Security Analysis and Security Optimizations for the Context Transfer Protocol
Fabien Allard, Jean-Michel Combes, Rafa Marin, Antonio F. Gomez · 2008
Protocol security dealing with mobility is strongly necessary since mobile nodes are more prone to attacks. The Context Transfer Protocol allows applications running on mobile nodes to operate with minimal disruption by transferring contexts between access routers. In this paper, after a practical study using the AVISPA tool and a more conceptual one, we will show that this protocol does not work in a secure way. We will then propose a first solution to fix the security flaws. However, this solution decreases the context transfer efficiency. Hence, we will finally propose a second solution based on Cryptographically Generated Addresses that guarantees the same security level than the first one and is as efficient as the original CXTP specification.