Mobile IPv6 Route Optimization Security via Authentication Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing messages in Mobile IPv6, such as IPSec ESP, cause delays and computational overhead, and alternative protocols like the Authentication Protocol do not provide confidentiality protection for the Return Routability procedure, limiting the use of route optimized communication.

Innovation Solution

A method that secures messages between the mobile node and the home agent using initiating and responsive messages with authentication codes and tokens, generated using shared secrets or authentication servers, to authorize communication without relying on IPSec, by incorporating a Return Routability Security Option in the HoTI and HoT messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec ESP is used to secure messages between mobile node and home agent, then message confidentiality and authentication are improved, but latency and computational overhead increase

Engineering Contradiction:
Improvemessage securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security function from the full IPSec ESP protocol and implements only the essential authentication mechanism through authentication codes (MACs) in the Return Routability Security Option. This selective extraction maintains message authentication and confidentiality while eliminating the latency and computational overhead associated with complete IPSec tunneling and encryption/decryption operations.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If IPSec ESP is used to secure messages between mobile node and home agent, then message authentication is improved, but computational overhead increases

Engineering Contradiction:
Improvemessage authenticationVSAvoidcomputational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the authentication function from IPSec ESP by implementing authentication codes (MACs) that provide message authentication without requiring the full IPSec encryption/decryption computational overhead. The authentication is performed using shared secrets or authentication servers with lightweight cryptographic operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses temporary authentication codes and tokens that are generated and validated during the Return Routability procedure, then discarded. These short-lived authentication mechanisms provide sufficient security for the routing decision without requiring long-term key management or complex computational operations.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Productivity

If Authentication Protocol is used to secure messages, then computational overhead is reduced, but confidentiality protection for Return Routability procedure is lost

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidconfidentiality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent merges the authentication mechanism (from Authentication Protocol) with the Return Routability Security Option to achieve both computational efficiency and confidentiality protection. The authentication codes are integrated into the HoTI and HoT messages, allowing the mobile node to authenticate with the home agent while maintaining confidentiality for the routing procedure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces authentication codes and tokens as intermediary elements that mediate between the mobile node and home agent. These intermediaries provide both authentication and confidentiality protection without requiring full IPSec tunneling, enabling route optimized communication while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of time

If route optimized communication is enabled, then latency is reduced and reliability is improved, but security of message exchange is compromised

Engineering Contradiction:
ImprovelatencyVSAvoidmessage security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent introduces authentication codes and tokens as intermediary security mechanisms that enable route optimized communication while maintaining message security. These intermediaries verify the legitimacy of routing decisions and protect against unauthorized route changes without requiring the messages to traverse the home agent for encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs security authentication and authorization actions before establishing the route optimized communication path. The mobile node authenticates with the home agent and obtains authorization tokens before sending packets directly to the correspondent node, ensuring security is established in advance rather than during data transmission.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7551915B1Method of establishing route optimized communication in mobile IPv6 by securing messages sent between a mobile node and home agent
Publication Date: 2009.06.23 SPRINT SPECTRUM LLC
  • US7551915B1 patent drawing
  • US7551915B1 patent drawing
  • US7551915B1 patent drawing

AI summary

A mobile node that is in communication with a correspondent node via a home agent initiates a process for establishing a route optimized mode of communication between the mobile node and the correspondent node. The mobile node sends a first initiating message to the home agent for delivery to the correspondent node and sends a second initiating message directly to the correspondent node. The mobile node secures the first initiating message by including an initiating-message authentication code that can be validated by the home agent or by an authentication server. The correspondent node responds by sending a first responsive message to the home agent for delivery to the mobile node and by sending a second responsive message directly to the mobile node. The home agent secures the first responsive message by adding a responsive-message authentication code that can be validated by the mobile node.