Enhancing ZRTP by using Computational Puzzles

dc.creatorHlavacs,Helmut
dc.creatorGansterer,Wilfried
dc.creatorSchabauer,Hannes
dc.creatorZottl,Joachim
dc.creatorPetraschek,Martin
dc.creatorHoeher,Thomas
dc.creatorJung,Oliver
dc.date2008
dc.date.accessioned2024-02-06T12:56:18Z
dc.date.available2024-02-06T12:56:18Z
dc.descriptionIn this paper we present and discuss a new approach for securing multimedia communication, which is based on three innovations. The first innovation is the integration of a challenge-response scheme for enhancing the Diffie-Hellman based ZRTP protocol. When being called, a callee must present the result of a computational puzzle (a "token") within a short amount of time. A Man-in-the-Middle (MitM) would not be able to compute such a token within the required time, and thus fail to get into the media path. The scheme works best in situations when ZRTP is most vulnerable to so-called Mafia Attacks, i.e., if both caller and callee do not know each other. The second innovation complements the first one on those occasions where the above scheme may fail. The call is delayed for a certain amount of time which depends on the agreed session key. Since during a MitM attack two different keys (and thus waiting times) exist, caller and callee would not start their call at the same time and the MitM attack would fail. The third innovation is in the definition of a new computational puzzle which forms the basis of the challenge-response scheme. We propose a computational puzzle which is based on computing selected eigenvectors of real symmetric matrices. In contrast to existing puzzles, the one we propose does not rely on a shared secret, can be validated quickly, and existing solution methods exhibit limited scalability so that the threat from attacks based on massively parallel computing resources can be controlled.
dc.formattext/html
dc.identifierhttps://doi.org/10.3217/jucs-014-05-0693
dc.identifierhttps://lib.jucs.org/article/28997/
dc.identifier.urihttps://openrepository.mephi.ru/handle/123456789/9644
dc.languageen
dc.publisherJournal of Universal Computer Science
dc.relationinfo:eu-repo/semantics/altIdentifier/eissn/0948-6968
dc.relationinfo:eu-repo/semantics/altIdentifier/pissn/0948-695X
dc.rightsinfo:eu-repo/semantics/openAccess
dc.rightsJ.UCS License
dc.sourceJUCS - Journal of Universal Computer Science 14(5): 693-716
dc.subjectVoIP
dc.subjectSRTP
dc.subjectZRTP
dc.subjectcomputational puzzle
dc.subjectchallenge-response
dc.subjecteigenvectors
dc.subjectcall delay
dc.titleEnhancing ZRTP by using Computational Puzzles
dc.typeResearch Article
Файлы