Введение
Профиль безопасности для протокола реального времени
Протокол защищенного транспорта в реальном времени (SRTP) — это профиль для протокола реального времени (RTP), предназначенный для обеспечения шифрования, аутентификации сообщений и целостности, а также защиты от атак повторного воспроизведения данных RTP как в одноадресных, так и в многоадресных приложениях. Он был разработан небольшой группой экспертов в области интернет-протоколов и криптографии из компаний Cisco и Ericsson. Впервые он был опубликован IETF в марте 2004 года. Поскольку RTP сопровождается протоколом управления RTP (RTCP), который используется для управления сеансом RTP, у SRTP есть сопутствующий протокол — Secure RTCP (SRTCP); он безопасно предоставляет те же функции для SRTP, что и RTCP для RTP. Использование SRTP или SRTCP является необязательным в приложениях RTP или RTCP; однако даже при использовании SRTP или SRTCP все предоставляемые функции (например, шифрование и аутентификация) являются необязательными и могут включаться или отключаться независимо друг от друга. Единственным исключением является функция аутентификации сообщений, которая необходима и обязательна при использовании SRTCP.
Since RTP is accompanied by the RTP Control Protocol (RTCP) which is used to control an RTP session, SRTP has a sister protocol, called Secure RTCP (SRTCP); it securely provides the same functions to SRTP as the ones provided by RTCP to RTP. Utilization of SRTP or SRTCP is optional in RTP or RTCP applications; but even if SRTP or SRTCP are used, all provided features (such as encryption and authentication) are optional and can be separately enabled or disabled. The only exception is the message authentication feature which is indispensable and required when using SRTCP.
Шифрование потока данных
SRTP и SRTCP используют Advanced Encryption Standard (AES) в качестве шифра по умолчанию. Определены два режима шифрования, позволяющие использовать блочный шифр AES как поточный шифр:
Segmented Integer Counter Mode A typical counter mode, which allows random access to any blocks, which is essential for RTP traffic running over unreliable network with possible loss of packets. In the general case, almost any function can be used in the role of counter, assuming that this function does not repeat for a large number of iterations. But the standard for encryption of RTP data is just a usual integer incremental counter. AES running in this mode is the default encryption algorithm, with a default key size of 128 bits and a default session salt key length of 112 bits. f8 mode A variation of output feedback mode, enhanced to be seekable and with an altered initialization function. The default values of the encryption key and salt key are the same as for AES in counter mode. (AES running in this mode has been chosen to be used in 3G mobile networks.) Besides the AES cipher, SRTP allows the ability to disable encryption outright, using the so called null encryption cipher, which can be assumed as an alternate supported cipher. In fact, the null encryption cipher does not perform any encryption; the encryption algorithm functions as the identity function, and copies the input stream to the output stream without any changes. It is mandatory for this cipher mode to be implemented in any SRTP compatible system. As such, it can be used when the confidentiality guarantees ensured by SRTP are not required, while other SRTP features, such as authentication and message integrity, may be used. Though SRTP can easily accommodate new encryption algorithms, the SRTP standard states that new encryption algorithms may only be introduced through publication of a new companion standard track RFC which must clearly define the new algorithm.
Сегментированный целочисленный счетный режим. Типичный счетный режим, обеспечивающий произвольный доступ к любым блокам, что критически важно для RTP-трафика, передаваемого по ненадежной сети с возможной потерей пакетов. В общем случае, в качестве счетчика может использоваться практически любая функция, при условии, что она не повторяется в течение большого числа итераций. Однако, стандарт для шифрования данных RTP использует обычный инкрементальный целочисленный счетчик. AES, работающий в этом режиме, является алгоритмом шифрования по умолчанию, с размером ключа по умолчанию 128 бит и длиной ключа соли по умолчанию 112 бит.
