Title :
IPSec authentication using certificateless signature in heterogeneous IPv4/IPv6 network
Author :
Ahmad, Nazrul M. ; Yaacob, Asrul H. ; Fauzi, Ridza ; Khorram, Alireza
Author_Institution :
Fac. of Inf. Sci. & Technol. (FIST), Multimedia Univ. (MMU), Ayer Keroh, Malaysia
Abstract :
This paper studies the incompatibilities issues on deploying IPSec Encapsulating Security Payload (ESP) in providing end to end security between heterogeneous IPv4 and IPv6 networks. The presence of IPv4/IPv6 translation gateway violates the TCP/UDP intrinsic functionalities due to the translation of the IP addresses in IP packets. We address these interoperability issues by modifying IKE negotiation with NAT-Traversal capability and some improvements on IPSec software. However, the implementation of the conventional IKE authentication mechanisms such as pre-shared key and Public Key Infrastructure (PKI) certificate-based requires both nodes either to be manually configured, or to exchange the certificates and the necessity to enrol to certain Certificate Authority (CA). This paper proposes a new Internet Key Exchange (IKE) authentication based on certificateless public key infrastructure in order to alleviate the limitation of the conventional IKE authentication. We also propose an efficient public and shared parameters distribution mechanism whereby the translation gateway acts as Key Generator Centre (KGC).
Keywords :
IP networks; Internet; public key cryptography; transport protocols; IKE negotiation; IP address; IPSec authentication; IPSec encapsulating security payload; Internet key exchange authentication; NAT-traversal capability; TCP-UDP intrinsic functionalities; certificate authority; certificateless public key infrastructure; certificateless signature; heterogeneous IPv4 network; heterogeneous IPv6 network; interoperability issues; key generator centre; Authentication; IP networks; Logic gates; Payloads; Peer to peer computing; Public key;
Conference_Titel :
Computers & Informatics (ISCI), 2011 IEEE Symposium on
Conference_Location :
Kuala Lumpur
Print_ISBN :
978-1-61284-689-7
DOI :
10.1109/ISCI.2011.5958996