%% You should probably cite rfc8844 instead of this I-D. @techreport{ietf-mmusic-sdp-uks-07, number = {draft-ietf-mmusic-sdp-uks-07}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-mmusic-sdp-uks/07/}, author = {Martin Thomson and Eric Rescorla}, title = {{Unknown Key-Share Attacks on Uses of TLS with the Session Description Protocol (SDP)}}, pagetotal = 17, year = 2019, month = aug, day = 9, abstract = {This document describes unknown key-share attacks on the use of Datagram Transport Layer Security for the Secure Real-Time Transport Protocol (DTLS-SRTP). Similar attacks are described on the use of DTLS-SRTP with the identity bindings used in Web Real-Time Communications (WebRTC) and SIP identity. These attacks are difficult to mount, but they cause a victim to be misled about the identity of a communicating peer. This document defines mitigation techniques that implementations of RFC 8122 are encouraged to deploy.}, }