ESP Header Structure

ESP headers and trailers contain the following fields:

■ The SPI shows the SA used for this packet. The SPI identifies the SA on the receiver's side to properly authenticate and check the integrity of the packet, as well as decrypt the packet.

■ A Sequence Number (64-bit) prevents packet replay. A receiver will drop packets with replayed sequence numbers. Spoofed sequence numbers will not pass the integrity check (if used).

The Authentication Data is a keyed digest (HMAC) of the packet. The HMAC algorithm used by IPSec produces a 96-bit fingerprint (usually MD5 or SHA-1, AES-XCBC might be used in the future).

Initialization vector is an important parameter that should contain good random numbers, which prevent an attacker from building a dictionary. Encryption algorithms use the Initialization Vector (IV) to XOR it with the first block of cleartext. A truly random IV prevents two equal cleartext blocks from resulting in the same ciphertext. Furthermore, encryption algorithms use the result of the previous block to XOR it with subsequent blocks.

Payload data contains the encrypted payload. This encrypted payload is rounded to the encryption algorithm's (8 bytes for DES and 3DES, 16 bytes for AES) block size.

Pad length identifies the number of unused bytes in the decrypted message (padding created by encryption).

The next header contains the protocol number in the payload. The value from the original IP header is copied into the next header field and the new IP header contains number 50, identifying ESP as the payload.

New ESP (and optionally tunnel) headers and trailer are added to the packet:

■ In transport mode, the ESP header/trailer normally adds up to 37 bytes (if 3DES is used, 63 if AES is used) to each packet

■ In tunnel mode, the tunnel IP and ESP headers/trailer add up to 57 bytes (if 3DES is used, 83 if AES is used) to each packet

Overhead is variable because of the padding that rounds the encrypted payload to a multiple of 8 or 16 bytes. Using both AH and ESP in tunnel mode can add up to 81 bytes to each packet or even more if AES is used.

Continue reading here: IKE Lifetime

Was this article helpful?

+1 -1