Generation of IPsec
Keying Material
¨
Both peers generate new DH shared secret =
(X
b
`)
a
mod p
= (X
a
`)
b
mod p
¨
Both peers generate shared session keys for
incoming and outgoing IPsec SAs based on
SKEYID_d, new DH shared secret, SPI,
and N
i
` and N
r
`
¨