Mechanisms to Ensure Continuity of Service for IPsec/IKEv2 Based Communications - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

Mechanisms to Ensure Continuity of Service for IPsec/IKEv2 Based Communications

Résumé

Today, the internet is crucial in almost any possible area, idea or project. The exponential growth of such network (particularly the growth of mobile internet in short term) makes the security a very important issue to manage. The IPsec suite is presented as one of the most used and deployed protocols on the net, commonly implemented as VPN , accompanied by a mechanism called IKE (IKEv2 stands for version two). It ensures maintaining a shared state between the connected entities in a dynamic way, called Security Associations (SAs). IPsec and IKE protocols both maintain what is called an IPsec/IKEv2 security context. When implementing IPsec/IKEv2 clusters, the main goal is to maintain the same security level even if the connection is moved from one gateway to another with no need for starting a new IPsec/IKEv2 negotiation. This would save ISP's costs and would assure high availability. In the other hand, in order to offer a continuous service, the main issue is to synchronize all security context parameters. This document gives first the definition of an IPsec/IKEv2 context, the description of what a Security Association is and how to establish them. Following sections define the parameters needed as well as the manner to successfully transfer a security context in order to ensure continuity of service for an IPsec/IKEv2 based communication, and finally, the framework defined under StrongSWAN, a well known OpenSource IPsec-based VPN Solution for Linux systems.
Fichier principal
Vignette du fichier
Mechanism_to_ensure_continuity_of_service_for_IPsec_and_IKEv2-_ICSNA2011.pdf (409.16 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00863428 , version 1 (19-09-2013)

Identifiants

  • HAL Id : hal-00863428 , version 1

Citer

Daniel Palomares, Maryline Laurent. Mechanisms to Ensure Continuity of Service for IPsec/IKEv2 Based Communications. ICSNA-2011: International Conference on Secure Networking and Applications ,24-25 October, Paris, France, Oct 2011, Paris, France. pp.1. ⟨hal-00863428⟩
166 Consultations
269 Téléchargements

Partager

Gmail Facebook X LinkedIn More