Presents Fall Forum 2002
H.235 Security Status Quo and Perspectives Presented by Martin Euchner, Rapporteur Q.G/16 Siemens AG
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA Outline Status Quo of H.235 Some insights into work under development
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA Evolution of H Initial Draft H.323V2 H.323V4 H.323V5 H.235V1 approved Core Security Framework Engineering Consolidation Improvement and Additions 1st Deployment H.235V2 Annex D Annex E approved Annex F H.530 consent H.235V3 consent H.235 Annex G consent Security Profiles Annex D Annex E started
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA Status of H.235 and related Recommendations Approved and published: H.235 Version 2 (2000): Main text including Annex D “Baseline Security Profile” Annex E “Signature Security Profile” H.235 Annex F “Hybrid PKI Security Profile“ H.323 Annex J “Security for SETs” H.530 “Mobility Security in H.510”
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA Work under development Scheduled for consent AAP: 5/2003 Draft H.235 V3 Draft H.235 Annex G “SRTP Usage“
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA Draft H.235 Version 3 Features Annex D “Authentication-Only” Option for improved NAT/FW traversal of the security protocol Acknowledged and more robust key update mechanism Encrypted H.245 inband DTMF signaling OIDs for AES encryption algorithm and (E)OFB mode 1536-bit Diffie-Hellman group defined for high security Key distribution procedure on the RAS channel Enhanced error return codes Secure multiple payload stream and secure MoIP (tbd) …
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA Draft H.235 Annex G “SRTP Usage“ Goals Make IETF Secure RTP Protocol available to H.235- based systems Be interoperable with other SRTP terminals Use a stream cipher for improved performance, robustness and security Yield the improved security for RTCP protection Obtain improved integrity spanning the entire RTP/RTCP packet Deploy state-of-the art AES encryption algorithm, Use session encryption/authentication keys derived from a pseudo-random function at both ends
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA H.235 Annex G Approach Provide integration with key management for SRTP and SRTCP Address fast connect with forward and reverse logical channels Negotiate SRTP features Negotiate a SRTP master key(s) and derive SRTP/SRTCP session keys Use also IETF MIKEY Key Management???
Sponsored in part by: IMTC Fall Forum – November 2002 – New York, NY, USA