1 / 7

Improvement of Return Routability Protocol

Improvement of Return Routability Protocol. draft-qiu-mip6-RR-improvement-00.txt Institute for Infocomm Research Singapore. Outline. Three attacks to RR. Our Improvement to RR. MN 1. CN / Server. MN 2. MN 3. Intruder. Traffic Permutation Attacks. Intruder

perry-avery
Download Presentation

Improvement of Return Routability Protocol

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Improvement of Return Routability Protocol draft-qiu-mip6-RR-improvement-00.txt Institute for Infocomm Research Singapore

  2. Outline • Three attacks to RR. • Our Improvement to RR.

  3. MN1 CN / Server MN2 MN3 Intruder Traffic Permutation Attacks • Intruder • Collect HoTs and CoTs at the server edge • Randomly form Kbu • Send BU to CN • Random redirection

  4. Session Hijacking Attacks MN2 CN CoTI MN2 / CoTMN2 MN1 FWD HoTMN1 HoTMN1 HA • Intruder • Get HoTMN1 • MN2 send its own CoTIMN2 and get CoTMN2 • MN2 forges as MN1 Intruder

  5. CoA CN / Server CoA’ Intruder Movement Halting Attacks CoTold CoT HoT’ HoTnew • Intruder • Get old CoT • Get new HoT’ • Form valid Kbu • Redirect to old CoA

  6. The Improvement • HoA and CoA are bound together HoTI = {HoA, CNA, CoA, HomeInitCookie } CoTI = {CoA, CNA, HoA, CareInitCookie } HomeKeygenToken = HMAC_SHA1(Kcn, (HoA|Nj|CoA|0)) CareKeygenToken= HMAC_SHA1(Kcn, (CoA|Ni|HoA|1)) • Advantages: • Prevent the 3 attacks • No additional cost • No change of RR protocol architecture

  7. Thank You!

More Related