Thoughts on Bootstrapping Mobility Securely Chairs, with help from James Kempf, Jari Arkko MIP6 WG/BOF 57 th IETF Vienna Wed. July 16, 2003.

Slides:



Advertisements
Similar presentations
1 IETF KEYPROV WG Protocol Basis and Characteristics IEEE P April 11, 2007 Andrea Doherty.
Advertisements

Washinton D.C., November 2004 IETF 61 st – mip6 WG Goals for AAA-HA interface (draft-giaretta-mip6-aaa-ha-goals-00) Gerardo Giaretta Ivano Guardini Elena.
MIP Extensions: FMIP & HMIP
1Nokia Siemens Networks Presentation / Author / Date University of Twente On the Security of the Mobile IP Protocol Family Ulrike Meyer and Hannes Tschofenig.
Mobile IPv6 趨勢介紹 1. Mobile IP and its Variants Mobile IPv4 (MIPv4) – MIPv4 – Low-Latency Handover for MIPv4 (FMIPv4) – Regional Registration for MIPv4.
1 DSMIP6 Support QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota Notice.
AAA Mobile IPv6 Application Framework draft-yegin-mip6-aaa-fwk-00.txt Alper Yegin IETF 61 – 12 Nov 2004.
Overview of the Mobile IPv6 Bootstrapping Problem James Kempf DoCoMo Labs USA Thursday March 10, 2005.
Bootstrapping MIP6 Using DNS and IKEv2 (BMIP) James Kempf Samita Chakrarabarti Erik Nordmark draft-chakrabarti-mip6-bmip-01.txt Monday March 7, 2005.
AAA-Mobile IPv6 Frameworks Alper Yegin IETF Objective Identify various frameworks where AAA is used for the Mobile IPv6 service Agree on one (or.
ERP for IKEv2 draft-nir-ipsecme-erx-01. Why ERP for IKEv2? RFC 5296 and the bis document define a quick re- authentication protocol for EAP. ERP requires.
1 MIPv6 CN-Targeted Location Privacy and Optimized Routing draft-weniger-mobopts-mip6-cnlocpriv-01 IETF #68, Prague, March 2007.
1 Sideseadmed (IRT0040) loeng 5/2010 Avo
November st IETF MIP6 WG Mobile IPv6 Bootstrapping Architecture using DHCP draft-ohba-mip6-boot-arch-dhcp-00 Yoshihiro Ohba, Rafael Marin Lopez,
1 EAP Usage Issues Feb 05 Jari Arkko. 2 Typical EAP Usage PPP authentication Wireless LAN authentication –802.1x and i IKEv2 EAP authentication.
1 IPsec-based MIP6 Security Qualcomm Inc. Starent Inc. Notice: Contributors grant free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
3Com Confidential Proprietary 3G CDMA AAA Function Yingchun Xu 3COM.
1 Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained.
1 Motorola PMIPv4 Call Flows: Bearer Setup with Dual Anchoring Parviz YeganiVojislav VuceticAlmon Tang (408) (732) (847)
1 Julien Laganier MEXT WG, IETF-79, Nov Authorizing MIPv6 Binding Update with Cryptographically Generated Addresses
1 RADIUS Mobile IPv6 Support draft-ietf-mip6-radius-01.txt Kuntal Chowdhury Avi Lior Hannes Tschofenig.
1 IETF 78: NETEXT Working Group IPSec/IKEv2 Access Link Support in Proxy Mobile IPv6 IPSec/IKEv2-based Access Link Support in Proxy Mobile IPv6 Sri Gundavelli.
AAA and Mobile IPv6 Franck Le AAA WG - IETF55. Why Diameter support for Mobile IPv6? Mobile IPv6 is a routing protocol and does not deal with issues related.
Draft-ietf-dime-ikev2-psk-diameter-0draft-ietf-dime-ikev2-psk-diameter-08 draft-ietf-dime-ikev2-psk-diameter-09 in progress Diameter IKEv2 PSK: Pre-Shared.
1 NetLMM Vidya Narayanan Jonne Soininen
111 © 2001, Cisco Systems, Inc. All rights reserved. Presentation_ID Mobile IPv4 Dynamic Home Agent Assignment Framework (draft-kulkarni-mobileip-dynamic-assignment-01.txt)
Spring 2004 Mobile IP School of Electronics and Information Kyung Hee University Choong Seon HONG
