I have tried to spot the security measures used in the draft and i fond that:
in section 6 you say that: The ODT authentication information consists of a secret or semi-secret key that each side announces to its correspondent.
How is this key obtained? is the key that it is sent in step 2 of the procedure described in section 8 (as a challenge) Or is it another key
Then you say that this key can be protected using IPsec, but in this case
how is the IPSec SA established between two generic nodes on the internet
(where no previous interaction can be assumed)