Contribution to enhance IPSec security by a safe and efficient internet key exchange protocol
Marwa Ahmim, Malika Babes, Ghoualmi Nacira
Abstract
Marwa Ahmim, Malika Babes, Ghoualmi Nacira
Abstract
IPSec is a suite of protocols that provides security for internet communications at the IP layer. The security properties of IPSec mainly depend on the key exchange protocols where the efficiency and security of the key management are important parts of IPSec. Internet Key Exchange (IKE) protocol is the most common mechanism for the two hosts to exchange key materials. However, IKE is complex and vulnerable due to attacks such as (DOS,...). In this paper, we propose a new IKE protocol based on D-H. This protocol uses three round-trips the exchange message. The advantages of our contribution are: one phase (vs. two phases on standard IKE), Best efficiency ie. optimizes transmission time (vs. longer negotiation time). The security analysis and formal verification using Automated Validation of Internet Security Protocols and Applications (AVISPA) show that our contribution can resist to various attack types such as ( Replay, DOS, man in the middle).
OpenAlex reports 7 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
IPSec is a suite of protocols that provides security for internet communications at the IP layer. The security properties of IPSec mainly depend on the key exchange protocols where the efficiency and security of the key management are important parts of IPSec. Internet Key Exchange (IKE) protocol is the most common mechanism for the two hosts to exchange key materials. However, IKE is complex and vulnerable due to attacks such as (DOS,...). In this paper, we propose a new IKE protocol based on D-H. This protocol uses three round-trips the exchange message. The advantages of our contribution are: one phase (vs. two phases on standard IKE), Best efficiency ie. optimizes transmission time (vs. longer negotiation time). The security analysis and formal verification using Automated Validation of Internet Security Protocols and Applications (AVISPA) show that our contribution can resist to various attack types such as ( Replay, DOS, man in the middle).
Key concepts: IPsec, Security association, Computer science, Computer security, Computer network, The Internet, Internet layer, Internet security