Internet Key Exchange Protocol Version 2 Session Resumption
RFC 5723, “Internet Key Exchange Protocol Version 2 Session Resumption”, is a Proposed Standard document published in January 2010 by Y. Sheffer, H. Tschofenig. The canonical text is published by the RFC Editor.
Abstract
The Internet Key Exchange version 2 (IKEv2) protocol has a certain computational and communication overhead with respect to the number of round trips required and the cryptographic operations involved. In remote access situations, the Extensible Authentication Protocol (EAP) is used for authentication, which adds several more round trips and consequently latency.
To re-establish security associations (SAs) upon a failure recovery condition is time consuming especially when an IPsec peer (such as a VPN gateway) needs to re-establish a large number of SAs with various endpoints. A high number of concurrent sessions might cause additional problems for an IPsec peer during SA re-establishment.
In order to avoid the need to re-run the key exchange protocol from scratch, it would be useful to provide an efficient way to resume an IKE/IPsec session. This document proposes an extension to IKEv2 that allows a client to re-establish an IKE SA with a gateway in a highly efficient manner, utilizing a previously established IKE SA.
A client can reconnect to a gateway from which it was disconnected. The proposed approach encodes partial IKE state into an opaque ticket, which can be stored on the client or in a centralized store, and is later made available to the IKEv2 responder for re-authentication. We use the term ticket to refer to the opaque data that is created by the IKEv2 responder. This document does not specify the format of the ticket but examples are provided. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5723 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5724 URI Scheme for Global System for Mobile Communications Short Message Service
- RFC 5721 POP3 Support for UTF-8
- RFC 5725 Post-Repair Loss RLE Report Block Type for RTP Control Protocol Extended Reports
- RFC 5720 Routing and Addressing in Networks with Global Enterprise Recursion
- RFC 5726 Mobile IPv6 Location Privacy Solutions
- RFC 5719 Updated IANA Considerations for Diameter Command Code Allocations
- RFC 5727 Change Process for the Session Initiation Protocol and the Real-time Applications and Infrastructure Area
- RFC 5718 An In-Band Data Communication Network For the MPLS Transport Profile