Sciweavers

ICDCSW
2003
IEEE

Convergence of IPsec in Presence of Resets

13 years 10 months ago
Convergence of IPsec in Presence of Resets
IPsec is the current security standard for the Internet Protocol IP. According to this standard, a selected computer pair (p, q) in the Internet can be designated a “security association”. This designation guarantees that all sent IP messages whose original source is computer p and whose ultimate destination is computer q cannot be replayed in the future (by an adversary between p and q) and still be received by computer q as fresh messages from p. This guarantee is provided by adding increasing sequence numbers to all IP messages sent from p to q. Thus, p needs to always remember the sequence number of the last sent message, and q needs to always remember the sequence number of the last received message. Unfortunately, when computer p or q is reset these sequence numbers can be forgotten, and this leads to two bad possibilities: unbounded number of fresh messages from p can be discarded by q, and unbounded number of replayed messages can be accepted by q. In this paper, we propose...
Chin-Tser Huang, Mohamed G. Gouda, E. N. Elnozahy
Added 04 Jul 2010
Updated 04 Jul 2010
Type Conference
Year 2003
Where ICDCSW
Authors Chin-Tser Huang, Mohamed G. Gouda, E. N. Elnozahy
Comments (0)