SeQoMo
1. Introduction
The focus of the SeQoMo (Security, QoS and Mobility) project (funded by Siemen AG) is to investigate the suitability of IP-based networks for support of mobility under the perspective of advanced mobility mechanisms, security, and Quality of Service (QoS). As the result of the project, a proposal for a secure and efficient QoS-aware mobility support in IP-based cellular networks has been concluded.The investigation of mobility mechanisms started from the development of the MOMBASA architecture and its software environment that enabled the use of multicast for mobility support. Finally, the Hierarchical Mobile IPv6 architecture was adapted as the mobility environment; The QoS support at first rested upon the concept of a binding update which was conditionalized upon the availability of sufficient resources in a new path during a handover. To cooperate with mobility and security functions, a CASP Mobility Client protocol was invented, subsituting the idea of QoS-conditionalized binding update approach; The security part focused on authentication, authorization and temporary security assocation establishment.
Integrating these three components harmonically for a secure and efficient QoS-aware mobility support in IP-based cellular networks was the ultimate goal of this project. To achieve the goal, the main measures include:
- enhance access router's advertisements with QoS parameters;
- separate authentication into two steps: cookie verifcation as the first step to prevent Denial of Service (DoS) attacks; authenticity verifcation with the session key as the second step;
- piggyback binding update (BU) information in the QoS signaling;
- parallelize the BU+QoS process with the authorization process;
- protect user data over wireless channels with a temporary IPSec security association if necessary.
![]() |
![]() |
| Figure 1 | Figure 2 |
Security
The identified issues in the SeQoMo environment were:- Authentication: how to authenticate a mobile node during handover;
- Authorization: how to check whether a mobile node is allowed to use the resources it requests for QoS support;
- Avoidance of explosure of user's confidential data: it is not preferable to distribute user's subscribed values contained in his Service Level Agreement (SLA) to a foreign visited domain unnecessarily for the purpose of re-authorization;
- Denial of Service (DoS) attacks: how to minimize the risk of DoS attacks such as reserving resources by bogus QoS requests and depleting the signaling capacities in the access network;
- Protection of data user over the wireless channel: how to enable IPSec between a mobile user and its associated access router efficiently.
Two patent applications have been submitted in the respect of security:
- Tianwei Chen, Guenter Schaefer, Changpeng Fan. "A Denial of Service Protection Scheme for Optimized and QoS-aware Handover in Mobile Communication Networks Based on Localized Cookies"
- Tianwei Chen, Sven Hermann, Guenter Schaefer. "User Data Protection over Wireless Channel in IP Mobility by Establishing Temporary IPSec Security Associations"
QoS
Some problems exist in current mobility protocols and QoS mechanisms: mobility mechanisms are QoS-unware and QoS mechanisms are mobility-unaware. The consequences of this situation is that after a handover QoS is either not assured or has to be renegotiated and existing end-to-end QoS signalings are not appropriate to deal with local handover operations.The QoS-conditionalized Binding Update scheme was proposed first. The basic idea is that QoS requests are carried in mobility's handover signaling messages, and evaluated by intermediate routers. If routers reserve resources if they can satisfies the requests fully or partially. The switching router decides whether a handover should take place. The prototypical implementation and the simulation of this concept have been finished.
To cooperate with mobilty and security, CASP Mobility Client Protocol was invented. The details see TKN technical reports:
- TKN-03-014: Report on CASP Mobility Client Protocol Implementation Design and First Prototype Functionality
- TKN-03-011: CASP Mobility Client Protocol specification
Mobility
The goal of the mobility in this project is to provide fast local handover support (including LL-triggers) and seamless handover support by realizing macro diversity. The approach to achieve this goal is to move th re-routing node close to the mobile node. Two approaches have been studied completely: Hierarchical Mobile IP (HMIP) and Multicast Based Mobility Support.The Hierarchical Mobile IP approach is suitable in this project. Hierarchical mobility entities address a drawback of Mobile IP: If the distance between the access point in a foreign domain and the home agent is large, the signaling delay for the registration may be long, which then results in long service disruption and packet losses. HMIPv6 proposes a hierachical mobility management model to minimize the latency due to handovers and reduce amount of mobility signalings.
