[Demexp-dev] zPhone of Philip Zimmermann

2006-02-03 Par sujet David MENTRE
Hello,

Philip Zimmermann, author of PGP, works on secure VoIP (Voice over IP)
and is starting to make some noise about his zPhone (temporary name):
  http://www.philzimmermann.com/EN/zfone/
  http://www.voip-magazine.com/content/view/1674

No much precise information right now, however :
  - it should be OpenSource (but Free Software???) ;

  - it uses an new approach (to my knowledge) to authentication and
confidentiality:

   1. generate a session key with Diffie Hellman protocol,

   2. generate a fingerprint that users see on their screen and that
they can check by voice over the phone,

   3. this fingerprint is reused from one session to the other one
between 2 people, so that confidentiality and authentication from
session 1 to n is guaranteed by checking the fingerprint at session n;

 - no key server, neither centralised (PKI) or distributed (Web of Trust);

 - works within RTP protocol (UDP voice data stream) and an IETF draft
is prepared.

I find this approach very interesting, especially regarding end user
aspects (no key to generate, very simple, should work with NATs,
etc.).

Of course, one should know more details (patents?) to make one precise
idea of it.

Best wishes,
d.


___
Demexp-dev mailing list
Demexp-dev@nongnu.org
http://lists.nongnu.org/mailman/listinfo/demexp-dev


Re: [Demexp-dev] zPhone of Philip Zimmermann

2006-02-03 Par sujet William D. Neumann

On Fri, 3 Feb 2006, David MENTRE wrote:


 - it uses an new approach (to my knowledge) to authentication and
confidentiality:


That sound like it's based on (or possibly the same as, I'd have to reread 
the paper) a scheme presented by Serge Vaudenay at Crypto'05.  If anyone 
is interested, the paper can be found at 
http://lasecwww.epfl.ch/php_code/publications/search.php?ref=Vau05a


William D. Neumann

---

There's just so many extra children, we could just feed the
children to these tigers.  We don't need them, we're not doing 
anything with them.


Tigers are noble and sleek; children are loud and messy.

-- Neko Case

Life is unfair.  Kill yourself or get over it.
-- Black Box Recorder


___
Demexp-dev mailing list
Demexp-dev@nongnu.org
http://lists.nongnu.org/mailman/listinfo/demexp-dev