Project IEEE 802.21 Media Independent Handover Services <http://www.ieee802.org/21/> Title Higher Layer Requirements for MIH Services Date Submitted Source(s) HL Adhoc group Ref: 21-06-0xxx-04-0000-MIH-HL-Reqs.doc Abstract This contribution provides HL requirements for IETF work Purpose Discuss and adopt in the draft. Edited: Srinivas Sreemanthula Release This document has been prepared to assist the IEEE 802.21 Working Group. It is offered as a basis for discussion and is not binding on the contributing individual(s) or organization(s). The material in this document is subject to change in form and content after further study. The contributor(s) reserve(s) the right to add, amend or withdraw material contained herein. The contributor grants a free, irrevocable license to the IEEE to incorporate material contained in this contribution, and any modifications thereof, in the creation of an IEEE Standards publication; to copyright in the IEEE’s name any IEEE Standards publication even though it may include portions of this contribution; and at the IEEE’s sole discretion to permit others to reproduce in whole or in part the resulting IEEE Standards publication. The contributor also acknowledges and accepts that this contribution may be made public by IEEE 802.21. Patent Policy The contributor is familiar with IEEE patent policy, as outlined in Section 6.3 of the IEEE-SA Standards Board Operations Manual <http://standards.ieee.org/guides/opman/sect6.html#6.3> and in Understanding Patent Issues During IEEE Standards Development <http://standards.ieee.org/board/pat/guide.html>. Notice 1 IETF Requirements for IEEE 802.21 support Adopt into the annex sections of the draft specification. 1.1 Transport Requirements TR1. The transport mechanism must work regardless of the network location of the MIH service entity e.g. on the same subnet, or deep in the network belonging to same or different administrative domain. TR2. The transport mechanism must be capable to support both IPv4 and IPv6 versions. TR3. The transport mechanism must enable timely delivery of MIH communication. TR4. The transport mechanism must be efficient and optimized. TR5. The transport mechanism must enable NAT traversal for IPv4 networks. TR6. The transport mechanism must enable Firewall pass-through for IPv4 and IPv6 networks. 1.2 Proxy Requirements PR1. The transport mechanism must provide mechanism to distinguish between the packet source and query source. 1.3 Discovery Requirements DR1. The discovery mechanism must work regardless of the network location of the MIH service entity e.g. on the same subnet, or deep in the network belonging to same or different administrative domain. DR2. The discovery mechanism must work for IPv4 and IPv6 hosts. DR3. The discovery mechanism may allow for more than one MIH service entity to be discovered at a time. DR4. The discovery mechanism may enable NAT traversal for IPv4 networks. DR5. The discovery mechanism may enable Firewall pass-through for IPv4 and IPv6 networks. 1.4 Security Requirements SR1. The security mechanism must provide a common security association (SA) negotiation method regardless of the network location of the MIH service entity e.g. on the same subnet, or deep within the network. SR2. The security mechanism must provide mutual authentication of MIH end nodes. SR3. The security mechanism may provide one way authentication of either of MIH end nodes. SR4. The security mechanism must provide integrity protection for MIH communications. SR5. The security mechanism may provide confidentiality for the MIH communications. SR6. The security mechanism must protect against replay attacks. SR7. The security mechanism may protect MIH service entities and discovery resources against denial of service attacks. SR8. The security mechanism must not be dependent on the MIH protocol information. SR9. The security mechanism may provide means to reuse or fast reestablishment the SA due to host mobility. SR10. The security mechanism may not be computationally intensive in order for support of smaller devices. SR11. The security mechanism may provide means to disable the security services listed here.