Mobile IPv6 Route Optimization Security via Authentication Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing messages in Mobile IPv6, such as IPSec ESP, cause delays and computational overhead, and alternative protocols like the Authentication Protocol do not provide confidentiality protection for the Return Routability procedure, limiting the use of route optimized communication.
Innovation Solution
A method that secures messages between the mobile node and the home agent using initiating and responsive messages with authentication codes and tokens, generated using shared secrets or authentication servers, to authorize communication without relying on IPSec, by incorporating a Return Routability Security Option in the HoTI and HoT messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec ESP is used to secure messages between mobile node and home agent, then message confidentiality and authentication are improved, but latency and computational overhead increase
Solution Approach 1:
The patent extracts the security function from the full IPSec ESP protocol and implements only the essential authentication mechanism through authentication codes (MACs) in the Return Routability Security Option. This selective extraction maintains message authentication and confidentiality while eliminating the latency and computational overhead associated with complete IPSec tunneling and encryption/decryption operations.
2Reliability
If IPSec ESP is used to secure messages between mobile node and home agent, then message authentication is improved, but computational overhead increases
Solution Approach 1:
The patent extracts only the authentication function from IPSec ESP by implementing authentication codes (MACs) that provide message authentication without requiring the full IPSec encryption/decryption computational overhead. The authentication is performed using shared secrets or authentication servers with lightweight cryptographic operations.
Solution Approach 2:
The patent uses temporary authentication codes and tokens that are generated and validated during the Return Routability procedure, then discarded. These short-lived authentication mechanisms provide sufficient security for the routing decision without requiring long-term key management or complex computational operations.
3Productivity
If Authentication Protocol is used to secure messages, then computational overhead is reduced, but confidentiality protection for Return Routability procedure is lost
Solution Approach 1:
The patent merges the authentication mechanism (from Authentication Protocol) with the Return Routability Security Option to achieve both computational efficiency and confidentiality protection. The authentication codes are integrated into the HoTI and HoT messages, allowing the mobile node to authenticate with the home agent while maintaining confidentiality for the routing procedure.
Solution Approach 2:
The patent introduces authentication codes and tokens as intermediary elements that mediate between the mobile node and home agent. These intermediaries provide both authentication and confidentiality protection without requiring full IPSec tunneling, enabling route optimized communication while maintaining security.
4Loss of time
If route optimized communication is enabled, then latency is reduced and reliability is improved, but security of message exchange is compromised
Solution Approach 1:
The patent introduces authentication codes and tokens as intermediary security mechanisms that enable route optimized communication while maintaining message security. These intermediaries verify the legitimacy of routing decisions and protect against unauthorized route changes without requiring the messages to traverse the home agent for encryption.
Solution Approach 2:
The patent performs security authentication and authorization actions before establishing the route optimized communication path. The mobile node authenticates with the home agent and obtains authorization tokens before sending packets directly to the correspondent node, ensuring security is established in advance rather than during data transmission.
Data Source
AI summary
A mobile node that is in communication with a correspondent node via a home agent initiates a process for establishing a route optimized mode of communication between the mobile node and the correspondent node. The mobile node sends a first initiating message to the home agent for delivery to the correspondent node and sends a second initiating message directly to the correspondent node. The mobile node secures the first initiating message by including an initiating-message authentication code that can be validated by the home agent or by an authentication server. The correspondent node responds by sending a first responsive message to the home agent for delivery to the mobile node and by sending a second responsive message directly to the mobile node. The home agent secures the first responsive message by adding a responsive-message authentication code that can be validated by the mobile node.


