March 12, 2002
Practical Aspects of Modern Cryptography
15
Security Associations (SA)
nNew concept for IP communication
nSA not a “connection”, but very similar
nEstablishes trust between computers
nIf securing with IPSEC, need SA
nISAKMP protocol negotiates security parameters according to policy
nManages cryptographic keys and lifetime
nEnforces trust by mutual authentication