CH - 2 Mobile IP
CH - 2 Mobile IP
CH - 2 Mobile IP
Agenda
What is Mobile IP?
Mobile IP Architecture
Why Mobile IP?
How Mobile IP Works
Registration Message Format
Tunneling in Mobile IP
Mobile IP in Action
Security in Mobile IP
Mobile in IPv6
Conclusion
What is Mobile IP
Definition:
Entities in Mobile IP
Mobile Node (MN) - A Node moving to different network, with permanent Home Address.
Home Agent (HA) - A router on a mobile node's home network which tunnels datagrams for delivery to the mobile
node when it is away from home, and maintains current location information for the mobile node.
Home Address - The static fixed IP Address allocated to a mobile node by Home Agent.
Home Network - A network, having a network prefix/network id.matching that of a mobile node's home address
Foriegn Network - A network other than a Mobile node’s home network.
Foreign Agent - Router in foreign network that provides CoA and tunneling with HA and forward the packets to MN.
Care-of Address - Termination point of a tunnel toward a MN in the foreign netwrok.
Mobility Binding - The association of a home address with a care-of address (CoA).
Correspondent Node (CN) - A peer node with which a Mobile node is communicating.
Why Mobile IP ?
CN is successfully communicating with MN via HA
Correspondent node (CN)
Packets for MN are dropped by the
Home Agent as Mobile node is not
Mobile node (MN) present in its network
Router
Home Agent (HA)
Need: Increase in the variety of mobile devices, such as PDA’s, laptops and
cellular phones, more and more internet services are accessible to
moving users with the widely deployed wireless networks.
1. Registration Request by MN to FA
2
2. FA Relays Registration request to HA 1
4 3
3. HA sends Registration reply to FA
HA
MN
Mobility Binding Table
Registration message format
HA tunnels the
Packet and sends to FA
MN moves to FA Foreign Agent(FA)
FA extracts original
Packet and sends to the MN
When CN sends the data to MN, it uses the original address of the MN, so the
packet goes to HA.
From the mobility binding HA encapsulates the packet (IP-in-IP or GRE) and
sends to CoA.
The FA de-capsulate the packet and extracts the original packet that was sent
by the CN.
The FA then sends this packet to the MN using the Home address destination.
The reverse route from MN to CN may or may not follow this path.
CoA = B
Mobile Node moves to remote network
Security in Mobile IP
Required as Mobile Nodes are often in unprotected remote network
Authenticity and Integrity of Registration messages using
Authentication (e.g. HMAC-MD5).
Replay attack protection for Registration messages using sequence
number.
Security Issues in Mobile IP
Issue Protocol Solution
Optional authentication between MN and FA IPv4 AAA and Broker AAA
services
Location Privacy IPv4,IPv6 None
5 6
Remote Agent (RA)
1 10
Home Agent (HA)
Registration Request
Registration Response
Mobile node (MN)
Security in Mobile IP (Cont.)
IPSec for Data Confidentiality
IPSec Tunnel