+ Solution Overview (LR procedure) The whole sequence for localized routing Local routing capability detection Local routing Initiation LR scope or LR.
1 HRPD Roamer Authentication Zhibi Wang, Sarvar Patel, Simon Mizikovsky, Nancy Lee.
Implications of Trust Relationships for NSIS Signaling (draft-tschofenig-nsis-casp-midcom.txt) Authors: Hannes Tschofenig Henning Schulzrinne.
Mobile IPv6 with IKEv2 and revised IPsec architecture IETF 61
IETF 57 PANA WG PANA Discussion and Open Issues (draft-ietf-pana-pana-01.txt) Dan Forsberg, Yoshihiro Ohba, Basavaraj Patil, Hannes Tschofenig, Alper Yegin.
Draft-ietf-aaa-diameter-mip-15.txt Tom Hiller et al Presented by Pete McCann.
1 Alternative (Future) Proposals for MIPv6 Security MIP6 BOF/WG IETF-57 Jari Arkko, Ericsson Research NomadicLab Charlie Perkins, Nokia Research Center.
Washinton D.C., November 2004 IETF 61 st – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-02) Gerardo.
Network Mobility (NEMO) Advanced Internet 2004 Fall
1 Mobility for IPv6 [MIP6] November 12 th, 2004 IETF61.
San Diego, August 2004 IETF 60 th – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-01) Gerardo Giaretta.
Minneapolis, March 2005 IETF 62 nd – mip6 WG Goals for AAA-HA interface (draft-giaretta-mip6-aaa-ha-goals-00) Gerardo Giaretta Ivano Guardini Elena Demaria.
Diameter Mobile IPv6: HA-to-AAAH support draft-ietf-dime-mip6-split-01.txt Julien Bournelle (Ed.) Gerardo Giaretta Hannes Tschofenig Madjid Nakhjiri.
Paris, August 2005 IETF 63 rd – mip6 WG Mobile IPv6 bootstrapping in split scenario (draft-ietf-mip6-bootstrapping-split-00) mip6-boot-sol DT Gerardo Giaretta,
MIP6 RADIUS IETF-72 Update draft-ietf-mip6-radius-05.txt A. LiorBridgewater Systems K. ChowdhuryStarent Networks H. Tschofenig Nokia Siemens Networks.
1 IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: EAP Pre-authentication Problem Statement in IETF HOKEY WG Date Submitted: September,
V4 traversal for IPv6 mobility protocols - Scenarios Mip6trans Design Team MIP6 and NEMO WGs, IETF 63.
IEEE MEDIA INDEPENDENT HANDOVER DCN:
Pre-authentication Problem Statement (draft-ohba-hokeyp-preauth-ps-00
Mobility for IPv6 (mip6) IETF64 November 10, 05
<draft-ohba-pana-framework-00.txt>
Booting up on the Home Link
Mobile Networking (I) CS 395T - Mobile Computing and Wireless Networks
Networking Applications
PANA Discussion and Open Issues (draft-ietf-pana-pana-01.txt)
Katrin Hoeper Channel Bindings Katrin Hoeper
Carrying Location Objects in RADIUS
for IP Mobility Protocols
IEEE MEDIA INDEPENDENT HANDOVER DCN: xxxx
2002 IPv6 技術巡迴研討會 IPv6 Mobility
Goals Introduce the Windows Server 2003 family of operating systems
IEEE MEDIA INDEPENDENT HANDOVER DCN:
Link Setup Flow July 2011 Date: Authors: Name Company
Mobile IP Presented by Team : Pegasus Kishore Reddy Yerramreddy Jagannatha Pochimireddy Sampath k Bavipati Spandana Nalluri Vandana Goyal.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: March 18, 2010 Presented at IEEE session.
IEEE MEDIA INDEPENDENT HANDOVER DCN: sec
IEEE MEDIA INDEPENDENT HANDOVER
Security Activities in IETF in support of Mobile IP
Mobile IP Outline Homework #4 Solutions Intro to mobile IP Operation
IEEE MEDIA INDEPENDENT HANDOVER
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: May 13, 2010 Presented at IEEE session.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Qin Wu Zhen Cao Yang Shi Baohong He
Presentation transcript:

