Abstract
In 2014, Tu et al. proposed an authentication scheme for session initiation protocol. Very soon Farash realized that Tu et al.'s scheme can not resist server forgery attack, then Farash proposed an improved protocol. However in this paper, we show that Tu et al.'s scheme can not resist server forgery attack as well as strong replay and denial of services attack. Furthermore, we show that Farash's improved scheme can not resists strong replay and denial of services attack. Then we propose an improved and robust scheme. The improved scheme while resisting forgery and related attacks do not make any extra computation as compared Tu et al. and Farash's schemes.