ITU-T H 235 9-2005 H 323 security Security gateway support for H 323 (Study Group 16)《H 323 安全框架 H 323安全网关支持 研究组16》.pdf
《ITU-T H 235 9-2005 H 323 security Security gateway support for H 323 (Study Group 16)《H 323 安全框架 H 323安全网关支持 研究组16》.pdf》由会员分享,可在线阅读,更多相关《ITU-T H 235 9-2005 H 323 security Security gateway support for H 323 (Study Group 16)《H 323 安全框架 H 323安全网关支持 研究组16》.pdf(18页珍藏版)》请在麦多课文档分享上搜索。
1、 International Telecommunication Union ITU-T H.235.9TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (09/2005) SERIES H: AUDIOVISUAL AND MULTIMEDIA SYSTEMSInfrastructure of audiovisual services Systems aspects H.323 security: Security gateway support for H.323 ITU-T Recommendation H.235.9 ITU-T H-SER
2、IES RECOMMENDATIONS AUDIOVISUAL AND MULTIMEDIA SYSTEMS CHARACTERISTICS OF VISUAL TELEPHONE SYSTEMS H.100H.199 INFRASTRUCTURE OF AUDIOVISUAL SERVICES General H.200H.219 Transmission multiplexing and synchronization H.220H.229 Systems aspects H.230H.239 Communication procedures H.240H.259 Coding of mo
3、ving video H.260H.279 Related systems aspects H.280H.299 Systems and terminal equipment for audiovisual services H.300H.349 Directory services architecture for audiovisual and multimedia services H.350H.359 Quality of service architecture for audiovisual and multimedia services H.360H.369 Supplement
4、ary services for multimedia H.450H.499 MOBILITY AND COLLABORATION PROCEDURES Overview of Mobility and Collaboration, definitions, protocols and procedures H.500H.509 Mobility for H-Series multimedia systems and services H.510H.519 Mobile multimedia collaboration applications and services H.520H.529
5、Security for mobile multimedia systems and services H.530H.539 Security for mobile multimedia collaboration applications and services H.540H.549 Mobility interworking procedures H.550H.559 Mobile multimedia collaboration inter-working procedures H.560H.569 BROADBAND AND TRIPLE-PLAY MULTIMEDIA SERVIC
6、ES Broadband multimedia services over VDSL H.610H.619 For further details, please refer to the list of ITU-T Recommendations. ITU-T Rec. H.235.9 (09/2005) i ITU-T Recommendation H.235.9 H.323 security: Security gateway support for H.323 Summary This Recommendation defines a method for the discovery
7、of Security Gateways in the signalling path between communicating H.323 entities, and for sharing of security information between a gatekeeper and the SGs in order to preserve signalling integrity and privacy. Source ITU-T Recommendation H.235.9 was approved on 13 September 2005 by ITU-T Study Group
8、 16 (2005-2008) under the ITU-T Recommendation A.8 procedure. Keywords Gateway, security, signalling. ii ITU-T Rec. H.235.9 (09/2005) FOREWORD The International Telecommunication Union (ITU) is the United Nations specialized agency in the field of telecommunications. The ITU Telecommunication Standa
9、rdization Sector (ITU-T) is a permanent organ of ITU. ITU-T is responsible for studying technical, operating and tariff questions and issuing Recommendations on them with a view to standardizing telecommunications on a worldwide basis. The World Telecommunication Standardization Assembly (WTSA), whi
10、ch meets every four years, establishes the topics for study by the ITU-T study groups which, in turn, produce Recommendations on these topics. The approval of ITU-T Recommendations is covered by the procedure laid down in WTSA Resolution 1. In some areas of information technology which fall within I
11、TU-Ts purview, the necessary standards are prepared on a collaborative basis with ISO and IEC. NOTE In this Recommendation, the expression “Administration“ is used for conciseness to indicate both a telecommunication administration and a recognized operating agency. Compliance with this Recommendati
12、on is voluntary. However, the Recommendation may contain certain mandatory provisions (to ensure e.g. interoperability or applicability) and compliance with the Recommendation is achieved when all of these mandatory provisions are met. The words “shall“ or some other obligatory language such as “mus
13、t“ and the negative equivalents are used to express requirements. The use of such words does not suggest that compliance with the Recommendation is required of any party. INTELLECTUAL PROPERTY RIGHTS ITU draws attention to the possibility that the practice or implementation of this Recommendation ma
14、y involve the use of a claimed Intellectual Property Right. ITU takes no position concerning the evidence, validity or applicability of claimed Intellectual Property Rights, whether asserted by ITU members or others outside of the Recommendation development process. As of the date of approval of thi
15、s Recommendation, ITU had not received notice of intellectual property, protected by patents, which may be required to implement this Recommendation. However, implementors are cautioned that this may not represent the latest information and are therefore strongly urged to consult the TSB patent data
16、base. ITU 2006 All rights reserved. No part of this publication may be reproduced, by any means whatsoever, without the prior written permission of ITU. ITU-T Rec. H.235.9 (09/2005) iii CONTENTS Page 1 Scope 1 2 References. 1 2.1 Normative references 1 2.2 Informative references 1 3 Definitions 1 4
17、Abbreviations 2 5 Conventions 2 6 Basic operation . 4 6.1 Endpoint gatekeeper discovery. 4 6.2 Endpoint authentication key distribution 5 6.3 Address manipulation. 6 7 Signalling details 7 8 SG configuration considerations. 8 8.1 SG registration 8 8.2 Authentication credentials 9 9 Security consider
18、ations. 9 10 Applicability . 10 11 Object Identifier 10 iv ITU-T Rec. H.235.9 (09/2005) Introduction The use of Firewalls and/or Network Address Translation devices to provide traffic security between network regions under different administrative controls creates problems for telephony signalling p
19、rotocols that must exchange network addresses for signalling and media exchange. ITU-T Rec. H.235.5 introduces a framework by which an endpoint and its gatekeeper, or two gatekeepers, can use the initial RAS messages to negotiate a set of strong-shared secrets between them, and use those secrets to
20、encrypt selected parts of subsequent RAS and call signalling messages and to authenticate those messages. The method applies to gatekeeper-routed signalling only. Similar methods and security profiles are defined by ITU-T Recs H.235.1, H.235.2 and H.235.3. This security can come into conflict with A
21、pplication Level Gateways (ALGs) which interconnect network realms and manipulate the signalling and media transport addresses carried in the H.225.0 RAS and/or call signalling messages. Such changes in the message will cause the message authentication check to fail at the destination. This Recommen
22、dation describes a simple means by which the gatekeeper may be informed of the ALGs in a signalling path, and may share the negotiated signalling authentication key with those ALGs. This will permit the ALGs to manipulate non-private data, particularly transport addresses, in the signalling messages
23、, and then authenticate the result before passing the modified messages onward. Such devices are referred to as Security Gateways (SGs) in the subsequent text. This technique retains the end-to-end privacy of any encrypted elements in the signalling. ITU-T Rec. H.235.9 (09/2005) 1 ITU-T Recommendati
24、on H.235.9 H.323 security: Security gateway support for H.323 1 Scope This Recommendation is usable by any gatekeeper and endpoint using the H.225.0 RAS protocols, with one or more intervening Security Gateways with the prescribed behaviour. 2 References 2.1 Normative references The following ITU-T
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ITUTH23592005H323SECURITYSECURITYGATEWAYSUPPORTFORH323STUDYGROUP16H323 安全 框架 H323 安全网关 支持 研究 16 PDF

链接地址:http://www.mydoc123.com/p-797463.html