Comments on dmm-requirements
Alper Yegin <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <[email protected]> |
Hello, Here I have a comment on the DMM requirements document. 6. Security Considerations Distributed mobility management (DMM) requires two kinds of security considerations. The first consideration is on access network security required between the mobile host/router and the access network deploying DMM. It allows only a legitimate mobile host/ router to use DMM. The second consideration is on end-to-end security required between nodes that participate in the DMM protocol. It protects the DMM signaling messages. I'm not sure I understand this. Is the first one about "access network security"? Like ensuring only the authorized nodes can attach to the access network, and once they attach their traffic can be origin authenticated, replay and integrity protected? If so, that's not related to DMM. In fact, one could even claim that nodes attached to unsecure network, e.g., open WiFi, should also be able to use DMM. It is necessary to provide sufficient defense against possible security attacks, or to adopt existing security mechanisms and protocols to provide sufficient security protections. For instance, EAP-based authentication can be used for access network security, while IPsec can be used for end-to-end security. Again, the former is about access network security, and the latter is about end-to-end communication security. None of these are related to "DMM security." Btw, I'd have expected this section to state just this: "Security considerations related to the DMM are described in section 5.6." Alper _______________________________________________ dmm mailing list [email protected] https://www.ietf.org/mailman/listinfo/dmm