JP4267008B2

RTP/SIP authentication in client server systems

Abstract

This record has no abstract on file.

Term

Term ended

Expired 28 July 2026, 0.2 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

42 claims: 5 independent, 37 dependent

  1. 1
    A client-server distributed system that supports the SIP (Session Initiation Protocol) protocol that connects to the Internet, intranet, and LAN (Local Area Network), and is located between the SIP protocol-compatible client device and the SIP protocol-compatible server device. Authentication is completed, and the RTP (Real-time Transport Protocol) connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the server deviceButA means for setting one or more types of RTP encryption information used for sending and receiving RTP packets between the client devices for each client device and managing them as encryption capability information of the client device, and each occurrence of RTP communication between the client devices. Has a means for determining one type of RTP encryption information to be used between the client devices and a means for creating a SIP message to which the determined RTP encryption information is added and notifying the client device.With, The client deviceBut, A means for setting the RTP encryption information added to the SIP message when the SIP message is received from the server device as the RTP encryption information used when sending and receiving RTP packets with another client device.Have,The client deviceRTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information added to the SIP message received from the server device during the RTP communication.Means to doReceives an encrypted RTP packet from the opposite client device and decrypts it.Including meansA client-server distributed system characterized by this. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムであって、 前記SIPプロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置との間の認証が完了し、前記クライアント装置間のRTP(Real-time Transport Protocol)接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、 前記サーバ装置が、前記クライアント装置間のRTPパケット送受信の際に用いるRTP暗号情報を前記クライアント装置単位に1種類以上設定して該クライアント装置の暗号能力情報として管理する手段と、前記クライアント装置間のRTP通信発生毎に前記クライアント装置間で使用するRTP暗号情報を1種類決定する手段と、その決定したRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する手段とを有するとともに、 前記クライアント装置が、前記サーバ装置から前記SIPメッセージを受信した時に当該SIPメッセージに付加されたRTP暗号情報を他のクライアント装置とのRTPパケット送受信の際に用いるRTP暗号情報として設定する手段を有し、前記クライアント装置は、前記RTP通信に際して前記サーバ装置から受信したSIPメッセージに付加されたRTP暗号情報にしたがって前記クライアント装置間のP2P(Peer-to-Peer)で対向クライアント装置にRTPパケットを暗号化して送信する手段と、前記対向クライアント装置から暗号化されたRTPパケットを受信して復号化する手段とを含むことを特徴とするクライアント・サーバ型分散システム。
  2. 3
    In the RTP communication encryption method between the client devices, the client device has means for managing the presence / absence of encryption and the priority of the cryptographic rules used for the RTP communication as RTP encryption capability information, and its own device for the server device. The server device manages the RTP encryption capability information received from the client device, and the server device holds the RTP encryption capability information. Select the function to compare and edit the information and the RTP encryption capability information of each of the client devices facing each other when making an RTP call connection, select whether to encrypt the RTP packet and the encryption rule used for encryption, and select the encryption key. Claim 1 or claim comprising a function of determining the RTP encryption information by randomly generating the RTP encryption information, creating a SIP message to which the determined RTP encryption information is added, and notifying the client device. The client-server type distributed system described in Section 2. 前記クライアント装置間のRTP通信暗号方式において、 前記クライアント装置は、暗号有無と前記RTP通信に使用する暗号則の優先順位とをRTP暗号能力情報として管理する手段と、 前記サーバ装置に対して自装置のRTP暗号能力情報を予め通知する手段とを含み、 前記サーバ装置は、前記クライアント装置から受信した前記RTP暗号能力情報を管理し、当該RTP暗号能力情報を前記サーバ装置が保持しているRTP暗号情報と比較して編集する機能と、 RTP呼接続を行う際に対向する前記クライアント装置各々のRTP暗号能力情報からRTPパケットの暗号有無と暗号化に使用する暗号則とを選択し、暗号鍵をランダムに生成することで前記RTP暗号情報を決定し、その決定済みのRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する機能とを含むことを特徴とする請求項1または請求項2記載のクライアント・サーバ型分散システム。
  3. 22
