Reverse Tunnelling for Mobile IPv6 Location Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Mobile IPv6 protocols face inefficiencies in location privacy and route optimization, particularly when both communication partners are mobile, as they either compromise location privacy or require significant infrastructure modifications and scalability issues.
Innovation Solution
The implementation of bi-directional tunnelling with proxy functionality in home agents, allowing secure and on-demand optimization of data packet routes between mobile nodes without revealing their locations, using existing infrastructure and maintaining compatibility with standard Mobile IPv6 security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If route optimization mode is used to reduce packet delay, then routing efficiency is improved, but location privacy is compromised because the correspondent node learns the mobile node's care-of-address
Solution Approach 1:
The patent introduces a tunnel endpoint as an intermediary node that sits between the correspondent node and the mobile node. This tunnel endpoint receives packets from the correspondent node and forwards them through a tunnel to the mobile node's care-of-address. The correspondent node never sees the actual care-of-address, only the tunnel endpoint's address, thus preserving location privacy while enabling direct routing through the optimized path.
2Loss of information
If bi-directional tunnelling is used to protect location privacy, then location privacy is maintained, but routing efficiency deteriorates due to unnecessary long communication paths
Solution Approach 1:
The tunnel endpoint acts as a mediator that enables direct routing without exposing the mobile node's location. Packets are routed directly from the correspondent node to the tunnel endpoint, then through the tunnel to the mobile node, creating an optimized path that is shorter than traditional bi-directional tunnelling through home agents, while still hiding the care-of-address.
Solution Approach 2:
The patent segments the routing path into two distinct segments: the first segment from the correspondent node to the tunnel endpoint (visible path), and the second segment from the tunnel endpoint through the tunnel to the mobile node (hidden path). This segmentation allows the visible portion to be optimized for direct routing while the hidden portion protects location privacy.
3Loss of information
If new infrastructure components are introduced in visited networks to achieve both location privacy and route optimization, then both goals are achieved, but device complexity and deployment difficulty increase
Solution Approach 1:
The tunnel endpoint performs multiple functions: it acts as a routing optimization point, a privacy protection mechanism, and a tunnel termination point. By consolidating these functions into a single component that can be implemented in existing network infrastructure (such as home agents or border routers), the patent avoids the need for multiple specialized new components, reducing overall system complexity.
Solution Approach 2:
The tunnel endpoint utilizes existing infrastructure components (home agents, border routers) to provide the optimization and privacy functions. Rather than requiring completely new infrastructure, the existing components are made to perform additional functions (self-service), reducing deployment complexity and leveraging already-deployed network elements.
Data Source
AI summary
A method and a server acting as a Home Agent are provided for packet switched data transmission between a first mobile node and a correspondent mobile node in a mobile communication system comprising a plurality of mobile networks. Each of the first mobile node and the correspondent mobile node are allocated to respective home networks, and a network server is provided as a home agent to each mobile node, respectively. Then, data packets are routed from the first mobile node to the correspondent mobile node, over a first data tunnel from the first mobile node to any first one of the home agents and over a second data tunnel from said first one of the home agents to the correspondent mobile node without passing the respective other home agent.


