Tunneled Group Secure Association Key Management Protocol
draft-ietf-msec-tgsakmp-00
Document | Type |
Expired Internet-Draft
(msec WG)
Expired & archived
|
|
---|---|---|---|
Author | Hugh Harney | ||
Last updated | 2003-05-20 | ||
RFC stream | Internet Engineering Task Force (IETF) | ||
Intended RFC status | (None) | ||
Formats | |||
Additional resources | Mailing list discussion | ||
Stream | WG state | WG Document | |
Document shepherd | (None) | ||
IESG | IESG state | Expired | |
Consensus boilerplate | Unknown | ||
Telechat date | (None) | ||
Responsible AD | (None) | ||
Send notices to | (None) |
This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:
Abstract
The Tunneled Group Secure Association Key Management Protocol (T-GSAKMP) provides a security framework for creating cryptographic groups on a network. It is designed to provide key distribution services under the cryptographic protection of a pairwise SA, like IPSec. T-GSAKMP relies on the pairwise SA to provide data confidentiality services for policy, DoS mitigation services, and protection from 'man-in-the-middle' attacks. It provides mechanisms to disseminate group security policy, perform access control based upon PKI certificates, generate group keys, and recover from compromise. This framework addresses group scalability issues by facilitating delegation of process-intensive actions in a secure and controlled manner.
Authors
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)