
                  +------------------+    +-------------+ 
                  | HIP daemon (hipd)|    | Application |
                  +------------------+    +-------------+
                       |           |        | 
                       |           |        | 
                       |           |        |          Applications
               ======[PF_KEY]===[PF_RAW]==[PF_INET]================
                       |           |        |          OS Kernel
               +------------+   +-----------------+
               | Key Engine |   | TCP/IP,         |
               |  or  SADB  |---| including IPsec |
               +------------+   |                 |
                                +-----------------+

Initiator (assume no prior SA exists)
---------

1.  hipd register with kernel via PF_KEY socket (SADB_REGISTER) 
 - register to handle AH and ESP requests, although we will not distinguish

2.  Application opens UDP socket, and sends.
 - with HIP socket option, will trigger HIP/IPsec handling
 - without HIP socket option, will use normal path w/o IPsec

3.  kernel sends SADB_ACQUIRE to hipd, requesting it to get a SA for the
connection

4.  hipd gets SPI from kernel (SADB_GETSPI).  Need to do this twice
because we need both directions

5.  Create HIP I1 packet, begin HIP negotiation
 - start timer to protect I1
 - must be able to handle ICMP "protocol not supported" with right app. error

6.  Process HIP R1 packet, solve cookie, send I2 packet
 - kernel must send hipd all HIP packets
 - hipd must demultiplex R1 to find right association 
 - start timer to protect I2 

7.  Handle R2 packet
 - generate keying material

8.  hipd issues SADB_UPDATE for the SA

9.  hipd issues SADB_ADD for the reverse direction

10. kernel can now send UDP packet out 


Responder (assume no prior SA exists)
---------

1.  hipd register with kernel via PF_KEY socket (SADB_REGISTER) 
 - register to handle AH and ESP requests, although we will not distinguish

2.  kernel sends hipd received I1 packet.  

3.  kernel sends SADB_ACQUIRE to hipd, requesting it to get a SA for the
connection

4.  hipd gets SPI from kernel (SADB_GETSPI).  Need to do this twice
because we need both directions

5.  Process HIP I1 packet, create R1 packet, send thru PF_RAW socket
 - start timer to protect R1 

7.  Handle I2 packet, generate R2
 - generate keying material
 - start timer to protect R2

8.  hipd issues SADB_UPDATE for the SA

9.  hipd issues SADB_ADD for the reverse direction

10. kernel can now receive UDP packet (udp-listen process must be active!) 


