| Mobile IP is a group of protocols introduced by IETF to fulfill the demand of supporting IP mobility. Mobile IP enables a mobile node to roam from one network to another freely without breaking the connection. Compared with fixed nodes, the mobile one is easier to suffer from network attack, and therefore, ways should be proposed to ensure its security.This paper gives a Mobile IP security solution based on IPSec VPN through the analysis of Mobile IP protocols and the threats it faces,also based on the analyzing and utilizing of existing security technologies. By using authentication, this solution avoids the counterfeit attack and replay attack directed against the Mobile IP register process. Meanwhile, the tunnel integrated reverse tunnel and transmitting tunnel between the mobile node and the home network firewall, not only brings the mobile node into the protection of the firewall but also secures the communication between the two sides.Because Mobile IP mostly works in wireless networks, a routing optimizing architecture called Mobile Mapping Table (MMT) is proposed in order to ensure the traffic efficiency and response ability of a roaming mobile node. Meanwhile, by combining the MMT with the tunnel establishing method based on Secure Centralized Management, an end-to-end communication security between the mobile node and its corresponding node can be provided. Furthermore, the end-to-end tunnel needs not to be re-established while the mobile nodes switch to another foreign network by using MMT. Finally, we get a Mobile IP security solution which gives consideration not only to Mobile IP security but also to its efficiency. In the end, an analysis of the secure resolution is given and some developing aspects are discussed. |