Security association

From Wikipedia, the free encyclopedia

A security association (SA) is the establishment of shared security information between two network entities to support secure communication. An SA may include cryptographic keys, initialization vectors or digital certificates.

An SA is a simplex (one-way channel) and logical connection which endorses and provides a secure data connection between the network devices. The fundamental requirement of an SA arrives when the two entities communicate over more than one channel. Take an example of mobile subscriber and a base station. The subscriber may subscribe itself for more than one service. Therefore each service may have different service primitives like a data encryption algorithm, public key or initialization vector. Now to make things easier, all this security information is grouped logically. This logical group itself is a Security Association. Each SA has its own ID called SAID. So now the base station and mobile subscriber will share the SAID and they will derive all the security parameters, making things a lot easier.

In a nutshell, an SA is a logical group of security parameters, that ease the sharing of information to another entity.

Contents

[edit] SA Types

Two basic types of SAs are as follows:

[edit] Transport mode

See main article: Transport mode

[edit] Tunnel mode

See main article: Tunnel mode

[edit] See also

[edit] References

  • Internet Key Exchange Protocol - RFC 2409
  • Internet Key Exchange (IKEv2) Protocol - RFC 4306
Languages