ãŸããã
![](https://habrastorage.org/webt/ln/xa/pt/lnxapt7_takofalazl-ss1evlmi.jpeg)
ã«ããã®äžã«ã¯ãå ã®èšäºã®ç¿»èš³ããããŸã ãããã¯ãè±èªã§åè£è ãã¹ãã«åæ Œããããã«è¡ãå¿ èŠããããŸããã ç§ããã®ç¹å®ã®ããã¹ããéžãã ã®ã¯ãè«æãæžããŠãããšãã§ããããã®å 容ãããç¥ã£ãŠããããã§ãã ããããçŽ1幎ãçµã¡ãŸãããããã£ãä»ãããåºçããããšã«ããŸããã ãã®éã IPãã¬ãã©ããŒãä¿è·ããã¿ã¹ã¯ã解決ãã TLS / SRTPãšIPsecã®äž¡æ¹ã§äœæ¥ããæ©äŒããã£ãããšã¯æ³šç®ã«å€ããŸã ã ããã誰ãã«ãšã£ãŠïŒäžåºŠã¯ç§ã«ãšã£ãŠïŒåœ¹ã«ç«ã€ããå°ãªããšãèå³æ·±ãèªæžã«ãªãããšãé¡ã£ãŠããŸãã ãã®è³æã«ã€ããŠæèŠãæžããŠãã ããã
PSããªã¥ãŒã ãååã«ãããããæå³çã«ããã€ãã®ããšãçç¥ããŸãããçç¥ã«ã¯çç¥èšå·ãä»ããŠããŸãã æ å ±ä¿èšŒãšããçšèªã¯ç¿»èš³ãªãã§æ®ããã;ç§ã¯ãã·ã¢èªã§é¡æšã«äŒã£ãããšããªãã
1.ã¯ããã«
...
ãã¹ãŠã®IPv6å®è£
ã«IPsecãå«ããããã®IETFïŒã€ã³ã¿ãŒããããšã³ãžãã¢ãªã³ã°ã¿ã¹ã¯ãã©ãŒã¹ïŒèŠä»¶ã®ããã VoIPã»ãã¥ãªãã£ã確ä¿ããããã®é©åãªãããã³ã«ãšããŠIPsecãæ€èšããããšã¯åççã§ãã ãã ããçŸåšã§ã¯ã ãã©ã³ã¹ããŒãå±€ã»ãã¥ãªãã£ïŒTLSïŒãããã³ã«ã䜿çšããŠSIPïŒã»ãã·ã§ã³éå§ãããã³ã«ïŒã»ãã¥ãªãã£ã確ä¿ãã SRTPïŒã»ãã¥ã¢ãªã¢ã«ã¿ã€ã ãã©ã³ã¹ããŒããããã³ã«ïŒã䜿çšããŠRTPãä¿è·ããŠããŸãã
çŸåšïŒ ãããTranslã - 2007幎ã®åæå·çæç¹ ïŒãããã2ã€ã®ã¢ãããŒãã®æ¯èŒã¯ãããŸããããã®äœæ¥ã§ã¯ãã®ãããªæ¯èŒãæäŸãããåã¢ãããŒãã®é·æãšçæãèæ ®ãããŸãã ãã®äœæ¥ã«åºã¥ããŠã IAïŒæ å ±ä¿èšŒïŒã®å®è£ è ããã³èšèšè ã¯ãæ å ±ã«åºã¥ããææ決å®ãè¡ãããšãã§ããŸãã
SIP㯠ãæ¯é çãªVoIPã»ãã·ã§ã³ãããã³ã«ã«ãªãã€ã€ãããŸã ã RTPã¯ãé³å£°ããŒã¿ãããã±ãŒãžåããããã®äž»èŠãªãããã³ã«ã§ããã IPãããã¯ãŒã¯ãä»ãã端æ«éã®ãã®åŸã®ãã©ã³ã¹ããŒãã§ãã TLS ã SRTPãããã³IPsecã¯ã SIPããã³RTPã»ãã·ã§ã³ãã»ãã¥ãªãã£ã§ä¿è·ããããã«äœ¿çšããããããã³ã«ã§ããã VoIPé¢é£IPãã±ããã®èªèšŒãæŽåæ§ãããã³æ©å¯æ§ãæäŸããŸã....次ã®å³ã¯ãã¢ãã«å ã®TLS ã IPsec ã SRTP ã SIPãããã³RTP ãããã³ã«ã®å Žæã瀺ããŠããŸãOSI
![](https://habrastorage.org/webt/al/e2/s7/ale2s7lztl_unytgrbcsn0kyirw.png)
äžã®å³ã¯ã SIPãšRTPã®äžè¬çãªåŒã³åºããã¿ãŒã³ã瀺ããŠããŸãã
![](https://habrastorage.org/webt/l1/ux/n0/l1uxn0sblsrxefndbfrvxd_y_gw.png)
...
