Mobile IPv6 Upper-Level Router Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network mobility solutions using Mobile IPv6 suffer from sub-optimal routing and security vulnerabilities due to the lack of verification methods for upper-level router information, which can lead to attacks and inefficient packet forwarding.

Innovation Solution

A network managing method and apparatus that verifies the validity of upper-level router information by using routing headers and cryptographic tokens to ensure that packets are routed correctly and securely, preventing attacks by validating the authenticity of the upper-level router information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If route optimization is implemented using Mobile IPv6, then packet forwarding efficiency is improved, but security vulnerabilities arise due to lack of verification for upper-level router information

Engineering Contradiction:
Improvepacket forwarding efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing return routability testing before allowing route optimization. The correspondent node sends test messages (HoTI and CoTI) to verify the mobile node's routing information before actually optimizing packets. This preliminary verification prevents security vulnerabilities while maintaining efficiency benefits.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through the return routability testing mechanism. The correspondent node receives feedback from the mobile node's routing information, verifies its validity through cryptographic tokens and test messages, and only then allows route optimization. This feedback loop ensures security while maintaining productivity.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If upper-level router information is accepted without verification, then network mobility is simplified, but flooding attacks can occur

Engineering Contradiction:
Improvenetwork mobilityVSAvoidflooding attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary verification mechanism (return routability testing) between the mobile node and the correspondent node. This intermediary process validates upper-level router information before packets are forwarded, preventing flooding attacks while maintaining ease of network mobility operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary anti-action by performing security verification before allowing potentially harmful routing changes. The return routability test acts as a preventive measure that detects and blocks flooding attacks before they can affect the network, while allowing legitimate mobility operations to proceed.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If return routability testing is performed, then security is improved, but message transmission complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidmessage transmission complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security verification process into distinct phases: sending HoTI and CoTI test messages, receiving HoT and CoT responses, and validating routing information. This segmentation makes the complex security verification process more manageable and implementable while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7895339B2Network managing method and network managing apparatus
Publication Date: 2011.02.22 REDWOOD TECHNOLOGIES LLC
  • US7895339B2 patent drawing
  • US7895339B2 patent drawing
  • US7895339B2 patent drawing

AI summary

In order to verify if upper-level router information, or ULRI (information on the upper-level router with respect to a predetermined node) is valid, MN (Mobile Node) 220 associated to ULMR (Upper-Level Mobile Router) 210 acquires ULRI such as the address of ULMR (310), inserts ULRI into a BU (Binding Update) message, and sends it to HA (Home Agent) 235 (320). On receiving the BU message with ULRI, HA sends a BA (Binding Acknowledgement) message set to pass through the router that is specified in ULRI (330). If ULRI is valid, ULMR forwards the BA message to MN (340). If ULRI is not valid, ULMR discards the BA message.