Signature-based handling of Asserted information using toKENs (SHAKEN): SHAKEN Support of "div" PASSporT
使用令牌对断言信息进行基于签名的处理(Shaked):Shaked对“div”PASSporT的支持
发布日期:
2020-09-01
base SHAKEN规范提供了重播检测机制,用于识别恶意实体试图通过重播合法邀请请求的一部分来伪装成另一个用户的情况。然而,这些机制不包括在短时间新鲜度窗口内重播邀请的情况。本技术报告描述了如何将ietf草案[Ref 4]定义的机制集成到SHAKEN框架中,以关闭该重放攻击窗口。
The base SHAKEN specification provides replay-detection mechanisms to identify cases where a malicious entity attempts to masquerade as another user by replaying parts of a legitimate INVITE request. However, these mechanisms don't cover cases where the INVITE is replayed within the short time freshness window. This technical report describes how the mechanisms defined by draft-ietf-stir-passport-divert [Ref 4] can be integrated within the SHAKEN framework to close this replay attack window.