RE: issue 12: interaction with other protocols doing RR
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <DC504E9C3384054C8506D3E6BB012460CD8C28@bsebe001.americas.nokia.com> |
I think RR should only be attempted after MOBIKE/IKE informational exchange has been validated. It should not be attempted for every possible address updates. RR is useful for an authenticated attacker only. For an unauthenticated attacker (psuedo-NAT attack) it is wasteful. I did not understand the comment on "...but if it were included then Mobile IPv6 home agent service could easier be offered to unknown peers." Given that such a RR test done by MOBIKE can be used elsewhere and similarly connectivity information elsewhere could be used in MOBIKE, MOBIKE should work on defining such cross-layer/cross-protocol APIs. Atul > -----Original Message----- > From: [email protected] > [mailto:[email protected]]On > Behalf Of ext Jari Arkko > Sent: Sunday, October 31, 2004 10:48 AM > To: MOBIKE Mailing List > Subject: [Mobike] issue 12: interaction with other protocols doing RR > > > > Background: a number of protocols employ return > routability tests. In the mobility space we have > this at least in MOBIKE, Mobile IPv6, MULTI6, and > HIP. > > Tero's design document discusses some differences > these tests have in different contexts; not all > do exactly the same thing even if all at least > verify there's someone willing to respond on the > path towards the tested address. > > I would like to suggest that we do our own specific > type of test, but allow same tests to be "reused" across > protocols where this makes sense. That is, in MOBIKE > we do our own test that verifies liveness of the address > and that the peer is indeed still the same IKEv2 > node and has knowledge of some secret keying material. > In addition, we add a note saying that the use of > the results of this test may be possible in other > protocol layers*. > > Ok for everyone? > > --Jari > > *) The example that comes to my mind is that since the > mobile node - home agent interface in mobile IPv6 runs > with IPsec, then the use of MOBIKE in that context > would provide an RR test to home registrations. That > does not exist in Mobile IPv6 at the moment, but if > it were included then Mobile IPv6 home agent service > could easier be offered to "unknown" peers. Currently > "unknown" peers are only support as correspondent > nodes. > > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike >