RFC 5269: Distributing a Symmetric Fast Mobile IPv6 (FMIPv6) Handover Key Using SEcure Neighbor Discovery (SEND)
In plain English — editorial summary, not part of the RFC
Fast Mobile IPv6 requires that a Fast Binding Update is secured using a security association shared between an Access Router and a Mobile Node in order to avoid certain attacks. In this document, a method for provisioning a shared key from the Access Router to the Mobile Node is defined to protect this signaling. The Mobile Node generates a public/private key pair using the same public key algorithm as for SEND (RFC 3971). The Mobile Node sends the public key to the Access Router. The Access Router encrypts a shared handover key using the public key and sends it back to the Mobile Node. The Mobile Node decrypts the shared handover key using the matching private key, and the handover key is then available for generating an authenticator on a Fast Binding Update. The Mobile Node and Access Router use the Router Solicitation for Proxy Advertisement and Proxy Router Advertisement from Fast Mobile IPv6 for the key exchange. The key exchange messages are required to have SEND security; that is, the source address is a Cryptographically Generated Address (CGA) and the messages are signed using the CGA private key of the sending node. This allows the Access Router, prior to providing the shared handover key, to verify the authorization of the Mobile Node to claim the address so that the previous care-of CGA in the Fast Binding Update can act as the name of the key. [STANDARDS-TRACK]
Document record
- Document ID
- RFC5269
- Published
- June 2008
- Authors
- J. Kempf; R. Koodli
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- int
- Pages
- 14
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 5268Mobile IPv6 Fast HandoversObsoleted
June 2008
- RFC 5270Mobile IPv6 Fast Handovers over IEEE 802.16e NetworksCurrent
June 2008
- RFC 5271Mobile IPv6 Fast Handovers for 3G CDMA NetworksCurrent
June 2008
- RFC 5266Secure Connectivity and Mobility Using Mobile IPv4 and IKEv2 Mobility and Multihoming (MOBIKE)Current
June 2008
- RFC 5265Mobile IPv4 Traversal across IPsec-Based VPN GatewaysCurrent
June 2008
- RFC 5247Extensible Authentication Protocol (EAP) Key Management FrameworkUpdated
August 2008
- RFC 5213Proxy Mobile IPv6Updated
August 2008
- RFC 5206End-Host Mobility and Multihoming with the Host Identity ProtocolObsoleted
April 2008
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?