Segmented Integer Counter Mode A typical counter mode, which allows random access to any blocks, which is essential for RTP traffic running over unreliable network with possible loss of packets. In the general case, almost any function can be used in the role of counter, assuming that this function does not repeat for a large number of iterations. But the standard for encryption of RTP data is just a usual integer incremental counter. AES running in this mode is the default encryption algorithm, with a default key size of 128 bits and a default session salt key length of 112 bits. f8 mode A variation of output feedback mode, enhanced to be seekable and with an altered initialization function. The default values of the encryption key and salt key are the same as for AES in counter mode. (AES running in this mode has been chosen to be used in 3G mobile networks.) Besides the AES cipher, SRTP allows the ability to disable encryption outright, using the so called null encryption cipher, which can be assumed as an alternate supported cipher. In fact, the null encryption cipher does not perform any encryption; the encryption algorithm functions as the identity function, and copies the input stream to the output stream without any changes. It is mandatory for this cipher mode to be implemented in any SRTP compatible system. As such, it can be used when the confidentiality guarantees ensured by SRTP are not required, while other SRTP features, such as authentication and message integrity, may be used. Though SRTP can easily accommodate new encryption algorithms, the SRTP standard states that new encryption algorithms may only be introduced through publication of a new companion standard track RFC which must clearly define the new algorithm.
Режим f8. Вариация режима обратной связи, улучшенная для произвольного доступа и с измененной функцией инициализации. Значения ключа шифрования и ключа соли по умолчанию совпадают со значениями для AES в счетном режиме. (AES, работающий в этом режиме, был выбран для использования в мобильных сетях 3G.)
Segmented Integer Counter Mode A typical counter mode, which allows random access to any blocks, which is essential for RTP traffic running over unreliable network with possible loss of packets. In the general case, almost any function can be used in the role of counter, assuming that this function does not repeat for a large number of iterations. But the standard for encryption of RTP data is just a usual integer incremental counter. AES running in this mode is the default encryption algorithm, with a default key size of 128 bits and a default session salt key length of 112 bits. f8 mode A variation of output feedback mode, enhanced to be seekable and with an altered initialization function. The default values of the encryption key and salt key are the same as for AES in counter mode. (AES running in this mode has been chosen to be used in 3G mobile networks.) Besides the AES cipher, SRTP allows the ability to disable encryption outright, using the so called null encryption cipher, which can be assumed as an alternate supported cipher. In fact, the null encryption cipher does not perform any encryption; the encryption algorithm functions as the identity function, and copies the input stream to the output stream without any changes. It is mandatory for this cipher mode to be implemented in any SRTP compatible system. As such, it can be used when the confidentiality guarantees ensured by SRTP are not required, while other SRTP features, such as authentication and message integrity, may be used. Though SRTP can easily accommodate new encryption algorithms, the SRTP standard states that new encryption algorithms may only be introduced through publication of a new companion standard track RFC which must clearly define the new algorithm.
Помимо шифра AES, SRTP позволяет полностью отключить шифрование, используя так называемый нулевой шифр, который рассматривается как альтернативный поддерживаемый шифр. Фактически, нулевой шифр не выполняет никакого шифрования: алгоритм шифрования функционирует как тождественная функция, копируя входной поток в выходной поток без изменений. Реализация этого режима шифрования обязательна для любой системы, совместимой с SRTP. Таким образом, он может использоваться, когда гарантии конфиденциальности, обеспечиваемые SRTP, не требуются, в то время как другие функции SRTP, такие как аутентификация и целостность сообщений, могут быть использованы.
Segmented Integer Counter Mode A typical counter mode, which allows random access to any blocks, which is essential for RTP traffic running over unreliable network with possible loss of packets. In the general case, almost any function can be used in the role of counter, assuming that this function does not repeat for a large number of iterations. But the standard for encryption of RTP data is just a usual integer incremental counter. AES running in this mode is the default encryption algorithm, with a default key size of 128 bits and a default session salt key length of 112 bits. f8 mode A variation of output feedback mode, enhanced to be seekable and with an altered initialization function. The default values of the encryption key and salt key are the same as for AES in counter mode. (AES running in this mode has been chosen to be used in 3G mobile networks.) Besides the AES cipher, SRTP allows the ability to disable encryption outright, using the so called null encryption cipher, which can be assumed as an alternate supported cipher. In fact, the null encryption cipher does not perform any encryption; the encryption algorithm functions as the identity function, and copies the input stream to the output stream without any changes. It is mandatory for this cipher mode to be implemented in any SRTP compatible system. As such, it can be used when the confidentiality guarantees ensured by SRTP are not required, while other SRTP features, such as authentication and message integrity, may be used. Though SRTP can easily accommodate new encryption algorithms, the SRTP standard states that new encryption algorithms may only be introduced through publication of a new companion standard track RFC which must clearly define the new algorithm.
