DocumentCode
2431871
Title
MIND (Mobility-oriented IPSec Daemon): a tool for integrated mobility and security support in the Ecumene network
Author
Floridia, C. ; Giordana, S. ; Lucetti, S. ; Risi, G. ; Tomasi, A.
Author_Institution
I.D.S. Informatica Distribuita e Software, Navacchio, Italy
fYear
2005
fDate
23-25 Feb. 2005
Firstpage
306
Lastpage
307
Abstract
The IP protocol is stateless and connectionless, hence cannot guarantee a secure delivery of the information. IPSec offers stateful security introducing logical connections between couples of peers. The management of these IPSec Security Associations is often delegated to dynamic protocols, such as ISAKMP and IKE, because of the obvious scalability problem of a manual configuration approach. However, the address of each peer must be known in advance to the other one in order for the ISAKMP exchange to be completed successfully. This assumption cannot be always guaranteed, especially when mobility is taken into consideration. In such cases, a proper mechanism to retrieve the correspondent peer IPv6 address must be taken into account. The demo consists of an overview of the functionalities of the Ecumene Web Information System, developed in the groundwork of the Ecumene Project, focusing mainly on the enhancements developed (in the form of the MIPSD daemon) to allow automatic IPSec SA insaturation between hosts which wants to access the network and the appropriate Site Gateway.
Keywords
IP networks; Web sites; internetworking; mobile radio; telecommunication security; transport protocols; Ecumene Web information system; Ecumene project; IP protocol; ISAKMP exchange; MIND; automatic IPSec SA insaturation; logical connection; mobility oriented IPSec daemon; peer IPv6 address; security association; site gateway; Access protocols; Communication system security; Cultural differences; Information security; Information systems; Intelligent networks; Libraries; Network servers; Scalability; Testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Testbeds and Research Infrastructures for the Development of Networks and Communities, 2005. Tridentcom 2005. First International Conference on
Print_ISBN
0-7695-2219-X
Type
conf
DOI
10.1109/TRIDNT.2005.24
Filename
1386208
Link To Document