34 IP Security

IP security refers to security mechanisms implemented at the IP (Internet Protocol) Layer to ensure integrity, authentication and confidentiality of data during transmission in the open Internet environment. The primary objective of recent work in this area, mainly by members in the IETF IP Security (IPsec) working group is to improve the robustness of the cryptographic key-based security mechanisms at IP layer for users who request security.

“Security in the Internet Architecture” (RFC 1636) report issued in 1994 by the Internet Architecture Board (IAB). This report identifies key areas for security mechanisms.

To provide security, IAB included authentication and encryption as necessary security features in the next generation IP (IPv6). The IPsec specification now exists as a set of Internet standards.

1.2 Applications of IPsec

IPsec provides the capability to secure communications across a LAN, private and public WANs, and the Internet. Examples of it are including:

Principal feature of IPsec is that it can encrypt and/or authenticate all traffic at the IP level. Thus all distributed applications (remote logon, client/server, e-mail, file transfer, Web access) can be secured.

1.3 Benefits of IPSec

When IPsec is implemented in a firewall or router, it provides strong security that can be applied to all traffic crossing the perimeter. Traffic within a company or workgroup does not incur the overhead of security-related processing.

IPsec in a firewall is resistant to bypass if all traffic from the outside must use IP and the firewall is the only means of entrance from the Internet into the organization.

IPsec is below the transport layer (TCP, UDP) and so is transparent to applications. There is no need to change software on a user or server system when IPsec is implemented in the firewall or router.

IPsec can be transparent to end users. There is no need to train users on security mechanisms, issue keying material on a per-user basis, or revoke keying material when users leave the organization.

IPsec can provide security for individual users if needed. This is useful for offsite workers and for setting up a secure virtual subnetwork within an organization for sensitive applications.

1.4 Routing Applications

IPsec can play a vital role in the routing architecture required for internetworking. IPsec can assure that