[anonsec] I-D Action:draft-ietf-btns-connection-latching-06.txt

Nicolas Williams Nicolas.Williams at sun.com
Mon Apr 7 12:38:11 PDT 2008


On Mon, Apr 07, 2008 at 01:00:04PM -0500, Nicolas Williams wrote:
> On Fri, Mar 14, 2008 at 06:53:24AM +0100, Daniel Migault wrote:
> > < The considered model can be thus represented by the figure below:
> 
> I like your ASCII art, but I'm going to modify it somewhat.

How about this (GIF version attached):

   +--------------------------------------------+
   |                       +--------------+     |
   |                       |Administrator |     |
   |                       |apps          |     |
   |                       +--------------+     |
   |                              ^             |
   |                              |             | user mode
   |                              v             |
   | +--------------+      +---------------+    |
   | |App           |      |IKEv2          |    |
   | |              |      | +---+  +----+ |    |
   | |              |      | |PAD|  |SPD | |    |
   | |              |      | +---+  +--^-+ |    |
   | +--------------+      +-----------|---+    |
   |   ^                               |        |
   +---|-------------------------------|--------+  user/kernel mode
   +---|-------------------------------|--------+  interface
   |   v                               |        |
   |+-------+   +----------------------|-------+|
   ||ULP    |   | IPsec key manager    |       ||
   |+-------+   |               +------v------+||
   | ^  ^       |               | Logical SPD |||
   | |  |       |               +-----------^-+||
   | |  |       | +----------+    +-----+   |  ||  kernel mode
   | |  +-------->| Latch DB |<-->| SAD |   |  ||
   | |          | +----------+    +--^--+   |  ||
   | |          +--------------------|------|--+|
   +-|-------------------------------v------v---+
   | | IPsec Layer  (ESP/AH)                    |
   | |                                          |
   +-v------------------------------------------+
   |   IP Layer                                 |
   +--------------------------------------------+
-------------- next part --------------
A non-text attachment was scrubbed...
Name: conn-latching-arch.gif
Type: image/gif
Size: 7967 bytes
Desc: not available
Url : http://mailman.postel.org/pipermail/anonsec/attachments/20080407/dcab6f47/conn-latching-arch.gif


More information about the ANONSEC mailing list