[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

SRTP Key Disclosure



Business requirements of some businesses require recording certain
phone calls.  For example, stock brokers, banks, mail-order catalog
companies, travel agencies, and so on, find it useful to record calls
with customers.  With PSTN gateways and RTP this is trivially 
accomplished today.  Tomorrow, where PSTN gateways are replaced
with SIP trunking, and SRTP is preferred over RTP (especially for
transactions with your bank, stockbroker, and doctor), this 
business need will become more difficult to meet.

To meet this need for recording SRTP-encrypted calls, we 
wrote "Disclosing Secure RTP (SRTP) Session Keys with a SIP 
Event Package", draft-wing-sipping-srtp-key-02, abstract:
   Many Secure RTP (SRTP) key exchange mechanisms do not disclose the
   SRTP session keys to intermediate SIP proxies.  However, these key
   exchange mechanisms cannot be used in environments where transcoding,
   monitoring, or call recording are needed.  This document specifies a
   secure mechanism for a cooperating endpoint to disclose its SRTP
   master keys to an authorized party.

If there is sufficient interest I would like to present
draft-wing-sipping-srtp-key-02 at the upcoming SIPPING meeting in Vancouver.

Comments welcome.

-d