A Hybrid Approach to Secure Hierarchical Mobile IPv6 Networks

Tianhan Gao1, Nan Guo2 and Kangbin Yim3

  1. Faculty of Software College, Northeastern University
    110819 Shenyang, China
  2. Faculty of Information Science and Engineering College, Northeastern University
    110819 Shenyang, China
  3. Faculty of Information Security Engineering, Soonchunhyang University
    336745 Asan, Korea


Establishing secure access and communications in a hierarchical mobile IPv6 (HMIPv6) network, when a mobile node is roaming into a foreign network, is a challenging task and has so far received little attention. Existing solutions are mainly based on public key infrastructure (PKI) or identity-based cryptography (IBC). However, these solutions suffer from either efficiency or scalability problems. In this paper, we leverage the combination of PKI and certificate-based cryptography and propose a hierarchical security architecture for the HMIPv6 roaming service. Under this architecture, we present a mutual authentication protocol based on a novel cross-certificate and certificate-based signature scheme. Mutual authentication is achieved locally during the mobile node�s handover. In addition, we propose a key establishment scheme and integrate it into the authentication protocol which can be utilized to set up a secure channel for subsequent communications after authentication. As far as we know, our approach is the first addressing the security of HMIPv6 networks using such a hybrid approach. In comparison with PKI-based and IBC-based schemes, our solution has better overall performance in terms of authenticated handover latency.

Key words

hierarchical mobile IPv6, mutual authentication, identity-based cryptography, certificate-based cryptography, cross-certificate

Volume 10, Issue 2 (April 2013)
Special Issue on Advances on Mobile Collaborative Systems
Year of Publication: 2013
ISSN: 1820-0214 (Print) 2406-1018 (Online)
Publisher: ComSIS Consortium

Gao, T., Guo, N., Yim, K.: A Hybrid Approach to Secure Hierarchical Mobile IPv6 Networks. Computer Science and Information Systems, Vol. 10, No. 2, 913-938. (2013)