Re: [MEXT] [dmm] Draft related to DMM

Carlos Jesús Bernardos Cano <[email protected]>
Newsgroups gmane.ietf.nemo
Organization Universidad Carlos III de Madrid
Message-ID <[email protected]>
Hi Pete,

Thanks for the feedback

On Mon, 2011-03-07 at 16:31 -0600, Pete McCann wrote:
> Hi, Carlos,
> 
> 2011/3/7 Carlos Jesús Bernardos Cano <[email protected]>:
> >
> > We have just submitted a draft related to DMM. The draft describes a
> > possible way of achieving a distributed mobility behavior with Client
> > Mobile IP, based on Mobile IPv6 and the use of Cryptographic Generated
> > Addresses.
> >
> > The draft is already on the I-D repository:
> >
> > http://www.ietf.org/id/draft-bernardos-mext-dmm-cmip-00.txt
> 
> I read through your draft, and I have a couple of questions.
> 
> First, it seems that you require a BU sent to the DAR right after
> SLAAC.  Is this the case?  Why do we need such a BU?

The BU is only sent if the MN wants to keep the reachability and session
continuity of an IPv6 address that was configured (and therefore is
anchored) at a previous DAR. In this case, the BU is sent to that
previous DAR, using as CoA the IPv6 address that has just configured
from the current DAR.

> 
> Second, how is the PHKT protected when it transits from the
> DAR to the MN?  Did you consider doing a simple Diffie-Hellman
> exchange to derive a PHKT for later use by the MN?  That would
> neatly avoid having to send the PHKT in the clear or to protect
> it with some sort of encryption wrapper.

We rely on the mechanisms described in
draft-laganier-mext-cga-01/RFC4866 for that (I don't remember the
details). I guess using D-H could also be a good option to derive the
token.

> 
> Third, how do you expect the CGA configuration to interact with
> the access network authentication that will be performed before
> the MN is allowed to attach to the first DAR?  Do you see any
> opportunities for synergy here, if say, EAP was used to authenticate
> and derive an MSK?

We haven't gone to that level of detail yet, to be honest. Interactions
with access network authentication and BU authorization issues are
definitely things that need to be further analyzed.

Thanks!

Carlos

> 
> -Pete

-- 
Carlos Jesús Bernardos Cano     http://www.netcoms.net
GPG FP: D29B 0A6A 639A A561 93CA  4D55 35DC BA4D D170 4F67

_______________________________________________
MEXT mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mext
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEABECAAYFAk13sqIACgkQNdy6TdFwT2f36QCgjSTJa5wbw2ACxyB9b/snb1FD
RX4AoMUsS03dnW5UhY836dWTXXLbOlg5
=fHrA
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.