Overview
ISO/IEC TR 16166:2010 provides guidance on the security of session-based communications in Next Generation Corporate Networks (NGCN). Focused on real‑time communications (voice, video, real‑time text, instant messaging and multimedia), the report examines both signalling security and media security, identifies requirements affecting NGN standardization, makes deployment recommendations for enterprise networks, and highlights standardization gaps. It builds on terminology and concepts from ISO/IEC TR 12860 and references IETF, 3GPP and ITU work.
Key topics and requirements
- Signalling security (SIP-centric)
- Protection of session signalling hops (TLS, IPsec) and approaches to ensure all hops are secured.
- End‑to‑end and near end‑to‑end signalling options (S/MIME, SIP Identity, P-Asserted-Identity, Authenticated Identity Body).
- Authentication and delivery of asserted identity across domains.
- Media security (RTP-centric)
- Use of SRTP for media transport protection and related key management techniques.
- Key management approaches: signalling-path key distribution (MIKEY and SDP security descriptions), media-path methods (DTLS‑SRTP, ZRTP).
- Media authentication, recording considerations and NGN implications.
- Operational and deployment considerations
- Threats, countermeasures, authorisation, mobility impacts, software trust/status and call recording/audit.
- Requirements for interworking with PSTN and hosted NGN services.
- Standards and gaps
- The report lists requirements, recommendations for enterprises and identifies areas needing further standardization.
Practical applications - who uses this standard
- Enterprise network architects and IT security teams designing secure VoIP, video conferencing, and unified communications.
- Telecom carriers and NGN service providers implementing hosted enterprise services and inter-domain SIP routing.
- Product vendors of SIP endpoints, SBCs, media gateways, and key management solutions (MIKEY, DTLS‑SRTP).
- Standards bodies and integrators using the report as a reference for interoperability, policy and security requirement definition.
Benefits and implementation value
- Helps organizations select appropriate signalling and media protection mechanisms (e.g., TLS, IPsec, SRTP, DTLS‑SRTP).
- Guides secure inter-domain session design and authenticated identity delivery for fraud reduction and regulatory compliance.
- Clarifies deployment trade-offs for call recording, mobility and NGN interworking.
Related standards
- ISO/IEC TR 12860 (NGCN general concepts)
- IETF RFCs referenced in the report: SIP (RFC 3261), SRTP (RFC 3711), DTLS‑SRTP (RFC 5764/5763), SIP Identity (RFC 4474) and key management drafts (MIKEY, ZRTP)
Keywords: ISO/IEC TR 16166:2010, NGCN, session-based communications, SIP security, SRTP, DTLS-SRTP, TLS, IPsec, enterprise VoIP security.