Summary

  • RFC 3543 lets a Mobile IPv4 tunnel endpoint revoke a registration and receive an authenticated acknowledgment from the other endpoint. That acknowledgment proves a bounded agent-to-agent result: a valid request was matched to an existing binding, processed and answered.
  • Mobile-node notification is a different step, normally a foreign-agent Advertisement with sequence number zero. The negotiated I bit assigns responsibility for deciding whether to notify; it is not proof that the node received the signal, re-registered or recovered service.

A clean acknowledgment is one of the most dangerous shapes in operations. It is crisp, signed and easy to graph. Its precision tempts a dashboard to extend the claim beyond the system that actually produced it.

RFC 3543, published in August 2003 as a Proposed Standard, is unusually useful because it refuses that extension. Its Registration Revocation mechanism has two signaling surfaces. Home and foreign agents exchange an authenticated revocation message and acknowledgment. A foreign agent can separately alert a mobile node by sending an Agent Advertisement whose sequence number is zero. The first exchange can finish while the second has not yet happened, has been ignored, or has been spoofed.

The specification sought timely release of mobility resources, cleaner accounting and fewer packets sent into a tunnel whose state had changed. Those are design goals, not measurements from a named deployment. No operator incident is asserted here. The operational question is narrower: what may each receipt honestly prove?

Revocation reports a decision already taken

The protocol's framing matters. A Registration Revocation message is not a request asking whether a binding may be terminated. It notifies the peer that Mobile IP service for one or more registrations has been discontinued. The decision therefore precedes the packet.

That distinction changes the failure model. If the acknowledgment is late or absent, the sender does not infer that the binding remains valid. It retransmits the notification. The receiver, after authenticating a valid request, can revoke the matching binding, release associated resources and return an acknowledgment. The response closes a signaling obligation; it does not create the underlying revocation.

An operator who models the exchange as a two-phase approval will wait for the wrong event. An operator who models it as fire-and-forget will discard useful proof. The accurate state machine preserves both facts: service termination is the sender's asserted accomplished act, while acknowledgment is evidence that the other tunnel endpoint received and processed that act for an existing binding.

What the acknowledgment actually closes

Before acting, the receiver checks the applicable authenticator, the direction expressed through the A bit, replay protection and the existence of the named mobility binding. Only then does it remove the registration and answer. A valid acknowledgment therefore carries real weight.

It can support a statement such as: this endpoint authenticated this revocation, found the referenced binding, applied the required local revocation action and emitted this response under this replay identifier. It can retire the sender's retransmission loop for that transaction.

It cannot support a larger sentence without more evidence. It does not show that a handset heard an advertisement, stopped using an old care-of address, acquired a new one, completed a new registration, restored traffic, reconciled accounting or presented the right user-visible explanation. Nor does it prove that every data-plane packet stopped at the same instant.

The boundary is architectural rather than semantic hair-splitting. The two agents can authenticate each other across the tunnel. The mobile node may be reached only through a local advertisement mechanism. A receipt issued by one trust relationship cannot automatically sign for a different path and actor.

The I bit is delegated policy, not a delivery receipt

RFC 3543 negotiates an I bit during registration. It decides which side has authority to determine whether the mobile node should be informed. That is useful because the home agent may know the reason for termination while the foreign agent controls the local link.

When the bit appears in the acknowledgment, it helps coordinate that responsibility. It can indicate the notification policy selected for the transaction. It does not transform the acknowledgment into evidence from the mobile node.

This is an important governance pattern. A field can say who owns the decision without saying that the decision was executed. It can say that notification is indicated without proving delivery. It can even produce a perfectly valid exchange in which policy responsibility is unambiguous and the mobile node remains unaware.

The receipt chain should therefore store the negotiated I value, which endpoint made the notification decision, the reason code or policy input, and the subsequent local-link action. Collapsing those entries into one Boolean called “notified” destroys the distinction the protocol went to the trouble to preserve.

Sequence zero speaks on a weaker channel

The ordinary way for a foreign agent to alert the node is an Agent Advertisement with sequence number zero. In Mobile IPv4, that special value tells the mobile node that it should attempt registration even if it has not missed the usual sequence. The busy bit may be used to discourage renewal through the same foreign agent.

This is a prompt to act, not evidence that action succeeded. The base mechanism does not cryptographically authenticate that advertisement to the mobile node. RFC 3543 discusses measures such as a time-to-live of one and checking that the link-layer source is the same as the foreign agent previously used. Those checks reduce exposure; they do not turn the signal into a signed receipt.

The asymmetry is striking. The agent-to-agent revocation can be authenticated and replay-protected. The final signal that is meant to move the user endpoint may be link-local and spoofable. A status page that reports the strongest upstream property as if it applied end to end reverses the evidence hierarchy.

At minimum, retain the advertisement generation event, interface, sequence value, source address, link-layer source, TTL and transmit result. Then look for a separate response from the node: solicitation, registration request, movement to a different agent, or another observable recovery step. Silence remains ambiguous.

