25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

9.2.5 <strong>IP</strong>v6 security<br />

There are two optional headers defined for security purposes:<br />

► Authentication Header (AH)<br />

► Encapsulated Security Payload (ESP)<br />

AH <strong>and</strong> ESP in <strong>IP</strong>v6 support authentication, data integrity, <strong>and</strong> optionally<br />

confidentiality. AH conveys the authentication information in an <strong>IP</strong> package,<br />

while ESP carries the encrypted data of the <strong>IP</strong> package.<br />

Either or both can be implemented alone or combined in order to achieve<br />

different levels of user security requirements. Note that they can also be<br />

combined with other optional header to provision security features. For example,<br />

a routing header can be used to list the intermediate secure nodes for a packet to<br />

visit on the way, thus allowing the packet to travel only through secure routers.<br />

<strong>IP</strong>v6 requires support for <strong>IP</strong>Sec as a m<strong>and</strong>atory st<strong>and</strong>ard. This m<strong>and</strong>ate<br />

provides a st<strong>and</strong>ards-based solution for network security needs <strong>and</strong> promotes<br />

interoperability.<br />

Authentication header<br />

The authentication header is used to ensure that a received packet has not been<br />

altered in transit <strong>and</strong> that it really came from the claimed sender (Figure 9-11).<br />

The authentication header is identified by the value 51 in the preceding Next<br />

Header field. The format of the authentication header <strong>and</strong> further details are<br />

specified in REF 4302.<br />

Figure 9-11 <strong>IP</strong>V6 security authentication header<br />

Where:<br />

Security Parameters Index (SPI)<br />

Sequence Number (SN) Field<br />

Integrity Check Value-ICV<br />

Security Parameters Index (SPI)<br />

The SPI is an arbitrary 32-bit value that is used by a<br />

Chapter 9. <strong>IP</strong> version 6 347

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!