Name: draft-jangir-replay-attack-protection-00
Title: IPSec Replay Attack Protection in Multisender Environment
State: Active
Authors: Mohanlal Jangir
Group: Individual Submissions (none)
Date: 2004-06-30
The IPsec Architecture [RFC 2401] and IPsec transform RFCs [RFC 2402,
RFC 2406] define certain mechanisms for protecting IP traffic. One of the
mechanisms defined is replay attack protection. But this mechanism is not
addressed in multisender environment where multiple senders are sending
packets for same destination SA (This includes sharing of SA as well as
multicast). This document reviews the issues in multisender environment and
addresses solution for this by identifying the sending SA and having replay
attack protection against each sending SA. The documents also summarizes
the changes needed in AH, ESP, Key management protocols, which would enable
IPSec to protect against replay attack protection in multisender
environment for same destination SA.
|
|
|