2.ãããã³ã«ã®æŠèŠ
äžå£
SIP㯠ã1人以äžã®åå è
ãšã®éä¿¡ã»ãã·ã§ã³ãäœæãå€æŽãããã³çµäºããããã®ã¢ããªã±ãŒã·ã§ã³å±€å¶åŸ¡ãããã³ã«ãšããŠRFC 3261ã§èª¬æãããŠããŸã ã VoIPãµãŒãã¹ãããã€ããŒã¯ ã VoIPã®ã·ã°ããªã³ã°ã«äœ¿çšãããSIPã®éçºã«å€é¡ã®æè³ãè¡ã£ãŠããŸã ã äžã®å³ã®å³ã¯ãäžè¬ã«ã SIPé³å£°éä¿¡ã»ãã·ã§ã³ã®ç¢ºç«ã«é¢é£ããã¡ãã»ãŒãžãããŒã瀺ããŠããŸãã
...
RTP
RTP㯠ããããŒããã£ã¹ããŸãã¯ã¿ãŒã²ãããããã¯ãŒã¯ãµãŒãã¹ã§ãªãŒãã£ãªãªã©ã®ãªã¢ã«ã¿ã€ã ããŒã¿ãéä¿¡ããã¢ããªã±ãŒã·ã§ã³ã«é©ããããšã³ãããŒãšã³ãã®ãããã¯ãŒã¯è»¢éæ©èœãæäŸãããããã³ã«ãšããŠRFC 3550ã§èª¬æãããŠããŸãã ããã¯çŸåšã VoIPã«é©ããå¯äžã®ãããã³ã«ã§ãã äžã®å³ã«ç€ºãããã«ã ACKãŸãã¯OKã¡ãã»ãŒãžãåä¿¡ãããšãåSIPã¯ã©ã€ã¢ã³ãã«ãã£ãŠRTPã»ãã·ã§ã³ãéå§ãããŸãã
IPsec
IPsec㯠ã IPã¬ãã«ã®ã»ãã¥ãªãã£ãµãŒãã¹ã®ã»ãããšããŠRFC 4301ã§èª¬æãããŠããŸããããã«ãããã¿ãŒã²ããã·ã¹ãã ã¯å¿ èŠãªã»ãã¥ãªãã£ãããã³ã«ãéžæããã¢ã«ãŽãªãºã ã決å®ããèŠæ±ããããµãŒãã¹ãæäŸããããã«å¿ èŠãªæå·ããŒãå®æœã§ããŸãã IPsec SAïŒã»ãã¥ãªãã£ã¢ãœã·ãšãŒã·ã§ã³ïŒã¯ ã SIPããã³RTPã»ãã·ã§ã³ã®éå§åã«ç¢ºç«ããã確ç«ããããšã IPã¹ã¿ãã¯å ã§OSIã¢ãã«ã®ãããã¯ãŒã¯ã¬ã€ã€ãŒãééããSIPããã³RTPãã±ããã®ã»ãã¥ãªãã£ã確ä¿ããããã«ã IPsecãèªåçã«äœ¿çšãããŸãã
TLS
TLS㯠ãã€ã³ã¿ãŒãããéä¿¡ãä¿è·ããããã®ãããã³ã«ãšããŠRFC 4346ã§èª¬æãããŠããŸã ã ãã®ãããã³ã«ã«ãããã¯ã©ã€ã¢ã³ããµãŒããŒã¢ããªã±ãŒã·ã§ã³ã¯ãã¡ãã»ãŒãžã®çèŽãæå·ãããã³/ãŸãã¯æ¹ããããä¿è·ãããæ¹æ³ã§éä¿¡ã§ããŸãã TLSããŒãžã§ã³1.0ã¯ã SSLïŒSecure Socket LayerïŒããŒãžã§ã³3.1ãšãåŒã°ããŸãã SIPã»ãã·ã§ã³ãéå§ããåã«ãå®å šãªTLSæ¥ç¶ã確ç«ãããŸãã IPã¹ã¿ãã¯å ã®OSIã¢ãã«ã®ãã©ã³ã¹ããŒãå±€ãééããSIPãã±ãããä¿è·ããããã«ã TLSã䜿çšãããŸãã
SRTP
