Prefix-Scope Binding Update Security via Router Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network mobility solutions, such as Mobile IPv6, suffer from sub-optimal routing and security vulnerabilities, particularly in verifying the authenticity of network prefixes in prefix-scoped binding update messages, which can lead to denial-of-service and spoofing attacks.

Innovation Solution

A mechanism is introduced to verify the authenticity of network prefixes by using router certificates issued by a trust anchor, which are included in prefix-scoped binding update messages, allowing correspondent nodes to ensure the mobile router owns the specified prefixes, thereby preventing false route setups and ensuring secure direct routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Return Routability procedure is used to verify binding updates, then security against spoofing attacks is improved, but the complexity of the verification process increases due to multiple message exchanges and token generation

Engineering Contradiction:
Improvesecurity against spoofing attacksVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-distributing public keys to correspondent nodes before they need to verify binding updates. This eliminates the need for real-time key generation and complex token exchange procedures, while maintaining security against spoofing attacks. The correspondent node can directly verify the mobile node's public key against the pre-stored public key, significantly simplifying the verification process.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If direct routing is enabled between mobile nodes and correspondent nodes, then packet latency is reduced, but security vulnerabilities increase due to inability to verify prefix ownership

Engineering Contradiction:
Improvepacket latencyVSAvoidsecurity against denial-of-service attacks
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent implements feedback by requiring the mobile node to include its public key in the binding update message sent to the correspondent node. The correspondent node then verifies this public key against the pre-distributed public key for the mobile network prefix. This feedback mechanism provides cryptographic proof that the mobile node legitimately owns the prefix, enabling direct routing while maintaining security against denial-of-service attacks.

Inventive Principle:
Principle #23Feedback

3Productivity

If prefix-scoped binding updates are allowed without verification, then route optimization is improved, but the system becomes vulnerable to false route setups and spoofing attacks

Engineering Contradiction:
Improveroute optimizationVSAvoidauthenticity of network prefixes
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent uses public keys as an intermediary mechanism to verify prefix ownership in binding updates. Instead of requiring complex verification procedures or trusting the mobile node directly, the system uses cryptographically signed public keys as an intermediary proof of ownership. This allows route optimization through prefix-scoped binding updates while ensuring the authenticity of network prefixes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1875710B1System, associated methods and apparatus for securing prefix-scoped binding updates
Publication Date: 2011.11.23 PANASONIC HOLDINGS CORP
  • EP1875710B1 patent drawingFigure 1
  • EP1875710B1 patent drawingFigure 2
  • EP1875710B1 patent drawingFigure 3

AI summary

Route optimization between a mobile network and correspondent node may be achieved by having the mobile router of the mobile network sending prefix-scoped binding update messages to the correspondent node. In order to allow the recipient of a prefix-scoped binding update message to verify the mobile network prefix information contained in the said prefix-scoped binding update message, the present invention provides a system, and associated methods and apparatus thereof, of using special cryptographic certificates to prove the ownership of the network prefixes. The certificates, or parameters derived from the certificates, are transmitted alongside the network prefix in the binding update message sent to the correspondent node. By verifying the network prefix against the certificates, or parameters derived from the certificates, a correspondent node can determine the validity of a prefix-scoped binding update message.