internet goes mobile

35
Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

Upload: ulema

Post on 25-Feb-2016

29 views

Category:

Documents


0 download

DESCRIPTION

Internet Goes Mobile. Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea. Internet - Yesterday. T1. Enterprise Network. Internet. Dial up. DSL. Home user. Home Network. Internet - Today and Tomorrow. W-CDMA. T1. Enterprise Network. Operator Network. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Internet Goes Mobile

Internet Goes Mobile

Alper Yegin

KIOW 2003 at APNIC 16August 19th, 2003. Seoul, Korea

Page 2: Internet Goes Mobile

2

Internet - Yesterday

Internet

DSL

Home Network

Dial up

Home user

T1Enterprise Network

Page 3: Internet Goes Mobile

3

Internet - Today and Tomorrow

Internet

DSL

Home Network

DSL

Home NetworkMobile Network

GPRSDial up

Home user

W-CDMA

T1Enterprise Network Operator NetworkCommunity Network

PAN

Page 4: Internet Goes Mobile

4

Challenge

• Users expect the same characteristics (greedy!)– Secure– Reliable– Seamless– High performance

• Burden is on:– Standards bodies (IETF, IEEE, 3GPP, 3GPP2, etc.)– Vendors– Operators

Page 5: Internet Goes Mobile

5

Security

• First things first!• Physical security is replaced with crypto-

based security– Threats: Eavesdropping, spoofing– Not a full replacement!

• Crypto designs and experts get a good exercise!

Page 6: Internet Goes Mobile

6

Solutions

• Good solutions:– 3GPP, 3GPP2

• Bad solutions– IEEE WEP fiasco!

• Practical but less than adequate solutions:– WECA WISPer: HTTP redirect and web-based login

hackery• Practical and reasonable solutions:

– IEEE 802.11b access outside VPN gateway

Page 7: Internet Goes Mobile

7

The Right Solution• Authenticate, authorize the client• Accounting and privacy

Home Network

Visited Network

host

AP

AccessRouter

HomeAAA ISP

AAA

PANA, 802.1X

Diameter, RADIUS

Diameter, RADIUS

Page 8: Internet Goes Mobile

8

The Right Solution• IETF AAA, EAP, and PANA Working Groups• IEEE 802.11i, 802.1aa

Home Network

Visited Network

host

AP

AccessRouter

HomeAAA ISP

AAA

PANA, 802.1X

Diameter, RADIUS

Diameter, RADIUS

Page 9: Internet Goes Mobile

9

Global AAA

• AAA web of trust is here (unlike global PKI) and more capable.

Home Network

Visited Network

AAAserver

AAAserver

Visited Network

AAAserver

Home Network

AAAserver

AAAbroker

AAAbroker

Page 10: Internet Goes Mobile

10

Impact• Security is never plug-and-play (plug-and-get-hacked!)• Additional infrastructure

– Front-end AAA servers (NAS)– Backend AAA servers (RADIUS, Diameter servers)– VPN gateways

• Configuration– On the clients– Per-client configuration on the servers (keys, authorization

parameters, etc.) – Configuration to join the AAA web-of trust

Page 11: Internet Goes Mobile

11

Impact

• Increased popularity of IPsec and TLS– AAA requires confidential information exchange– VPN– Anonymizer.com

• Strengthening internal network is a MUST– Unless you are 100% sure that wireless access is secure– Partitioning, IDS, enforcing strict policy execution

(social aspects)

Page 12: Internet Goes Mobile

12

But Still

• …. You are vulnerable to attacks!

• Price of going wireless

Page 13: Internet Goes Mobile

13

Mobility Management

• Host at home (fixed Internet).

Home Network

Visited Network

Web server

hosta::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

a::/64

AP

Page 14: Internet Goes Mobile

14

Mobility Management

• You move, you break!

Home Network

Visited Network

Web server

AP

AP APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

hostb::1

b::/64

Page 15: Internet Goes Mobile

15

Mobile IP

• IETF Mobile IP Working Group– www.ietf.org/html.charters/mobileip-charter.html

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

a::1b::1

homeaddress

care-ofaddress

Page 16: Internet Goes Mobile

16

Mobile IP

• Traffic tunneled through home network

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

Page 17: Internet Goes Mobile

17

Mobile IP

• End-to-end signaling for route optimization

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

a::1b::1

homeaddress

care-ofaddress

Page 18: Internet Goes Mobile

18

Mobile IP

• Most direct path for data traffic.

