Securing Dynamic Home Agent Address Discovery with Cryptographically Generated Addresses and RSA Signatures

With dynamic home agent address discovery (DHAAD), as specified in Mobile IPv6, a Mobile Node can discover the address of a suitable Home Agent on the home link. However, DHAAD suffers from security problems as the signaling is not authenticated nor integrity protected. The IETF has defined SEcure Neighbor Discovery that is providing security for the IPv6 Neighbor Discovery protocol, based on several asymmetric cryptographic mechanisms. It is shown that these mechanisms can also be used to secure DHAAD to increase its level of protection and to provide resistance against attacks.