<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.kempf-mobopts-handover-key" target="https://datatracker.ietf.org/doc/html/draft-kempf-mobopts-handover-key-01">
   <front>
      <title>Bootstrapping a Symmetric IPv6 Handover Key from SEND</title>
      <author initials="R." surname="Koodli" fullname="Rajeev Koodli">
         </author>
      <author initials="J." surname="Kempf" fullname="James Kempf">
         </author>
      <date month="July" day="6" year="2005" />
      <abstract>
	 <t>Multiple IPv6 handover optimization protocols (for example, Fast Mobile 
IPv6 and Context Transfer Protocol) require an Access Router to verify 
that signaling received to perform an IP handover operation originated 
from a Mobile Node having authorization to claim a particular address 
on the Access Router&#x27;s wireless subnet. In this document, a method for 
securing such signaling is defined. The method utilizes a secret key 
sent from the Access Router to the Mobile Node prior to handover, 
encrypted with an RSA public key that the Mobile Node used to generate 
its Cryptographically Generated Address. The ability of the Mobile Node 
to decrypt the secret key verifies its possession of the private key 
corresponding to the public key used to generate the address. This 
allows the Mobile Node to use the secret key to sign and authorize 
signaling causing changes affecting traffic to and from that address. 
The use of symmetric cryptography avoids the time consuming public key 
operation associated with using the RSA key directly during 
performance-sensitive IP subnet handover.  
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-kempf-mobopts-handover-key-01" />
   
</reference>
