Improvement of Return Routability Protocol draft-qiu-mip6-RR-improvement-00.txt Institute for Infocomm Research Singapore
Outline Three attacks to RR. Our Improvement to RR.
MN 2 CN / Server MN 1 Intruder MN 3 Intruder Collect HoTs and CoTs at the server edge Randomly form Kbu Send BU to CN Random redirection Traffic Permutation Attacks
Session Hijacking Attacks MN 1 CN MN 2 Intruder HA HoT MN1 FWD HoT MN1 CoTI MN2 / CoT MN2 Intruder Get HoT MN1 MN2 send its own CoTI MN2 and get CoT MN2 MN2 forges as MN1
Movement Halting Attacks CoT old HoT new CN / Server CoA Intruder CoA’ Intruder Get old CoT Get new HoT’ Form valid Kbu Redirect to old CoA HoT’ CoT
The Improvement HoA and CoA are bound together HoTI = {HoA, CNA, CoA, HomeInitCookie } CoTI = {CoA, CNA, HoA, CareInitCookie } HomeKeygenToken = HMAC_SHA1(Kcn, (HoA|Nj|CoA|0)) CareKeygenToken = HMAC_SHA1(Kcn, (CoA|Ni|HoA|1)) Advantages: Prevent the 3 attacks No additional cost No change of RR protocol architecture
Thank You!