@techreport{kuthan-sip-derive-00, number = {draft-kuthan-sip-derive-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-kuthan-sip-derive/00/}, author = {Dorgham Sisalem and Victor Pascual and Raphael Coeffic}, title = {{Dialog Event foR Identity VErification }}, pagetotal = 24, year = 2008, month = oct, day = 27, abstract = {This document provides a simple mechanism to prevent an attacker from presenting a forged "From" header field. It offers an end-to-end identity assumption which does not require any previous association or trust relationship between administrative domains or the UAs. The UAS verifies the "From" header by subscribing to the Dialog Event package {[}RFC 4235{]} at the AOR in the "From" header field. If the entity calling is registered under this AOR, it will confirm that it is calling by sending some valid dialog state. In this case, the identity of the caller is considered to be verified.}, }