Experience with the host identity protocol for secure host mobility and multihoming

نویسندگان

  • Thomas R. Henderson
  • Jeffrey M. Ahrenholz
  • Jae H. Kim
چکیده

The Host Identity Protocol (HIP) is a recent protocol proposal for secure host mobility and multihoming using a cryptographic-based name space for Internet hosts. HIP aims to decouple IP addresses from transport connections in a secure manner, thereby admitting network-level mobility and multihoming solutions that do not require the use of a single IP address as a host identifier. Although HIP and related protocol proposals have been circulating for several years, there has been little reported implementation experience with the approach. This paper reports on our experience with implementing HIP and experimenting with it as a mobility management and host multihoming solution. After first introducing the HIP approach and contrasting it with other solutions, we describe our approach for implementing HIP as an extension to Linux and FreeS/WAN IPsec, including our use and extension of standard APIs. We then characterize the performance of HIP packet exchanges experimentally, and report that the computational overhead is dominated by the DSA signing of the HIP packets. Using 266MHz Pentium II-based laptops, our HIP implementation took slightly under 1 second on average to complete connection setup, and less than 200 ms to process a mobility-initiated readdress. We also characterize the overhead due to the HIP “cookie challenge” used for stateless connection setup. We conclude by identifying areas for continued HIP development.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

On Supporting Multicast an

Recently, much effort was applied to enable secure multihoming and mobility for Internet hosts. The Host Identity Indirection Infrastructure (Hi3) is a proposal that combines benefits of Secure-i3 and the Host Identity Protocol (HIP). In this paper, we extend the Hi3 architecture to enable multicast traffic and describe the delegation mechanism in detail. A prototype implementation and prelimin...

متن کامل

Hi3: An efficient and secure networking architecture for mobile hosts

The Host Identity Indirection Infrastructure (Hi3) is a networking architecture for mobile hosts, derived from the Internet Indirection Infrastructure (i3) and the Host Identity Protocol (HIP). Hi3 has efficient support for secure mobility and multihoming, which both are crucial for future Internet applications. In this paper, we describe and analyze Hi3 in detail. Compared to existing solution...

متن کامل

Traversing Middleboxes with the Host Identity Protocol

The limited flexibility of the Internet to support mobility has motivated many researchers to look for alternative architectures. One such effort that combines security and multihoming together is the Host Identity Protocol (HIP). HIP is a signaling protocol that adds a new protocol layer to the Internet stack between the transport and the network layer. HIP establishes IPsec associations to pr...

متن کامل

End-Host Mobility and Multihoming with the Host Identity Protocol

This document defines mobility and multihoming extensions to the Host Identity Protocol (HIP). Specifically, this document defines a general "LOCATOR" parameter for HIP messages that allows for a HIP host to notify peers about alternate addresses at which it may be reached. This document also defines elements of procedure for mobility of a HIP host -the process by which a host dynamically chang...

متن کامل

Inter-subnet localized mobility support for host identity protocol

Host identity protocol (HIP) has security support to enable secured mobility and multihoming, both of which are essential for future Internet applications. Compared to end host mobility and multihoming with HIP, existing HIPbased micro-mobility solutions have optimized handover performance by reducing location update delay. However, all these mobility solutions are client-based mobility solutio...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2003