Re: [MEXT] [dmm] Draft related to DMM
Carlos Jesús Bernardos Cano <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Organization | Universidad Carlos III de Madrid |
| Message-ID | <[email protected]> |
Hi Pete, Thanks for the feedback On Mon, 2011-03-07 at 16:31 -0600, Pete McCann wrote: > Hi, Carlos, > > 2011/3/7 Carlos Jesús Bernardos Cano <[email protected]>: > > > > We have just submitted a draft related to DMM. The draft describes a > > possible way of achieving a distributed mobility behavior with Client > > Mobile IP, based on Mobile IPv6 and the use of Cryptographic Generated > > Addresses. > > > > The draft is already on the I-D repository: > > > > http://www.ietf.org/id/draft-bernardos-mext-dmm-cmip-00.txt > > I read through your draft, and I have a couple of questions. > > First, it seems that you require a BU sent to the DAR right after > SLAAC. Is this the case? Why do we need such a BU? The BU is only sent if the MN wants to keep the reachability and session continuity of an IPv6 address that was configured (and therefore is anchored) at a previous DAR. In this case, the BU is sent to that previous DAR, using as CoA the IPv6 address that has just configured from the current DAR. > > Second, how is the PHKT protected when it transits from the > DAR to the MN? Did you consider doing a simple Diffie-Hellman > exchange to derive a PHKT for later use by the MN? That would > neatly avoid having to send the PHKT in the clear or to protect > it with some sort of encryption wrapper. We rely on the mechanisms described in draft-laganier-mext-cga-01/RFC4866 for that (I don't remember the details). I guess using D-H could also be a good option to derive the token. > > Third, how do you expect the CGA configuration to interact with > the access network authentication that will be performed before > the MN is allowed to attach to the first DAR? Do you see any > opportunities for synergy here, if say, EAP was used to authenticate > and derive an MSK? We haven't gone to that level of detail yet, to be honest. Interactions with access network authentication and BU authorization issues are definitely things that need to be further analyzed. Thanks! Carlos > > -Pete -- Carlos Jesús Bernardos Cano http://www.netcoms.net GPG FP: D29B 0A6A 639A A561 93CA 4D55 35DC BA4D D170 4F67 _______________________________________________ MEXT mailing list [email protected] https://www.ietf.org/mailman/listinfo/mext
signature.asc
(application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEABECAAYFAk13sqIACgkQNdy6TdFwT2f36QCgjSTJa5wbw2ACxyB9b/snb1FD RX4AoMUsS03dnW5UhY836dWTXXLbOlg5 =fHrA -----END PGP SIGNATURE-----