Registration Revocation in Mobile IP draft-glass-mobileip-reg-revok-00.txt (soon to be -01!) Steven M. Glass - Sun Microsystems

Slides:



Advertisements
Similar presentations
Security Issues In Mobile IP
Advertisements

Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
1 Introduction to Mobile IPv6 IIS5711: Mobile Computing Mobile Computing and Broadband Networking Laboratory CIS, NCTU.
MIP Extensions: FMIP & HMIP
1Nokia Siemens Networks Presentation / Author / Date University of Twente On the Security of the Mobile IP Protocol Family Ulrike Meyer and Hannes Tschofenig.
Mobile IPv6 趨勢介紹 1. Mobile IP and its Variants Mobile IPv4 (MIPv4) – MIPv4 – Low-Latency Handover for MIPv4 (FMIPv4) – Regional Registration for MIPv4.
資 管 Lee Lesson 12 IPv6 Mobility. 資 管 Lee Lesson Objectives Components of IPv6 mobility IPv6 mobility messages and options IPv6 mobility data structures.
IPv4 and IPv6 Mobility Support Using MPLS and MP-BGP draft-berzin-malis-mpls-mobility-00 Oleg Berzin, Andy Malis {oleg.berzin,
1 © NOKIA NSIS MIPv6 FW/ November 8 th 2004 Mobile IPv6 - NSIS Interaction for Firewall traversal draft-thiruvengadam-nsis-mip6-fw-01 S. Thiruvengadam.
Mobile IP Overview: Standard IP Standard IP Evolution of Mobile IP Evolution of Mobile IP How it works How it works Problems Assoc. with it Problems Assoc.
MOBILITY SUPPORT IN IPv6
Chapter 13 Mobile IP. Outline  ADDRESSING  AGENTS  THREE PHASES  AGENT DISCOVERY  REGISTRATION  DATA TRANSFER  INEFFICIENCY IN MOBILE IP.
CMPE Wireless and Mobile Networking 1 CMPE 257 Spring 2006 Wireless Internetworking Wireless and Mobile Networks.
TCP/IP Protocol Suite 1 Upon completion you will be able to: Mobile IP Understand the addressing scheme for mobile hosts. To define home, care-of, and.
IPv6 Mobility David Bush. Correspondent Node Operation DEF: Correspondent node is any node that is trying to communicate with a mobile node. This node.
Mobile IP Regional Registration Ashutosh Sharma CS401A Spring 2002.
Mobile IP.
Slide 1, Dr. Wolfgang Böhm, Mobile Internet, © Siemens AG 2001 Dr. Wolfgang Böhm Siemens AG, Mobile Internet Dr. Wolfgang.
1 Chapter06 Mobile IP. 2 Outline What is the problem at the routing layer when Internet hosts move?! Can the problem be solved? What is the standard solution?
1 Utilizing Multiple Home Links on Mobile IPv6 Waseda University Hongbo Shi Shigeki Goto
Lectured By: Vivek Dimri Asst Professor CSE Deptt. Sharda University, Gr. Noida.
Mobile IP Overview and Discussion. 2 Spectrum of Mobility – from network perspective no mobility high mobility mobile user, using same access point mobile.
National Institute Of Science & Technology Mobile IP Jiten Mishra (EC ) [1] MOBILE IP Under the guidance of Mr. N. Srinivasu By Jiten Mishra EC
Mobile IP Most of the slides borrowed from Prof. Sridhar Iyer
Mobile IP Chapter 19. Introduction Mobile IP is designed to allow portable computers to move from one network to another Associated with wireless technologies.
1 Sideseadmed (IRT0040) loeng 5/2010 Avo
1 Motorola PMIPv4 Call Flows: Bearer Setup with Dual Anchoring Parviz YeganiVojislav VuceticAlmon Tang (408) (732) (847)
A Mobility Management Protocol for IP-Based Cellular Networks P.D. Silva and H. Sirisena, University of Canterbury IEEE Wireless Communications, June 2002.
AAA Registration Keys Charles E. Perkins/Nokia Research Pat R. Calhoun/Sun Microsystems.
