requirements and the security considerations
Jouni Korhonen <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <[email protected]> |
<no co-chair cap/bowler> Folks, I have been reading Section 6 Security Considerations: It is necessary to provide sufficient defense against possible security attacks, or to adopt existing security mechanisms and protocols to provide sufficient security protections. For instance, EAP-based authentication can be used for access network security, while IPsec can be used for end-to-end security. I think this text still deserves some tweaking. First, "provide sufficient defense against possible security attacks".. against whom? Second, should the text say something that the DMM protocol itself must not be usable as a tool to launch an attack by a malicious mobile node that happens to know that it is attached to a network implementing DMM and knows (somehow) how the DMM protocol functions? - Jouni