1 November 2006 in Dagstuhl, Germany

Slides:



Advertisements
Similar presentations
Approaches to Multi-Homing for IPv6 An Architectural View of IPv6 MultiHoming proposals Geoff Huston 2004.
Advertisements

Architectural Approaches to Multi-Homing for IPv6 A Walk-Through of draft-huston-multi6-architectures-00 Geoff Huston June 2004.
1 An Update on Multihoming in IPv6 Report on IETF Activity IPv6 Technical SIG 1 Sept 2004 APNIC18, Nadi, Fiji Geoff Huston.
Internet Area IPv6 Multi-Addressing, Locators and Paths.
3G WLAN handover Gabor Bajko Nokia. Experiment Upstream-router DSMIP6-HA V6 V4 V6 Internet WiFi HSPA DSMIP6 Home Agent.
CCNA1 v3 Module 9 v3 CCNA 1 Module 9 JEOPARDY K. Martin Galo Valencia.
CST Computer Networks NAT CST 415 4/10/2017 CST Computer Networks.
NAT, firewalls and IPv6 Christian Huitema Architect, Windows Networking Microsoft Corporation.
IPv4 - IPv6 Integration and Coexistence Strategies Warakorn Sae-Tang Network Specialist Professional Service Department A Subsidiary.
Transitioning to IPv6 April 15,2005 Presented By: Richard Moore PBS Enterprise Technology.
Auto Configuration and Mobility Options in IPv6 By: Hitu Malhotra and Sue Scheckermann.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implementing IP Addressing Services Accessing the WAN – Chapter 7.
IPv6 Overview Brent Frye EECS710. Overview Google Drive Microsoft Cloud Drive Dropbox Paid-for alternatives 2.
Project by: Palak Baid (pb2358) Gaurav Pandey (gip2103) Guided by: Jong Yul Kim.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 W. Schulte Chapter 5: Network Address Translation for IPv4  Connecting.
© 2007 Cisco Systems, Inc. All rights reserved.ICND2 v1.0—7-1 Address Space Management Transitioning to IPv6.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Lecture15: Network Address Translation for IPv4 Connecting Networks.
1 Introduction "Internet Protocol version 6" Presenter Veena Merz Manager Cisco Networking Area Academy.
CMPE 150- Introduction to Computer Networks 1 CMPE 150 Fall 2005 Lecture 25 Introduction to Computer Networks.
IP Version 6 Next generation IP Prof. P Venkataram ECE Dept. IISc.
Understanding Internet Protocol
1 Address Selection, Failure Detection and Recovery in MULTI6 draft-arkko-multi6dt-failure-detection-00.txt Multi6 Design Team -- Jari Arkko, Marcelo Bagnulo,
IPv6 Multihoming Support in the Mobile Internet Presented by Paul Swenson CMSC 681, Fall 2007 Article by M. Bagnulo et. al. and published in the October.
Ch. 1 – Scaling IP Addresses NAT/PAT and DHCP CCNA 4 version 3.0.
IPv4 and IPv6 Mobility Support Using MPLS and MP-BGP draft-berzin-malis-mpls-mobility-00 Oleg Berzin, Andy Malis {oleg.berzin,
IPv6 Address Provisioning In IPv6 world there are three provisioning aspects wich are independent of whether the IPv6 node is a Host or CE router: IPv6.
COM555: Mobile Technologies Location-Identifier Separation.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
Lecture Week 7 Implementing IP Addressing Services.
1 IPv6 Address Management Rajiv Kumar. 2 Lecture Overview Introduction to IP Address Management Rationale for IPv6 IPv6 Addressing IPv6 Policies & Procedures.
1 Introduction on the Architecture of End to End Multihoming Masataka Ohta Tokyo Institute of Technology
Host Identity Protocol
2002 년 2 학기이동인터넷프로토콜 1 Mobile IP:Overview 년 2 학기이동인터넷프로토콜 2 Mobile IP overview Is Mobile IP an official standard? What problems does Mobile IP solve?
Host Mobility for IP Networks CSCI 6704 Group Presentation presented by Ye Liang, ChongZhi Wang, XueHai Wang March 13, 2004.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 4 v3.0 Module 1 Scaling IP Addresses.
7 IPv6: transition and security challenges Selected Topics in Information Security – Bazara Barry.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Implementing IP Addressing Services Accessing the WAN – Chapter 7.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Cisco Certified Network Associate CCNA Access the WAN Asst.Prof. It-arun.
Implementing IP Addressing Services Accessing the WAN – Chapter 7.
NEMO Requirements and Mailing List Discussions/Conclusions T.J. Kniveton - Nokia Pascal Thubert - Cisco IETF 54 – July 14, 2002 Yokohama, Japan.
 An Internet Protocol address (IP address) is a numerical label assigned to each device (e.g., computer, printer) participating in a computer network.
Page 1 Network Addressing CS.457 Network Design And Management.
1 NCM _05_2001_c1 © 2001, Cisco Systems, Inc. All rights reserved. How would you prepare for the technology you need.
Lesson 2 Introduction to IPv6.
An Update on Multihoming in IPv6 Report on IETF Activity RIPE IPv6 Working Group 22 Sept 2004 RIPE 49 Geoff Huston, APNIC.
Approaches to Multi6 An Architectural View of Multi6 proposals Geoff Huston March 2004.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 11: Network Address Translation for IPv4 Routing And Switching.
W&L Page 1 CCNA CCNA Training 3.4 Describe the technological requirements for running IPv6 in conjunction with IPv4 Jose Luis Flores /
Making SIP NAT Friendly Jonathan Rosenberg dynamicsoft.
Deploying IPv6, Now Christian Huitema Architect Windows Networking & Communications Microsoft Corporation.
Ασύρματες και Κινητές Επικοινωνίες Ενότητα # 10: Mobile Network Layer: Mobile IP Διδάσκων: Βασίλειος Σύρης Τμήμα: Πληροφορικής.
Site Multihoming for IPv6 Brian Carpenter IBM TERENA Networking Conference, Poznan, 2005.
PAGE 1 A Firewall Control Protocol (FCON) draft-soliman-firewall-control-00 Hesham Soliman Greg Daley Suresh Krishnan
1 John Scudder, David Ward Emerging Routing Issues.
Network Layer IP Address.
CCNA4-1 Chapter 7-1 IP Addressing Services Scaling Networks With Network Address Translation (NAT)
CCNA4-1 Chapter 7-1 NAT Chapter 11 Routing and Switching (CCNA2)
Lightweight 4over6: An Extension to DS-Lite Architecture draft-cui-softwire-b4-translated-ds-lite-09 Y. Cui, Q. Sun, M. Boucadair, T. Tsou, Y. Lee and.
COM594: Mobile Technologies Location-Identifier Separation.
Mobile IP THE 12 TH MEETING. Mobile IP  Incorporation of mobile users in the network.  Cellular system (e.g., GSM) started with mobility in mind. 
Instructor Materials Chapter 9: NAT for IPv4
Global Locator, Local Locator, and Identifier Split (GLI-Split)
Routing and Switching Essentials v6.0
Implementing IP Addressing Services
Routing and Switching Essentials v6.0
Instructor Materials Chapter 9: NAT for IPv4
An Update on Multihoming in IPv6 Report on IETF Activity
Implementing IP Addressing Services
Chapter 11: Network Address Translation for IPv4
Computer Networks Protocols
Presentation transcript:

1 November 2006 in Dagstuhl, Germany

2 Identity - Locator Merge November 2006 in Dagstuhl, Germany

3 Goals of the Talk Generate some controversy Suggest that the benefits of identity- locator split are far from clear Explore a design alternative that focuses on repairing the original IP model and minimal change

4 Erosion of Identity in Addresses Addresses are both identifiers and locators. But the identity part no longer works well: No secure way to verify owner Dynamics of address assignment and node mobility make it hard to use them for identification The use of non-unique address spaces Lost in various translations

5 Identity-Locator Split Architecture A commonly suggested response to these issues involves the separation of the roles Locators are only used for routing Upper layer protocols bound to identities Cryptographic identifiers allow movement between locators, multi-homing, etc.

6 But There’s a Downside! Making applications aware of identities requires a major rewrite Identity-unaware applications will be unable to handle referrals This in turn forces us to create reverse lookup services that have either significant infrastructure costs or create administrative bottlenecks Enough bang for the buck?

7 Reality Check for the Goals (1) Solving the right problem is crucial So what is the problem? What already works?

8 Reality Check for the Goals (2) End-to-end security –High-value traffic is already secure, often application specific –(There may be value in opportunistic security) Mobility and multihoming –On longer time scales, applications, DNS etc work well –L2 handles tiny time scale; medium scale session survivability remains Multiple name spaces –But we seem to be able to do this already Routing scalability –It’s a problem. But will id/locator split help?

9 Our Suggestion 1. Repair our ability to use addresses as identifiers 2. Make the IP layer robust and secure enough to perform internetworking -- but not more Constraints: Get a 99% solution -- build for the common case NO additional configuration over basic IP Incrementally deployable Do NOT make the registry owner filthy rich

10 The Ingredients of A Solution The basic approach is to communicate using secure IPv6 addresses, employing an overlay where no native IPv6 is available –Cryptographic addresses –Overlays –IPv6 Provide reachability and secure binding for: –Mobility –Local operations, such as ND, DHCP, RVS allocation, or IPv6 transition

11 Cryptographically Generated Addresses Employ generalized CGAs: address1 = prefix | h(PK1 | PK2 … | prefix |...) Binds an IPv6 address to public keys and other data Private key can be used to sign statements from the “owner” Statement can indicate node’s other addresses (including IPv4 and MAC)

12 How Does it Work? (1) Mobility, multi-homing, ND: we have already done this earlier –See Shim6, CGA-based mobile IPv6 proposals With the session bound to overlay address, we can handle IPv4 as well –“I moved to ” Even bindings to NAT port can be handled –“I moved to :56”

13 How Does it Work? (2) DHCP, RVS or home agent allocation, tunneled IPv6 connectivity: These are similar –No pre-configuration or AAA –Modeled after local DHCP servers or anycast- reachable IPv6 tunnel servers –You do not get a permanent resource Always the same generic approach: –Agreement of a server to delegate one of its addresses for a host (address PK delegates to the host PK) –Ability of the host to prove its ownership –Optional server forwarding capability

14 Observations (1) What did NOT change: No new identity space -- no IANA, RIRs, DHTs Referrals work just like today TCP works just like today No forklift upgrade to routers ISP does not have to deploy IPv6 Backwards compatible with existing hosts

15 Observations (2) What DID change: Restores the ability of the IP address to function as an identifier Secures all address operations on hosts Sessions survive across mobility events DHCP server-like forwarding agents Challenges: Host that want the benefits need to be modified