摘要:
Methods and apparatus for establishing an optimized route between a Mobile Node and a Correspondent Node are disclosed. In particular, a Correspondent Node is notified of the location of a Mobile Node, thereby enabling the Correspondent Node to communicate directly with the Mobile Node. This is accomplished by sending a HOTi message protected in IPSec transport mode from the Mobile Node to a Home Agent associated with the Mobile Node for modification and transmission of a modified HOTi message to the Correspondent Node. The Mobile Node then receives a HOT message protected in IPSec transport mode from the Home Agent associated with the Mobile Node, the HOT message being received from the Home Agent associated with the Mobile Node after modification has been performed by the Home Agent on an initial HOT message received by the Home Agent from the Correspondent Node.
摘要:
A method and implementation are disclosed for binding a mobile node to a subnet. The invention comprises steps and implementations for intercepting messages sent by a mobile node to a server, associating a predetermined subnet with the intercepted messages and forwarding the intercepted messages to the server. The invention intercepts reply messages sent by at least one server, selects reply messages that are associated with the predetermined subnet. The selected reply messages are forwarded to the mobile node and reply messages that are not associated with the predetermined subnet are discarded.
摘要:
Methods and apparatus for implementing a Mobile IP mobile router are provided. In accordance with one aspect, the Home Agent receives a registration request packet. The registration request packet may include a care-of address for the mobile router. Networks associated with the mobile router are then identified. The Home Agent then updates a routing table to associate the identified networks with the care-of address. In addition, the Home Agent updates a mobility binding table with the care-of address for the mobile router. In accordance with another aspect, routing information is exchanged between the Home Agent and the mobile router. A routing table associated with at least one of the Home Agent and the mobile router is then updated as appropriate to include the exchanged routing information.
摘要:
Methods and apparatus for registering a mobile device such as a mobile node or mobile router with a Home Agent in an asymmetric link environment. A Foreign Agent associates each of one or more interfaces of the Foreign Agent with a different care-of address. An agent advertisement including the care-of address for the one or more interfaces of the Foreign Agent is then sent via one or more uplinks. A registration request is received via a downlink router. The registration request identifies a care-of address associated with one of the one or more interfaces of the Foreign Agent. One of the interfaces identified by the care-of address is ascertained, thereby identifying the interface to which the mobile device has roamed. The registration request is forwarded to the Home Agent. A registration reply is received from the Home Agent. The registration reply is then forwarded to the mobile device via the ascertained interface.
摘要:
Methods and apparatus for processing registration requests by a Home Agent supporting Mobile IP are disclosed. A registration request is received from each of a plurality of Mobile Nodes, the registration request specifying a care-of address. A binding is established between each of the plurality of Mobile Nodes and the associated care-of address, each of the plurality of Mobile Nodes being associated with one another. For instance, the plurality of Mobile Nodes may be statically or dynamically assigned the same Home Address. A tunnel is then created between the Home Agent and the care-of address for each of the plurality of Mobile Nodes, thereby enabling a server request to be distributed by the Home Agent to one of the plurality of Mobile Nodes via the associated tunnel. For instance, a server request addressed to the Home Address may be forwarded to one of the Mobile Nodes assigned that Home Address.
摘要:
Methods and apparatus for optimizing IP multicast data transmission in a mobile IP environment include a Foreign Agent that is capable of receiving an information request associated with a host membership report sent from a mobile node and for providing information identifying a Home Agent associated with the mobile node to a multicast router process to enable the multicast router process to send a join host group message to the Home Agent. A Home Agent receives the join host group message and sends the join host group message toward a source of IP multicast data packets. Both the Foreign Agent and the Home Agent set up a data path between the Home Agent and the Foreign Agent, thereby enabling data packets addressed to the multicast group address to be forwarded by the Home Agent to the Foreign Agent. The Home Agent does not replicate multicast IP data packets addressed to the multicast group address prior to being forwarded by the Home Agent to the Foreign Agent. Rather, the multicast router process is responsible for replication and transmission of multicast IP data packets to one or more network segments associated with the Foreign Agent.
摘要:
Disclosed is a method and apparatus for automatically backing up a Home Agent in Mobile IP. The method employs important components of the widely-used Hot Standby Router Protocol, but extends it to include synchronization of the mobility binding table between an active Home Agent and a standby Home Agent that backs it up. Also disclosed is a more general protocol for extending HSRP and related redundancy protocols to synchronize higher level functions other than mobility binding lists in Mobile IP (e.g., address translation tables in Network Address Translation (NAT), address bindings in Dynamic Host Configuration Protocol (DHCP) servers, dynamic ACL in Reflexive Access List, and TCP and GTP layer context in GPRS support nodes: SGSN & GGSN). Still other protocols that could benefit from HSRP include Lock and Key, Context-Based Access List, IP Security (IPSec), and H.323 gatekeeper.
摘要:
In one embodiment, a method includes identifying unusual behavior with respect to a handshake between a first endpoint and a second endpoint that are included in a network, and determining whether the unusual behavior with respect to the handshake indicates presence of malicious software. The method also includes identifying at least one of the first endpoint and the second endpoint as potentially being infected by the malicious software if it is determined that the unusual behavior with respect to the handshake indicates the presence of malicious software.
摘要:
A method is provided in one example embodiment and includes receiving a discover message over a network; determining that the discover message is associated with an unauthenticated client (e.g., identifying a media access control (MAC) address); communicating a proxy binding update (PBU) having a binding type value set to a temporary status; and establishing a bidirectional tunnel for transporting traffic for the client.
摘要:
Various security mechanisms may be used independently, or in combination with one another, to authenticate the identity of a node during the Mobile IP registration process. First, an Access Point receiving a packet from a node verifies that the source MAC address identified in the packet is in the Access Point's client association table. In addition, as a second mechanism, the Access Point ensures that a one-to-one mapping exists for the source MAC address and source IP address identified in the packet in a mapping table maintained by the Access Point. As a third mechanism, a binding is not modified in the mobility binding table maintained by the Home Agent unless there is a one-to-one mapping in the mobility binding table between the source MAC address and the source IP address. Similarly, the Foreign Agent may also maintain a mapping between the source IP address and the source MAC address in its visitor table to ensure a one-to-one mapping between a source IP address and the associated MAC address.