
Data Security Overview
page 42
Data Security Overview
Since version 2.0, the Dialogic
®
Diva
®
SIPcontrol
TM
software provides additional security options for transmitted
and received data:
•
: You may use Secure HTTP (HTTPS) to transmit data between the web-based configuration
interface of the Diva SIPcontrol software and your web browser.
•
: The Transport Layer Security (TLS) protocol may be used to encrypt and authorize SIP messages.
•
: The Secure Real-time Transport Protocol (SRTP) may be used for encrypting the data of the
actual conversation.
Note:
The HTTPS and TLS protocols require digital identity
(e.g., public key certificates).
Secure HTTP
HTTP is a protocol that transmits data between the web-based configuration interface of the Diva SIPcontrol
software and your web browser. Even though the HTTP interface has access security (via a password), the
transmitted data is not entirely secure. The data is transmitted as clear text and thus it is possible for the
transmission to be intercepted and, in turn, for the data to be read.
HTTPS uses HTTP over an encrypted Secure Sockets Layer (SSL) or Transport Layer Security (TLS) connection
and with a different default port than HTTP.
As an example, if a message containing a request to change a password was captured by a third party, the third
party could log on to the Diva SIPcontrol software web interface and change the configuration. HTTPS encrypts
and authenticates HTTP data, and thus the data is no longer transmitted as clear text and is not easily readable.
HTTPS requires two actions by the user:
• Both the Diva SIPcontrol software and the computer on which the web browser used to connect to the Diva
SIPcontrol software via HTTPS is running must be configured with the proper certificate.
• When accessing the Diva SIPcontrol software web interface, use https:// instead of the non-secure http://
followed by the URL of the PC on which the Diva SIPcontrol software is installed.
TLS
SIP (Session Initiation Protocol) is a signaling protocol used for VoIP calls over the Internet. SIP messages contain
information such as call-party information, call media type, whether it is a secure call, and if so, what encryption
algorithm is used, etc. SIP can be carried by UDP, TCP, or TLS transports. Both UDP and TCP transport data in
clear text. As a result, UDP and TCP can easily be monitored by a third party. TLS, on the other hand, carries
SIP data in a secure way by encrypting the data and authenticating the transport connections. Authentication
provides that you are talking to the intended peer. For authentication purposes, you need to install
on page 30 and enable TLS as transport protocol, as described in
Secure RTP
Once a Voice over IP (VoIP) call is established, voice data is transported in packets with the Real-time Transport
Protocol (RTP). The voice data can be easily extracted from RTP packets and replayed using commercially
available software. SRTP adds security by encrypting voice data and authenticating packets. Digital identity
certificates are not required, the parameters are negotiated during call initiation time. SRTP mode is activated
typically in combination with TLS, but in some cases (e.g., testing, intranet connections only) it is useful to allow
SRTP also without TLS being activated.
For encryption and decryption of data, SRTP uses ciphers. The two parties involved in a conversation must be
"compatible" in the sense that each party understands the other party's cipher requirements and supports them.
The Diva SIPcontrol software supports the following ciphers: DH, ADH, AES (128-256 bits), 3DES (64 bits), DES
(64 bits), RC4 (64bytes), RC4 (256 bytes), MD5, SHA1.
SRTP can be set for each SIP peer in the
configuration, as described on page 25. The cipher level can
be set in the
Содержание 4000 Media Gateway Series
Страница 1: ...www dialogic com Dialogic 4000 Media Gateway Series Reference Guide...
Страница 8: ...page 8...