Method of securing binding update by using address based key
Abstract
Problem to be solved.To secure binding updates in a wireless telecommunications system.
Solution.A public key is generated by using a home address of a mobile host. A home agent, such as a router, generates a private key by using public cryptographic parameters corresponding to the mobile host or the public key. A node of a communication destination uses the public key to encrypt a shared key and sends the encrypted shared key to the mobile host. The mobile host decrypts the shared key by using its original private key. The shared key is used for signing the binding update. Thereafter, the node of the communication destination utilizes the shared key to verify the authenticity of the binding update.
Copyright (C)2004,JPO
Term
Term ended
Projected expiry passed 19 February 2023, 3.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
26 claims: 3 independent, 23 dependent
- 1[Claims] [Claim 1] A method of protecting correspondence information updates in a wireless communication system. Steps to generate a public key using a public identifier, The steps to generate a private key using the public key, A method comprising:a step of protecting correspondence information update by using the public key and the private key. 【特許請求の範囲】 【請求項1】 無線通信システムで対応情報更新を保護する方法であり、 公開識別子を使用して公開鍵を生成するステップと、 前記公開鍵を使用して秘密鍵を生成するステップと、 前記公開鍵および前記秘密鍵を利用して対応情報更新を保護するステップとを備えることを特徴とする方法。
- 10A system that protects correspondence information updates in a wireless communication system. A mobile host that can connect to the communication system A system including a communication destination node that can connect to the mobile host, which protects correspondence information updates transmitted to and from the mobile host by using a public key and a private key. 【請求項10】 無線通信システムでの対応情報更新を保護するシステムであって、 前記通信システムに接続可能な移動ホストと、 公開鍵と秘密鍵を使用して、移動ホストとの間で伝達される対応情報更新を保護する、前記移動ホストに接続可能な通信先ノードとを備えることを特徴とするシステム。
- 19Used in wireless communication systems, A public key and a private key are used to protect the corresponding communication information transmitted to and from the communication destination node, and having an interface capable of connecting itself to the home agent and the communication destination node. Characterized mobile node. 【請求項19】 無線通信システムで使用され、 前記通信先ノードとの間で伝達される対応交信情報を保護するために、公開鍵および秘密鍵が使用される、自身をホームエージェントと通信先ノードに接続することが可能なインターフェースを有することを特徴とする移動ノード。
Independent claims3
169 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to an individual encryption system, and more particularly to a method and system for protecting correspondence information updates within a wireless communication system.
【0002】
[Conventional technology]
This application claims priority based on provisional US patent application numbers 60 / 358,177 (filed February 19, 2002) and 60 / 416,029 (filed October 3, 2002). These are named "Protection of MIPv6 Support Information Update (Binding Update) Using Address-Based Key" and are also referred to in the text.
【0003】
The background of the present invention is the trend of technical discussion on whether or not to accept Return Routability as a result of the well-known research on the mobile IP format and the basic technology for protecting the update of MIPv6 compatible information. Today, there are various mechanisms devised for round-trip route confirmation. However, round-trip route confirmation has problems with its protection characteristics and performance.
【0004】
[Problems to be Solved by the Invention]
In the cryptographic society, individual cryptographic systems are known, but such systems are not used in networking protection measures. The latest networking protection measures utilize Diffie-Hellmann technology. Also, until recently, there were no individual encryption algorithms available for encryption. The conventional algorithm deals only with electronic signatures, and its technical scope is limited. The latest research presents a new algorithm based on elliptic curves that also enables encryption.
【0005】
[Means for solving problems]
The present invention discloses a system and a method for protecting correspondence information update in a wireless communication system. In this system, a public key is created using the home address of the mobile host. The home agent then creates a private key using public cryptographic parameters that correspond to the mobile host and public key.
【0006】
When starting communication with the communication destination node, the mobile host transmits a message requesting the communication destination node to acquire the public cryptographic parameters from the home agent to the communication destination node through the home agent. Here, if the communication destination node does not have the encryption parameter, the communication destination node acquires the encryption parameter from the home agent. The communication destination node then uses the home address of the mobile host and encryption parameters to encrypt the shared key sent to the mobile host via the home agent. The mobile host uses the public key to decrypt the received shared key, and uses this shared key to calculate the message authentication code included in the corresponding information update. In response to this process, the communication destination node protects the correspondence information update by inspecting the message authentication code using the shared private key.
【0007】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, preferred embodiments in the mechanism for protecting the communication correspondence information update will be described with reference to the drawings. The same component shall be identified by the same number. Such protection mechanisms include address-based keys (ABKs), or other cryptographic methods that refer to wale pairing and cryptosystems based on a combination of secret cryptosystems. The following description is intended to show one aspect of the properties of the present invention and does not limit the scope of its technical ideas.
【0008】
A system and method for protecting the update of correspondence information in MIPv6 using encryption based on an individual identifier (hereinafter referred to as individual encryption) will be described. Individual encryption includes a series of encryption methods in which a client uses the client's public identifier such as its IP address as a public key. The client obtains the private key from the individual private key generator (IPKG) along with the public cryptographic parameters. The communication partner that needs to encrypt the message uses the public ID and public encryption parameters of the client to which the message is destined. Furthermore, the communication partner acquires public cryptographic parameters from IPKG. The client decrypts the encrypted message with the client's private key.