AAA and Mobile IPv6 Franck Le AAA WG - IETF55. Why Diameter support for Mobile IPv6? Mobile IPv6 is a routing protocol and does not deal with issues related.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
1 NetLMM Vidya Narayanan Jonne Soininen
Performance Validation of Mobile IP Wireless Networks Presented by Syed Shahzad Ali Advisor Dr. Ravi Pendse.
An end-to-end usage of the IPv6 flow label
111 © 2001, Cisco Systems, Inc. All rights reserved. Presentation_ID Mobile IPv4 Dynamic Home Agent Assignment Framework (draft-kulkarni-mobileip-dynamic-assignment-01.txt)
Spring 2004 Mobile IP School of Electronics and Information Kyung Hee University Choong Seon HONG
Santhosh Rajathayalan ( ) Senthil Kumar Sevugan ( )
Mobile IP 순천향대학교 정보기술공학부 이 상 정 VoIP 특론 순천향대학교 정보기술공학부 이 상 정 2 References  Tutorial: Mobile IP
Ασύρματες και Κινητές Επικοινωνίες Ενότητα # 10: Mobile Network Layer: Mobile IP Διδάσκων: Βασίλειος Σύρης Τμήμα: Πληροφορικής.
Binding Revocation for IPv6 Mobility draft-muhanna-mip6-binding-revocation-01.txt MIP6 WG, IETF 69 Ahmad Muhanna Mohamed Khalil
Mobile IPv4 – Diameter Draft Status Tom Hiller Lucent Technologies.
Mobile IP Definition: Mobile IP is a standard communication protocol, defined to allow mobile device users to move from one IP network to another while.
MIPv6Security: Dimension Of Danger Unauthorized creation (or deletion) of the Binding Cache Entry (BCE).
An Introduction to Mobile IPv4
Click to edit Master title style Click to add subtitle © 2008 Wichorus Inc. All rights reserved. CONFIDENTIAL - DO NOT DISTRIBUTE rfc3775bis Issues March.
DMET 602: Networks and Media Lab Amr El Mougy Yasmeen EssamAlaa Tarek.
MOBILE IP. What is mobile IP Mobile IP is an Internet Engineering Task Force standard communications protocol that is designed to allow mobile device.
Mobility support in IP v4. Internet Computing (CS-413) 2.
Mobile IP Aamir Sohail NGN MS(TN) IQRA UNIVERSITY ISLAMABAD.
Mobile IP THE 12 TH MEETING. Mobile IP  Incorporation of mobile users in the network.  Cellular system (e.g., GSM) started with mobility in mind. 
ROUTING MOBILE IP  Motivation  Data transfer  Encapsulation.
DMET 602: Networks and Media Lab
Booting up on the Home Link
Mobile Networking (I) CS 395T - Mobile Computing and Wireless Networks
Mobile IP.
Support for Flow bindings in MIPv6 and NEMO
EA C451 Vishal Gupta.
for IP Mobility Protocols
Introduction to Wireless Networking
Mobility And IP Addressing
2002 IPv6 技術巡迴研討會 IPv6 Mobility
Unit 3 Mobile IP Network Layer
DMET 602: Networks and Media Lab
CSE 4215/5431: Mobile Communications Winter 2010
CSE 4215/5431: Mobile Communications Winter 2011
Mobile IP Presented by Team : Pegasus Kishore Reddy Yerramreddy Jagannatha Pochimireddy Sampath k Bavipati Spandana Nalluri Vandana Goyal.
Mobile IP Regional Registration
Mobile IP Outline Homework #4 Solutions Intro to mobile IP Operation
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Presentation transcript:

Registration Revocation in Mobile IP draft-glass-mobileip-reg-revok-00.txt (soon to be -01!) Steven M. Glass - Sun Microsystems

Why the Need? RFC2002, etc. was designed when access was the issue. Mobile IP's focus was on functionality. No real-world example existed to revok a registration. At the time, short registration lifetimes were sufficient for WG consensus. Now, AAA is [one of] the "killer apps" here. AAA requires the possibility that a registration can be immediately terminated, and Mobile IP services suspended for a particular mobile node.