SRTP㯠ãæ©å¯æ§ãã¡ãã»ãŒãžèªèšŒã RTPããã³RTCPïŒãªã¢ã«ã¿ã€ã 転éå¶åŸ¡ãããã³ã«ïŒä¿è·ãæäŸã§ããRTPãããã¡ã€ã«ãšããŠRFC 3711ã§èª¬æãããŠããŸã ã SRTPããã³SIPã®äžè¬çãªã¡ãã»ãŒãžã³ã°ã¹ããŒã ã¯ãäžã®å³ãšåãã§ãã SRTP㯠ã IPã¹ã¿ãã¯å ã§OSIã¢ãã«ãã©ã³ã¹ããŒãå±€ãééããRTPãã±ããã®ã»ãã¥ãªãã£ã確ä¿ããããã«äœ¿çšãããããŒäº€æã®SIPã¡ãã»ãŒãžãšSIPã¯ã©ã€ã¢ã³ãèªèšŒã®TLSã«äŸåããŸãã
3.æ¯èŒ
...
æšæºã®å®è£ ãšã«ããŒã®é£ãã
å®è£ ã«é¢ããŠã¯ã TLS㯠IPsecãããSIPãšçµ±åããã®ãç°¡åã§ãã RFC 4346ã«ã¯ãçŽ200ã®TLSå®è£ èŠä»¶ããããŸãã äžæ¹ã IPsecã«ã¯ãçŽ11ã®RFCã§èª¬æãããŠãã500以äžã®å®è£ åºæã®èŠä»¶ããããŸãã
IETF㯠ã SIP ã TLSãããã³SRTPã®çµ±åæ¹æ³ã«é¢ããããã€ãã®ããã¥ã¡ã³ããå ¬éããŠããŸãã ããã«ãåœé²çïŒ ãããTranslã-åœæå®ãªãïŒã¯ã TLSããã³SRTPãšã®SIP / TLSçµ±åã䜿çšããSIPã»ãã¥ãªãã£ã«é©çšå¯èœãªçžäºéçšæ§ä»æ§ãéçºããŸããã ãã®èšäºã®èè ã¯ã IPsecãSIPãŸãã¯RTPãšçµ±åããæ¹æ³ã説æããIEFTææžã®ååšãèªèããŠããŸãã;ãã®åé¡ã¯ãéä¿¡æ¥çã§ã¯ååã«ç 究ãããŠããŸããã ããã«ããããããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã«ãŒãã«ã«ã¢ã¯ã»ã¹ããå¿ èŠããããããå®è£ ãããå°é£ã§ããããšã瀺ãç 究æåã®å®è£ ãããã€ãç»å ŽããŸããã VoIPãããã€ããŒã¯éåžžã Windows ã Linuxã UNIXãªã©ã®æ¢åã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«VoIPã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããŸããéåžžããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã«ãŒãã«ãžã®ã¢ã¯ã»ã¹ã¯å¶éãããŠããããã¢ã¯ã»ã¹ã§ããŸããã
ãããã€ããŒãšããã€ã¹ã®çš®é¡ã«ãã£ãŠã¯ã VoIPããã€ã¹ã«äž¡æ¹ã®ã¢ãããŒããå®è£ ã§ããªãå ŽåããããŸãã ããšãã°ãäžéšã®ãšã³ããã€ã³ãããã€ã¹ã¯ã¡ã¢ãªãããŒã¿ã¹ãã¬ãŒãžãµã€ãºãããã³èšç®èœåãå¶éãããŠããã TLS ã SRTPãããã³IPsecã®å®è£ ãåæã«ãµããŒãããŠããªãå ŽåããããŸã ã
éå±€çãªã·ã°ããªã³ã°ã®ãµããŒã
