2010網際網路技術學刊Requires access

An Intelligent Internet Key Exchange Protocol Resistant to Denial-of-Service Attacks

Ming‐Yang Su

Open publisher page 1 citations

Abstract

IPsec provides encryption and authentication for data packets, and protects them from eavesdropping and falsification. Prior to performing IPsec functions, authentication must be mutually assured between the two parties in communication, usually two security gateways, and shared session keys between them must be safely generated. Internet Key Exchange (IKE) protocol is the most common mechanism for two security gateways to negotiate. Haddad et al. proposed a simplified DoS-resistant protocol for such negotiation. Besides, the new version of IKE, named IKEv2 as defined in RFC 4306, can also achieve limited DoS prevention. This paper proposes a simplified, but intelligent design for an internet key exchange protocol, which has greater DoS-resistant than the protocol by Haddad et al. or IKEv2, while maintaining important security properties.

About this research paper

What this paper is about

IPsec provides encryption and authentication for data packets, and protects them from eavesdropping and falsification. Prior to performing IPsec functions, authentication must be mutually assured between the two parties in communication, usually two security gateways, and shared session keys between them must be safely generated. Internet Key Exchange (IKE) protocol is the most common mechanism for two security gateways to negotiate. Haddad et al. proposed a simplified DoS-resistant protocol for such negotiation. Besides, the new version of IKE, named IKEv2 as defined in RFC 4306, can also achieve limited DoS prevention. This paper proposes a simplified, but intelligent design for an internet key exchange protocol, which has greater DoS-resistant than the protocol by Haddad et al. or IKEv2, while maintaining important security properties.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

IPsec provides encryption and authentication for data packets, and protects them from eavesdropping and falsification. Prior to performing IPsec functions, authentication must be mutually assured between the two parties in communication, usually two security gateways, and shared session keys between them must be safely generated. Internet Key Exchange (IKE) protocol is the most common mechanism for two security gateways to negotiate. Haddad et al. proposed a simplified DoS-resistant protocol for such negotiation. Besides, the new version of IKE, named IKEv2 as defined in RFC 4306, can also achieve limited DoS prevention. This paper proposes a simplified, but intelligent design for an internet key exchange protocol, which has greater DoS-resistant than the protocol by Haddad et al. or IKEv2, while maintaining important security properties.

Key concepts: Computer science, IPsec, Security association, Computer network, Computer security, Eavesdropping, Key exchange, Denial-of-service attack

Related papers

Back to paper searchBrowse research topicsOriginal source
An Intelligent Internet Key Exchange Protocol Resistant to Denial-of-Service Attacks — Research Paper | ScholarLens