Skip to main content

IKEv2 Session Resumption
draft-tschofenig-ipsecme-ikev2-resumption-01

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Yaron Sheffer , Hannes Tschofenig , Lakshminath R. Dondeti , Vidya Narayanan
Last updated 2008-12-01 (Latest revision 2008-11-03)
Replaced by draft-ietf-ipsecme-ikev2-resumption
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-ietf-ipsecme-ikev2-resumption
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

The Internet Key Exchange version 2 (IKEv2) protocol has a certain computational and communication overhead with respect to the number of round-trips required and the cryptographic operations involved. In remote access situations, the Extensible Authentication Protocol (EAP) is used for authentication, which adds several more round trips and consequently latency. To re-establish security associations (SA) upon a failure recovery condition is time consuming, especially when an IPsec peer, such as a VPN gateway, needs to re-establish a large number of SAs with various end points. A high number of concurrent sessions might cause additional problems for an IPsec peer during SA re-establishment. In order to avoid the need to re-run the key exchange protocol from scratch it would be useful to provide an efficient way to resume an IKE/IPsec session. This document proposes an extension to IKEv2 that allows a client to re-establish an IKE SA with a gateway in a highly efficient manner, utilizing a previously established IKE SA. A client can reconnect to a gateway from which it was disconnected. The proposed approach uses a ticket to store state information that is later made available to the IKEv2 responder for re-authentication. Restoring state information by utilizing a ticket is one possible way. This document does not specify the format of the ticket but recommendations are provided.

Authors

Yaron Sheffer
Hannes Tschofenig
Lakshminath R. Dondeti
Vidya Narayanan

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)