An improved Authentication Protocol for SIP-based VoIP
Husnain A. Naqvi, Shehzad Ashraf Chaudhry, Khalid Mahmood · 2016
The SIP being an application layer protocol for signaling has been considered as the most appropriate one for multimedia applications.In order to detect some collisions and replay attacks, the SIP offers built-in authentication mechanism as per its specification, designated as HTTP digest based authentication, but study reveals that it is vulnerably susceptible to heterogeneous security issues such as impersonation attacks, man-in-the-middle attacks (MITM), server spoofing and password guessing attacks.Very recently Zhang et al. proposed symmetric key based anonymous authentication scheme for SIP.They claimed the scheme to provide privacy and anonymity, but the analysis in this paper expose that Zhang et al.'s scheme does not provide dynamic identity hence it is not anonymous.Furthermore, we proposed an improved anonymous authentication scheme for SIP.The scheme is more secure as compared with Zhang et al.'s scheme.