Problem Space Terminations must be able to be originated by either side - home or foreign domains. Currently there is no "signaling" message to do this. Terminations must be [able to be] relayed to the revoked MN (policy issue). It MUST be understood by ALL mobile nodes, not just those "enhanced" based on this draft. => This must be a server-only solution! Termination messages must be Authenticated! SAs MUST exist between HA and FA. (AAA)

An Easy Solution? 2002: MN notification mechanism already exists! Compliant MNs understand FA becon sequence number reset means current registration is gone! Already provide for unicast becons to MNs. Today, triggered from Agent Solicitation messages, however:  Mobile Nodes MUST support Agent Solicitations  Mobile Nodes MUST process received Agent Advertisements  Not prohibited by RFC1256 (router discovery)  Already used by [an]other MIP draft, but let's not split hairs... If revok-becon isn't from current FA it will be ignored, so no increased risk for denial-of-service attack.

Mobility Agent Solution FA MAY unicast becon with sequence number 0 to MN indicating registration is gone (mipv4). Need to add a deRegistration message that can be sent between HA and CoA (MIPv4/v6). MUST be authenticated, and "unreplayable" Authentication/replay failure means silently ignore. Would be nice to specify either "unconditionally revoke" or "allow reregistration" (renegotiate).

Details... New Registration type - Revocation "Request". Not really a "request", more like a "notification". MUST be sent only HA to CoA, or FA to HA. MN's "revocation request" is the deregistration (lifetime = 0, etc)! If Revocation Request has been accepted, Revocation Reply MAY be sent, but if not, clearly registration has still been revoked.

Network View – Foreign Domain Foreign Domain Triggered Revocation: (MIPv4-centric) MN FA HA |<--Becon(0)---| |-RevReq(FA-HA)->| |<-RevRep(HA-FA)-| Revoke = e.g. AAA to FA (not shown) Becon(0) = Agent Adv w/seq#=0 RevReq = "Request" with auth, etc. RevRep = optional, wit auth, etc.

Network View – Home Domain Home Domain Triggered Revocation MN FA/CoA HA |<---RevReq----| |<--Becon(0)---| |----RevRep--->| revoke = e.g.AAA to HA (not shown) RevReq = "Request" with auth, etc. Becon(0) = Agent Advert w/seq#=0 RevRep = optional, with auth, etc.

Revocation Message Format | Type | Code | Lifetime | | Home Address | | Agent Address | | Identifier | |... (other extensions, e.g. HA-FA authenticator)... Type: (TBD) Code: Indicates "unconditionally revoke" or "allow rereg". Lifetime: The lifetime of this deRegistration. Home Address: registered address of the MN. Agent Address: address of the agent sending the revocation. * Identifier: used for replay protection (same in req and rep).

Observations MN will almost certainly attempt to reregister: FA MUST NOT silently ignore! => MNconfusion! FA MAY reply with "administratively prohibited", or FA MAY forward to HA to respond.  Different reasons for revocation lead to different reregistration actions. "unconditional" vs. "renegotiate" MN may then attempt to reregister with different FA, but HA will handle this. Changes to FA, and HA (obviously), but also to MNs that will colocate to understand HA revoke!

Pitfalls? Comments from the audience???

Final Thoughts Multiple Bindings: HA may revoke any of multiple bindings. If one of multiple-binding FAs revokes a registration, HA may revoke other of multiple- bindings. The "R" bit (another use?): An FA may set the R-bit to be able to inform MNs of other service revocations resulting in MIP revocation.