Professional Documents
Culture Documents
• Security
– authentication with FA problematic, for the FA typically belongs to another
organization
– no protocol for key management and key distribution has been
standardized in the Internet
– patent and export restrictions
• Firewalls
– typically mobile IP cannot be used together with firewalls, special set-ups
are needed (such as reverse tunneling)
• QoS
– many new reservations in case of RSVP
– tunneling makes it hard to give a flow of packets a special treatment
needed for the QoS
• Security, firewalls, QoS etc. are topics of research and discussions
Security in Mobile IP
• Security requirements (Security Architecture for the Internet Protocol,
RFC 4301, was: 1825, 2401)
– Integrity
any changes to data between sender and receiver can be detected by the
receiver
– Authentication
sender address is really the address of the sender and all data received is really
data sent by this sender
– Confidentiality
only sender and receiver can read the data
– Non-Repudiation
sender cannot deny sending of data
– Traffic Analysis
creation of traffic and user profiles should not be possible
– Replay Protection
receivers can detect replay of messages
IP Micro-mobility support
• Micro-mobility support:
– Efficient local handover inside a foreign domain
without involving a home agent
– Reduces control traffic on backbone
– Especially needed in case of route optimization
• Example approaches (research, not products):
– Cellular IP
– HAWAII
– Hierarchical Mobile IP (HMIP)
• Important criteria:
Security Efficiency, Scalability, Transparency, Manageability
Cellular IP
• Operation:
– “CIP Nodes” maintain routing
entries (soft state) for MNs Internet
– Multiple entries possible
Mobile IP
– Routing entries updated based on
packets sent by MN CIP Gateway
• CIP Gateway: data/control
– Mobile IP tunnel endpoint packets
from MN 1
– Initial registration processing
• Security provisions:
– all CIP Nodes share BS BS BS
“network key” packets from
– MN key: MD5(net key, IP addr) MN2 to MN 1
– MN gets key upon registration MN1 MN2
Cellular IP: Security
• Advantages:
– Self configuring
– All control messages by MNs are authenticated
• Potential problems:
– MNs can directly influence routing entries
– Network key known to many entities
(increases risk of compromise)
– No re-keying mechanisms for network key
– No choice of algorithm (always MD5, prefix+suffix mode)
– Proprietary mechanisms (not, e.g., IPSec AH)
HAWAII
• Operation:
– MN obtains co-located COA 1
and registers with HA Internet
2 HA
– Handover: MN keeps COA,
new BS answers Reg. Request 3 Backbone
and updates routers 4
Router
– MN views BS as foreign agent
Crossover
• Security provisions: Router
– MN-FA authentication mandatory 2
– Challenge/Response Extensions 4 Mobile IP
mandatory
BS BS BS DHCP
Server
Mobile IP
3
MN MN DHCP
1
HAWAII: Security
• Advantages:
– Mutual authentication and Challenge/Response
extensions mandatory
– Transparent
• Potential problems:
– Co-located COA raises DHCP security issues
(DHCP has no strong authentication)
– Authentication of HAWAII protocol messages unspecified
(potential attackers: stationary nodes in foreign network)
Hierarchical Mobile IPv6 (RFC 4140)
• Operation:
– Network contains mobility anchor
point (MAP) Internet
• mapping of regional COA (RCOA) to
HA
link COA (LCOA)
RCOA
– Upon handover, MN informs
MAP only MAP
• gets new LCOA, keeps RCOA
– HA is only contacted if MAP
changes binding AR AR
update
LCOAnew LCOAold
• Security provisions:
– no HMIP-specific MN MN
security provisions
– binding updates should be
authenticated
Hierarchical Mobile IP: Security
• Advantages:
– Local COAs can be hidden, which provides at least
some location privacy
– Direct routing between CNs sharing the same link is
possible (but might be dangerous)
• Potential problems:
– Additional component
– MNs can (must!) directly influence routing entries via
binding updates (authentication necessary)
DHCP: Dynamic Host Configuration Protocol
• Application
– simplification of installation and maintenance of networked computers
– supplies systems with all necessary information, such as IP address,
DNS server address, domain name, subnet mask, default router etc.
– enables automatic integration of systems into an Intranet or the
Internet, can be used to acquire a COA for Mobile IP
• Client/Server-Model
– the client sends via a MAC broadcast a request to the DHCP server
(might be via a DHCP relay)
DHCPDISCOVER
DHCPDISCOVER
server client
client relay
DHCP - protocol mechanisms
server client server
(not selected) initialization (selected)
DHCPDISCOVER DHCPDISCOVER
determine the determine the
configuration configuration
DHCPOFFER DHCPOFFER
collection of replies
time
selection of configuration
DHCPREQUEST DHCPREQUEST
(reject) (options) confirmation of
configuration
DHCPACK
initialization completed
release
DHCPRELEASE delete context
DHCP characteristics
• Server
– several servers can be configured for DHCP, coordination
not yet standardized (i.e., manual configuration)
• Renewal of configurations
– IP addresses have to be requested periodically, simplified
protocol
• Options
– available for routers, subnet mask, NTP (network time
protocol) timeserver, SLP (service location protocol)
directory, DNS (domain name system)
Mobile ad hoc networks
• Standard Mobile IP needs an infrastructure
– Home Agent/Foreign Agent in the fixed network
– DNS, routing etc. are not designed for mobility
• Sometimes there is no infrastructure!