Design of Multicast Based
Mobility Support (MOMBASA) has been finished. Detailed information is
available from here.
The software environment can be found from here.
To coordinate with the design of security and QoS, HMIPv6 has been selected as the mobility management scheme. A prototypical implementation of HMIPv6 and QoS-conditionalized Binding Update approach has been completed in a diploma work.
2. Publications
- T. Chen, M. Sortais, G. Schaefer, and A. Wolisz, "A Performance Study of Session State Re-establishment S chemes in IP-based Micro-mobility Scenarios", In Proc. of 12th Annual Meeting of the IEEE / ACM International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems (MASCOTS), Volendam, Netherlands, October 2004, To appear.
- T. Chen, G. Schaefer, C. Fan, S. Adams, M. Sortais, and A. Wolisz, "Denial of Service Protection for Optimized and QoS-aware Handover Based on Localized Cookies", In Proc. European Wireless 2004, Barcelona, Spain, February 2004.
- X. Fu, T. Chen, A. Festag, H. Karl, G. Sch?fer, and C. Fan, "Secure, QoS-enabled Mobility Support for IP-based Networks", In Proc. IP Based Cellular Network Conference (IPCN), Paris, France, December 2003.
- A. Neumann, X. Fu, and H. Karl, "Prototype Implementation and Performance Evaluation of a QoS-Conditionalized Handoff Scheme for Mobile IPv6 Networks", In Proc. IEEE Computer Communications Workshop (CCW), Laguna Niguel, California,USA, October 2003.
- A. Festag, H.Karl, and A. Wolisz, "Classification and Evaluation of Multicast-Based Mobility Support in All-IP Cellular Networks", In K. Irmscher, editor, Proc. Kommunikation in Verteilten Systemen (KiVS), pp. 233-244, Leipzig, Germany, February 2003.
- A. Hess and G. Sch?fer, "Performance Evaluation of AAA / Mobile IP Authentication", In Proc. of 2nd Polish-German Teletraffic Symposium (PGTS'02), Gdansk, Poland, September 2002.
- X. Fu, C. Kappler, and H. Tschofenig, "Analysis on RSVP regarding Multicast", In Proc. of 54th IETF Meeting, Yokohama, Japan, July 2002.
- X. Fu, H. Karl, and C. Kappler, "QoS-Conditionalized Handoff for Mobile IPv6", In Proc. 2nd IFIP-TC6 Networking Conf. (Networking2002), Volume 2345 of Lecture Notes in Computer Sciece (LNCS), pp. 721-730, Pisa, Italy, May 2002 Springer.
- A. Festag, L. Westerhoff, and A. Wolisz, "The MOMBASA Software Environment -- A Toolkit for Performance Evaluation of Multicast-Based Mobility Support", In Proc. of Performance Tools 2002, pp. 212-219, London, GB, April 2002.
- H. Karl and G. Sch?fer, "Location Privacy for Mobile Internet Access. Presentation", In Proc. of IP Based Cellular Network Conf. (IPCN 2001), Paris, France, May 2001.
- A. Festag and A. Wolisz, "Performance Evaluation of Mobile IP: Investigating the Concept of Hierarchical Foreign Agents", In Proc. of Mobility for All-IP Networks - Mobile IP (MAIN 2001), Berlin, Germany, April 2001.
- A. Festag and A. Wolisz, "MOMBASA: Mobility Support - A Multicast-based Approach", In Proc. of European Wireless 2000 together with ECRR 2000 (EW'2000), pp. 491-499, Dresden, Germany, September 2000.
- A. Festag, "Mobility Support in IP-based Networks - A Multicast-Based Approach", In Proc. of Eighth Workshop of the HP OpenView University Association, Berlin, Germany, June 2000.
- A. Festag, T. Assimakopoulos, L. Westerhoff, and A. Wolisz, "Rerouting for Handover in Mobile Networks with Connection-Oriented Backbones: An Experimental Testbed", In Proc. of IEEE Conf. on High Performance Switching and Routing (ICATM'2000), pp. 491-499, Heidelberg, Germany, June 2000.
