DocumentCode :
423240
Title :
Security analysis and concept for the multicast-based handover support architecture MOMBASA
Author :
Westerhoff, L. ; Reinhardt, S. ; Schäfer, G. ; Wolisz, A.
Author_Institution :
Telecommun. Networks Group, Technische Univ. Berlin, Germany
Volume :
4
fYear :
2004
fDate :
29 Nov.-3 Dec. 2004
Firstpage :
2201
Abstract :
The multicast-based mobility architecture, MOMBASA, has proven to be an efficient and elegant approach for achieving low latency handover with minimum packet loss in mobile Internet communications (Festag, A. et al., Proc. Performance Tools, p.212-19, 2002). The original MOMBASA specification, however, did not include any precautions against malicious attacks on its protocol operation. We present the principal results of a security analysis of the MOMBASA architecture and describe our security concept to counter the identified threats. A main focus is put on attacks against the MOMBASA protocol operation coming into the access network from two main sources: the public Internet and the wireless link. The design of our security concept is specifically suited to ensuring a seamless handover by augmenting the predictive handover functionality of MOMBASA with an accompanying predictive distribution of authentication keys. Furthermore, the security concept includes a rate control mechanism for traffic destined for idle mobile nodes in order to limit the risks of potential denial of service (DoS) attacks against the paging mechanism. While our security measures effectively counter the identified threats from the wireless link and the Internet, first measurements with our prototype implementation show only negligible degradation of handover performance compared to unsecured MOMBASA operation.
Keywords :
4G mobile communication; IP networks; Internet; cellular radio; multicast communication; protocols; security of data; telecommunication security; telecommunication traffic; DoS attacks; IP networks; access network; authentication keys; denial of service attacks; fourth generation cellular networks; malicious attacks; mobile Internet communications; multicast-based handover support architecture; multicast-based mobility architecture; packet loss; paging mechanism; predictive handover functionality; protocol operation; public Internet; rate control mechanism; security analysis; wireless link; Access protocols; Authentication; Communication system security; Computer crime; Counting circuits; Delay; IP networks; Internet; Mobile communication; Wireless application protocol;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference, 2004. GLOBECOM '04. IEEE
Print_ISBN :
0-7803-8794-5
Type :
conf
DOI :
10.1109/GLOCOM.2004.1378400
Filename :
1378400
Link To Document :
بازگشت