18th Annual Computer Security Applications Conference (ACSAC '02) Security of Internet Location Management San Diego California December 09-December 13 ISBN: 0-7695-1828-1
In the Mobile IPv6 protocol, the mobile node sends binding updates to its correspondents to inform them about its current location. It is well-known that the origin of this location information must be authenticated. This paper discusses several threats created by location management that go beyond unauthentic location data. In particular, the attacker can redirect data to bomb third parties and induce unnecessary authentication. We introduce and analyze protection mechanisms with focus on ones that work for all Internet nodes and do not need a PKI or other new security infrastructure. Our threat analysis and assessment of the defense mechanisms formed the basis for the design of a secure location management protocol for Mobile IPv6. Many of the same threats should be considered when designing any location management mechanism for open networks.
Citation:
Tuomas Aura, Michael Roe, Jari Arkko, "Security of Internet Location Management," acsac, pp.78, 18th Annual Computer Security Applications Conference (ACSAC '02), 2002 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||