• DocumentCode
    2364028
  • Title

    IPSec authentication using certificateless signature in heterogeneous IPv4/IPv6 network

  • Author

    Ahmad, Nazrul M. ; Yaacob, Asrul H. ; Fauzi, Ridza ; Khorram, Alireza

  • Author_Institution
    Fac. of Inf. Sci. & Technol. (FIST), Multimedia Univ. (MMU), Ayer Keroh, Malaysia
  • fYear
    2011
  • fDate
    20-23 March 2011
  • Firstpage
    668
  • Lastpage
    673
  • Abstract
    This paper studies the incompatibilities issues on deploying IPSec Encapsulating Security Payload (ESP) in providing end to end security between heterogeneous IPv4 and IPv6 networks. The presence of IPv4/IPv6 translation gateway violates the TCP/UDP intrinsic functionalities due to the translation of the IP addresses in IP packets. We address these interoperability issues by modifying IKE negotiation with NAT-Traversal capability and some improvements on IPSec software. However, the implementation of the conventional IKE authentication mechanisms such as pre-shared key and Public Key Infrastructure (PKI) certificate-based requires both nodes either to be manually configured, or to exchange the certificates and the necessity to enrol to certain Certificate Authority (CA). This paper proposes a new Internet Key Exchange (IKE) authentication based on certificateless public key infrastructure in order to alleviate the limitation of the conventional IKE authentication. We also propose an efficient public and shared parameters distribution mechanism whereby the translation gateway acts as Key Generator Centre (KGC).
  • Keywords
    IP networks; Internet; public key cryptography; transport protocols; IKE negotiation; IP address; IPSec authentication; IPSec encapsulating security payload; Internet key exchange authentication; NAT-traversal capability; TCP-UDP intrinsic functionalities; certificate authority; certificateless public key infrastructure; certificateless signature; heterogeneous IPv4 network; heterogeneous IPv6 network; interoperability issues; key generator centre; Authentication; IP networks; Logic gates; Payloads; Peer to peer computing; Public key;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers & Informatics (ISCI), 2011 IEEE Symposium on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-61284-689-7
  • Type

    conf

  • DOI
    10.1109/ISCI.2011.5958996
  • Filename
    5958996