Mobile IP Security Konidala M. Divyan International Research Center for Information Security Network Security (ICE 615) Term Project – 2002 Autumn.

Slides:



Advertisements
Similar presentations
Mobile IP How Mobile IP Works? Agenda What problems does Mobile IP solve? Mobile IP: protocol overview Scope Requirements Design goals.
Advertisements

Security Issues In Mobile IP
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
INTRODUCTION WIRELESS TECHNOLOGY BECOMING HOTTER WIRELESS TECHNOLOGY BECOMING HOTTER TRANSITION TOWARDS MOBILITY OVER PAST 20 YEARS TRANSITION TOWARDS.
Why do current IP semantics cause scaling issues? −Today, “addressing follows topology,” which limits route aggregation compactness −Overloaded IP address.
MIP Extensions: FMIP & HMIP
1Nokia Siemens Networks Presentation / Author / Date University of Twente On the Security of the Mobile IP Protocol Family Ulrike Meyer and Hannes Tschofenig.
1 Mobile IP Myungchul Kim Tel:
IPv4 and IPv6 Mobility Support Using MPLS and MP-BGP draft-berzin-malis-mpls-mobility-00 Oleg Berzin, Andy Malis {oleg.berzin,
NISNet Winter School Finse Internet & Web Security Case Study 2: Mobile IPv6 security Dieter Gollmann Hamburg University of Technology
Mobile IP Overview: Standard IP Standard IP Evolution of Mobile IP Evolution of Mobile IP How it works How it works Problems Assoc. with it Problems Assoc.
MOBILITY SUPPORT IN IPv6
A Study of Mobile IP Kunal Ganguly Wichita State University CS843 – Distributed Computing.
IPv6 Mobility David Bush. Correspondent Node Operation DEF: Correspondent node is any node that is trying to communicate with a mobile node. This node.
Mobile IP.
Slide 1, Dr. Wolfgang Böhm, Mobile Internet, © Siemens AG 2001 Dr. Wolfgang Böhm Siemens AG, Mobile Internet Dr. Wolfgang.
Mobile IP: Introduction Reference: “Mobile networking through Mobile IP”; Perkins, C.E.; IEEE Internet Computing, Volume: 2 Issue: 1, Jan.- Feb. 1998;
1 Chapter06 Mobile IP. 2 Outline What is the problem at the routing layer when Internet hosts move?! Can the problem be solved? What is the standard solution?
National Institute Of Science & Technology Mobile IP Jiten Mishra (EC ) [1] MOBILE IP Under the guidance of Mr. N. Srinivasu By Jiten Mishra EC
1 Mohamed M Khalil Mobile IPv4 & Mobile IPv6. 2 Mohamed M Khalil Mobile IP- Why ? IP based Network Sub-network A Sub-network B Mobile workforce carry.
NEtwork MObility (NEMO) Houcheng Lee. Main Idea NEMO works by moving the mobility functionality from Mobile IP mobile nodes to a mobile router. The router.
49th IETF - San Diego - 1 Mobile Networks Support in IPv6 - Draft Update draft-ernst-mobileip-v6-01.txt - Thierry Ernst - MOTOROLA Labs Ludovic Bellier.
AAA and Mobile IPv6 Franck Le AAA WG - IETF55. Why Diameter support for Mobile IPv6? Mobile IPv6 is a routing protocol and does not deal with issues related.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Thierry Ernst - MOTOROLA Labs / INRIA Ludovic Bellier - INRIA project PLANETE Claude Castelluccia - INRIA project PLANETE Hong-Yon Lach - MOTOROLA Labs.
Introduction to Mobile IPv6
Santhosh Rajathayalan ( ) Senthil Kumar Sevugan ( )
Mobile IP 순천향대학교 정보기술공학부 이 상 정 VoIP 특론 순천향대학교 정보기술공학부 이 상 정 2 References  Tutorial: Mobile IP
Mobile IPv6 and Firewalls: Problem Statement Speaker: Jong-Ru Lin
Ασύρματες και Κινητές Επικοινωνίες Ενότητα # 10: Mobile Network Layer: Mobile IP Διδάσκων: Βασίλειος Σύρης Τμήμα: Πληροφορικής.
Mobile IPv6 with IKEv2 and revised IPsec architecture IETF 61
Mobile IP Definition: Mobile IP is a standard communication protocol, defined to allow mobile device users to move from one IP network to another while.
An Introduction to Mobile IPv4
Network Mobility (NEMO) Advanced Internet 2004 Fall
2003/3/1856th IETF NEMO WG1 Basic Network Mobility Support draft-wakikawa-nemo-basic-00.txt Ryuji Wakikawa Keisuke Uehara
Mobile IP 순천향대학교 전산학과 문종식
Service Flows Distribution and Handoff Technique based on MIPv6 draft-liu-dmm-flows-distribution-and-handoff-00
Lecture 14 Mobile IP. Mobile IP (or MIP) is an Internet Engineering Task Force (IETF) standard communications protocol that is designed to allow mobile.
Mobile IP THE 12 TH MEETING. Mobile IP  Incorporation of mobile users in the network.  Cellular system (e.g., GSM) started with mobility in mind. 
ROUTING MOBILE IP  Motivation  Data transfer  Encapsulation.
MOBILE IP & IP MICRO-MOBILITY SUPPORT Presented by Maheshwarnath Behary Assisted by Vishwanee Raghoonundun Koti Choudary MSc Computer Networks Middlesex.
 Mobile IP is the underlying technology for support of various mobile data and wireless networking applications.  It is designed by IETF.
1 OverviewOverview A device on a network is reachable through normal IP routing by the IP address it is assigned on the network. The problem occurs when.
Mobile IP Lecture 5.
DMET 602: Networks and Media Lab
Introduction Wireless devices offering IP connectivity
RFC 3775 IPv6 Mobility Support
Lecture 30 QoS in WLAN / Mobile IP Dr. Ghalib A. Shah
Security Issues With Mobile IP
Booting up on the Home Link
Mobile Networking (I) CS 395T - Mobile Computing and Wireless Networks
Route Optimization of Mobile IP over IPv4
Mobile IP.
IP for Mobile hosts.
Support for Flow bindings in MIPv6 and NEMO
Introduction to Wireless Networking
IETF67 B. Patil, Gopal D., S. Gundavelli, K. Chowdhury
2002 IPv6 技術巡迴研討會 IPv6 Mobility
Net 431: ADVANCED COMPUTER NETWORKS
Network Virtualization
Unit 3 Mobile IP Network Layer
DMET 602: Networks and Media Lab
CSE 4215/5431: Mobile Communications Winter 2010
CSE 4215/5431: Mobile Communications Winter 2011
Mobile IP Presented by Team : Pegasus Kishore Reddy Yerramreddy Jagannatha Pochimireddy Sampath k Bavipati Spandana Nalluri Vandana Goyal.
Mobile IP Outline Homework #4 Solutions Intro to mobile IP Operation
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Lecture 4a Mobile IP 1.
Mobile IP Neil Tang 11/12/2008 CS440 Computer Networks.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Presentation transcript:

Mobile IP Security Konidala M. Divyan International Research Center for Information Security Network Security (ICE 615) Term Project – 2002 Autumn

8 th October 2002Mobile IP Security Konidala M. Divyan 2 Mobile Devices

8 th October 2002Mobile IP Security Konidala M. Divyan 3 Demand for Mobility

8 th October 2002Mobile IP Security Konidala M. Divyan 4 Mobile IP solves the following problems: If node moves from one link to another without changing its IP address, it will be unable to receive packets at the new link If a node changes its IP address when it moves, it will have to terminate and restart any ongoing communications each time it moves Mobil IP solves these problems in secure, robust, and medium-independent manner whose scaling properties make it applicable throughout the entire Internet

8 th October 2002Mobile IP Security Konidala M. Divyan 5 Example Internet Home Agent R R R Home network A Network B Network C Corresp. Node C R Router

8 th October 2002Mobile IP Security Konidala M. Divyan 6 Triangle Routing (Mobile IPv4) Internet  Corresp. Node C initiates communication with Mobile Node and sends packets to MN‘s home address  Home Agent intercepts packets and forward them to the Mobile Node (proxy functionality)  Mobile Node replies directly to Corresp. Node C Home Agent R Mobile Node    R R Network B Network C Network A Corresp. Node C

8 th October 2002Mobile IP Security Konidala M. Divyan 7 Internet  Mobile Node sends Binding Update  Home Agent replies with Binding Acknowledgement Home Agent Mobile Node R   R R Network B Network C Network A Corresp. Node C Mobile Node registers at its Home Agent

8 th October 2002Mobile IP Security Konidala M. Divyan 8 Internet  Mobile Node sends Binding Updates to Home Agent and all Corresp. Nodes, which already received a previous Binding Update from this Mobile Node Home Agent R R  R R Network B Network C Network A Network D Corresp. Node C Mobile IPv6 Roaming

8 th October 2002Mobile IP Security Konidala M. Divyan 9 Binding Updates Mobile IPv6 creates a new class of messages called binding updates that confirm the identity of a device as it moves to a new location Binding updates are a shortcut designed to speed wireless communications that use IPv6 Once the binding update is authenticated, communications go straight to the new location without passing through the home address

8 th October 2002Mobile IP Security Konidala M. Divyan 10 Security Requirements for Binding Updates Authentication is a must. Minimize number of messages and bytes exchanged. Not too computationally intensive for mobile nodes. Resist denial-of-service attacks. No weaker than Mobile IPv4.

8 th October 2002Mobile IP Security Konidala M. Divyan 11 Reasons for choosing this topic (1/2) Mobile IP working group planned to use the existing protocol IP Security (IPSec) to secure binding update messages But the IETF's security experts recently announced that IPSec will not work for these messages for two reasons –IPSec depends on a public-key infrastructure that has not yet been deployed. –The key management component of IPSec requires heavy processing by end devices.

8 th October 2002Mobile IP Security Konidala M. Divyan 12 Reasons for choosing this topic (2/2) Using IPsec to Protect Mobile IPv6 Signaling between Mobile Nodes and Home Agents –draft-ietf-mobileip-mipv6-ha-ipsec-00.txt –20 September 2002 Mobility Support in IPv6 –draft-ietf-mobileip-ipv6-18.txt –1 June 2002 A great deal of attention is being focused on making Mobile IP coexist with the security features coming into use within the Internet

8 th October 2002Mobile IP Security Konidala M. Divyan 13 Goal of this project Study Mobile IP Study security issues with respect to –Mobile IPv4 –Mobile IPv6 Study current drafts relating to Mobile IP Security Propose new ideas to improve the Mobile IP Security

8 th October 2002Mobile IP Security Konidala M. Divyan 14 Security issues The sender of the BU is easily authenticated Protection of Binding Updates both to home agents and correspondent nodes, and the protection of tunnels, home address information, and routing instructions in data packets Signaling between the mobile node and the home agent requires message integrity, correct ordering and replay protection

8 th October 2002Mobile IP Security Konidala M. Divyan 15 One of the open issue Authorization for the MR to manage mobility of the entire network But same problem with respect to MNs: –a MN needs to be authorized to send a BU for a home address –a MR needs to be authorized to send a BU for a network prefix –this is presently discussed at the IETF