IPsecã®äž»ãªããŒã±ãã£ã³ã°æ©èœã¯ãã»ãšãã©ã®ããŒã¿ã¢ããªã±ãŒã·ã§ã³ã«å¿ èŠãªãšã³ãããŒãšã³ãã®æå·åãæäŸããããšã§ãã ãã ããåçšé³å£°ãªãã¡ãŒã¯ãç¬èªã®ä¿¡å·ãããã³ã«ã䜿çšããŠéä¿¡ã»ãã·ã§ã³ã確ç«ããããã«ããªãã¢ã³ãïŒç«¯æ«ããã€ã¹ïŒãLCCïŒããŒã«ã«ã³ãŒã«ã³ã³ãããŒã©ïŒã«éç¥ããé局信å·ã¢ãã«ã«åºã¥ããŠããŸãã ååãšããŠã LCCã¯ãå€éšãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããã«SIPã䜿çšããŠãããã€ããŒã®SSïŒãœãããŠã§ã¢ã¹ã€ããïŒã«éç¥ãã SSã¯å¥ã®SSãŸãã¯LCCã«éç¥ããŠããªã¢ãŒãOSãšã®éä¿¡ã»ãã·ã§ã³ã®ç¢ºç«ãå®äºããããšãã§ããŸãïŒå·Šå³ïŒ ã ç¬èªã®ã·ã°ããªã³ã°ãããã³ã«ããªãã¢ã³ããšLCCã®éã§äœ¿çšãããããããµãŒãã¹ãããã€ããŒã¯ãŠãŒã¶ãŒã«ç¬èªã®ä»å 䟡å€æ©èœãæäŸã§ããŸããããã¯ãæšæºåããããããã³ã«ãæ¡çšãããŠããå Žåã¯äžå¯èœã§ãã
![](https://habrastorage.org/webt/ja/v_/w6/jav_w6hgllmrxkuxh4wibqprraw.png)
éå±€ã¢ãã«ã§ã¯ãéå±€ã®åãããã¯ãéä¿¡åã«ä¿¡å·ãã±ããã埩å·åãåŠçãããã³åŸ©å·åã§ããå¿ èŠããããŸãã ããã¯ããšã³ãããŒãšã³ãã®ã»ãã¥ãªãã£ã¢ãã«ã«åããŸãã ãã ãã IPsecãšTLSã®äž¡æ¹ãéå±€ã¢ãã«å ã«å®è£ ã§ããŸãããçŸåšã VoIPãããã€ããŒã¯TLSããã®ã¢ãã«ã«é©ããŠãããšèããŠããŸã ã
ãšã³ãããŒãšã³ãã®ã»ãã¥ãªãã£ã¢ãã«ã¯ãããŒã¿ãã£ãã«ã®æŽçã«äœ¿çšããã SRTPãšIPsecã®äž¡æ¹ã䜿çšããŠå®è£ ã§ããŸãã IEFT㯠ã SRTP over SIPãã±ããã®ããŒã亀æããæ¹æ³ãå ¬éããŠãããããã·ã°ããªã³ã°ã®å®äºåŸã«ã»ãã·ã§ã³ã確ç«ã§ããŸãã IPsecã«ã€ããŠãåæ§ã®ã¢ãããŒããéçºã§ããŸãããããã¯ãŸã è¡ãããŠããŸããã
垯åå¹ å¹ç
垯åå¹ ã«å¯ŸããããŒã¿ãã±ããã«é¢ããã·ã°ããªã³ã°ãã±ããã®åœ±é¿ã¯ç¡èŠã§ããããã垯åå¹ å¹çã®æ¯èŒã¯é³å£°ããŒã¿ãã£ãã«ã«é¢ããŠæå³ããããŸãã
IPsecãã±ããã®ãµã€ãºãSRTPãšæ¯èŒããããšã¯ã䜿çšãããã¢ãŒãïŒãã©ã³ã¹ããŒããŸãã¯ãã³ãã«ïŒãããã£ã³ã°ã®ãã€ãæ°ãèªèšŒã¢ã«ãŽãªãºã ãããã³äœ¿çšãããæŽåæ§å¶åŸ¡ã«äŸåãããããéåžžã«å°é£ã§ãã IPsecã®ESPïŒEncapsulating Security PayloadïŒãããã³ã«ãæå°éã®å å¡«ãšå°ããªãµã€ãºã®æ¿å ¥ã§ãã©ã³ã¹ããŒãã¢ãŒãã§äœ¿çšãããããšãåãå ¥ãããšã SRTPã¯IPsecããIPv6ãã±ããã«å¯ŸããŠ6ïŒ å¹æçã§ãããšäž»åŒµã§ããŸãã IPããããŒã®æŽåæ§ãå¶åŸ¡ããå Žåã¯ã IPsecã§AHïŒèªèšŒããããŒïŒã䜿çšã§ããŸããããã«ã¯è¿œå ã®ãªãŒããŒãããã䌎ããŸãã
