Methods and apparatus are provided to allow Internet Key Exchange (IKE)
phase 1 keying materials to be periodically refreshed in a secure manner
without requiring user interaction. A client and server perform
authentication and key exchange during set up of a secure connection. A
token is passed to the client by the server during or after the initial
user authentication phase. The token is stored both at the client and at
the server. Instead of requiring user credentials, the token can be used
to securely prove the identity of the client.