Re: Any other security other than IPSec?
Jari Arkko <[email protected]> Sun, 03 Aug 2003 11:21:00 +0300
| Newsgroups | gmane.ietf.mobileip |
|---|---|
| Message-ID | <[email protected]> |
Tan, Tat Kin wrote: > Hello, > > Would like to know if anyone had ever consider to implement or had any idea to use other security measurements in mipv6 instead of the much talked IPSec? Yes. Some folks have worked with the use of Binding Authorization Data option, for instance, to secure even BUs to the home agent. > While the draft indicated most of the communications SHOULD use IPSec, such as during binding, i was thinking performance would be a huge factor under processing bandwidth hunger area such as real time voice processing. In terms of per-packet processing requirements, other security mechanisms would probably be in the same class; authentication, replay protection, and confidentiality services are needed in any case. But IPsec has limitations in the area of requiring specific security policies, which can be troublesome especially if you want to have dynamically allocated (e.g. RFC 3041) home addresses. Going forward and looking at the new features as a part of the planned MIP6 WG work, we need to address these concerns. As was discussed in IETF-57, alternatives for this include coming up with something IKEv2 based or using an "application" (Mipv6) layer solution. --Jari