| IKE(Internet Key Exchange) protocol is an important part of the IPSec(IP Security) protocol suite. IKE serves as negotiator and manager of IPSec SA(Security Association). The paper introduces IKE protocol,including the protocol framework,the process of negotiation and the format of IKE messages. The paper presents a new architecture and feasible implementation of IKE,also describes the design approach and function partition of such implementation and discusses the main data structures and flow charts. Then the paper analyzes the protocol security. The discussion of the limitation and development of the protocol finishes this paper. |