{"title":"NeoMAN: A Negotiation Management System for IKE Protocol Based on X.509 Certificate in Cross Domain Application","authors":"Zhen Zhao, Taehyoun Kim, J.H. Kim, I. Kim, Y. Eom","doi":"10.1109/SECTECH.2008.13","DOIUrl":null,"url":null,"abstract":"IPSec VPN is widely used to protect remote data access. IKE protocol is the mandatory key management protocol of IPSec protocol, it provides a manual configuration method for IPSec VPN. But manual configuration is complex, unreliable, unmanageable, and especially less of support for cross-domain management. This paper proposes an IKE negotiation management system based on X.509, called NeoMAN. The NeoMAN system is designed to analysis the security requirements in intra-/cross- domain, provides cross-domain security requirement negotiation, security policy generation, and automatic IKE client configuration. The proposed method reduces the complexity of the IKE configuration process, improves the adaptability of the IKE protocol in cross-domain application, and also provides the management approach for IPSec VPN application.","PeriodicalId":377461,"journal":{"name":"2008 International Conference on Security Technology","volume":"75 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-12-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 International Conference on Security Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SECTECH.2008.13","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
IPSec VPN is widely used to protect remote data access. IKE protocol is the mandatory key management protocol of IPSec protocol, it provides a manual configuration method for IPSec VPN. But manual configuration is complex, unreliable, unmanageable, and especially less of support for cross-domain management. This paper proposes an IKE negotiation management system based on X.509, called NeoMAN. The NeoMAN system is designed to analysis the security requirements in intra-/cross- domain, provides cross-domain security requirement negotiation, security policy generation, and automatic IKE client configuration. The proposed method reduces the complexity of the IKE configuration process, improves the adaptability of the IKE protocol in cross-domain application, and also provides the management approach for IPSec VPN application.