发明名称 METHODS AND APPARATUS FOR SECURING PROXY MOBILE IP BACKGROUND OF THE INVENTION
摘要 An invention is disclosed that enables proxy Mobile IP registration to be performed in a secure manner. Various security mechanisms may be used independently, or in combination with one another, to authenticate the identity of a node during the registration process. First, an Access Point receiving a packet from a node verifies that the source MAC address identified in the packet is in the Access Point's client association table. In addition, as a second mechanism, the Access Point ensures that a one-to-one mapping exists for the source MAC address and source IP address identified in the packet in a mapping table maintained by the Access Point. As a third mechanism, a binding is not modified in the mobility binding table maintained by the Home Agent unless there is a one-to-one mapping in the mobility binding table between the source MAC address and the source IP address. Similarly, the Foreign Agent may also maintain a mapping between the source IP address and the source MAC address in its visitor table to ensure a one-to-one mapping between a source IP address and the associated MAC address. The MAC address is preferably transmitted in a MAC address extension to the registration request and registration reply packets. In this manner, the Access Point, Home Agent, and Foreign Agent may ascertain the node's MAC address and ensure a one-to-one mapping between the IP address and the MAC address during the registration process.
申请公布号 CA2520501(C) 申请公布日期 2013.04.23
申请号 CA20042520501 申请日期 2004.04.28
申请人 CISCO TECHNOLOGY, INC. 发明人 LEUNG, KENT K.;DOMMETY, GOPAL
分类号 H04L29/06;H04L12/56;H04L29/08;H04L29/12 主分类号 H04L29/06
代理机构 代理人
主权项
地址