MKI support to SRTP in FreeSWITCH

In this blog entry we describe Master Key Identifier feature in Secure RTP and the addition of this feature to FreeSWITCH platform.

FreeSWITCH and Skype For Business

FreeSWITCH is a media processing platform and a very popular software for VOIP telephony, WebRTC, audio and video conferencing. It supports multiple protocols, audio/video profiles and implements range of multimedia endpoints. Unfortunately, up till now FreeSWITCH couldn’t be used with Skype For Business because of the limitation of it’s Secure RTP protocol implementation. The MKI feature was missing.

MKI

MKI is a Master Key Identifier send in SRTP packet to associate an incoming packet with a particular master key. It can be used as a security enhancement to the SRTP endpoint which can arrange for the change of the security key by expiring the key or by issuing the dynamic request. It is described in RFC 4568 – Session Description Protocol (SDP) Security Descriptions for Media Streams.

SRTP packet

Figure 1. SRTP packet format (Source: RFC 3711)

An example of SDP with MKI is:

v=0
o=- 177 1 IN IP4 169.55.36.24
s=session
c=IN IP4 169.55.36.24
b=CT:1000
t=0 0
m=audio 50638 RTP/SAVP 97 101 13 0 8
c=IN IP4 169.55.36.24
a=rtpmap:97 RED/8000
a=rtpmap:101 telephone-event/8000
a=fmtp:101 0-16
a=rtpmap:13 CN/8000
a=rtpmap:0 PCMU/8000
a=rtpmap:8 PCMA/8000
a=rtcp:50639
a=label:Audio
a=crypto:1 AES_CM_128_HMAC_SHA1_80 inline:zl7kZCox/PtpvvL87wX9N2HyPSS7Lph4HftGQWBQ|2^31|1:1
a=crypto:2 AES_CM_128_HMAC_SHA1_80 inline:HSC2fkk7oSQ+a1JgmdhWpMoDmFDfILC+Z248whUE|2^31
a=ptime:20

Two crypto attributes are present in this media description. Both crypto use AES_CM_128_HMAC_SHA1_80 suite for encryption/decryption. The first crypto identified with tag :1 contains a master key “in line” with lifetime of 2^31 packets and identified by Master Key Index of 1, 1 byte in size in RTP packet. Second crypto contains security key with it’s lifetime only.

If the SDP response sent to Skype For Business doesn’t contain MKI, the call get’s rejected or packet decryption fails and audio can’t be played correctly.

Solution

In November 2017, Data And Signal worked with FreeSWITCH and TelnyxVOIP infrastructure provider. The result of this effort is the support for MKI added to the FreeSWITCH’s implementation of SRTP. FreeSWITCH now parses master keys with their indices as per RFC 4568 and maps the MKI incoming in RTP packets to specific master key. From then on, the packets are decrypted properly and calls between Skype For Business clients and the FreeSWITCH platform can be connected.

New feature is available in FreeSWITCH Advantage.




Reference:
RFC 1890 – RTP Profile for Audio and Video Conferences with Minimal Control
RFC 3550 – RTP: A Transport Protocol for Real-Time Applications
RFC 3551 – RTP Profile for Audio and Video Conferences with Minimal Control
RFC 4568 – Session Description Protocol (SDP) Security Descriptions for Media Streams
RFC 3711 – The Secure Real-time Transport Protocol (SRTP)

Leave a Reply

Bitnami