计算机工程与应用 ›› 2014, Vol. 50 ›› Issue (13): 87-89.

• 网络、通信、安全 • 上一篇    下一篇

SIP协议的SPIN模型检测

尤启房,杨晋吉   

  1. 华南师范大学 计算机学院,广州 510631
  • 出版日期:2014-07-01 发布日期:2015-05-12

Model checking of SIP protocol via SPIN

YOU Qifang, YANG Jinji   

  1. School of Computer, South China Normal University, Guangzhou 510631, China
  • Online:2014-07-01 Published:2015-05-12

摘要: 2010年Yoon等人提出一种基于椭圆曲线的三要素SIP认证密钥协商协议TAKASIP,但其存在一些攻击。对唐宏斌等人提出的该协议的改进方案使用SPIN进行了分析,发现仍然存在安全漏洞。针对这些缺陷,提出了一种有效的改进方案,采用在协议的消息中加入只有双方共享的秘密值的方法,克服了安全漏洞。新方案在不降低效率的情况下,提高了安全性。

关键词: TAKASIP协议, 椭圆曲线, SPIN工具, 模型检测

Abstract: In 2010, Yoon et al. proposed a three-factor authenticated key agreement scheme for SIP on Elliptic Curves named TAKASIP, but it exists some attacks. Using SPIN to analysis that the version given by Tang et al still exists an attack. Based on these flaws, an effective improvement for TAKASIP protocol is given, which adds a secret value only shared by both sides in the protocol and overcomes the security drawbacks. New scheme not only improves security but also maintains the high efficiency.

Key words: TAKASIP protocol, Elliptic curve, SPIN, model checking