let Authentication Header(AH provides support for data integrity authentication of iP packets end system/router can authenticate user/app prevents address spoofing /replay attacks by tracking sequence numbers based on use of a mac HMAC-MD5-96 or HMAC-SHA-1-96 parties must share a secret key 復大辱软件学院
11 Authentication Header (AH) • provides support for data integrity & authentication of IP packets – end system/router can authenticate user/app – prevents address spoofing / replay attacks by tracking sequence numbers • based on use of a MAC – HMAC-MD5-96 or HMAC-SHA-1-96 • parties must share a secret key
o Authentication Header Bit: 0 8 31 Next Header Payload Length RESERVED Security Parameters Index(SPl) Sequence Number Authentication Data (variable) 12 復大辱软件学院
12 Authentication Header