Keychain Module Overview

Keychain is a utility module that can be used by any application or routing protocol that requires authentication keys to establish secure communication with peers and validate the control packets.

The keychain module provides a secure infrastructure to prevent unauthorized routing updates to the network and ensure that only trusted routers participate in routing updates. Apart from authentication, the keychain module provides a mechanism to ensure key rollover based on the duration specified for each key.

How the Keychain Module Works

The keychain module is independent of the protocols or applications that use it. The protocol packets use one of the active keys from the designated keychain profile. The keychain profile may have multiple keys with different attributes, such as authentication algorithms, passwords, and lifetimes.

Each key in the keychain has a lifetime associated with it. A key is considered active if it is within the configured time range and has an authentication algorithm and a password. When a key expires, the keychain module notifies the application.

Note: All participating routers must have Network Time Protocol (NTP) enabled before setting their lifetimes.

Keys cannot be used for authentication if they are not active. To allow for key rollover, the lifetime of the keys must be configured so that the key activation periods overlap and active keys are available at any time. As an option, a tolerance value can be configured for the accept-keys and send-keys in the keychain to extend the lifetime of the keys. The tolerance period smooths the transition to a new key.

An application uses a specified key and algorithm from the keychain module to generate a message digest for sent messages. It uses the message digest to validate packets when they are received.

When an application requests keys from the keychain module for sending and accepting the packets, the keychain module supplies all the active keys from the keychain, and the application picks the desired key based on criteria specific to the protocol or application. The sending peer picks the key based on its lifetime and a cryptographic algorithm that matches its criteria. The receiving peer selects the key it uses for authentication based on the incoming key ID. When a keychain is configured for a protocol, all the packets generated by the protocol, such as routing updates and hello packets, are validated with that key ID. Because the same key ID is used to validate packets received, it is imperative that the neighbors and participating routers have the same configuration at the other end.