At the outset the gateway authenticates itself to the client by sending an IKEv2 RSA signature accompanied by a certificate. The roadwarrior carol sets up a connection to gateway moon. carol uses the Extensible Authentication Protocol in association with the Authentication and Key Agreement protocol (EAP-AKA) to authenticate against the gateway. In this scenario, quintuplets from the SQL database /etc/ipsec.d/ipsec.db are used instead of a physical USIM card on the client carol. The USIM provider on gateway moon also stores the quintuplets in an SQL database.