IP Security
1
Outline
• Internetworking and Internet Protocols
• IP Security Overview
• IP Security Architecture
• Authentication Header
• Encapsulating Security Payload
• Combinations of Security Associations
• Key Management
[Link] 2
[Link]
TCP/IP Example
3
TCP: Transmission Control Protocol, IP: Internet Protocol, LLC: Logical Link Control, MAC: Message Access Control
IPv4 Header
[Link] 4
[Link]
IPv6 Header
[Link] 5
[Link]
IP Security Overview
• IPSec is not a single protocol.
• Instead, IPSec provides a set of security
algorithms plus a general framework that
allows a pair of communicating entities to use
whichever algorithms to provide security
appropriate for the communication.
• Applications of IPSec
– Secure branch office connectivity over the
Internet
– Secure remote access over the Internet
– Establsihing extranet and intranet
connectivity with partners
– Enhancing electronic commerce security
[Link] 6
[Link]
IP Security Scenario
[Link] 7
[Link]
IP Security Overview
• Benefits of IPSec
– Transparent to applications - below
transport layer (TCP, UDP)
– Provide security for individual users
• IPSec can assure that
– A router or neighbor advertisement comes
from an authorized router
– A redirect message comes from the router
to which the initial packet was sent
– A routing update is not forged
[Link] 8
[Link]
IP Security Architecture
• IPSec documents: NEW updates in 2005!
– RFC 2401: Security Architecture for the Internet Protocol. S. Kent, R.
Atkinson. November 1998. (An overview of security architecture) RFC 4301
(12/2005)
– RFC 2402: IP Authentication Header. S. Kent, R. Atkinson. November 1998.
(Description of a packet encryption extension to IPv4 and IPv6) RFC 4302
(12/2005)
– RFC 2406: IP Encapsulating Security Payload (ESP). S. Kent, R. Atkinson.
November 1998. (Description of a packet emcryption extension to IPv4 and
IPv6) RFC 4303 (12/2005)
– RFC2407 The Internet IP Security Domain of Interpretation for
ISAKMP D. Piper. November 1998. PROPOSED STANDARD. (Obsoleted by
RFC4306)
– RFC 2408: Internet Security Association and Key Management Protocol
(ISAKMP). D. Maughan, M. Schertler, M. Schneider, J. Turner. November 1998.
(Specification of key managament capabilities) (Obsoleted by RFC4306)
– RFC2409 The Internet Key Exchange (IKE) D. Harkins, D. Carrel. November
1998. PROPOSED STANDARD. (Obsoleted by RFC4306, Updated by
RFC4109)
[Link] 9
[Link]
IP Security Architecture
• Internet Key Exchange (IKE)
A method for establishing a security association (SA)
that authenticates users, negotiates the
encryption method and exchanges the secret
key. IKE is used in the IPsec protocol. Derived from
the ISAKMP framework for key exchange and the
Oakley and SKEME key exchange techniques, IKE
uses public key cryptography to provide the secure
transmission of the secret key to the recipient so
that the encrypted data may be decrypted at the
other end. ([Link]
• RFC4306 Internet Key Exchange (IKEv2) Protocol C. Kaufman, Ed.
December 2005 (Obsoletes RFC2407, RFC2408, RFC2409) PROPOSED
STANDARD
• RFC4109 Algorithms for Internet Key Exchange version 1
(IKEv1) P. Hoffman. May 2005 (Updates RFC2409) PROPOSED
STANDARD
[Link] 10
[Link]
IPSec Document Overview
ESP: Encapsulating Security Payload, AH: Authentication Header, DOI: Domain of Interpretation
IPSec Services
• Access Control
• Connectionless integrity
• Data origin authentication
• Rejection of replayed packets
• Confidentiality (encryption)
[Link] 12
[Link]
Security Associations
(SA)
• A one way relationsship between a
sender and a receiver.
• Identified by three parameters:
– Security Parameter Index (SPI)
– IP Destination address
– Security Protocol Identifier
[Link] 13
[Link]
Transport Mode Tunnel Mode SA
SA
AH Authenticates IP payload Authenticates entire
and selected portions of IP inner IP packet plus
header and IPv6 extension selected portions of outer
headers IP header
ESP Encrypts IP payload and Encrypts inner IP packet
any IPv6 extesion header
ESP with Encrypts IP payload and Encrypts inner IP packet.
any IPv6 extesion header. Authenticates inner IP
authenticatio Authenticates IP payload packet.
n but no IP header
[Link] 14
[Link]
Before applying AH
[Link] 15
[Link]
Transport Mode
(AH Authentication)
[Link] 16
[Link]
Tunnel Mode
(AH Authentication)
[Link] 17
[Link]
Authentication Header
• Provides support for data integrity and
authentication (MAC code) of IP packets.
• Guards against replay attacks.
[Link] 18
[Link]
End-to-end versus End-to-
Intermediate Authentication
[Link] 19
[Link]
Encapsulating Security
Payload
• ESP provides confidentiality services
[Link] 20
[Link]
Encryption and
Authentication Algorithms
• Encryption:
– Three-key triple DES
– RC5
– IDEA
– Three-key triple IDEA
– CAST
– Blowfish
• Authentication:
– HMAC-MD5-96
– HMAC-SHA-1-96
[Link] 21
[Link]
ESP Encryption and
Authentication
[Link] 22
[Link]
ESP Encryption and
Authentication
Trlr: Trailer 23
Combinations of
Security Associations
[Link] 24
[Link]
Combinations of
Security Associations
[Link] 25
[Link]
Combinations of
Security Associations
[Link] 26
[Link]
Combinations of
Security Associations
[Link] 27
[Link]
Key Management
• Two types:
– Manual
– Automated
• Oakley Key Determination Protocol
• Internet Security Association and Key
Management Protocol (ISAKMP)
[Link] 28
[Link]
Oakley
• Three authentication methods:
– Digital signatures
– Public-key encryption
– Symmetric-key encryption (aka.
Preshare key)
[Link] 29
[Link]
ISAKMP
[Link] 30
[Link]
Recommended Reading
• Comer, D. Internetworking with TCP/IP,
Volume I: Principles, Protocols and
Architecture. Prentic Hall, 1995
• Stevens, W. TCP/IP Illustrated, Volume
1: The Protocols. Addison-Wesley,
1994
[Link] 31
[Link]