and continuous session.
In this paper, we propose then a secure and seam-
less session management solution applied in mobile
and heterogeneous environment. This solution per-
mits to answer principally the following questions:
How to guarantee a secure service access within a
continuous session? How to manage user terminals
and ensure secure usage of these terminals during his
session? And how to ensure security continuity dur-
ing user mobility?
The remainder of the paper is organized as fol-
lows. In section 2, we present an overview of ex-
isting approaches that invoke security and mobil-
ity aspects and use the Session Initiation Protocol
(SIP)(Rosenberget al., 2002) to support these aspects.
In section 3, we describe our proposition. In this sec-
tion, we define first our security management solu-
tion based on security service components and a to-
ken used for single sign seamless session. Then, we
introduce the VPDN concept. Next, we address user
mobility aspect by proposing a token based SIP+ pro-
tocol to ensure the continuity of security. Section 4
shows the feasibility of our proposition. Finally, sec-
tion 5 presents the conclusion and perspectives for fu-
ture work.
2 RELATED WORK
Mobility management, within a seamless session
while ensuring a secured access in continuous and
simplified way, is still a major research issue. We
present and discuss, in this part, some research works
related to the different aspects involved in this context
and that are based on SIP the most popular signalling
protocol for this issue.
(Schulzrinne and Wedlund, 2000), is the very ini-
tial paper that shows how mobility management can
be supported by SIP in order to provide all common
forms of mobility, including terminal, session, per-
sonal and service mobility for SIP-based applications.
Particularly, we are interested to session, and personal
mobility. As it is defined by authors, session mobility
allows a user to maintain a media session even while
changing.terminals. They describe the way when it
is supported by SIP using REFER and INVITE mes-
sages. Personal mobility, as it is defined in this paper,
allows to address a single user located at different ter-
minals by the same logical address. This type of mo-
bility is ensured by a SIP forking proxies making the
user reached at any of his devices. These different
types of mobility are addressed without taking into
account security aspects.
(Zhang et al., 2009), propose SIP security mecha-
nisms that support seamless mobility only during the
handover of mobile terminals among different access
networks (terminal mobility). This solution does not
address user mobility that consists of changing termi-
nal with ensuring service continuity. Moreover, au-
thors focus on security aspects for network and trans-
port layer to secure SIP signaling and data transmis-
sion of SIP services. But, they do not consider non-
functional security aspects such as identification, au-
thentication and authorization.
As defined in (ETSI, 2010), IMS is an Overlay
Session/ Control Architecture that acts as a session
middleware in NGN. IMS uses basically SIP for con-
trolling sessions. This protocol supports terminal and
user mobility. However, when dealing with user mo-
bility, a new session is established with the second
terminal and services offered by the prime terminal
become inaccessible.
In (Vim et al., 2010), authors deal with session
mobility which allows user to maintain his session
and ensures service continuity even while changing
terminals. They discuss two ways for supporting ses-
sion mobility: network- and user equipment- based
approach. In network based approach, network ini-
tiates a session transfer while user equipment initi-
ates a session transfer in user equipment based ap-
proach. They show the feasibility of session mobility
control according to the former approach in IMS. This
work focuses only on continuity of media services,
and does not consider continuity of security services
that ensures a secure and simplified access to any ser-
vice during a seamless session.
None of the cited work has treated mobility im-
pact on security aspects, namely, access control. Most
of these recent work deal only with functional aspect
of mobility independently of security aspects. Even
there is some work that introduce security to mobile
environment, they consider this aspect only on net-
work level. Therefore, a new solution that integrates
security to service, equipment (terminal) and user lev-
els, while supporting mobility, is needed. Thus, we
propose, through this paper, an innovative security
management approach that guarantees a secure termi-
nal and service access for each end-user. Moreover,
our proposal supports mobility, particularly, user mo-
bility, in a seamless way while keeping all user re-
sources, namely his terminals considered as service
platforms, accessible in a secured way during his ses-
sion. So, for example, when a user wants to continue
a session begun on his mobile phone on his laptop,
he can remain using the GPS service offered by his
mobile phone after he changes the terminal. For this
purpose, we introduce the VPDN concept. Finally,
we propose mechanisms to ensure security continuity
SecureandSeamlessSessionManagementinMobileandHeterogeneousEnvironment
283