internet goes mobile alper yegin kiow 2003 at apnic 16 august 19th, 2003. seoul, korea

35
Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

Upload: caroline-preston

Post on 30-Dec-2015

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

Internet Goes Mobile

Alper Yegin

KIOW 2003 at APNIC 16

August 19th, 2003. Seoul, Korea

Page 2: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

2

Internet - Yesterday

Internet

DSL

Home Network

Dial up

Home user

T1Enterprise Network

Page 3: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

3

Internet - Today and Tomorrow

Internet

DSL

Home Network

DSL

Home NetworkMobile Network

GPRS

Dial up

Home user

W-CDMA

T1Enterprise Network Operator Network

Community Network

PAN

Page 4: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

4

Challenge

• Users expect the same characteristics (greedy!)– Secure

– Reliable

– Seamless

– High performance

• Burden is on:– Standards bodies (IETF, IEEE, 3GPP, 3GPP2, etc.)

– Vendors

– Operators

Page 5: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

5

Security

• First things first!

• Physical security is replaced with crypto-based security– Threats: Eavesdropping, spoofing– Not a full replacement!

• Crypto designs and experts get a good exercise!

Page 6: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

6

Solutions

• Good solutions:– 3GPP, 3GPP2

• Bad solutions– IEEE WEP fiasco!

• Practical but less than adequate solutions:– WECA WISPer: HTTP redirect and web-based login

hackery

• Practical and reasonable solutions:– IEEE 802.11b access outside VPN gateway

Page 7: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

7

The Right Solution

• Authenticate, authorize the client• Accounting and privacy

Home Network

Visited Network

host

AP

AccessRouter

HomeAAA

ISPAAA

PANA, 802.1X

Diameter, RADIUS

Diameter, RADIUS

Page 8: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

8

The Right Solution• IETF AAA, EAP, and PANA Working Groups• IEEE 802.11i, 802.1aa

Home Network

Visited Network

host

AP

AccessRouter

HomeAAA

ISPAAA

PANA, 802.1X

Diameter, RADIUS

Diameter, RADIUS

Page 9: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

9

Global AAA

• AAA web of trust is here (unlike global PKI) and more capable.

Home Network

Visited Network

AAAserver

AAAserver

Visited Network

AAAserver

Home Network

AAAserver

AAAbroker

AAAbroker

Page 10: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

10

Impact

• Security is never plug-and-play (plug-and-get-hacked!)

• Additional infrastructure– Front-end AAA servers (NAS)– Backend AAA servers (RADIUS, Diameter servers)– VPN gateways

• Configuration– On the clients– Per-client configuration on the servers (keys, authorization

parameters, etc.) – Configuration to join the AAA web-of trust

Page 11: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

11

Impact

• Increased popularity of IPsec and TLS– AAA requires confidential information exchange

– VPN

– Anonymizer.com

• Strengthening internal network is a MUST– Unless you are 100% sure that wireless access is secure

– Partitioning, IDS, enforcing strict policy execution (social aspects)

Page 12: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

12

But Still

• …. You are vulnerable to attacks!

• Price of going wireless

Page 13: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

13

Mobility Management

• Host at home (fixed Internet).

Home Network

Visited Network

Web server

hosta::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

a::/64

AP

Page 14: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

14

Mobility Management

• You move, you break!

Home Network

Visited Network

Web server

AP

AP APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

hostb::1

b::/64

Page 15: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

15

Mobile IP

• IETF Mobile IP Working Group– www.ietf.org/html.charters/mobileip-charter.html

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

a::1b::1

homeaddress

care-ofaddress

Page 16: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

16

Mobile IP

• Traffic tunneled through home network

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

Page 17: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

17

Mobile IP

• End-to-end signaling for route optimization

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

a::1b::1

homeaddress

care-ofaddress

Page 18: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

18

Mobile IP

• Most direct path for data traffic.

Home Network

Visited Network

Web server

hostb::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APb::/64

Page 19: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

19

… Fast and Smooth

• Problem: Signaling latency.

