An improved and provably secure privacy preserving authentication protocol for SIP

被引:0
|
作者
Shehzad Ashraf Chaudhry
Husnain Naqvi
Muhammad Sher
Mohammad Sabzinejad Farash
Mahmood Ul Hassan
机构
[1] International Islamic University,Department of Computer Science and Software Engineering
[2] Department of Mathematics and Computer Sciences Kharazmi University,undefined
关键词
Authentication; Authenticated key agreement; Elliptic curve cryptography; Impersonation attack; Provable security; ProVerif;
D O I
暂无
中图分类号
学科分类号
摘要
Session Initiation Protocol (SIP) has proved to be the integral part and parcel of any multimedia based application or IP-based telephony service that requires signaling. SIP supports HTTP digest based authentication, and is responsible for creating, maintaining and terminating sessions. To guarantee secure SIP based communication, a number of authentication schemes are proposed, typically most of these are based on smart card due to its temper resistance property. Recently Zhang et al. presented an authenticated key agreement scheme for SIP based on elliptic curve cryptography. However Tu et al. (Peer to Peer Netw. Appl 1–8, 2014) finds their scheme to be insecure against user impersonation attack, furthermore they presented an improved scheme and claimed it to be secure against all known attacks. Very recently Farash (Peer to Peer Netw. Appl 1–10, 2014) points out that Tu et al.’s scheme is vulnerable to server impersonation attack, Farash also proposed an improvement on Tu et al.’s scheme. However, our analysis in this paper shows that Tu et al.’s scheme is insecure against server impersonation attack. Further both Tu et al.’s scheme and Farash’s improvement do not protect user’s privacy and are vulnerable to replay and denial of services attacks. In order to cope with these limitations, we have proposed a privacy preserving improved authentication scheme based on ECC. The proposed scheme provides mutual authentication as well as resists all known attacks as mentioned by Tu et al. and Farash.
引用
收藏
页码:1 / 15
页数:14
相关论文
共 50 条
  • [41] EPSAPI: An efficient and provably secure authentication protocol for an IoT application environment
    Bahaa Hussein Taher Algubili
    Neeraj Kumar
    Hongwei Lu
    Ali A. Yassin
    Rihab Boussada
    Alzahraa J. Mohammed
    Huiyu Liu
    Peer-to-Peer Networking and Applications, 2022, 15 : 2179 - 2198
  • [42] EPSAPI: An efficient and provably secure authentication protocol for an IoT application environment
    Algubili, Bahaa Hussein Taher
    Kumar, Neeraj
    Lu, Hongwei
    Yassin, Ali A.
    Boussada, Rihab
    Mohammed, Alzahraa J.
    Liu, Huiyu
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2022, 15 (05) : 2179 - 2198
  • [43] SIP network secure communication model based on improved SIP protocol
    Min, Shi
    INTERNATIONAL JOURNAL OF AUTONOMOUS AND ADAPTIVE COMMUNICATIONS SYSTEMS, 2021, 14 (1-2) : 48 - 63
  • [44] An improved Authentication Protocol for SIP-based VoIP
    Naqvi, Husnain
    Chaudhry, Shehzad Ashraf
    Mahmood, Khalid
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON RECENT ADVANCES IN COMPUTER SYSTEMS, 2016, 38 : 7 - 12
  • [45] An Efficient and Provably Secure ECC-Based Conditional Privacy-Preserving Authentication for Vehicle-to-Vehicle Communication in VANETs
    Ali, Ikram
    Chen, Yong
    Ullah, Niamat
    Kumar, Rajesh
    He, Wen
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2021, 70 (02) : 1278 - 1291
  • [46] Privacy preserving broadcast message authentication protocol for VANETs
    Ying, Bidi
    Makrakis, Dimitrios
    Mouftah, Hussein T.
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2013, 36 (05) : 1352 - 1364
  • [47] A Novel and Efficient Privacy Preserving TETRA Authentication Protocol
    Zahednejad, Behnam
    Azizi, Mahdi
    Pournaghi, Morteza
    2017 14TH INTERNATIONAL ISC (IRANIAN SOCIETY OF CRYPTOLOGY) CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2017, : 125 - 132
  • [48] An Efficient Privacy-preserving Authentication Protocol in VANETs
    Zhang, Jianhong
    Zhen, Weina
    Xu, Min
    2013 IEEE NINTH INTERNATIONAL CONFERENCE ON MOBILE AD-HOC AND SENSOR NETWORKS (MSN 2013), 2013, : 272 - 277
  • [49] A Hierarchical Privacy Preserving Pseudonymous Authentication Protocol for VANET
    Rajput, Ubaidullah
    Abbas, Fizza
    Oh, Heekuck
    IEEE ACCESS, 2016, 4 : 7770 - 7784
  • [50] A Lightweight Privacy-Preserving Authentication Protocol for VANETs
    Li, Xiong
    Liu, Tian
    Obaidat, Mohammad S.
    Wu, Fan
    Vijayakumar, Pandi
    Kumar, Neeraj
    IEEE SYSTEMS JOURNAL, 2020, 14 (03): : 3547 - 3557