IKEv2 can not achieve active identity protection to initiator in initial exchange
and it has the security flaw of authentication failure.So an improvement protocol is presented.In the new protocol
the SIGn-andMAc approach is adopted to realize explicit key authentication and the responder is first authenticated to actively protect the initiator’s identity.By including the peer’s identity in the sending messages
the new protocol solves the problem of authentication failure.Moreover
the non-repudiation of the peers for their interactions is also achieved.The analysis results show that our protocol is session key secure and has a good performance.