![](https://habrastorage.org/webt/fc/mf/3v/fcmf3v16l9kj98izp8xbpq0ke_m.png)
SIPã®å Žåã«åãä»®å®ã䜿çšããŠã IPsecã¯TLSãã2ãã€ã以äžSIPãä¿è·ããã®ãå¿ èŠãšããŸãã
![](https://habrastorage.org/webt/uj/ik/rn/ujikrne4wjfcb5ppddwqfjramnc.png)
è©äŸ¡ãªãã§ã¯ã RTPããããŒã®å§çž®ã®å¹æã¯æ®ããŸããã ãã®å§çž®ã䜿çšãããç°å¢ã§ã¯ã SRTPã¯IPsecããã10ãã€ãå¹ççã§ãã 以äžã®è¡šã¯ãäžèšãèŠçŽããŠããŸãã
ãããã³ã« | ãã±ãããµã€ãºããã€ã | 垯åå¹ ãkb / s |
---|---|---|
SRTP | 254 | 101.6 |
RTP / IPsec | 270 | 108,0 |
SIP / TLS | 1280 | N / a |
SIP / IPsec | 1282 | N / a |
åçšã¢ããªã±ãŒã·ã§ã³
åçšVoIPãµãŒãã¹ãããã€ããŒã¯ ã TLSãšSRTPã䜿çšããŠVoIPã»ãã¥ãªãã£ã確ä¿ããããšã«å€é¡ã®æè³ãè¡ã£ãŠããŸã ã ãã®ã¿ã¹ã¯ã§ã¯IPsecãèæ ®ãããŸãããã TLSãšSRTPãæé©ãªãœãªã¥ãŒã·ã§ã³ãšããŠèªèãããŸããã çŸåšã SIPããŒã¹ã®VoIPã»ãã¥ãªãã£ãæäŸããããã«èšèšãããåçšIPsecå®è£ ã¯ãããŸããã é³å£°ãœãªã¥ãŒã·ã§ã³ã«H.323ã¬ã¬ã·ãŒã·ã°ããªã³ã°ã䜿çšããŠãããã³ããŒã¯ããœãªã¥ãŒã·ã§ã³ãä¿è·ããããã«IPsecãéžæããå¯èœæ§ããããŸãã ãã ããçŸåšãã»ãšãã©ã®H.323ãããã€ããŒã¯æå·åãããŠããªããœãªã¥ãŒã·ã§ã³ã䜿çšããŠããã SIPããŒã¹ã®ãœãªã¥ãŒã·ã§ã³ã«ç§»è¡ããŠããŸãã
æ å ±ä¿èšŒ
IPsecã䜿çšããããã®æãäžè¬çãªè°è«ã¯ããšã³ãããŒãšã³ãã®æå·åãæäŸããããšã§ãã ãã ããåè¿°ã®ããã«ãã»ãšãã©ã®å®è£ ã¯éå±€ã·ã°ããªã³ã°ã¢ãã«ã«åºã¥ããŠããã TLSã¯ãã®ã¢ãã«ã«é©ããŠããããã VoIPã·ã°ããªã³ã°ã®å Žåããã®å©ç¹ã¯äœ¿çšãããŸããã ...
IPsecã®å©ç¹ã¯ããã©ã³ã¹ããŒãå±€ã®ã»ãã¥ãªãã£ãæäŸããTLSããããããã³ã«ã¹ã¿ãã¯ãäœãIPãããã¯ãŒã¯å±€ã§ããŒã¿ãä¿è·ããããšã§ãã ...
