会话初始协议(SIP)是TETF制订的多媒体通信系统框架协议之一,也是3GPP的IP多媒体子系统(IMS)的重要组成部分。面对复杂、开放的因特网环境,SIP协议自身缺乏有力的安全机制,使其在安全性方面显得较为薄弱。该文从分析SIP的安全威胁入手,针对SIP协议报文明文传送、缺乏有力的身份认证这两大脆弱性,从数据加密和身份鉴定两方面研究了相应的安全解决方案,讨论了如何利用现有技术和手段改善SIP的安全性,并提出了进一步改善SIP安全性的一些思路。
Session Initiation Protocol (SIP) is an important protocol adopted by the 3rd Generation Partnership Project (3GPP) for the IP Multimedia Subsystem (IMS). Facing the complex and open lnternet environment, the security of SIP is poor. After the analysis of the security threats to SIP aiming at cleartext transmission of SIP message and lack of authentication methods, the scheme of data encryption and authentication are researched. And then, we discuss how using the existent techniques for improving the security of SIP and propose the ideas of the security solution to SIP.