SPI 2003 Secure Audio and Video Conferencing system Jaroslav Dočkal, Tomáš Bouček, Petr Dušek, Tomáš Koníř
Current status ● Many audio/video conferencing systems ● Many incompatibile protocols (some are proprietary) ● Not secured: – No authentication – No authorization – No secured data over transfer
Our Goal ● Find suitable solution based on multicast or similar ● Improve existing solution (add the security parts) ● Security funcions MUST NOT affect the usability ● Our solution must be able to run on the most commonly used platforms.
Software we used as basement ● Audio and video conferencing tools, based on packet reflector technology ● Programs, named VIC (video conferencing tool) and RAT (robust audio tool) Packet Reflector Client AClient B Client C
Security model ● Add one security module to each client ● Not modify existing client ● Rewrite the packet reflector Packet Reflector Module AModule B Module C Client A
Server improvements ● Use authentication ● Key generation and distribution ● User authorization
What to do now? ● Login / password –> X.509 digital certificates ● Attribute certificates ● User – friendly interface
Thank you for patience Questions ?