A missing ACK also has a bounded meaning

If the acknowledgment does not arrive, the sender retransmits. Each retry receives a new timestamp-based replay value and a new authenticator. The semantic revocation may be the same, but the protected message instance is fresh. RFC 3543 limits retransmission to no more than once per second, uses exponential backoff and ends the effort when the binding would naturally expire.

That schedule prevents uncontrolled signaling and limits how long a notification chases state that will disappear anyway. It also means “retry count” is not “number of revocations”. An audit record must connect every message instance to one revocation intent.

Absence of an acknowledgment does not prove that the receiver kept the binding. The first message may have been processed and its answer lost. A later retransmission may find no binding because the earlier request already removed it. Conversely, the return path may work while the receiver never accepted the request. Only the reasoned validation and local state receipt distinguishes those cases.

The natural-expiry stop condition is equally easy to misread. It ends the need to synchronize that registration; it does not prove that the mobile node recovered before expiry or that all accounting closed cleanly.

Resource release can race user recovery

One motivation for revocation is to free resources promptly. A foreign agent may stop providing Mobile IP services and release tunnel state after processing a valid revocation. A home agent can avoid forwarding traffic into a dead path. Accounting can be closed nearer to the actual policy decision.

Those are legitimate gains. They also create a deliberate race: infrastructure cleanup can lead the endpoint's understanding of what happened. The agent's local success can make the old path fail more decisively before the node has selected a new one.

The operational remedy is not to delay every revocation until the handset signs a receipt. The protocol does not supply that transaction. The remedy is to name the gap, measure its duration and own the recovery mechanism. Resource release, notification dispatch, re-registration and restored forwarding should be four timestamps, not one green event.

For a directly attached co-located mobile node, the path differs. The node can participate in the revocation exchange, acknowledge and tear down its reverse tunnel and resources. That case should not be used to infer equivalence for foreign-agent care-of-address operation. The actors and evidence paths are different.

Neighboring Mobile IPv4 mechanisms do not fill the gap

Registration under RFC 3344 or its later revision RFC 5944 establishes and refreshes mobility bindings. Earlier RFC 2002 is historical context. A successful registration gives the home agent a care-of address and lifetime under the protocol; it still does not prove application delivery.

The challenge/response mechanisms in RFC 3012 and RFC 4721 address freshness and authentication around registration. Reverse tunneling in RFC 3024 addresses traffic direction and ingress-filtering constraints. None of them makes a revocation acknowledgment into a mobile-node recovery receipt.

Keeping these boundaries matters because Mobile IPv4 has several adjacent authenticators, identifiers and advertisements. Reusing a familiar security noun can hide a change of principal. Always ask: which entity generated the evidence, for which message, under which association, and what later actor remains unobserved?

The evidence chain a revocation review should demand

Begin with the decision record: binding identity, mobile home address, home and care-of agents, policy owner, reason, prior lifetime, decision time and whether termination had already taken effect. Preserve the exact revocation payload, direction, A and I values, authenticator, replay identifier and send time.

At the receiving endpoint, record authentication result, replay decision, binding lookup, state transition, resources released and acknowledgment contents. At the sender, record response validation, correlation and retransmission retirement. If no answer returns, preserve each fresh timestamp and authenticator with its backoff interval and final stop reason.

For notification, record who owned the policy decision, whether a sequence-zero advertisement was generated, its interface and link guards, and any independent evidence that the mobile node reacted. Finally, observe re-registration, tunnel establishment, forwarding, accounting reconciliation and usable traffic.

The leadership sentence can then stay inside the evidence: “Both tunnel endpoints agreed that this binding was revoked at these times; the foreign agent emitted this local notification; the node re-registered here; traffic and accounting recovered here.” When the last clauses are missing, report an agent-level completion with mobile recovery unproved.

Evidence boundary

This Article names no operator, device maker, home agent, foreign agent, subscriber, outage, fraud event or affected population. It asserts no current deployment, adoption rate, measured recovery time or production failure. The scenarios are protocol-derived possibilities and governance inferences.

RFC 3543 is treated according to its August 2003 Proposed Standard status and its explicit message semantics. RFC 3344 was the base Mobile IPv4 specification in that period; RFC 5944 later obsoleted it. RFC 8174 bounds normative terms. The IANA registry supplies current message and extension allocations but no implementation evidence.

Heng Lu's Running-Code Primacy and Minimum Initial Specification essays are disclosed editorial lenses. They motivate separating published coordination machinery from deployed behavior and keeping the common layer small while local actors own later decisions. They are not evidence of the RFC authors' intent or of any network's operation.

The bounded conclusion is exact: an authenticated Registration Revocation Acknowledgment can prove that the other mobility agent processed a valid revocation for a binding. It cannot prove that the mobile node was notified, understood the change, re-registered or regained service. Those are later receipts.

Sources