Ipv4域和Ipv6域之间的SIP端到端安全

Xing Jiang, J. Atwood
{"title":"Ipv4域和Ipv6域之间的SIP端到端安全","authors":"Xing Jiang, J. Atwood","doi":"10.1109/SECON.2005.1423294","DOIUrl":null,"url":null,"abstract":"The session initiation protocol (SIP) carries the endpoint IP addresses, as part of its message format. When one end-point is in an IPv4 addressing domain, and the other is in an IPv6 addressing domain, a NAT-PT gateway must be used at the network level, to translate the protocol headers. The message bodies are altered by an application level gateway (ALG), to reflect the changed addresses. However, this alteration causes end-to-end security mechanisms to fail. We describe a proposal for a SIP end-to-end security mechanism between IPv4 networks and IPv6 stub domains, which overcomes the failure. We have validated the proposal using the PROMELA formal specification language and the SPIN validation system.","PeriodicalId":129377,"journal":{"name":"Proceedings. IEEE SoutheastCon, 2005.","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-04-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"SIP end-to-end security between Ipv4 domain and Ipv6 domain\",\"authors\":\"Xing Jiang, J. Atwood\",\"doi\":\"10.1109/SECON.2005.1423294\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The session initiation protocol (SIP) carries the endpoint IP addresses, as part of its message format. When one end-point is in an IPv4 addressing domain, and the other is in an IPv6 addressing domain, a NAT-PT gateway must be used at the network level, to translate the protocol headers. The message bodies are altered by an application level gateway (ALG), to reflect the changed addresses. However, this alteration causes end-to-end security mechanisms to fail. We describe a proposal for a SIP end-to-end security mechanism between IPv4 networks and IPv6 stub domains, which overcomes the failure. We have validated the proposal using the PROMELA formal specification language and the SPIN validation system.\",\"PeriodicalId\":129377,\"journal\":{\"name\":\"Proceedings. IEEE SoutheastCon, 2005.\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2005-04-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings. IEEE SoutheastCon, 2005.\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SECON.2005.1423294\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings. IEEE SoutheastCon, 2005.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SECON.2005.1423294","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

会话发起协议(SIP)携带端点IP地址,作为其消息格式的一部分。当一端在IPv4地址域中,另一端在IPv6地址域中时,必须在网络层使用NAT-PT网关对协议头进行转换。消息体由应用程序级网关(ALG)更改,以反映更改的地址。但是,这种更改会导致端到端安全机制失败。我们提出了一个在IPv4网络和IPv6存根域之间建立SIP端到端安全机制的建议,该机制克服了这一缺陷。我们已经使用PROMELA正式规范语言和SPIN验证系统验证了该提案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
SIP end-to-end security between Ipv4 domain and Ipv6 domain
The session initiation protocol (SIP) carries the endpoint IP addresses, as part of its message format. When one end-point is in an IPv4 addressing domain, and the other is in an IPv6 addressing domain, a NAT-PT gateway must be used at the network level, to translate the protocol headers. The message bodies are altered by an application level gateway (ALG), to reflect the changed addresses. However, this alteration causes end-to-end security mechanisms to fail. We describe a proposal for a SIP end-to-end security mechanism between IPv4 networks and IPv6 stub domains, which overcomes the failure. We have validated the proposal using the PROMELA formal specification language and the SPIN validation system.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信