RFC 5245 - 交互式连接建立 (ICE)
- 状态: Proposed Standard
- 发布日期: April 2010
- Stream: IETF
- 废弃了: RFC4091, RFC4092
- 被废弃: RFC8445, RFC8839
- 勘误: 无勘误
摘要
本文档定义了一种用于网络地址转换 (NAT) 遍历的协议, 适用于基于 UDP 的多媒体会话, 这些会话通过 offer/answer 模型建立.该协议称为交互式连接建立 (Interactive Connectivity Establishment, ICE).ICE 利用了 NAT 会话遍历实用程序 (Session Traversal Utilities for NAT, STUN) 协议及其扩展——通过中继穿越 NAT (Traversal Using Relay NAT, TURN).任何使用 offer/answer 模型的协议 (例如会话发起协议 (Session Initiation Protocol, SIP)) 都可以使用 ICE.
本备忘录的状态
本文档是互联网标准跟踪规范.
本文档是互联网工程任务组 (Internet Engineering Task Force, IETF) 的产品.它代表了 IETF 社区的共识.它已经过公开审查, 并已获得互联网工程指导组 (Internet Engineering Steering Group, IESG) 的批准发布.有关互联网标准的更多信息, 参见 RFC 5741 的第 2 节.
有关本文档当前状态、任何勘误表以及如何提供反馈的信息, 可以在 http://www.rfc-editor.org/info/rfc5245 获得.
版权声明
版权所有 (c) 2010 IETF Trust 和被确认为文档作者的人员.保留所有权利.
本文档受 BCP 78 以及 IETF Trust 关于 IETF 文档的法律规定 (http://trustee.ietf.org/license-info) 的约束, 这些规定在本文档发布之日有效.请仔细阅读这些文档, 因为它们描述了您对本文档的权利和限制.从本文档中提取的代码组件必须包含简化 BSD 许可证文本, 如 Trust 法律规定第 4.e 节所述, 并按简化 BSD 许可证中所述不提供任何担保.
目录
- 1. 简介 (Introduction)
- 2. ICE 概览 (Overview of ICE)
- 3. 术语 (Terminology)
- 4. 发送初始 Offer (Sending the Initial Offer)
- 4.1. Full 实现的需求 (Full Implementation Requirements)
- 4.2. Lite 实现的需求 (Lite Implementation Requirements)
- 4.3. 编码 SDP (Encoding the SDP)
- 5. 接收初始 Offer (Receiving the Initial Offer)
- 5.1. 验证 ICE 支持 (Verifying ICE Support)
- 5.2. 确定角色 (Determining Role)
- 5.3. 收集 Candidates (Gathering Candidates)
- 5.4. 确定 Candidates 优先级 (Prioritizing Candidates)
- 5.5. 选择 Default Candidates (Choosing Default Candidates)
- 5.6. 编码 SDP (Encoding the SDP)
- 5.7. 形成检查列表 (Forming the Check Lists)
- 5.8. 调度检查 (Scheduling Checks)
- 6. 收到初始应答 (Receipt of the Initial Answer)
- 7. 执行连接检查 (Performing Connectivity Checks)
- 7.1. STUN Client 过程 (STUN Client Procedures)
- 7.2. STUN Server 过程 (STUN Server Procedures)
- 8. 结束 ICE 处理 (Concluding ICE Processing)
- 9. 后续 Offer/Answer 交换 (Subsequent Offer/Answer Exchanges)
- 9.1. 生成 Offer (Generating the Offer)
- 9.2. 接收 Offer 并生成 Answer (Receiving the Offer and Generating an Answer)
- 9.2.1. 所有实现的过程 (Procedures for All Implementations)
- 9.2.2. Full 实现的过程 (Procedures for Full Implementations)
- 9.2.2.1. ICE 运行且无 remote-candidates 的现有媒体流 (Existing Media Streams with ICE Running and no remote-candidates)
- 9.2.2.2. ICE 完成且无 remote-candidates 的现有媒体流 (Existing Media Streams with ICE Completed and no remote-candidates)
- 9.2.2.3. 现有媒体流与 remote-candidates (Existing Media Streams and remote-candidates)
- 9.2.3. Lite 实现的过程 (Procedures for Lite Implementations)