【0009】
Figure 1 shows an example of a wireless mobile access IP (Internet Protocol) network. The wireless mobile access IP network includes a fixed node IP data network 120 composed of a large number of fixed nodes (ie, fixed connection points or fixed connection networks). In this network, data flows according to Internet Protocol such as IPv6, which is specified as IETF RFC 2460, which is a reference of this specification. The core network 120 is provided with a collection of a large number of gate routers 130 forming the IP mobile backbone 140, and this group of routers functions according to the conventional Internet addressing protocol and the Internet routing protocol to form the core network. Route data packets between source and destination nodes connected to. The individual gate routers 130 that form the IP mobile backbone 140 are nodes themselves connected to the core network 120 and also have their own addresses for communicating within the core network 120.
【0010】
A server or router 145 is connected to each of the gate routers 130, which have unique IP addresses and are home agents that interface mobile hosts such as mobile node 135 and destination nodes 142 to core network 120. It has a function as (HA). The mobile node 135 has an interface for communicating with the communication destination node 142. Similarly, the communication destination node side also has an interface for communicating with the mobile node. The communication destination node 142 may be a mobile node. The mobile node 135 and the communication destination node 142 may include various wireless mobile devices such as a mobile handset, a mobile phone, a portable computer, a personal information manager, and a wireless data terminal, respectively.
【0011】
Mobile node 135 establishes a security association with one or more home agents 145 on the home link. Mobile node 135 is then programmed to detect movement between different connection points within network 100. The mobile node 135 can be identified by a home address, i.e., the address of the mobile node 135 that does not change as the mobile node 135 itself moves within network 100. In addition, mobile node 135 acquires a temporary care of address (COA) at each point visited within network 100. In addition, the mobile node 135 notifies the home agent of the noticed address change by sending a response information update message protected by the IPsec security association.
【0012】
The home agent and foreign agent 145 have a radio access network 150 for the mobile node 135 and the communication destination node 142 to communicate with the home agent and foreign agent. The home agent 145 may be provided with a home link router that tracks the location of the mobile node 135 and forwards packets to the mobile node 135 (from the mobile node in some embodiments). The home agent address (HAA) refers to the network address of the home agent 145.
【0013】
The radio access network 150 may include a plurality of radio access points 155. The structure, installation, and function of the radio access network shall be conventional and standard. Wireless LAN or digital communication technology is performed in the usual way on multiple wireless mobile nodes 135 and wireless access points. Details on this point are not necessarily necessary for a complete understanding and recognition of the present invention and will be omitted below.
【0014】
The mechanism that protects the correspondence information update in communication uses an address-based key to further ensure communication protection between the mobile node 135 and a large number of home agents 145. This address-based key takes advantage of the long-term results of individual cryptosystems to create a public key based on the IP address of mobile node 135.
【0015】
The Security Association is established between Mobile Node 135 and Home Agent 145 by the IP security protocol shown at ftp://ftp.isi.edu/in-notes/rfc2401.txt. The security association communicates cryptographic parameter information to mobile node 135 in a confidential and authenticated manner. The mobile node 135, the home agent 145, and the communication destination node 142 constitute an individual encryption system. The home agent 145 is provided with an individual private key generator (hereinafter, IPKG) or a secure access means to the IPKG.
【0016】
Mobile node 135 is preferably the node that has established a security association with one or more home agents 145 on the home link. The home link contains a subnet within the mobile node's home network, where the mobile node's home address is arranged topologically. Mobile node 135 is capable of detecting movement between different connection points within network 100 by itself. The mobile node 135 can acquire a temporary awareness address at the destination in the network 100, and uses the security association to notify the home agent 145 of the currently held awareness address. The communication destination node 142 refers to the destination node with which the mobile node 135 communicates. The communication destination node may be mobile. The mobile node 135 has a home address (HoA) that includes the address of the mobile node, which itself does not change as it travels 100 within the network. The home agent can assign a home address and send it to mobile node 135.
【0017】
Home agent 145 may be implemented on a router on the home link. The home agent 145 is used to keep track of the current location of the mobile node and forward packets to the mobile node 135 (in some embodiments, from the mobile node). A notice address (CoA) IP address is assigned to the mobile node 135 to identify the mobile node's current location. The mobile node 135 may perform route optimization with and from the communication destination node 142 in order to avoid routing packets via the home agent. Route optimization can reduce the latency of communication between the mobile node 135 and the destination node 142. When the noticed address is changed, the mobile node 135 executes route optimization by transmitting the correspondence information update to the communication destination node 142. The address-based key is a technology that enables the mobile node 135 and the communication destination node 142 to confirm the validity of such correspondence information update.
【0018】
Address-based key cryptography employs an individual encryption system that uses the home address of a mobile node to generate its public key. In addition, individual encryption systems include systems that use well-known identifiers such as IPv6 addresses as public keys for authentication, encryption key usage arrangements, and encryption. The individual private key generator (IPKG) includes agents such as computer processors. When the computer processor receives a public identifier that acts as a public key, it executes an individual encryption algorithm to create a private key.
【0019】
In individual cryptosystems, commonly known identifiers such as node email addresses and IP addresses act as public keys in public / private key combinations used for electronic authentication operations, cryptographic key usage arrangements, and encryption. To do. In the individual signature protocol, the host, or mobile node 135, signs the message using the private key provided by IPKG. Then, this signature is authenticated using the identifier of the host. In individual encryption, the encrypting party encrypts the message using the public identifier of the receiving party. The message recipient decrypts the ciphertext encrypted by the recipient's private key. As is common in public key cryptography, the security of cryptosystems depends on the difficulty of solving specific numerical theory problems such as factoring and individual log (or Diffi-Hillman) problems. Individual encryption systems are interpreted with or without key escrow. Protocols that utilize key deposits can be executed with fewer paths than protocols that do not utilize key deposits. Since the master key information is distributed or shared among many IPKGs by the technology applying the distributed generation method, it is possible for all IPKGs to collude to know the private key of the host. Such a scenario leaves room for the key deposit method, if necessary, by agreement of all IPKGs. As a result, information about the private key is protected by IPKG without mutual agreement.
【0020】
Individual cryptosystems include cryptosystems that can use well-known identifiers such as IPv6 as public keys used for authentication, cryptographic key usage arrangements, and encryption. Address-based key is an encryption technology that introduces an individual encryption system in order to create a public key and a private key of a mobile node using public encryption parameters. It is preferable to implement an elliptic curve algorithm for individual keys. This is because the elliptic curve algorithm fits well into small keys, streamlines operations on small hosts such as small radios, and produces smaller signatures. By using abelian varieties instead of elliptic curves, different types of algorithms, such as non-elliptic curve algorithms, may be implemented on individual keys.
【0021】
Public cryptographic parameters include various publicly available parameters. These various parameters are parameters specific to the individual encryption algorithm, formed by a constant and a secret master key, known only to the IPKG (Individual Private Key Generator). IPKG includes an agent that, when provided with a public identifier that acts as a public key, executes a personal cryptographic algorithm to create a private key. Preferred public identifiers include the home address (HoA) of the mobile node. IPKG uses the private master key to create the private key and the public cryptographic parameters provided to the mobile node 135 and the destination node 142. The public cryptographic parameters generated by the private master key are used for encryption processing between nodes such as mobile node 135 and communication destination node 142, which are involved in each operation of message protection or encryption.
【0022】
FIG. 2 is a ladder diagram showing how to use the individual encryption system to protect the correspondence information update. Mobile node 135 sends the public identifier to home agent 145, which acts as an IPKG (block 200). The public identifier includes the home address (HoA) of mobile node 135. The public key of a mobile node is obtained by applying a unique hash function to the id cryptographic algorithm to the association between the home address and a predetermined expiration time (eg, 1 hour). IPKG creates a private key using the id cryptographic algorithm and returns the created private key and expiration time to the mobile node 135 encrypted using the IP Security Association (block 210). The created public and private keys are used for authentication or encryption. The individual encryption algorithm uses a secret known only to IPKG when generating the private key. Therefore, unlike the algorithm proposed by Diffie-Hellmann, the public parameters of the cryptographic algorithm are not used, and the public parameters are not pre-programmed in the mobile node 135, the home agent 145, and the communication destination node 142. The public parameters are updated when the secret master key has expired or is about to expire.
【0023】
The individual encryption method includes an encryption algorithm and a decryption algorithm. The encrypted object (that is, the ciphertext) is obtained by using the following algorithm. ciphertext = ENCRYPT (contents, IPuK, Params) In the above algorithm ciphertext Ciphertext ENCRYPT Individual encryption algorithm for encrypting the message body contents Message body to protect IPuK Individual public key used by mobile node Params IPKG public cryptographic parameters Means each. If IPuK = H (ID, time) holds, H ... A unique hashing algorithm for individual algorithms used to create a public key from an ID ID: Public identifier used to create a key time: Indicates the IPv6 expiration time of the public / private key indicated by SNTP (Simple Network Time Protocol) version 4. The ciphertext is decrypted using the following algorithm. contents = DECRYPT (ciphertext, IPrK, Params) In the above algorithm IPrK Private key of mobile node DECRYPT Individual decryption algorithm used when decrypting ciphertext Means each. The message authentication code (MAC) is calculated from the following theory. mac = MAC (contents, symK) In the above algorithm mac Calculated authentication token MAC Message authentication code algorithm by symmetric key used to calculate the authentication token of the message contents Message body to be authenticated symK Symmetric key shared by sender and receiver of mac [0024]
An IP security association is required to be established between the mobile node 135 and the home agent 145. The IP Security Association is an arrangement for securely transmitting cryptographic parameter information and private key information to mobile node 135. The mobile node 135, the home agent 145, and the communication destination node 142 each execute an individual encryption system. The home agent 145 provides a function as an individual private key generator (IPKG) or is a means for securely accessing the IPKG. Mobile node 135 is initially configured to have a private public key / private key pair associated with the mobile node's own 128-bit IPv6 home address (HoA), along with public cryptographic parameters.
【0025】
Next, when the mobile node 135 starts communication with the communication destination node 142, the mobile node 135 sends a parameter search start message to the communication destination node 142 (block 220). Here, if the destination node 142 has not recorded or cached the public cryptographic parameters associated with the mobile node, the destination node 142 downloads the parameters from the home agent 145 to which the mobile node 135 belongs (block 230 and block). 240). The communication destination node 142 then sends the shared key, encrypted by the mobile node's public key, to the mobile node 135 (block 250).
【0026】
Then, the mobile node 135 can safely send the correspondence information update (step 260). The mobile node 135 sends the correspondence information update protected by the shared key to the communication destination node 142. The communication destination node 142 authenticates the correspondence information update by the shared key. Further, the communication destination node 142 authenticates the authentication token using the shared key. Therefore, the mobile node does not need to send a public key or other certificate for authentication. Further, since the symmetric key method is adopted, it is not necessary to perform a potentially time-consuming public key encryption process for each correspondence information update in order to authenticate the correspondence information update. The communication destination node 142 sends a binding acknowledgement (BA) to the mobile node 135 (step 270).