IPsecãšSRTPã®ãã1ã€ã®éãã¯ã IPsecã¯RTPããããŒãæå·åããã®ã«å¯Ÿãã SRTPã¯æå·åããªãããšã§ãã ããã§IPsecã䜿çšããå©ç¹ã¯ãæœåšçãªæ»æè ããæçšãªæ å ±ãé ãããšã§ãã æ¬ ç¹ã¯ãç¹å®ã®ããŒãã§ãã€ã¯ããã£ãã«ã䜿çšãããã¡ã€ã¢ãŠã©ãŒã«ããã³SBCïŒã»ãã·ã§ã³ããŒããŒã³ã³ãããŒã©ãŒïŒã®æ©èœãå¶éãããããšã§ãã ããã¯è€æ°ã®éè€ããLCCsã®ããã«Network Address TranslationïŒ NAT ïŒããã€ã¹ãšããŠæ©èœããŠãããã¡ã€ã¢ãŠã©ãŒã«ãšSBCsã«ç¹ã«éèŠã«ãªã£ãŠããŸã ã å°çãããã¹ãŠã®VoIPãã±ããã®IPã¢ãã¬ã¹ã¯ãã¡ã€ã¢ãŠã©ãŒã«ãŸãã¯SBCã«åãããããããç»é¢ãŸãã¯SBCã察å¿ããã¿ãŒã²ããLCCã決å®ããããã«äœ¿çšã§ããå¯äžã®ç¹åŸŽçãªæ©èœã¯ããŒãçªå·ã§ãã
äž¡æ¹ã®ãããã³ã«ã¯ãåæ§ã®æå·åãèªèšŒãããã³æŽåæ§ã¡ã«ããºã ã䜿çšããŸãã ããšãã°ãäž¡æ¹ã®ãããã³ã«ã¯ãå ¬ééµæå·åã察称AESæå·åãããã³HMAC-SHA1ã»ãã¥ãªãã£ããµããŒãããŠããŸã ã ãããã£ãŠããã®èŠ³ç¹ãããå®å šæ§ã«éãã¯ãããŸããã
æ¥ç¶ã®ç¢ºç«ãããŒã®å€æŽãããã³æ¥ç¶æé
ã»ãã·ã§ã³ã®æ¥µç«¯ã«é·ãã»ããã¢ããæéãšã«ãããªãå¹æïŒé³å£°éä¿¡ã»ãã·ã§ã³ã®éå§æã®ãã±ããæ倱ïŒãåé¿ããããã«ãããŒã¿éä¿¡ãã£ãã«ã®æå·åããŒãã·ã°ããªã³ã°ããã»ã¹ã®äžéšãšããŠé åžããããšãéåžžã«éèŠã§ãã IEFT㯠ã SIP ïŒã»ãã·ã§ã³èšè¿°ãããã³ã«ïŒ SIPã¡ãã»ãŒãžã®æ¬æã«ããŒãé 眮ããããšã«ããã SIPã·ã°ããªã³ã°ã®äžéšãšããŠSRTPããŒãé åžããæ¹æ³ãå®çŸ©ããŠããŸãã IEFTã¯ãæå·åããŒãIPsecã§é åžããããã®SDPã¡ã«ããºã ããŸã éçºããŠããŸããã ããã«ã RFC 3264ããã®èŠæ±/å¿çã¢ãã«ã«ããã SIPã·ã°ããªã³ã°ã«IPsecããŒæ å ±ãå«ããããšãã§ããªãå ŽåããããŸãã
å¥ã®åé¡ã¯ãããŒã®å€æŽã«é¢é£ããé 延ã§ãã TLSã»ãã·ã§ã³ãšIPsecã»ãã·ã§ã³ããŒå€æŽæéãæ¯èŒããæè¿ã®ç 究ã§ã¯ã IPsecãããŒãå€æŽããã®ã«TLSãããçŽ20åïŒ26ããªç§å¯Ÿ1.3ããªç§ïŒé·ãæéãå¿ èŠã§ããããšã瀺ãããŠããŸã ã ããã¯ãåäžã®ã·ããã§ã¯é·ãæéã§ã¯ãããŸããããæ°åã®ç«¯æ«ãåæã«ããŒãå€æŽããããšãããšåé¡ã«ãªãå¯èœæ§ããããŸãã
æåŸã®è³ªåã¯ãå®å šãªæ¥ç¶ã®åŸ©å ã«é¢é£ããé 延ã§ãã TLSã䜿çšããSIPã«ã¯ãå°ãªããšã6ã€ã®ã¡ãã»ãŒãžã³ã°ãå¿ èŠã§ãã IPsecã䜿çšããSIPæ¥ç¶ã®å埩ã¯ãäž»ã«Internet Key ExchangeïŒ IKEïŒãããã³ã«ã®å®è£ ã«é¢é£ããŠãããåºæ¬ãåºæ¬ããŸãã¯ã¢ã°ã¬ãã·ãã®ã¢ãŒãã亀æã®æåã®ãã§ãŒãºã§ã©ã®ããã«äœ¿çšããããã«äŸåããŸãã ã¡ã€ã³ã¢ãŒãã䜿çšããããšä»®å®ãããšã IPsecã«ã¯9ã€ã®ã¡ãã»ãŒãžäº€æãå¿ èŠã§ãïŒ çŽ -åæã§ã¯ãçŸåšIKEv2ã«çœ®ãæããããŠããIKEv1ã«ã€ããŠèª¬æããŠããŸããã EAPã䜿çšãããªãå Žåã IKEv2ã¯4åã®äº€æãå¿ èŠã§ãïŒã
...
