In this group key management model that extends the
ISAKMP standard, the protocol is run between a group member and a
"group controller/key server", which establishes security
associations [R4301] among authorized group members. The GDOI
protocol is itself protected by an ISAKMP phase 1 association.