– remote areas, ad-hoc meetings, disaster areas
– cost can also be an argument against an infrastructure!
• Main topic: routing
– no default router available
– every node should be able to forward
A B C
Manet: Mobile Ad-hoc Networking
Mobile
Router
Manet
Mobile
Devices
Mobile IP,
DHCP
Fixed
Network
1 2
A B C
Dest. Next Metric … Dest. Next Metric … Dest. Next Metric …
A A 0 A A 1 A B 3
B B 1 B B 0 B B 2
C B 3 C C 2 C C 0
Distance Vector (Update)
Routing table
is updated (A, 1) (A, 1)
(B, 0) (B, 0)
(C, 1) (C, 1)
1 1
A B C
Dest. Next Metric … Dest. Next Metric … Dest. Next Metric …
A A 0 A A 1 A B 3 2
B B 1 B B 0 B B 1
C B 3 2 C C 1 C C 0
Distance Vector (New Node)
broadcasts to update
tables of C, B, A with
new entry for D
(A, 1) (A, 2)
(B, 0) (B, 1)
(C, 1) (C, 0)
(D, 2) (D, 1) (D, 0)
1 1 1
A B C D
Dest. Next Metric … Dest. Next Metric … Dest. Next Metric …
A A 0 A A 1 A B 2
B B 1 B B 0 B B 1
C B 2 C C 1 C C 0
D B 3 D C 2 D D 1
Distance Vector (Broken Link)
1 1 1
A B C D
Dest. Next Metric … Dest.c Next Metric … Dest. Next Metric …
… … … … … … … … …
D B 3 D C 2 D B
D 1
Distance Vector (Loops)
(D, 2) (D, 2)
1 1 1
A B C D
Dest. Next Metric … Dest. Next Metric … Dest. Next Metric …
… … … … … … … … …
D B 3 D C 2 D B 3
Distance Vector (Count to Infinity)
(D,5)
(D,4) (D,4)
(D,3)
(D,2) (D,2)
1 1 1
A B C D
Dest. Next Metric … Dest.c Next Metric … Dest. Next Metric …
… … … … … … … … …
D B 3, 5, … D C 2, 4, 6… D B 3, 5, …
Distance Vector
• DV not suited for ad-hoc networks!
– Loops
– Count to Infinity
A 1 B 2 C
Dest. Next Metric Seq Dest. Next Metric Seq Dest. Next Metric Seq.
A A 0 A-550 A A 1 A-550 A B 1 A-550
B B 1 B-100 B B 0 B-100 B B 2 B-100
C B 3 C-586 C C 2 C-588 C C 0 C-588
DSDV (Route Advertisement)
A 1 B 1 C
Dest. Next Metric Seq Dest. Next Metric Seq Dest. Next Metric Seq.
A A 0 A-550 A A 1 A-550 A B 2 A-550
B B 1 B-102 B B 0 B-102 B B 1 B-102
C B 2 C-588 C C 1 C-588 C C 0 C-588
DSDV (Respond to Topology Changes)
• Immediate advertisements
– Information on new Routes, broken Links, metric change is
immediately propagated to neighbors.
• Full/Incremental Update:
– Full Update: Send all routing information from own table.
– Incremental Update: Send only entries that has changed.
(Make it fit into one single packet)
DSDV (New Node)
(D, 0, D-000)
A B C D
Dest. Next Metric Seq. Dest. Next Metric Seq. Dest. Next Metric Seq.
A A 0 A-550 A A 1 A-550 A B 2 A-550
B B 1 B-104 B B 0 B-104 B B 1 B-104
C B 2 C-590 C C 1 C-590 C C 0 C-590
D D 1 D-000
DSDV (New Node cont.)
A B C D
Dest. Next Metric Seq. Dest. Next Metric Seq. Dest. Next Metric Seq.
A A 0 A-550 A A 1 A-550 A B 2 A-550
B B 1 B-104 B B 0 B-102 B B 1 B-102
C B 2 C-590 C C 1 C-592 C C 0 C-592
D C 2 D-000 D D 1 D-000
DSDV (no loops, no count to infinity)
2. B does its broadcast
-> no affect on C (C knows that B has
stale information because C has higher
seq. number for destination D)
-> no loop -> no count to infinity 1. Node C detects broken Link:
-> Increase Seq. Nr. by 1
(only case where not the destination
sets the sequence number -> odd
number)
(D, 2, D-100) (D, 2, D-100)
A B C D
Dest. Next Metric Seq. Dest.c Next Metric Seq. Dest. Next Metric Seq.
