Cryptanalysis of Arshad Et Al.'S Ecc-Based Mutual Authentication Scheme for Session Initiation Protocol

Hongbin Tang,Xinsong Liu
DOI: https://doi.org/10.1007/s11042-012-1001-8
IF: 2.577
2012-01-01
Multimedia Tools and Applications
Abstract:Session Initiation Protocol (SIP) has been widely used in the current Internet protocols such as Hyper Text Transport Protocol (HTTP) and Simple Mail Transport Protocol (SMTP). However, the original SIP authentication scheme was insecure and many researchers tried to propose schemes to overcome the flaws. In the year 2011, Arshad et al. proposed a SIP authentication protocol using elliptic curve cryptography (ECC), but their scheme suffered from off-line password guessing attack along with password change pitfalls. To conquer the mentioned weakness, we proposed an ECC-based authentication scheme for SIP. Our scheme only needs to compute four elliptic curve scale multiplications and two hash-to-point operations, and maintains high efficiency. The analysis of security of the ECC-based protocol shows that our scheme is suitable for the applications with higher security requirement.
What problem does this paper attempt to address?