Lightweight Security for Host-Based Mobility Protocols
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Host-based mobility protocols face challenges in providing sufficient security against redirection and flooding attacks, particularly due to the lack of mutual trust relationships and network-based infrastructure, leading to insufficient protection and processing burdens on end nodes.
Innovation Solution
A lightweight security solution that combines methods of weak authentication with proof of session ownership capabilities, eliminating the need for mutual trust relationships and network-side anchors, by using mobility associations (MA) to establish simplex or duplex mobility sessions, which reduce processing and state information requirements, and provide enhanced protection against session hijacking and flooding attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If host-based mobility protocols are used to eliminate network-side anchors, then cost-effectiveness and scalability are improved, but security protection against redirection and flooding attacks deteriorates
Solution Approach 1:
The patent applies preliminary action by establishing security associations and pre-shared keys before mobility events occur. The system pre-configures security parameters and trust relationships between correspondant nodes and mobility nodes, enabling secure communication without requiring network-side anchors during actual mobility operations. This allows host-based mobility to maintain both cost-effectiveness and security.
2Ease of operation
If weak authentication methods are used in host-based mobility protocols, then processing burden on end nodes is reduced, but security protection deteriorates
Solution Approach 1:
The patent extracts the complex authentication and key management processes from the end nodes and relocates them to network entities. The mobility node and correspondant node establish security associations using pre-configured keys and simplified verification mechanisms, eliminating the need for heavy cryptographic operations at end devices while maintaining strong security protection.
3Reliability
If mutual trust relationships are established globally using PKI, then security protection is improved, but scalability and revocation issues significantly impair the advantages of host-based mobility
Solution Approach 1:
The patent segments the global trust relationship into localized security associations between specific mobility nodes and correspondant nodes. Instead of requiring universal PKI infrastructure, each mobility session establishes its own security context with dedicated keys and security parameters. This segmentation maintains security protection while dramatically improving scalability and eliminating revocation complexities.
4Adaptability or versatility
If host-based mobility protocols are used without network support, then versatility and scalability are improved, but security protection against flooding attacks deteriorates
Solution Approach 1:
The patent introduces security associations as intermediary structures that mediate between host-based mobility operations and security protection. These security associations act as virtual network support, providing authentication and authorization mechanisms without requiring actual network infrastructure. The security associations enable flooding attack protection while maintaining the versatility of host-based mobility protocols.
Data Source
AI summary
A transport connection system is set forth. The system includes a first device adapted to send and receive messages. A second device, adapted to send and receive message, is also provided. A message i generated by the first device includes a secret Ri-1 to a Hash (Ri-1) sent from the first device to the second device in a prior message i-1. The message i is signed by a random key Ai-1, the random key being derived from an update of a key Ai-2 from the prior message, wherein message i-1 is signed by the key Ai-2.