ãããã¯ãŒã¯ç®¡ç
SRTPã® IPsecã®äž»ãªå©ç¹ã¯ã UDPããã³RTPãã±ããã®ããããŒããããã¯ãŒã¯ã¡ã³ããã³ã¹æ åœè ã«éãããŠããããšã§ããåä¿¡ããæ å ±ã䜿çšããŠããããã¯ãŒã¯ã®åé¡ãèŠã€ããŠä¿®æ£ã§ããŸãã IPsecã¯ãããã®ããããŒãæå·åãããã®ãããªæ å ±ãç Žå£ããŸãåã芳ç¹ããã IPsecãšTLSã¯åçã§ãã
ããããžã®é衚瀺
IPsecã¯ããã³ãã«ã¢ãŒãã§äœ¿çšããããšãã«æå·åãããè² è·å ã«å ã®ããããŒãã«ãã»ã«åã§ããããããããã¯ãŒã¯ããããžãé ãç¹ã§TLSããã³SRTPãããå©ç¹ããããŸãã TLSãšSRTPã«ã¯ãã®ãããªæ©èœã¯ãããŸããããããä¿èšŒããã«ã¯ãå€éšNATããã€ã¹ã«äŸåããå¿ èŠããããŸãã ãã ããã»ãšãã©ã®VoIPå®è£ ã¯ãã³ãã«ã¢ãŒãã§ã¯ãªãããã©ã³ã¹ããŒãã¢ãŒãã§äœ¿çšãããŸããããã©ã³ã¹ããŒãã¢ãŒãã§ããã®ãããªæ©èœã¯æäŸãããŸããã
4.çµè«
VoIPã»ãã¥ãªãã£ã«IPsecãšTLS + SRTPãã³ãã«ã䜿çšããäºåæ¯èŒã«åºã¥ããŠãéçºè ã¯TLSãšSRTPã䜿çšããããšããå§ãããŸã ã ãã®ã¢ãããŒãã¯å®è£ ãšä¿å®ãç°¡åã§ããã垯åå¹ ã®äœ¿çšã«é¢ããŠãIPsecãããæçã§ãã IPsecãTLSãšSRTPçµç±ã§äœ¿çšããããšã«ããéèŠãªã»ãã¥ãªãã£äžã®å©ç¹ã¯ãããŸããã
ãã®ãããªçµè«ã¯ãæ¢åã®æšæºã®åæã VoIPãããã€ããŒããã®TLSããã³SRTPã®çŸåšã®å®è£ ã IPsecã®ç§åŠããŒã¹ã®å®è£ ãããã³ä»¥åã«å ¬éãããæ¯èŒã«åºã¥ããŠããŸãã ãã ãã IPsecãšTLS / SRTPã®å®è£ ãæ¯èŒããŠå ¬éãããŠããäœåã¯ãäœæ¥ç°å¢ã§ã®é³å£°éä¿¡ã»ãã·ã§ã³ã®ã»ãã¥ãªãã£ã確ä¿ããããã«ååšããªãããå¶éãããŠããããããªã䜿çšã®åºç€ã®ã¿ãæäŸããŸãã ãããªãç 究ã®ç®æšã®1ã€ã¯ã SIPã¡ãã»ãŒãžãä»ããŠIPsecããŒæ å ±ãéä¿¡ããåã¢ãããŒãã®ã»ãã¥ãªãã£ãšããã©ãŒãã³ã¹ãæ¯èŒããããã®å¹æçãªã¡ã«ããºã ã§ãã