【0027】
The protocol for securely distributing the private key and cryptographic parameters to mobile node 135 includes the following two messages: 1) ABK Request: Request private key and parameters 2) ABK Reply: Reply private key and parameters [0028]
The protocol for obtaining cryptographic parameters from the home agent and establishing a shared key using an address-based key includes the following four messages. 1) ABKp1: Instruction that the mobile node (MN) caches the parameters in the communication destination node (CN) 2) ABKp2: Communication destination node (CN) requests parameters from home agent (HA) 3) ABKp3: Home agent (HA) returns parameters to destination node (CN) 4) ABKp4: The destination node (CN) responds to the parameter cache instruction received from the mobile node (MN). If the destination node 142 has already cached the parameters of the home agent 145, the ABKp2 and ABKp3 messages are not needed. In addition, the following Standard Mobile IPv6 Support Information Update (BU) is used. 1) BU: The mobile node (MN) passes the correspondence information update + correspondence information authentication data to the communication destination node (CN). 2) BA: The communication destination node (CN) notifies the mobile node (MN) of receiving the correspondence information. Details of these messages are shown below.
【0029】
Home agent 145 can act as an IPKG for all mobile nodes contained in that domain. Home agent 145 generates public cryptographic parameters (Params). This parameter is used in the individual encryption algorithm. Mobile node 135 is assigned a 128-bit Internet Protocol version 6 (IPv6) home address (HoA) by home agent 145. This home address is the basic framework that constitutes the IP security association between the home agent 145 and the mobile node 135, which conforms to the core mobile IPv6 standard.
【0030】
Mobile node 135 requests the home agent for the private key IPrK and public cryptographic parameters. This request by the mobile node may be made at any time prior to the transmission of the response information update. As described above, the transmission of the correspondence information update is the exchange of messages between the home agent 145 and the mobile node 135 using the IP security association established in advance. Home agent 145 returns to the mobile node an SNTP indicating the private key (IPrK), public parameters, parameter version numbers, and the time when the public / private key expires. The mobile node 135 can calculate its public key from the formula defined by IPuK = H (home address, expiration time). The message format for configuring and updating itself with the address-based key of mobile node 135 is shown below.
【0031】
The mobile node 135 propagates an ABKp1 message to the destination node so that the destination node 142 initiates a request for public cryptographic parameters. The packet source address is the home address (HoA) of mobile node 135. The ABKp1 message contains the parameter version (Params ver), which is the version number of the parameter, and the time SNTP area, which is the time when the public / private key pair expires.
【0032】
Upon receiving the ABKp1 message, the destination node 142 defines the mobile IPv6 home agent anycast address (HAA) as the subnet prefix of the home address (HoA) of the mobile node 135. The communication destination node 142 checks whether the parameter with the correct parameter number cached to determine the HAA and the corresponding expiration time exist. If the existence of the parameter and its expiration time is confirmed, the communication destination node 142 does not need to send the ABKp2 message and the ABKp3 message to the home agent, and may send the ABKp4 message to the mobile node.
【0033】
On the other hand, the communication destination node 142 may cache parameters that are not correctly version-numbered or the elapsed expiration time. In this case, the communication destination node 142 sends an ABKp2 message to the home agent 145 by using the destination address HAA or the like. It is assumed that the expiration time is the same for the public / private key pair related to the specific home agent (HA) 145.
【0034】
When the destination node 142 needs to send the ABKp2 message and the ABKp3 message, the ABKp2 message includes the area shown below. HoA ... Home address of mobile node Nmac ... Interim message authentication code that depends on the home agent The provisional message authentication code is defined by the algorithm shown below. nmac = MAC (SHA1 (HAA, N1), k_CN) In the above algorithm N1: Provisional k_CN: Private key unique to the destination node [0035]
The provisional code N1 is preferably restored on a regular basis, but the same provisional code is used for all home agents 145 operating at the same time as the destination node 142. The communication destination node 142 may cache the recently used provisional code.
【0036】
Upon receiving the ABKp2 message, the home agent 145 determines if the home address (HoA) of mobile node 135 is already known. Then, the home agent 145 sends an ABKp3 message to the communication destination node 142 including the following message area. Params. Params_ver: Parameter version number time: Public / private key pair SNTP expiration time AF: Address translation permission flag nmac [0037]
If the home address (HoA) of the mobile node is an unknown home address, the parameter value is set to zero by the home agent (HA) 145. If the address translation authentication flag is not set, mobile node 135 may use a universal interface identifier. The communication destination node 142 determines whether the interface identifier of the home address and the interface identifier of the notice address are the same. When the address translation authentication flag is set, a medium different from the above interface identifier may be used to allow the routing change by the noticed address. Upon receiving the ABKp3 message, the destination node 142 checks the parameter value and calculates the MAC (SHA1 (HAA, N1), k_CN) expression. If the parameter value is set to zero, or the interim message authentication code and the calculated message authentication code (Message Authentication) If the Code) values do not match, the notice address will not be authenticated. The communication destination node 142 does not send an error message. If the parameter value is not set to zero, the destination node 142 has the home agent anycast address (source address of the ABPk3 message), parameters, parameter version number, current key expiration time, and address translation authorization. Cache the flag. The ABKp4 message has the following regions. E = ENCRYPT (k_m, IPuK, Params) In the above algorithm k_m = SHA1 (HoA, k_CN).
【0038】
k_m represents a key created by the communication destination node 142 and shared with the mobile node 135. The shared key is encrypted by the public key of the mobile node 135, which is calculated from the home address (HoA) of the mobile node 135 and the expiration time of the public / private key. Upon receiving the ABKp4 message, mobile node 135 uses k_m = DECRYPT (E, IPrK, Params) to request a response information update.
【0039】
The correspondence information update message is sent from the mobile node 135 to the communication destination node 142 according to the core mobile IPv6 processing. In addition to the standard area, the correspondence information update message includes the correspondence information permission data option area. The correspondence information permission data option area includes the message authentication code (MAC) calculated in the area shown below. Contents of correspondence information update (including home address) k_r ... Irregular values generated by the move node The authentication code is calculated from the formula shown below. mac = MAC (SHA1 (BU, k_r), k) Here, the session key is calculated by k = SHA1 (k_m | k_r).
