Re: Any other security other than IPSec?

Jari Arkko <[email protected]> Sun, 03 Aug 2003 11:21:00 +0300
Newsgroups gmane.ietf.mobileip
Message-ID <[email protected]>
Tan, Tat Kin wrote:
> Hello,
> 
> Would like to know if anyone had ever consider to implement or had any idea to use other security measurements in mipv6 instead of the much talked IPSec?

Yes. Some folks have worked with the use of Binding Authorization Data option,
for instance, to secure even BUs to the home agent.

> While the draft indicated most of the communications SHOULD use IPSec, such as during binding, i was thinking performance would be a huge factor under processing bandwidth hunger area such as real time voice processing.

In terms of per-packet processing requirements, other security mechanisms
would probably be in the same class; authentication, replay protection,
and confidentiality services are needed in any case.

But IPsec has limitations in the area of requiring specific security
policies, which can be troublesome especially if you want to have
dynamically allocated (e.g. RFC 3041) home addresses.

Going forward and looking at the new features as a part of the planned
MIP6 WG work, we need to address these concerns. As was discussed
in IETF-57, alternatives for this include coming up with something
IKEv2 based or using an "application" (Mipv6) layer solution.

--Jari