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

Page 19: Internet Goes Mobile

19

… Fast and Smooth

• Problem: Signaling latency.

Home Network

Visited Network

Web server

hostc::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64

a::1c::1

new care-ofaddress

Page 20: Internet Goes Mobile

20

… Fast and Smooth• Fast Handovers

– draft-ietf-mobileip-fast-mipv6-06.txt

• IETF Seamoby Working Group– www.ietf.org/html.charters/seamoby-charter.html

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64b::1c::1

hostc::1

old care-ofaddress new care-of

address

Page 21: Internet Goes Mobile

21

… Fast and Smooth• Context transferred and routes fixed.

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64

hostc::1

Page 22: Internet Goes Mobile

22

… Privacy

• Hide precise location and movement.

Home Network

Visited Network

Web server

hostd::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APd::/64

c::/64b::/64

cafeteria CEO’s office employee office

Page 23: Internet Goes Mobile

23

… Privacy

• Obtain an IP address from the localized mobility agent.

Home Network

Visited Network

Web server

hostd::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APd::/64

c::/64b::/64

LocalizedMobility Agent

e::1d::1

e::/64 a::1e::1

regionalcare-ofaddress

localcare-ofaddress

homeaddress

Page 24: Internet Goes Mobile

24

… Privacy

• Correspondent sends packets directly to the agent. Agent tunnels them to the precise location.

Home Network

Visited Network

Web server

hostd::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APd::/64

c::/64b::/64

LocalizedMobility Agent

Page 25: Internet Goes Mobile

25

… Privacy

• Correspondent does not know the real IP destination, or when it changes.

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64b::/64

LocalizedMobility Agent

hostb::1

Page 26: Internet Goes Mobile

26

… AAA

• Mobility management is a for-profit “service”

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64b::/64

LocalizedMobility Agent

hostb::1

HomeAAA ISP

AAA

Page 27: Internet Goes Mobile

27

… Network is Mobile

• IETF NEMO Working Group– www.ietf.org/html.charters/nemo-charter.html

Visited NetworkAccessRouter

AccessRouter

AccessRouter

BaseStation

BaseStation

BaseStation

Page 28: Internet Goes Mobile

28

Impact on Intranet

• More stateful servers– Home agents, access routers (for context transfer and

fast handovers), localized mobility agents– Mobile IP bindings, tunnels, host-routes– Redundancy and fault-tolerance are MUST!

• More configuration– Per client on the servers– Trust relations among communicating servers

Page 29: Internet Goes Mobile

29

Impact on Internet/Intranet

• Tunnels– Several levels of nesting

Web server HomeAgent

LocalizedMobility Agent

PreviousAccessRouter

hostCurrentAccessRouter

Fast Handovers

Localized Mobility Management

Mobile IP

HomeAddress (Regional)

Care-ofAddress

(Older local)Care-ofAddress

(Current local)Care-ofAddress

Page 30: Internet Goes Mobile

30

Impact on Internet

• Address consumption– Always-on hosts– Purpose-specific address usage (home address, care-of

address)– Multihomed devices (GPRS, IEEE 802.11b, Bluetooth)– Sensor networks

Page 31: Internet Goes Mobile

31

Impact on Internet

• Suboptimal routing, redirect servers

host A

host B

HomeAgent A

HomeAgent B

Page 32: Internet Goes Mobile

32

Host Assumptions

• Can be anything:

• Dynamic auto-configuration needed:– IPv6 address auto-configuration (RFC 2462)– IPv6 prefix delegation (draft-troan-dhcpv6-opt-prefix-delegation-02.txt)– Service discovery (IPv6 anycast address support)

Page 33: Internet Goes Mobile

33

IPv6• IPv6 benefits:

– Ability to run server apps on devices (accept incoming connections)

– Plug-and-play– End-to-end IPsec for thwarting first-hop and last-hop threats– Mobile IPv6 : Efficient, easy to deploy and manage, and

scalable mobility protocol– Extensibility

• Mobile and wireless Internet will expedite the transition from IPv4-NAT to IPv6

• www.isoc.org/briefings/014/index.html

Page 34: Internet Goes Mobile

34

Conclusion

• Wireless and mobility provide tremendous benefits, but they come with a price.

• Transitioning the Internet protocols, architectures, products, and running networks should be done very carefully.

Page 35: Internet Goes Mobile

Questions?