【0040】
When the address conversion permission flag AF is not set for the home address (HoA) of the mobile node 135 when receiving the correspondence information update, the communication destination node 142 has the home address as the interface identifier of the presented notice address (CoA). Determine if it matches the interface identifier of (HoA). The home address is included in the home address option area of the correspondence information update packet. If the interface identifiers do not match, the destination node 142 sends a binding receipt notification with the appropriate error code.
【0041】
When the address translation authentication flag AF is set, the communication destination node executes the address translation permission algorithm to determine whether the mobile node 135 may perform address translation.
【0042】
The address translation authentication flag AF may not be set, and the interface identifier of the presented notice address (CoA) may match the interface identifier of the home address (HoA) in the home address option of the corresponding information update packet. In addition, the address translation authentication flag AF may be set, and the address translation on the mobile node may be authenticated. In either case, the communication destination node 142 calculates k_m = SHA1 (HoA, k_CN) and then k = SHA1 (k_m | k_r). Then, by comparing the mac value obtained from the authentication code of the correspondence information authentication data option with the value obtained by calculating the MAC (SHA1 (BU, k_r), k), the communication destination node 142 updates the correspondence information. Authenticate. If the respective values match, the communication destination node 142 sends a correspondence information receipt notification (BA) message indicating that the authentication has been accepted. Alternatively, the communication destination node 142 sends a correspondence information receipt notification (BA) message indicating that the authentication has failed.
【0043】
Unless the home agent (HA) 145 gives an instruction to set the address translation permission flag in the ABPk3 message, the mobile node 135 uses the same interface identifier as the home address interface identifier for the notice address. Correspondence information update may indicate that the interface identifier is different even though the address exchange authentication flag is not set. In this case, the communication destination node 142 refuses to receive the correspondence information update and sends a correspondence information reception error to the mobile node 135.
【0044】
If the home agent 145 sets the address translation authentication flag to indicate that some processing is being performed, the interface identifier of the home address of the mobile node 135 may be different from that of the noticed address. The communication destination node 142 and the mobile node 135 are allowed to change to the specific awareness address (CoA) by the mobile node 135 having the specific home address (HoA) because the interface identifiers of the home address and the awareness address are different. Share. Examples of changing the home address to a noticed address include an encrypted address and AAA.
【0045】
The correspondence between the mobile node and its home address is authenticated. The destination node 142 receives the parameters directly from the home agent (HA) 145. Furthermore, only the qualified mobile node 135 can decrypt the shared key. The shared key is used to create a session key that authenticates the correspondence information update.
【0046】
If the mobile node 135 sends a large number of ABKp1 messages to satisfy the destination node 142, the destination node 142 checks the parameter table each time it receives a message. Then, it is determined whether the communication destination node 142 has the parameter of the related home agent 145. If there is no home agent parameter associated with the message, the destination node 142 sends an ABKp2 message to the home agent 145 to request that parameter. The destination node 142 does not resend the ABKp2 message to the same home agent 145 unless the parameter expires. The communication destination node 142 does not lead the exchange of messages. If home agent 145 is occupied by a large number of ABKp2 messages, home agent 145 discards all messages, including home addresses (HoA) outside its domain.
【0047】
Use provisional message authentication code (nmac) to prevent malicious third parties from attempting to communicate with the destination node 142 or sending a large number of ABKp3 messages to occupy the destination node 142. Can be done. For a large number of ABKp4 messages, if mobile node 135 is not involved in the formation of ABKp1 messages, mobile node 135 ignores any of those messages. The communication destination node ignores the correspondence information update message for which the message authentication code is not authenticated. The mobile node 135 ignores the correspondence information receipt notification (BA) message replied by the node to which it did not send the correspondence information update.
【0048】
In the worst case, if a malicious third party can modify the sent message on the path between two of the mobile node 135, the destination node 142, and the home agent 145, the correspondence information. Transmission of the update itself fails. The destination node 142 continues to send the mobile node packet to the notice address (CoA) before it was updated. Since the ABKp1 to ABKp3 messages are unsigned, they remain subject to change. However, just as an ABKp4 message is authenticated, if it is encrypted, the ABKp4 message will not be modified by a third party. Correspondence information update is protected by the message authentication code, so the data cannot be changed by a malicious third party.
【0049】
In another embodiment, if the destination node 142 contains a standard public key certificate for the home agent 145, the destination node 142 transits between ABKp2 and ABKp3, a TLS (Transport Level Security, RFC 2246) protocol. Etc. are used. This TLS protocol prevents interference with home agent transactions.
【0050】
Mobile node 135 can launch a redirect attack. In this case, a response information update is sent to the destination node 142, including a false awareness address (CoA) on a different subnet that houses the victim of the redirect attack. The communication destination node 142 redirects the traffic of the mobile node to the victim even if the victim of the redirect attack has no interest in the traffic of the mobile node. A redirect attack by requesting the mobile node 135 to use the interface identifier assigned to the mobile node 135 by the home agent 145 for the home address (HoA) of the mobile node 135 so that it also forms a notice address (CoA). Can be prevented. Further, by using the interface identifier as the home address, the mobile node 135 can prevent different nodes from forming an address other than the awareness address (CoA) corresponding to the mobile node 135. Mobile node 135 uses the same interface identifier for all care addresses (CoA). Using the same identifier does not limit route optimization. This is because route-optimized packets in any case include a home address option that includes a home address.