(PDF)
(PDF)
(PDF)
(PDF)
(PostScript) (PDF)
(PostScript) (PDF)
(PostScript) (PDF)
(PostScript) (PDF)
(PostScript) (PDF)
(PostScript) (PDF)
(PostScript) (PDF)
(PostScript) (PDF)
(PostScript) (PDF)
- T. Chen, S. Hermann, and
G. Schäfer,
"Secure, QoS-enabled Mobility Support in All-IP Networks",
Technical Report TKN-04-013, Telecommunication Networks Group, Technische
Universität Berlin, June 2004.
(PDF) - T. Chen, A. Neumann,
S. Hermann, and G. Schäfer,
"Rationale, Design and Functionality for Secure, QoS-enabled
Mobility",
Technical Report TKN-04-012, Telecommunication Networks Group, Technische
Universität Berlin, March 2004.
(PDF) - T. Chen, S. Hermann, and
G. Schaefer,
"Report on CASP Mobility Client Protocol Implementation Design and
First Prototype Functionality",
Technical Report TKN-03-014, Telecommunication Networks Group, Technische
Universität Berlin, June 2003.
(PDF) - T. Chen and G. Schaefer,
"QoS-aware authorization for mobile devices",
Technical Report TKN-03-009, Telecommunication Networks Group, Technische
Universität Berlin, March 2003.
(PostScript) (PDF) - A. Festag,
"Optimization of Handover Performance by Link Layer Triggers in
IP-Based Networks; Parameters, Protocol Extensions, and APIs for
Implementation",
Technical Report TKN-02-014, Telecommunication Networks Group, Technische
Universität Berlin, July 2002.
(PostScript) (PDF) - X. Fu, T. Chen, A. Festag, G. Schäfer,
and H. Karl,
"SeQoMo Architecture: Interactions of Security, QoS and Mobility
Components",
Technical Report TKN-02-008, Telecommunication Networks Group, Technische
Universität Berlin, April 2002.
(PostScript) (PDF) - L. Westerhoff and A. Festag,
"Testing the Implementation of the MOMBASA Software
Environment",
Technical Report TKN-01-018, Telecommunication Networks Group, Technische
Universität Berlin, December 2001.
(PostScript) (PDF) - L. Westerhoff and A. Festag,
"Implementation Design of the MOMBASA Software Environment",
Technical Report TKN-01-017, Telecommunication Networks Group, Technische
Universität Berlin, November 2001.
(PostScript) (PDF) - A. Festag
and L. Westerhoff,
"Design, Implementation and Performance of Multicast-Based Paging
for IP Mobility (Extended Version)",
Technical Report TKN-01-015, Telecommunication Networks Group, Technische
Universität Berlin, October 2001.
(PostScript) (PDF) - A. Festag
and L. Westerhoff,
"Protocol Specification of the MOMBASA Software Environment",
Technical Report TKN-01-014, Telecommunication Networks Group, Technische
Universität Berlin, October 2001.
(PostScript) (PDF) - A. Festag, X. Fu, H. Karl,
G. Schaefer, C. Fan, C. Kappler, and M. Schramm,
"QoS-Conditionalized Binding Update in Mobile IPv6",
Technical Report TKN-01-013, Telecommunication Networks Group, Technische
Universität Berlin and Siemens AG, July 2001.
(PostScript) (PDF) - G. Schaefer, H. Karl,
and A. Festag,
"Current Approaches to Authentication in Wireless and Mobile
Communications Networks",
Technical Report TKN-01-002, Telecommunication Networks Group, Technische
Universität Berlin, March 2001.
(PostScript) (PDF) - A. Festag, H. Karl, and G. Schaefer,
"Current developments and trends in handover design for ALL-IP
wireless networks",
Technical Report TKN-00-007, Telecommunication Networks Group, Technische
Universität Berlin, August 2000.
(PostScript) (PDF)