… … … … … … … … …
D B 3 D-100 D C 2 D-100 D D D-101
DSDV (Immediate Advertisement)
3. Immediate propagation 2. Immediate propagation
B to A: C to B:
(update information has higher (update information has higher
Seq. Nr. -> replace table entry) Seq. Nr. -> replace table entry)
1. Node C detects broken Link:
-> Increase Seq. Nr. by 1
(only case where not the destination
sets the sequence number -> odd
number)
(D, , D-101) (D, , D-101)
A B C D
Dest. Next Metric Seq. Dest.c Next Metric Seq. Dest. Next Metric Seq.
… … … ... … … …
… … … ...
D B 4
3 D-100 D B
D 1 D-100
D C 2 D-100
D B D-101
D C D-101
D D D-101
– No sleeping nodes
– Overhead: most routing information never used
– DSDV is not suitable for highly dynamic or large
scale networks
Dynamic source routing (DSR)
• Reactive routing protocol
• 2 phases, operating both on demand:
– Route discovery
• Used only when source S attempts to to send a packet
to destination D
• Based on flooding of Route Requests (RREQ)
– Route maintenance
• makes S able to detect, while using a source route to D,
if it can no longer use its route (because a link along
that route no longer works)
DSR: Route discovery (1)
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
DSR: Route discovery (2)
F K
H
Q A
S E G D P
(S)
J
B M
R
I
L
C
N
DSR: Route discovery (3)
(S,A) K
F H
Q A
(S,E)
S E G D P
J
B M
R
I
L
C
N
DSR: Route discovery (4)
F K
H
Q A
S E G (S,E,G) D P
J
B M
R
I
L
C
(S,B,C) N
DSR: Route discovery (5)
(S,A,F,H)
F K
H
Q A
S E G (S,E,G,J) D P
J
B M
R
I
L
C
N
DSR: Route discovery (6)
F K
H (S,A,F,H,K)
Q A
S E G D P
J
B M
R
I
L
C
N
DSR: Route discovery (7)
F K
H
Q A
S E G D P
J (S,A,F,H,K,P)
B M
R
I
L
C
N
DSR: Route discovery (8)
F K
H
Q A
S E G D P
J RREP(S,E,G,J,D)
B M
R
I
L
C
N
DSR: Route Discovery (9)
• Route reply by reversing the route (as
illustrated) works only if all the links along the
route are bidirectional
• If unidirectional links are allowed, then RREP
may need a route discovery from D to S
• Note: IEEE 802.11 assumes that links are
bidirectional
DSR: Data delivery
F K
H
Q A
DATA(S,E,G,J,D)
S E G D P
J
B M
R
I
L
C
N
DSR: Route maintenance (1)
F K
H
Q A
DATA(S,E,G,J,D)
S E G D P
X J
B M
R
I
L
C
N
DSR: Route maintenance (2)
F K
H
Q A
RERR(G-J)
S E G D P
X J
B M
R
I
L
C
N When receiving the Route Error message (RERR),
S removes the broken link from its cache.
It then tries another route stored in its cache; if none,
it initializes a new route discovery
DSR: Optimization of route discovery:
route caching
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
AODV : Route discovery (2)
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
AODV : Route discovery (5)
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
AODV : Route discovery (6)
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
AODV : Route discovery (7)
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
AODV : Route reply and setup of the
forward path
F K
H
Q A
S E G D P
J
B M
R
I
L
C
N
F K
H
Q A
Data
S E G D P
J
B M
R
I
L
C
N
F K
H
Q A
Data
S E G D P
X J
B M
R
I
L
C
N
AODV : Route maintenance (2)
F K
H
Q A
RERR(G-J)
S E G D P
X J
B M
R
I
L
C
N
B B
…
DSN(D) = 8
: Forward path D
3.
S A … 4.
S A …
RREQ DSN(D) = 5 RREP DSN(D) = 5
B B
DSN(D) = 8 DSN(D) = 8
…
D D
AODV : Avoiding loops
A B S X D
C
: Forward path
• Assume there is a route between A and D; link S-D breaks; assume A is not aware of this, e.g. because
RERR sent by S is lost
• Assume now S wants to send to D. It performs a RREQ, which can be received by A via path S-C-A
• Node A will reply since it knows a route to D via node B
• This would result in a loop (S-C-A-B-S)
• The presence of sequence numbers will let S discover that the routing information from A is outdated
• Principle: when S discovers that link S-D is broken, it increments its local value of DSN(D). In this way,
the new local value will be greater than the one stored by A.
Existing On-Demand Protocols
• Dynamic Source Routing (DSR)
• Associativity-Based Routing (ABR)
• Ad-hoc On-demand Distance Vector (AODV)
• Temporarily Ordered Routing Algorithm (TORA)
• Zone Routing Protocol (ZRP)
• Signal Stability Based Adaptive Routing (SSA)
• On Demand Multicast Routing Protocol (ODMRP)