【0051】
If the key expires or the parameters change, the address-based key (ABK) distribution protocol first moves the address-based key (ABK) from the home agent 145 (possibly periodically) to the mobile node 135. To provide. The ABK distribution protocol uses TCP (Transmission Control Protocol) transport for ports that should be assigned by, for example, IANA (Internet Assigned Number Authority). The ABK protocol is protected using the IPsec ESP (encapsulating security payload) and the Home Agent / Mobile Node Security Association defined by the Standard Mobile IPv6 Standard. The ABK protocol is a protocol that contains two messages, an ABK request and an ABK response.
【0052】
FIG. 3 shows the structure of the ABK request message. An ABK request message is sent from mobile node 135 to home agent 145 to request a new ABK. The source address of this message is the home address of the mobile node. The destination address is the home agent address. The ABK message may include an IPsec header, such as an ESP-IPsec header, to represent a security association established between the home agent and the mobile node. In addition, the packet containing the message may be encrypted using the shared key. A numerical value such as 5, for example, is set in the message type code area 300 of the identifier included in the ABK request message. The algorithm identifier number area 310 is a non-zero, non-zero, 4-byte algorithm identifier record number. The algorithm identifier area 320 has a 2-byte individual encryption algorithm identifier assigned to each record by IANA. The parameter version number area 330 contains a 2-byte parameter version number indicating the algorithm identifier.
【0053】
When the mobile node 135 is not in the home network, the notice address (CoA) and the home address (HoA) are effectively linked before sending the message. The mobile node 135 then reverse-tunnels the message to the home agent 145 to avoid ingress filtering to other subnets. The mobile node 135 has an identifier-based cryptographic algorithm identifier list showing the algorithm to which it corresponds and the latest version number of the parameter known to the mobile node 135. The list of individual cryptographic algorithm identifiers may be ordered in order of preference for the mobile node, eg, the most preferred algorithm.
【0054】
The IPsec Security Association ensures that only mobile node 135 assigned a valid home address (HoAs) can communicate with home agent 145. Upon receipt of the ABK request, Home Agent 145 calculates a private key (IPrK) for each algorithm in the algorithm identifier list whose parameter version number does not match the latest version number. First, the home agent 145 creates a public key based on the source address of the packet (pointing to the home address as a public identifier, etc.) and the SNTP expiration time. The home agent 145 then creates a private key from the public key, parameters, and algorithms. The result of generating the private key is replied to the mobile node 134 with an ABK response message.
【0055】
FIG. 4 shows the structure of the ABK response message. The ABK response message contains a list of parameters corresponding to the algorithm requested by mobile node 135 and corresponding to home agent 145. In addition, the (key) expiration time value used by mobile node 135 to calculate the public key is included in the ABK response message. For the IP area, the source address of the ABK response message corresponds to the home agent address. The destination address corresponds to the home address (HoA) of the mobile node. Regarding the IP header, the ESP-IPsec header is added to the security association of the home agent / mobile node, and the packet body is encrypted with the shared key.
【0056】
Regarding the configuration of the message area, a numerical value such as 6 is set in the ABK message type code area 400. This code separates ABK response messages from other messages. The key expiration time domain 410 contains a 4-byte positive number indicating the time the key expires. The parameter / key number record area 420 contains the number of variable length records (parameter records and key records to be followed) for each algorithm. For each parameter record and key record, the parameter / key record length area 430 contains an algorithm identifier area 440, a parameter version number area 450, and a parameter + private key list area 460 to follow. Indicates the length (bytes) of. The algorithm identifier area 440 contains a 2-byte individual cryptographic algorithm identifier assigned by IANA for each record. The parameter version number area 450 contains a 2-byte parameter version number indicating the algorithm identifier. The parameter + private key list area 460 contains a variable length parameter and a private key list whose format is specified by the algorithm identifier standard.
【0057】
In response to the ABK request, Home Agent 145 returns an ABK response message, encrypted and with the appropriate ESP protection headers. If mobile node 135 does not belong to the home network, the ABK response message is passed to mobile node 135 through the care address (CoA). This mechanism is the same as the flow in which traffic is routed through the home address (HoA) of mobile node 135. If the home agent 145 does not correspond to any algorithm requested by the mobile node 135, the key expiration time domain 410 and the parameter / key record number domain 420 each show zero. On the other hand, if the home agent supports the algorithm required by the mobile node, each region shows a non-zero value. If the home agent 145 does not correspond to a particular algorithm, a record is stored in the algorithm identifier area 440 of the indicated algorithm. Also, if the algorithm does not correspond, the parameter version number area 450 shows zero and the parameter + private key area 460 is not used.
【0058】
If the parameter version of the ABK request for the particular algorithm corresponding to mobile node 135 is the currently operating version, the records are stored in the algorithm identifier area 440 of the requested algorithm and the current parameter version number area 450. The algorithm. However, the parameter + private key area 460 is not used. The mobile node 135 continues to use the cached parameters and private key until the parameters change or the key expires. An IPsec security association is a connection that ensures that the home agent 145 can send ABK response messages to mobile node 135. Upon receiving the ABK response message, the mobile node caches the private key and parameters for each algorithm to protect the correspondence information update. When the private key in use expires, mobile node 135 requests the corresponding individual encryption algorithm from the home agent to issue a new private key.
