论文部分内容阅读
IMS即IP多媒体子系统,是被业界公认的下一代网络的核心技术.开放互联网环境的引入使IMS接入侧面临多种安全威胁.本文通过对IMS网络进行研究,针对IMS接入侧设计了一种安全通信模型.在原有SIP协议框架的基础上,通过扩展头域,引入两阶段Diffie-Hellman密钥交换算法模型等方式,实现了三项主要功能:1)终端和服务器的双向认证;2)终端间会话密钥的自主协商和保密通信;3)通话的合法监听.在相关开源库的基础上,对安全通信模型进行了实现.验证测试结果表明该模型可以有效满足安全性需求,万次测试平均时间延迟在可接受范围.
IMS is the IP multimedia subsystem, which is recognized as the core technology of next-generation network in the industry.An open Internet environment brings a variety of security threats to the IMS access side.This paper studies the IMS network and designs for the IMS access side A secure communication model based on the original SIP protocol framework achieves three main functions by extending the header field and introducing the two-phase Diffie-Hellman key exchange algorithm model: 1) Two-way authentication between the terminal and the server; 2) Autonomous negotiation and secure communication of session keys between terminals; 3) Legitimate interception of calls. The secure communication model is implemented based on the relevant open source libraries. The verification test results show that the model can effectively meet the security requirements, The average test time delay is within the acceptable range.