.Access security for IP-based services(Release7)[].GPP TSv.2007
  • 3.Network Domain Security:IP network layer security(Release7)[].GPP TSv.2006
  • 4FRANKS J,HALLAM-BAKER P,HOSTETLER J,et al.HTTP authentication:Basic and digest Access authentication[].RFCIETF.1999
  • 5.IP Multimedia(IM)subsystem Cx and Dx interfaces signalling flows and message contents(Release7)[].GPP TSv.2007
  • 6.Specification of the MILENAGE algorithm set:An example algorithm set for the3GPP authentication and key generation functions f1,f1*,f2,f3,f4,f5and f5*,Document2:Algorithm specification(Release6)[].GPP TSv.2004
  • 7CAMARILLO G.Compressing the session initiation protocol(SIP)[].RFCIETF.2003
  • 8IETF.Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement(AKA)[].RFC.2002

同被引文献2

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部