@techreport{ebalard-mext-pfkey-enhanced-migrate-01, number = {draft-ebalard-mext-pfkey-enhanced-migrate-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ebalard-mext-pfkey-enhanced-migrate/01/}, author = {Arnaud Ebalard and Sebastien Decugis}, title = {{PF\_KEY Extension as an Interface between Mobile IPv6 and IPsec/IKE}}, pagetotal = 21, year = 2010, month = sep, day = 30, abstract = {This document describes the need for an interface between Mobile IPv6 and IPsec/IKE and shows how the two protocols can interwork. An extension of the PF\_KEY framework is proposed which allows smooth and solid operation of IPsec/IKE in a Mobile IPv6 environment. This document is heavily based on a previous draft {[}MIGRATE{]} written by Shinta Sugimoto, Masahide Nakamura and Francis Dupont. It simply reuses the MIGRATE mechanism defined in the expired document, removes a companion extension (SADB\_X\_EXT\_PACKET) based on implementation feedback (complexity, limitations, ...) and fills the gap by very simple changes to MIGRATE mechanism. This results in a more simple and consistent mechanism, which also proved to be easier to implement. This document is expected to serve as a continuation of {[}MIGRATE{]} work. For that reason, the name of the extension has been kept. PF\_KEY MIGRATE message serves as a carrier for updated information for both the in-kernel IPsec structures (Security Policy Database / Security Association Database) and those maintained by the key managers. This includes in-kernel Security Policy / Security Association endpoints, key manager maintained equivalents, and addresses used by IKE\_SA (current and to be negotiated). The extension is helpful for assuring smooth interworking between Mobile IPv6 and IPsec/IKE for the bootstrapping of mobile nodes and their movements.}, }