An Intelligent Internet Key Exchange Protocol Resistant to Denial-of-Service Attacks
Ming‐Yang Su
Abstract
Ming‐Yang Su
Abstract
IPsec provides encryption and authentication for data packets, and protects them from eavesdropping and falsification. Prior to performing IPsec functions, authentication must be mutually assured between the two parties in communication, usually two security gateways, and shared session keys between them must be safely generated. Internet Key Exchange (IKE) protocol is the most common mechanism for two security gateways to negotiate. Haddad et al. proposed a simplified DoS-resistant protocol for such negotiation. Besides, the new version of IKE, named IKEv2 as defined in RFC 4306, can also achieve limited DoS prevention. This paper proposes a simplified, but intelligent design for an internet key exchange protocol, which has greater DoS-resistant than the protocol by Haddad et al. or IKEv2, while maintaining important security properties.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
IPsec provides encryption and authentication for data packets, and protects them from eavesdropping and falsification. Prior to performing IPsec functions, authentication must be mutually assured between the two parties in communication, usually two security gateways, and shared session keys between them must be safely generated. Internet Key Exchange (IKE) protocol is the most common mechanism for two security gateways to negotiate. Haddad et al. proposed a simplified DoS-resistant protocol for such negotiation. Besides, the new version of IKE, named IKEv2 as defined in RFC 4306, can also achieve limited DoS prevention. This paper proposes a simplified, but intelligent design for an internet key exchange protocol, which has greater DoS-resistant than the protocol by Haddad et al. or IKEv2, while maintaining important security properties.
Key concepts: Computer science, IPsec, Security association, Computer network, Computer security, Eavesdropping, Key exchange, Denial-of-service attack