- 9.3. 更新检查与有效列表 (Updating the Check and Valid Lists)
- 10. 保活 (Keepalives)
- 11. 媒体处理 (Media Handling)
- 12. 与 SIP 一起使用 (Usage with SIP)
- 13. 与 ANAT 的关系 (Relationship with ANAT)
- 14. 可扩展性考虑 (Extensibility Considerations)
- 15. 语法 (Grammar)
- 15.1. "candidate" 属性 ("candidate" Attribute)
- 15.2. "remote-candidates" 属性 ("remote-candidates" Attribute)
- 15.3. "ice-lite" 与 "ice-mismatch" 属性 ("ice-lite" and "ice-mismatch" Attributes)
- 15.4. "ice-ufrag" 与 "ice-pwd" 属性 ("ice-ufrag" and "ice-pwd" Attributes)
- 15.5. "ice-options" 属性 ("ice-options" Attribute)
- 16. 设置 Ta 和 RTO (Setting Ta and RTO)
- 17. 示例 (Example)
- 18. 安全考虑 (Security Considerations)
- 18.1. 对连接检查的攻击 (Attacks on Connectivity Checks)
- 18.2. 对服务器反射地址收集的攻击 (Attacks on Server Reflexive Address Gathering)
- 18.3. 对中继候选项收集的攻击 (Attacks on Relayed Candidate Gathering)
- 18.4. 对 Offer/Answer 交换的攻击 (Attacks on the Offer/Answer Exchanges)
- 18.5. 内部攻击 (Insider Attacks)
- 18.6. 与应用层网关及 SIP 的交互 (Interactions with Application Layer Gateways and SIP)
- 19. STUN 扩展 (STUN Extensions)
- 20. 运营考虑 (Operational Considerations)
- 21. IANA 考虑 (IANA Considerations)
- 21.1. SDP 属性 (SDP Attributes)
- 21.1.1. candidate 属性 (candidate Attribute)
- 21.1.2. remote-candidates 属性 (remote-candidates Attribute)
- 21.1.3. ice-lite 属性 (ice-lite Attribute)
- 21.1.4. ice-mismatch 属性 (ice-mismatch Attribute)
- 21.1.5. ice-pwd 属性 (ice-pwd Attribute)
- 21.1.6. ice-ufrag 属性 (ice-ufrag Attribute)
- 21.1.7. ice-options 属性 (ice-options Attribute)
- 21.2. STUN 属性 (STUN Attributes)
- 21.3. STUN 错误响应 (STUN Error Responses)
- 21.1. SDP 属性 (SDP Attributes)
- 22. IAB 考虑 (IAB Considerations)
- 23. 致谢 (Acknowledgements)
- 24. 参考文献 (References)
- Appendix A. Lite 与 Full 实现 (Lite and Full Implementations)
- Appendix B. 设计动机 (Design Motivations)
- B.1. STUN Transactions 的 Pacing (Pacing of STUN Transactions)
- B.2. 具有多个 Bases 的 Candidates (Candidates with Multiple Bases)
- B.3.
<rel-addr>与<rel-port>属性的用途 (Purpose of the <rel-addr> and <rel-port> Attributes) - B.4. STUN Username 的重要性 (Importance of the STUN Username)
- B.5. Candidate Pair Priority 公式 (The Candidate Pair Priority Formula)
- B.6. remote-candidates 属性 (The remote-candidates Attribute)
- B.7. 为什么需要保活 (Why Are Keepalives Needed?)
- B.8. 为什么优先使用 Peer Reflexive Candidates? (Why Prefer Peer Reflexive Candidates?)
- B.9. 为什么要发送更新后的 Offer? (Why Send an Updated Offer?)
- B.10. 为什么保活使用 Binding Indications? (Why Are Binding Indications Used for Keepalives?)
- B.11. 为什么需要冲突解决机制? (Why Is the Conflict Resolution Mechanism Needed?)