EP1381202A2

Apparatuses and computer software for providing seamless IP mobility across security boundaries

Abstract

An arrangement and a computer program product, for providing seamless IP mobility across a security boundary between two domains, secure domain (105) and insecure domain (107), is described. The invention comprises a novel architecture of known network infrastructure components, inner system home agent (130) and outer system home agent (102) along with enabling client software on the user device (103). The specific client software as well as the novel architecture represents the invention. Unlike state-of-art today, the method is based on the combined use of independent IP mobility systems in each of the two domains. The key to the invention is client software being able to operate with both mobility systems simultaneously. Moreover, communication takes place in such a way that the ordinary remote access security solution is in control of all access to the secure home domain of the user. The resulting method provides secure and seamless IP mobility in any domain with independent choice of mobility and security technologies. The invention does not require any significant changes (adaptations nor extensions) to any IP mobility or security technology beyond existing or upcoming standards. Nor does it require any significant changes to existing infrastructure components. The mobility client software is the only component that is affected, thus making the method client-centric, as opposed to a network-centric approach that is otherwise the alternative. The invention applies both for the current IPv4 family of standards as well as the forthcoming IPv6 family of standards. The invention applies in particular for the Mobile IP and IPSec VPN standards but is not restricted to these technologies. The invention is applicable for any IP mobility and IP security protocols as long as they are based on the same set of underlying principles.

EP1381202A2, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Projected expiry passed 10 July 2023, 3.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 6 independent, 4 dependent

  1. 1
    An arrangement in a mobil data communications terminal (103) for providing mobil IP communication via a dual tunnell IP packet data connection between a first application (121) in the mobil data communications terminal and a second application (101) in a second terminal in communication with an inner network (105), said inner network directly or via a firewall (104) connected with an outer network (107), wherein an outer mobil IP home agent (102) is arranged in the outer network or in a DMZ (106) associated with the firewall and an inner mobil IP home agent (130) is arranged in the inner netwotk, said arrangement comprising:a first mobil IP client part (116) configurable for association with the inner mobil IP home agent (130), said first mobil IP client part arranged to convey data between the first application and the second mobil IP client part and to an inner tunnell part (123) directed to the inner home agent, and a second mobil IP client part (115) configurable for association with the outer mobil IP home agent (102), said second mobil IP client part arranged to convey data between the first mobil IP client part and the outer network and to an outer tunnell part (124) directed to the outer home agent.
  2. 6
    Arrangement according to any one of the previous claims, wherein said arrangement further comprises, a third security client part interposed between the first and second mobil IP client parts and configurable for via a security arrangement arranged between said inner and outer networks establishing a secure connection with the inner network.
  3. 7
    A mobil IP terminal, wherein said mobil IP terminal comprises an arrangement according to any one of the previous claims.
  4. 8
    A computer program product comprising a data carrier having thereon a computer program code loadable and executable in a mobil IP data communications terminal, wherein said computer program code when loaded and executed in the mobil IP data communications terminal effects the establishment of an arrangement as recited in any one of claims 1 through 6.
  5. 9
    An information technology (IT) system for providing a packet data connection between a first application (121) operable in a mobil data communications terminal (103) and a second application (101) operable in a second terminal in an inner network (105) protected by a firewall (104), said system arranged for communication by means of mobil IP with a system comprising the inner network, an outer network (107) and an outer home agent (102) arranged in the outer network or in a DMZ (106) associated with the firewall arranged between the inner and outer network, wherein:an inner home agent (130) is arranged in the inner network, and said inner home agent is configurable for association with a first mobil IP client part (116) operable in the mobil data communications terminal, and said outer home agent is configurable for association with a second mobil IP client part (115) operable in the mobil data communications terminal, said first mobil IP client part being arranged to convey data between said first application and said other mobil IP client part and to an inner tunnell part (123) directed to the inner home agent, and said second mobil IP client part being arranged to convey data between said first mobil IP client part and said outer network and to an outer tunnell part (124) directed to said outer home agent.
  6. 10
    A data communications system for providing a packet data connection between a first application operable in a mobil data communications terminal (103) and a second application (101) operable in a second terminal connected to an inner network (105) protected by a firewall (104), said system arranged for communication by means of mobil IP via a system comprising the inner network, an outer network (107) and an outer home agent (102) arranged in said outer network or in a DMZ (106) associated with the firewall (104) being arranged between the inner and outer networks, wherein:an inner home agent (130) is arranged in the inner network, and said mobil data communications terminal including: c. a first mobil IP client part (116) configurable for association with said inner mobil IP home agent (130), said first mobil IP client part arranged to convey data between said first application and said second mobil IP client part and to an inner tunnell part (123) directed to said inner home agent, and d. a second mobil IP client part (115) configurable for association with said outer mobil IP home agent (102), said second mobil IP client part being arranged to convey data between said first mobil IP client part and said outer network and to an outer tunnell part (124) directed to said outer home agent.