    A client-to-client RTP (Real-time Transport Protocol) encryption method used for SIP (Session Initiation Protocol) protocol-compatible client-server distributed systems that connect to the Internet, intranet, and LAN (Local Area Network). Authentication between the client device and the server device compatible with the SIP protocol is completed, and the RTP connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the process of setting one or more types of RTP encryption information used by the server device for sending and receiving RTP packets between the client devices for each client device and managing the information as encryption capability information of the client device, and the client device. Each time RTP communication occurs between the client devices, one type of RTP encryption information to be used between the client devices is determined, and a SIP message to which the determined RTP encryption information is added is created and notified to the client device.With, A process of setting the RTP encryption information added to the SIP message when the client device receives the SIP message from the server device as RTP encryption information used when sending and receiving RTP packets with another client device.To run、The client deviceRTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information added to the SIP message received from the server device during the RTP communication.Processing to do andA client-to-client RTP encryption method, which comprises performing a process of receiving an encrypted RTP packet from the opposite client device and decrypting the packet. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムに用いるクライアント間RTP(Real-time Transport Protocol)暗号方法であって、 前記SIPプロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置との間の認証が完了し、前記クライアント装置間のRTP接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、 前記サーバ装置が、前記クライアント装置間のRTPパケット送受信の際に用いるRTP暗号情報を前記クライアント装置単位に1種類以上設定して該クライアント装置の暗号能力情報として管理する処理と、前記クライアント装置間のRTP通信発生毎に前記クライアント装置間で使用するRTP暗号情報を1種類決定する処理と、その決定したRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する処理とを実行するとともに、 前記クライアント装置が、前記サーバ装置から前記SIPメッセージを受信した時に当該SIPメッセージに付加されたRTP暗号情報を他のクライアント装置とのRTPパケット送受信の際に用いるRTP暗号情報として設定する処理を実行し、前記クライアント装置は、前記RTP通信に際して前記サーバ装置から受信したSIPメッセージに付加されたRTP暗号情報にしたがって前記クライアント装置間のP2P(Peer-to-Peer)で対向クライアント装置にRTPパケットを暗号化して送信する処理と、前記対向クライアント装置から暗号化されたRTPパケットを受信して復号化する処理とを実行することを特徴とするクライアント間RTP暗号方法。
  4. 41
    A client-server type distributed system that supports the SIP (Session Initiation Protocol) protocol that connects to the Internet, intranet, and LAN (Local Area Network). It is a program that is executed by the server device that supports the SIP protocol, and is a client that supports the SIP protocol. Authentication between the device and the server device is completed, and the RTP (Real-time Transport Protocol) connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the process of setting one or more types of RTP encryption information used for sending and receiving RTP packets between client devices for each client device and managing them as encryption capability information of the client devices, and generating RTP communication between the client devices. It is characterized by including a process of determining one type of RTP encryption information to be used between the client devices for each, and a process of creating a SIP message to which the determined RTP encryption information is added and notifying the client device. program. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムにおいて前記SIPプロトコル対応のサーバ装置に実行させるプログラムであって、 前記SIPプロトコル対応のクライアント装置と前記サーバ装置との間の認証が完了し、前記クライアント装置間のRTP(Real-time Transport Protocol)接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、 前記クライアント装置間のRTPパケット送受信の際に用いるRTP暗号情報を前記クライアント装置単位に1種類以上設定して該クライアント装置の暗号能力情報として管理する処理と、前記クライアント装置間のRTP通信発生毎に前記クライアント装置間で使用するRTP暗号情報を1種類決定する処理と、その決定したRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する処理とを含むことを特徴とするプログラム。
  5. 42
    A program to be executed by the SIP protocol-compatible client device in a SIP (Session Initiation Protocol) protocol-compatible client-server distributed system connected to the Internet, intranet, or LAN (Local Area Network). The client device and the SIP. Authentication with the protocol-compatible server device is completed, and the RTP (Real-time Transport Protocol) connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the process of setting the RTP encryption information added to the SIP message when the SIP message is received from the server device as the RTP encryption information used when sending and receiving RTP packets with another client device, and the above-mentioned RTP communication. RTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information received from the server device.Processing to do andA program including a process of receiving an encrypted RTP packet from the opposite client device and decrypting the packet. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムにおいて前記SIPプロトコル対応のクライアント装置に実行させるプログラムであって、 前記クライアント装置と前記SIPプロトコル対応のサーバ装置との間の認証が完了し、前記クライアント装置間のRTP(Real-time Transport Protocol)接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、前記サーバ装置からSIPメッセージを受信した時に当該SIPメッセージに付加されたRTP暗号情報を他のクライアント装置とのRTPパケット送受信の際に用いるRTP暗号情報として設定する処理と、 前記RTP通信に際して前記サーバ装置から受信した前記RTP暗号情報にしたがって前記クライアント装置間のP2P(Peer-to-Peer)で対向クライアント装置にRTPパケットを暗号化して送信する処理と、前記対向クライアント装置から暗号化されたRTPパケットを受信して復号化する処理とを含むことを特徴とするプログラム。