Prefix-Scope Binding Update Security via Router Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network mobility solutions, such as Mobile IPv6, suffer from sub-optimal routing and security vulnerabilities, particularly in verifying the authenticity of network prefixes in prefix-scoped binding update messages, which can lead to denial-of-service and spoofing attacks.
Innovation Solution
A mechanism is introduced to verify the authenticity of network prefixes by using router certificates issued by a trust anchor, which are included in prefix-scoped binding update messages, allowing correspondent nodes to ensure the mobile router owns the specified prefixes, thereby preventing false route setups and ensuring secure direct routing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the Return Routability procedure is used to verify binding updates, then security against spoofing attacks is improved, but the complexity of the verification process increases due to multiple message exchanges and token generation
Solution Approach 1:
The patent applies preliminary action by pre-distributing public keys to correspondent nodes before they need to verify binding updates. This eliminates the need for real-time key generation and complex token exchange procedures, while maintaining security against spoofing attacks. The correspondent node can directly verify the mobile node's public key against the pre-stored public key, significantly simplifying the verification process.
2Loss of time
If direct routing is enabled between mobile nodes and correspondent nodes, then packet latency is reduced, but security vulnerabilities increase due to inability to verify prefix ownership
Solution Approach 1:
The patent implements feedback by requiring the mobile node to include its public key in the binding update message sent to the correspondent node. The correspondent node then verifies this public key against the pre-distributed public key for the mobile network prefix. This feedback mechanism provides cryptographic proof that the mobile node legitimately owns the prefix, enabling direct routing while maintaining security against denial-of-service attacks.
3Productivity
If prefix-scoped binding updates are allowed without verification, then route optimization is improved, but the system becomes vulnerable to false route setups and spoofing attacks
Solution Approach 1:
The patent uses public keys as an intermediary mechanism to verify prefix ownership in binding updates. Instead of requiring complex verification procedures or trusting the mobile node directly, the system uses cryptographically signed public keys as an intermediary proof of ownership. This allows route optimization through prefix-scoped binding updates while ensuring the authenticity of network prefixes.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Route optimization between a mobile network and correspondent node may be achieved by having the mobile router of the mobile network sending prefix-scoped binding update messages to the correspondent node. In order to allow the recipient of a prefix-scoped binding update message to verify the mobile network prefix information contained in the said prefix-scoped binding update message, the present invention provides a system, and associated methods and apparatus thereof, of using special cryptographic certificates to prove the ownership of the network prefixes. The certificates, or parameters derived from the certificates, are transmitted alongside the network prefix in the binding update message sent to the correspondent node. By verifying the network prefix against the certificates, or parameters derived from the certificates, a correspondent node can determine the validity of a prefix-scoped binding update message.