Хотя SRTP может легко поддерживать новые алгоритмы шифрования, стандарт SRTP устанавливает, что новые алгоритмы шифрования могут быть введены только путем публикации нового сопутствующего RFC, который должен четко определять новый алгоритм.
Segmented Integer Counter Mode A typical counter mode, which allows random access to any blocks, which is essential for RTP traffic running over unreliable network with possible loss of packets. In the general case, almost any function can be used in the role of counter, assuming that this function does not repeat for a large number of iterations. But the standard for encryption of RTP data is just a usual integer incremental counter. AES running in this mode is the default encryption algorithm, with a default key size of 128 bits and a default session salt key length of 112 bits. f8 mode A variation of output feedback mode, enhanced to be seekable and with an altered initialization function. The default values of the encryption key and salt key are the same as for AES in counter mode. (AES running in this mode has been chosen to be used in 3G mobile networks.) Besides the AES cipher, SRTP allows the ability to disable encryption outright, using the so called null encryption cipher, which can be assumed as an alternate supported cipher. In fact, the null encryption cipher does not perform any encryption; the encryption algorithm functions as the identity function, and copies the input stream to the output stream without any changes. It is mandatory for this cipher mode to be implemented in any SRTP compatible system. As such, it can be used when the confidentiality guarantees ensured by SRTP are not required, while other SRTP features, such as authentication and message integrity, may be used. Though SRTP can easily accommodate new encryption algorithms, the SRTP standard states that new encryption algorithms may only be introduced through publication of a new companion standard track RFC which must clearly define the new algorithm.
Аутентификация, целостность и защита от повторного просмотра
Вышеперечисленные алгоритмы шифрования сами по себе не обеспечивают целостность сообщений: злоумышленник не сможет расшифровать данные, но может подделать или повторно использовать ранее переданные данные. Поэтому стандарт SRTP также предоставляет средства для обеспечения целостности данных и защиты от повторных атак. Для аутентификации сообщения и защиты его целостности используется алгоритм HMAC SHA1. Он генерирует 160-битный результат, который затем усекается до 80 или 32 бит и становится тегом аутентификации, добавляемым к каждому пакету. HMAC вычисляется на основе полезной нагрузки пакета и данных из заголовка пакета, включая порядковый номер пакета. Для защиты от атак повторного воспроизведения приемник сохраняет порядковые номера ранее полученных сообщений, сравнивает их с порядковым номером в каждом новом полученном сообщении и принимает новое сообщение только в том случае, если оно не было получено ранее. Этот подход опирается на защиту целостности, чтобы сделать невозможным изменение порядкового номера без обнаружения.
Вывод ключа
Функция вывода ключа используется для получения различных ключей, применяемых в криптографическом контексте (ключи и соли шифрования SRTP и SRTCP, ключи аутентификации SRTP и SRTCP) из одного мастер-ключа криптографически безопасным способом. Таким образом, протоколу управления ключами необходимо обмениваться только одним мастер-ключом, а все необходимые ключи сеанса генерируются путем применения функции вывода ключа. Периодическое применение функции вывода ключа не позволяет злоумышленнику собрать большой объем зашифрованных данных, зашифрованных одним и тем же ключом сеанса. Это обеспечивает защиту от определенных атак, которые легче осуществить при наличии большого объема зашифрованных данных. Кроме того, многократное применение функции вывода ключа обеспечивает ретроспективную и перспективную безопасность в том смысле, что скомпрометированный ключ сеанса не ставит под угрозу другие ключи сеанса, полученные из того же мастер-ключа. Это означает, что даже если злоумышленнику удастся восстановить ключ сеанса, он не сможет расшифровать сообщения, защищенные предыдущими и последующими ключами сеанса, полученными из того же мастер-ключа. (Следует отметить, что, конечно, утечка мастер-ключа раскрывает все ключи сеанса, полученные из него.) SRTP полагается на внешний протокол управления ключами для установки первоначального мастер-ключа. Два протокола, специально разработанные для использования с SRTP, – ZRTP и MIKEY. Существуют также другие методы согласования ключей SRTP. Есть несколько поставщиков, предлагающих продукты, использующие метод обмена ключами SDES.
DTLS-SRTP
определил DTLS SRTP. DTLS SRTP использует протокол DTLS для передачи главного ключа и обеспечивает аутентификацию по открытому ключу.
Совместимость и применения
См. телефоны, серверы и приложения с поддержкой SRTP.