Application of IKE protocol for IPsec VPN into embedded system
Jae-Deok Lim, Minho Han, Kiyoung Kim
Abstract
Jae-Deok Lim, Minho Han, Kiyoung Kim
Abstract
IPsec protocol has been deployed widely at remote business environment because of its properties, confidentiality and integrity for network traffic. Before using IPsec protocol, it is needed that negotiations of security associations and keys between two end points of IPsec tunnel. Internet Key Exchange protocol is used when negotiation is done automatically. But because full specification of Internet Key Exchange protocol introduced in RFC standards is so complex and heavy, it is not suitable for embedded system that has small resources. In this paper, we introduce the simplified Internet Key Exchange protocol for embedded system by supporting minimal function for co-working with other implementation. We will prove that this IKE protocol has been implemented based on RFC by working with other commercial IKE protocol and show the negotiation performance of IKE protocol by using test tool. The simplified Internet Key Exchange protocol that is designed and implemented within Xscale Core of Intel IXP2800 Network processor as a part of our works that integrating the security functions such as packet filtering, IDS, IPsec based VPN into network device, router, that is based on IXP2800 network processor.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
IPsec protocol has been deployed widely at remote business environment because of its properties, confidentiality and integrity for network traffic. Before using IPsec protocol, it is needed that negotiations of security associations and keys between two end points of IPsec tunnel. Internet Key Exchange protocol is used when negotiation is done automatically. But because full specification of Internet Key Exchange protocol introduced in RFC standards is so complex and heavy, it is not suitable for embedded system that has small resources. In this paper, we introduce the simplified Internet Key Exchange protocol for embedded system by supporting minimal function for co-working with other implementation. We will prove that this IKE protocol has been implemented based on RFC by working with other commercial IKE protocol and show the negotiation performance of IKE protocol by using test tool. The simplified Internet Key Exchange protocol that is designed and implemented within Xscale Core of Intel IXP2800 Network processor as a part of our works that integrating the security functions such as packet filtering, IDS, IPsec based VPN into network device, router, that is based on IXP2800 network processor.
Key concepts: IPsec, Computer science, Computer network, Internet protocol suite, User Datagram Protocol, Internet Protocol Control Protocol, IP tunnel, Key exchange