| (I) A relationship established between two or more entities to
enable them to protect data they exchange. The relationship is
used to negotiate characteristics of protection mechanisms, but
does not include the mechanisms themselves. (See: association.)
(C) A security association describes how entities will use
security services. The relationship is represented by a set of
information that is shared between the entities and is agreed upon
and considered a contract between them.
(O) IPsec usage: A simplex (uni-directional) logical connection
created for security purposes and implemented with either AH or
ESP (but not both). The security services offered by a security
association depend on the protocol selected, the IPsec mode
(transport or tunnel), the endpoints, and the election of optional
services within the protocol. A security association is identified
by a triple consisting of (a) a destination IP address, (b) a
protocol (AH or ESP) identifier, and (c) a Security Parameter
Index.
|