Browse > Article

A Study on Preventing SA Re-negotiation for Mobility Support in Mobile IP VPN Environment  

차정석 (연세대학교 컴퓨터과학·산업시스템공학과 정보통신연구실)
김태윤 (연세대학교 컴퓨터과학·산업시스템공학과 정보통신연구실)
송주석 (연세대학교 컴퓨터과학·산업시스템공학과 정보통신연구실)
Abstract
In the remote access VPN architecture which is based on IPsec, if the VPN client wants to be served the VPN service continuously during VPN client's handoff, It needs the techniques to merge VPN with Mobile IP. In this case, if the VPN client roams to new subnet, it acquires new CoA. As a result of changing IP address, existing SA becomes useless and new SA is required. The SA renegotiation process results from handoff of the VPN client and does not result from security aspect. Hence, In the environment which includes many handoffs, overhead by SA re-negotiation deteriorates performance. In this paper, we propose the technique provides that it doesn't need to renegotiate SA and be able to get the security service continuously even though MN's handoff occurs in Mobile IP VPN environment.
Keywords
Mobile IP; VPN; SA Re-negotiation;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Sanchez E, Edwards R, 'Optimisation ofthe establishment of secure communicationchannels in wireless mobile network', inProceedings of the International Paralleland Distributed Processing Symposium(IPDPS'02), 2002
2 Barton M, Atkins D, Lee J, Narain S,Ritcherson D, Tepe K.E, Wong K.D,'Integration of IP Mobility and Security forSecure Wireless Communications', inProceedings of IEEE International Conferenceon Communications, ICC 2002, Volume 2,pp. 1045-1049, 2002
3 D. Harkins, D. Carrel, 'The Internet KeyExchange (IKE)', RFC 2409, November1998
4 S. Kent, R. Atkinson, 'Security Architecturefor the Internet Protocol', RFC 2401,November 1998
5 David B. Johnson, Charles E. Perkins, JariArkko, 'Mobility Support in IPv6', InternetDraft draft-ietf-mobileip-ipv6 -19.txt, October2002
6 C. Perkins, 'IP Mobility Support for IPv4',RFC 3344, August 2002
7 Farid Adrangi, Prakash Iyer, Kent Leung,Milind Kulkarni, Alpesh Patel, QiangZhang, Joe Lau, 'Problem Statement andRequirements for Mobile IPv4 TraversalAcross IPsec-based VPN Gateways',Internet Draft draft-ietf-mobileip-vpn-problem-statement-req-OO.txt, July 2002
8 D. Morghan, M. Schertler, M. Schneider, J.Turner, 'Internet Security Association andKey Management Protocol (ISAKMP)',RFC 2408, November 1998
9 Ruixi Yuan, W. Timothy Strayer, 'VirtualPrivate Networks : Technologies andSolutions', Addison-Wesley, 2001
10 S. Deering, R. Hinden, 'Internet Protocol,Version 6 (IPv6) Specification', RFC 2460,December 1998