Mobile IPv4 Challenge/Response Extensions
RFC 4721, “Mobile IPv4 Challenge/Response Extensions”, is a Proposed Standard document published in January 2007 by C. Perkins, P. Calhoun, J. Bharatia. It updates RFC 3344. It obsoletes RFC 3012. The canonical text is published by the RFC Editor.
Abstract
Mobile IP, as originally specified, defines an authentication extension (the Mobile-Foreign Authentication extension) by which a mobile node can authenticate itself to a foreign agent. Unfortunately, that extension does not provide the foreign agent any direct guarantee that the protocol is protected from replays and does not allow for the use of existing techniques (such as Challenge Handshake Authentication Protocol (CHAP)) for authenticating portable computer devices.
In this specification, we define extensions for the Mobile IP Agent Advertisements and the Registration Request that allow a foreign agent to use a challenge/response mechanism to authenticate the mobile node.
Furthermore, this document updates RFC 3344 by including a new authentication extension called the Mobile-Authentication, Authorization, and Accounting (AAA) Authentication extension. This new extension is provided so that a mobile node can supply credentials for authorization, using commonly available AAA infrastructure elements. This authorization-enabling extension MAY co-exist in the same Registration Request with authentication extensions defined for Mobile IP Registration by RFC 3344. This document obsoletes RFC 3012. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4721 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4724 Graceful Restart Mechanism for BGP
- RFC 4728 The Dynamic Source Routing Protocol for Mobile Ad Hoc Networks for IPv4
- RFC 4745 Common Policy: A Document Format for Expressing Privacy Preferences
- RFC 4753 ECP Groups For IKE and IKEv2
- RFC 4754 IKE and IKEv2 Authentication Using the Elliptic Curve Digital Signature Algorithm
- RFC 4760 Multiprotocol Extensions for BGP-4
- RFC 4761 Virtual Private LAN Service Using BGP for Auto-Discovery and Signaling
- RFC 4762 Virtual Private LAN Service Using Label Distribution Protocol Signaling