【0059】
In the parameter initialization process, the mobile node 135 requests the communication destination node 142 to initialize the parameters received from the home agent 145. The mobile node 135 executes a parameter initialization protocol when changing its own private key or parameters. The parameter initialization protocol is the port assigned to the IANA destination option header, which is used as the ABK distribution protocol, and uses the TCP protocol. If the mobile node 135 is not in the home network when it initiates the protocol, it reverse-tunnels the ABKp1 message to the destination node 142 via the home agent 145 to initiate the protocol. The ABKp4 message is replied to the mobile node 135 via the home agent 145 by the standard mobile IP mechanism. The ABKp2 message and the ABKp3 message are exchanged between the communication destination node 142 and the home agent 145.
【0060】
Figure 5 shows the structure of the ABKp1 message. When the mobile node 135 is not in the home network, the ABKp1 message is reverse tunneled from the mobile node 135 via the home agent 145 to the communication destination node 142 as a protocol for protecting the correspondence information update. The source address at this time is the home address of the mobile node 135. The destination address is the address of the communication destination node 142. In order to distinguish it from other messages, a numerical value such as 1 is set in the message type code 500. The algorithm identifier number region 510 contains a contiguous 4-byte algorithm identifier record number 520 that is greater than zero. The algorithm identifier area 520 contains an encryption algorithm identifier based on a 2-byte identifier assigned to each record by IANA. The parameter version number area 530 is a 2-byte parameter version number assigned to the algorithm identifier. The parameter version number is a number that identifies the parameter version currently held by the mobile node 135. The key expiration time domain 540 is a 4-byte SNTP time that specifies the key expiration time of the mobile node.
【0061】
FIG. 6 shows the structure of the ABKp2 message. The ABKp2 message is sent to the home agent 145 by the destination node 142. The source address of the ABKp2 message is the address of the communication destination node 142. The destination address is a home agent anycast address located within the subnet of the mobile node. This home agent anycast address is determined by the home address subnet prefix contained in the mobile node 135. The message area includes the message type area 600. Then, the message type code is indicated by a different number such as 2, for each message. If you want to ignore sending and receiving messages, the spare area 610 is set to zero. In the provisional message authentication code area 620, the provisional message authentication code (160-bit H-MAC) Identify SHA-1). In the home address area 630, the home address of the mobile node 135 is specified. The algorithm identifier number area 640 identifies the number of consecutive 2-byte algorithm identifier records that are non-zero. The algorithm identifier list area 650 identifies a 2-byte individual cryptographic algorithm assigned to each record by IANA or another entity.
【0062】
Among the algorithms transmitted from the mobile node 135 and included in the ABKp1 message and corresponding to the communication destination node 142, there is an algorithm whose parameter version number does not match the parameter version number cached by the communication destination node 142. The algorithm identifier list identifies such algorithms. If a parameter version number that matches at least one of the algorithms contained in the list sent from the mobile node 135 in the ABKp1 message is cached internally, the destination node 142 does not send the ABKp2 message. This is because the communication node 142 uses an algorithm that matches the algorithm of the mobile node 135.
【0063】
FIG. 7 shows the structure of the ABKp3 message. The source address of this message is the home agent 145's address. The destination address is the address of the communication destination node 142. The message area includes the message type area 700. In this area, a unique message type code such as 3, for example, is shown for the ABK message. Area A 710 identifies an unconfigured command or a configured command. Here, when the home agent 145 asks the mobile node 135 to use the same interface identifier as the home address (HoA) for the awareness address (CoA), an unconfigured command is used. On the other hand, when a different address translation authentication process is performed, a setting command is used. The spare area 720 is set to zero when sending a message. In the provisional message authentication code area 730, the provisional message authentication code (160-bit H-MAC SHA-1) that matches the provisional value sent in the ABKp2 message is specified.
【0064】
The parameter record number area 740 identifies the variable length parameter record number. The parameter record length area 750 identifies the length (in bytes) of the parameter record, including the algorithm identifier area 760, the parameter version number area 770, and the parameter area 780 for each record. Algorithm identifier area 760 has a 2-byte individual cryptographic algorithm identifier assigned to each record by IANA. The parameter version number area 770 contains a 2-byte parameter version number attached to the algorithm identifier. The parameter area 780 includes a variable length parameter area 790 whose format is determined according to the algorithm identifier standard.
【0065】
If it does not have a record indicating the home address (HoA) of the mobile node 135, the home agent 145 responds to the destination node with an ABKp3 message with the parameter record number area 740 set to zero. The parameter record number area 740 does not have to be set to zero. If the home agent 145 does not support any of the algorithms in the list sent in the ABKp3 message, it sends a record containing that algorithm to the algorithm identifier area 760. In this record, the parameter version number area 770 is set to zero and there are no parameters in the parameter area 780. In another embodiment, the home agent 145 stores a parameter record for each algorithm contained in the ABKp2 message having that parameter.
【0066】
FIG. 8 shows the structure of the ABKp4 message. Regarding the IP address area of this message, the source address corresponds to the address of the communication destination node. On the other hand, the home address of the mobile node is the destination address. The message includes a message type region 800. In this area, a message number such as 4, indicating a message type code, is set for the ABK message. The status code area 810 contains a code indicating a message status. A code example is shown below. 0 Normal state 1 ... Algorithm is not supported. If the mobile node 135 and the destination node 142 do not share the algorithm, the code "1" is returned. 2 ... The parameter has expired. For all algorithms shared with the mobile node, the code "2" is returned if the version number of the parameter returned by the home agent 145 is newer than the version number of the parameter provided by the mobile node 135.
【0067】
The algorithm identifier area 820 contains a 2-byte algorithm identifier indicating the algorithm used by the destination node 142 to create the session key. The encryption key length area 830 reveals the length of the encrypted session key (E) in bytes. As mentioned above, E has the same meaning as ENCRYPT (k_m, IPuK, Params). The encrypted session key (E) is contained in the "E" area 840.