Home Network

Visited Network

Web server

hostc::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64

a::1c::1

new care-ofaddress

Page 20: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

20

… Fast and Smooth• Fast Handovers

– draft-ietf-mobileip-fast-mipv6-06.txt

• IETF Seamoby Working Group– www.ietf.org/html.charters/seamoby-charter.html

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64b::1c::1

hostc::1

old care-ofaddress new care-of

address

Page 21: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

21

… Fast and Smooth

• Context transferred and routes fixed.

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64

hostc::1

Page 22: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

22

… Privacy

• Hide precise location and movement.

Home Network

Visited Network

Web server

hostd::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

AP

d::/64

c::/64b::/64

cafeteria CEO’s office employee office

Page 23: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

23

… Privacy

• Obtain an IP address from the localized mobility agent.

Home Network

Visited Network

Web server

hostd::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

AP

d::/64

c::/64b::/64

LocalizedMobility Agent

e::1d::1

e::/64 a::1e::1

regionalcare-ofaddress

localcare-ofaddress

homeaddress

Page 24: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

24

… Privacy

• Correspondent sends packets directly to the agent. Agent tunnels them to the precise location.

Home Network

Visited Network

Web server

hostd::1

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

AP

d::/64

c::/64b::/64

LocalizedMobility Agent

Page 25: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

25

… Privacy

• Correspondent does not know the real IP destination, or when it changes.

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64b::/64

LocalizedMobility Agent

hostb::1

Page 26: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

26

… AAA

• Mobility management is a for-profit “service”

Home Network

Visited Network

Web server

AP

APAP

AccessRouter

AccessRouter

AccessRouter

AccessRouter

HomeAgent

APc::/64b::/64

LocalizedMobility Agent

hostb::1

HomeAAA

ISPAAA

Page 27: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

27

… Network is Mobile

• IETF NEMO Working Group– www.ietf.org/html.charters/nemo-charter.html

Visited Network

AccessRouter

AccessRouter

AccessRouter

BaseStation

BaseStation

BaseStation

Page 28: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

28

Impact on Intranet

• More stateful servers– Home agents, access routers (for context transfer and

fast handovers), localized mobility agents

– Mobile IP bindings, tunnels, host-routes

– Redundancy and fault-tolerance are MUST!

• More configuration– Per client on the servers

– Trust relations among communicating servers

Page 29: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

29

Impact on Internet/Intranet

• Tunnels– Several levels of nesting

Web server HomeAgent

LocalizedMobility Agent

PreviousAccessRouter

hostCurrentAccessRouter

Fast Handovers

Localized Mobility Management

Mobile IP

HomeAddress

(Regional)Care-ofAddress

(Older local)Care-ofAddress

(Current local)Care-ofAddress

Page 30: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

30

Impact on Internet

• Address consumption– Always-on hosts– Purpose-specific address usage (home address, care-of

address)– Multihomed devices (GPRS, IEEE 802.11b, Bluetooth)– Sensor networks

Page 31: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

31

Impact on Internet

• Suboptimal routing, redirect servers

host A

host B

HomeAgent A

HomeAgent B

Page 32: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

32

Host Assumptions

• Can be anything:

• Dynamic auto-configuration needed:– IPv6 address auto-configuration (RFC 2462)

– IPv6 prefix delegation (draft-troan-dhcpv6-opt-prefix-delegation-02.txt)

– Service discovery (IPv6 anycast address support)

Page 33: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

33

IPv6

• IPv6 benefits:– Ability to run server apps on devices (accept incoming

connections)– Plug-and-play– End-to-end IPsec for thwarting first-hop and last-hop threats– Mobile IPv6 : Efficient, easy to deploy and manage, and

scalable mobility protocol– Extensibility

• Mobile and wireless Internet will expedite the transition from IPv4-NAT to IPv6

• www.isoc.org/briefings/014/index.html

Page 34: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

34

Conclusion

• Wireless and mobility provide tremendous benefits, but they come with a price.

• Transitioning the Internet protocols, architectures, products, and running networks should be done very carefully.

Page 35: Internet Goes Mobile Alper Yegin KIOW 2003 at APNIC 16 August 19th, 2003. Seoul, Korea

Questions?