Thoughts on Bootstrapping Mobility Securely Chairs, with help from James Kempf, Jari Arkko MIP6 WG/BOF 57 th IETF Vienna Wed. July 16, 2003

What are we Bootstrapping? Not just a HA nor just a MN It takes two to tango Bootstrapping a security association between two devices, such that one is enabled as an MN and the other as its HA Bootstrapping a Mobility Security Association (MSA)

Why Bootstrapping Mobility Securely? Reduces RTT on HA/MN tunnels (optimal HA for distant locations) Hides MN topological location (though this precludes route optimization). Reduced configuration required (on either the MN or the HA) MN resilience to network renumbering Enables network to assign MN's to HA administratively Allows for HA load balancing by assigning MN according to load Authorizes a device to become an MN (security-wise)

Possible scenarios (1/2) No previous credential: Not a MIP6 issue? –Leap-of-faith: Too risky (the whole RO was predicated on some genuine trust or accountability between MN&HA) –Enrollment out-of-band model (separate path for confirmation via , human exchange) Transitive Trusted Introduction (visa/mcard, merchant, consumer) – reusable models?

Possible scenarios (2/2) Rolling over a Non-Mobile Security Association (e.g., Enterprise PKI, AAA infrastructure etc.) –Probably work on this Rolling over an existing MSA: –Existing HA with a new MN (RFC3041 private address scenario) –Existing MN to acquire a new HA (Dynamic HA scenario) –Yes, work on this

Existing MSA Certificate Possible meanings of bootstrap: –Complete the MN's Cert with info on HA –Change its HA info from HA_orig to HA_new (temp, permanent) –Complete the HA's Cert with info on MN –Change its MN info from MN_orig to MN_new (temp, permanent)

MIPv6 Dynamic MSA Outline Mobile Node comes up in a foreign domain, renumbering, creates an RFC3041, etc Performs authentication and is authorized to enter network as a roamer. –Authentication via EAPoL2 –PANA –EAP over IKEv2 Results in authentication and configuration info perhaps via a credential provisioning process

Further thoughts on Dynamic MSA’s Secure location of dynamic HA? –Protocol in Section of base draft is not secure. –IKE required w. anycast address – is this possible? –Issues w. IPsec on ICMP messages. –Encourage trend toward standardized, securable configuration/service discovery mechanisms. Establish an SA for draft-ietf-mobileip-mipv6-ha-ipsec-06.txt but… Is the MN authorized for HA service? –Binding between IKE and AAA. Not standardized in IKEv1. –Use IKEv2 EAP over IKE (Section 2.16). IDi instead of IKE AUTH in Message 2 from MN to HA. HA responds with EAP to initiate the EAP exchange. Shared key may be established as part of exchange (e.g. preshared secret). How to securely assign MN a HoA? –IKEv2 CFG_REQUEST (Section 2.19)? –DHCP in IKE (draft-ietf-ipsec-dhcp-over-ike-00.txt)?

Credential Provisioning What to create: Mobile IP variant of draft-ietf-ipsec-pki profile: "Certificate Extensions and Attributes for Mobile IP" ?? How to create them? Variant of: –draft-ietf-ipsra-pic* (over IKE) (which is a variant of draft-bellovin-ipsra-getcert-* ) –EAP to an auth server, which provisions credentials to the MN which can be used later MN and private addresses: –concept of a session –during the session, an MN-issued rfc3281 Attrib Cert(ideally a real authorization cert via SPKI) enables the rfc3041 address –communication outside of scope?