Past Paper
Group 1 Internet Key Exchange (IKE)
Question 1
(a) Shown below is the first message of the Main Mode of IKE Phase 1 using signature authentication:
write down the other five messages in this format.

(b) For the messages in (a) above, describe the contents of each of the IKE payloads in the messages sent by Responder, i.e. the second, fourth and sixth messages.
SA= is the Security Association payload, in message two it contains the responders choice of algorithm.
KE= is the key exchange payload, it contains the responders DH key exchange parameters.
This is more efficient as mutual authentication does not need to be performed in creating IPsec SAs, and the more permanent secretes are only used once.
In Phase 2, an IPsec SA can be created using 3 messages. All secrets used in the
IPsec SA and the IPsec SA itself are temporary. They can be created and terminated efficiently. Changing temporary secrets more often improves the security of the secure communications.
Written Tutorial
Question 1
The IKE protocol consists of two phases, i.e., IKE Phase 1 and IKE Phase 2.
a) Briefly describe the functions of the two phases, respectively;
Phase 1:
- Main purpose of phase 1 is to create a secure channel, by performing mutual authentication
- Negotiates crypto algorithms to be used
- DH values are exchanged which contribute to keying material, which in tern creates sessions keys
- Mutual authentication of end entities
Phase 2:
- Main purpose of phase 2 is to create 2 or more secure channels
- Negotiate crypto algorthms to be used
- Optionally, exchange dh values, which help to create keying material + session keys
- Optionally exchange traffic selectors.
b) Describe the advantages in separating the IKE protocol into two phases.
Advantages are mainly in security and efficiency.
Using Phase 1, mutual authentication is only performed once for the two end entities to create an IKE SA, which can then be used to create as many as IPsec SAs as required. This is more efficient as mutual authentication does not need to be performed in creating IPsec SAs, and the more permanent secretes are only used once.
In Phase 2, an IPsec SA can be created using 3 messages. All secrets used in the
IPsec SA and the IPsec SA itself are temporary. They can be created and terminated efficiently. Changing temporary secrets more often improves the security of the secure communications.
c) By comparing the messages used in IKE v1 Phases 1 and 2 with those used in IKE v2 Initial Exchange and CREATE_CHILD_SA Exchange, comment on their similarities and differences.
Question 2
From the corresponding RFC, list the six messages in IKE Main Mode with signature authentication. Describe the differences between this and IKE Main Mode with pre-shared key authentication. Describe briefly the contents and functions of the IKE payload types. Note that the level of description required for this question should be more or less the same as the lecture’s, not as that in the RFC.
From RFC2409, IKE Main Mode with signature authentication is

Question 3
In IKE Main Mode, all three methods of mutual authentications have been discussed, i.e.,
Describe exactly how mutual authentication is accomplished in each case.
1) Authentication with a pre-shared key in Lecture 4-14
From the lecture notes, the relevant messages in IKE Main Mode using preshared key for authentication:
Removing the irrelevant items as far as mutual authentication is concerned, we have:
