EP1993257A1

Method for providing secure connectivity to an internal network for a mobile node and related entity

Abstract

Method for providing secure connectivity to an internal network for a mobile node (MN) roaming in an external network, the internal network supporting Proxy MIP and comprising a home agent (i-HA), the internal network and the external network being connected through a VPN (virtual private network) gateway co-located with a gateway proxy mobile agent (GPMA). The method comprising the following steps: - performing preliminary actions (18,19,23) for the establishment of a VPN tunnel (25) between the mobile node and the VPN gateway ; - obtaining at the gateway proxy mobile agent, within the framework of the preliminary actions for the establishment of the VPN tunnel, a home address (HoA) of the mobile node from the home agent; and - using the home address of the mobile node as an inner address of the VPN tunnel to be established.

EP1993257A1, drawing sheet 1
Sheet 1 of 9

Term

Projected expiry 15 May 2027.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 6 independent, 9 dependent

  1. 1
    A method for providing secure connectivity to an internal network for a mobile node (MN) roaming in an external network, the internal network supporting Proxy MIP and comprising a home agent (i-HA), the internal network and the external network being connected through a VPN (virtual private network) gateway co-located with a gateway proxy mobile agent (GPMA), the method comprising the following steps:- performing preliminary actions (18,19,23) for the establishment of a VPN tunnel (25) between the mobile node and the VPN gateway ;- obtaining at the gateway proxy mobile agent, within the framework of the preliminary actions for the establishment of the VPN tunnel, a home address (HoA) of the mobile node from the home agent;and - using the home address of the mobile node as an inner address of the VPN tunnel to be established.
  2. 4
    The method as claimed in any one of the foregoing claims, wherein performing preliminary actions (18,19,23) for the establishment of the VPN tunnel (25) comprises receiving at the VPN gateway an IKE_AUTH request message (19) from the mobile node (MN) and wherein obtaining at the gateway proxy mobile agent (GPMA), within the framework of the preliminary actions for the establishment of the VPN tunnel, a home address (HoA) of the mobile node from the home agent (i-HA) results from the gateway proxy mobile agent sending a registration request message (21) for the mobile node to the home agent on reception of the IKE_AUTH request message by the VPN gateway.
  3. 6
    The method as claimed in any one of the foregoing claims, further comprising the following steps for maintaining session continuity and handling mobility for the mobile node (MN), after said VPN tunnel (25) has been established:- detecting that the mobile node has moved to the internal network ;and - deleting said VPN tunnel.
  4. 12
    An entity consisting in a VPN (virtual private network) gateway co-located with a gateway proxy mobile agent (GPMA), said entity being able to connect an internal network and an external network, the internal network supporting Proxy MIP and comprising a home agent (i-HA), said entity comprising, with respect to a mobile node (MN) roaming in the external network:- means for taking part in preliminary actions (18,19,23) for the establishment of a VPN tunnel (25) with the mobile node ;- means for obtaining, within the framework of the preliminary actions for the establishment of the VPN tunnel, a home address (HoA) of the mobile node from the home agent;and - means for using the home address of the mobile node as an inner address of the VPN tunnel to be established.
  5. 14
    A computer program product comprising code instructions for implementing the method as claimed in any one of claims 1 to 11, when loaded and run on computer means.
  6. 15
    A mobile node (MN) having a VPN (virtual private network) tunnel (25) established with a VPN gateway co-located with a gateway proxy mobile agent (GPMA), the co-located VPN gateway and gateway proxy mobile agent connecting an internal network supporting Proxy MIP and comprising a home agent (i-HA) and an external network, the mobile node comprising means for, after moving to the internal network, deleting said VPN tunnel by sending a Mobike delete message to the VPN gateway.