{"title":"An Efficient and Secured Internet Key Exchange Protocol Design","authors":"Ming-Yang Su, Jia-Feng Chang","doi":"10.1109/CNSR.2007.13","DOIUrl":null,"url":null,"abstract":"IPSec provides encryption and authentication on data packets protecting them from being eavesdropped or falsified. Prior to performing IPSec functions, shared session keys must be safely and secretly established between the two communication parties, usually two security gateways. Internet Key Exchange (IKE) protocol is the most common mechanism for two security gateways to exchange key materials. However, the original IKE is too flexible, complex, and vulnerable to DoS attack. Several enhanced IKE versions have been proposed to replace the original one. In this paper, we propose a new IKE version and analyze it extensively. The latest and most related version proposed in 2004 is used to compare with our version. Simulation results have shown that our protocol is more efficient and DoS resistant than the other, in addition to possessing more security merits.","PeriodicalId":266936,"journal":{"name":"Fifth Annual Conference on Communication Networks and Services Research (CNSR '07)","volume":"74 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-05-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Fifth Annual Conference on Communication Networks and Services Research (CNSR '07)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CNSR.2007.13","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9
Abstract
IPSec provides encryption and authentication on data packets protecting them from being eavesdropped or falsified. Prior to performing IPSec functions, shared session keys must be safely and secretly established between the two communication parties, usually two security gateways. Internet Key Exchange (IKE) protocol is the most common mechanism for two security gateways to exchange key materials. However, the original IKE is too flexible, complex, and vulnerable to DoS attack. Several enhanced IKE versions have been proposed to replace the original one. In this paper, we propose a new IKE version and analyze it extensively. The latest and most related version proposed in 2004 is used to compare with our version. Simulation results have shown that our protocol is more efficient and DoS resistant than the other, in addition to possessing more security merits.