【0068】
The algorithm identifier specification includes shared keys and other data, their respective formats. The destination node 142 selects an algorithm from the list that the mobile node 135 sends through the ABKp1 message. The parameters of the selected algorithm are available by being replied by the home agent 145 through the ABKp3 message, or by being cached from the destination node 142 if the ABKp2 or ABKp3 message is not needed. The communication destination node 142 has the identifier of the selected algorithm in the algorithm identifier area 820. Since the mobile node sorts the list according to its preference, the destination node 142 selects the algorithm closest to the first order in the list sent by the mobile node through the ABKp1 message.
【0069】
The encrypted session key area 840 contains a session key encrypted using the mobile node 135's public key (calculated from the mobile node 135's home address (HoA) and key expiration time) and algorithm parameters. .. The format of the above area is determined according to the algorithm and is an algorithm specification. If the home agent 145 informs that it does not know the home address (HoA) of the mobile node, the destination node 142 does not send a response message.
【0070】
If the destination node 142 can select an algorithm that agrees with the mobile node 135 along with its parameters, the state code area 810 is set to zero and the rest of the message is occupied. If the status code area is not set to zero, the destination node 142 does not include any other area. If the destination node 142 and the mobile node 135 agree on at least one algorithm and parameter version combination, the destination node 142 selects the agreed algorithm. The destination node 142 does not send a non-zero state code unless there is no combination option.
【0071】
The mobile node 135, which uses ABK to protect the correspondence information update, has the authentication token _mac_ calculated as described above, and the data extension that authenticates the correspondence information of standard mobile IPv6 in the authentication code area. Included in. As described above, the communication destination node 142 authenticates the authentication code. If the authentication code is not authenticated, the destination node 142 sends error code 137 (invalid authentication) to the Binding Acknowledgement. If the address translation authentication check fails, an error code is sent to mobile node 135 indicating that the care address (CoA) is not authenticated.
【0072】
Indicates the algorithm for the individual encryption algorithm to be used in the ABK correspondence information update, the algorithm type code assigned by IANA, the parameter in the ABK response message + the format representing the IPrK area, the parameter in the ABKp3 message. There is a specification that provides a format that represents the region and a format that represents the encrypted session key region in the ABKp4 message. This specification is established by the Internet Technology Task Force Standard Activity. It also asks for a TCP socket number for the protocol to be assigned by IANA. In addition, if mobile node 135 is not authenticated for changes to a care address (CoA), a mobile IP binding acknowledgment error code may be determined.
【0073】
Although the present invention has been described above with reference to various embodiments, the present invention can be modified in various ways within the ideas and scope described in the claims. Therefore, the following detailed description is intended to illustrate preferred embodiments of the invention and should be construed as not defining the invention. The present invention is defined only in the claims described above, including all relevant elements.
【0074】
[Effect of the invention]
As described above, according to the present invention, it is possible to protect the corresponding update information in the wireless communication system.
[Simple explanation of drawings]
[Figure 1]
This is an example of a wireless mobile access IP (Internet Protocol) network.
[Figure 2]
It is a ladder diagram which shows the Example of the individual encryption system for protecting the correspondence information update.
[Fig. 3]
This is a configuration example of the ABK request message.
[Fig. 4]
This is a configuration example of the ABK response message.
[Fig. 5]
This is a configuration example of ABKp1 message.
[Fig. 6]
This is a configuration example of ABKp2 message.
[Fig. 7]
This is a configuration example of ABKp3 message.
[Fig. 8]
This is a configuration example of ABKp4 message.
[Explanation of symbols]
135 ... mobile node, 142 ... communication destination node, 145 ... home agent.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9614822B2 | Cited by | United States of America | Applicant |
| JP2013506388A | Cited by | Japan | Examiner |
| JP2010504667A | Cited by | Japan | Examiner |
| US8468354B2 | Cited by | United States of America | Applicant |
12 priority claims, no other members on record
Priority claims12
| Document | Office | Kind | Date |
|---|---|---|---|
| 35817702 | United States of America | P | |
| 60358177 | United States of America | – | |
| 41602902 | United States of America | P | |
| 60416029 | United States of America | – | |
| 10364289 | United States of America | – | |
| 36428903 | United States of America | A | |
| 2002358177 | – | – | – |
| 2002416029 | – | – | – |
| 2003364289 | – | – | – |
| US20020358177P | – | – | – |
| US20020416029P | – | – | – |
| US20030364289 | – | – | – |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawn because no request for examination was validly filedWithdrawnA300 | A300 |
Numbers
- Publication
- 2003-324419
- Publication, DOCDB
- 2003324419
- Publication, EPODOC
- JP2003324419
- Application
- 41758
- Application, DOCDB
- 2003041758
- Application, EPODOC
- JP20030041758
Titles3
- Japanese
- 【発明の名称】アドレス・ベースド・キ-を使用して対応情報更新を保護する方法
- English
- [Title of the Invention] A method of protecting correspondence information update by using an address-based key.
- English
- METHOD OF SECURING BINDING UPDATE BY USING ADDRESS BASED KEY
Classification
- CPC, 16
- H04M1/68
- H04L9/0825
- H04L9/0891
- H04L63/0272
- H04L63/0442
- H04L63/06
- H04L63/123
- H04L63/164
- H04L2209/80
- H04L2463/062
- H04W8/06
- H04W80/04
- H04W12/0431
- H04W12/0433
- H04W12/102
- H04W12/108
- IPC, 10
- H04L9 08
- H04L9 30
- H04L12 28
- H04L12 56
- H04L29 06
- H04M1 68
- H04W8 04
- H04W12 04
- H04W12 06
- H04W36 00