Summary
- Pilot strength, SectorID and ANID are evidence about radio and access-network context. A previous access router still needs a current operator-topology mapping to turn them into a candidate new access router.
- Predictive handover authority is causal, not permanent. If the preparation message reaches the new router after the mobile's arrival signal, RFC 5271 says to reject the prediction and proceed reactively.
The measurement arrives before its meaning
In a 3G CDMA system, a mobile node can keep measuring pilot channels while data continues to flow. It maintains sets of candidate pilots, compares carrier-to-interference estimates and can report when another pilot becomes stronger than the one it is using. That is early evidence, exactly the kind a latency-sensitive system wants.
It is not yet an IP route.
The pilot belongs to a base-station sector. The sector may remain behind the same access router, in which case the access network handles movement internally and the IP-layer connection need not be rebuilt. Or it may lie behind a different Packet Data Serving Node, which RFC 5271 treats as the visited access router. The same kind of radio observation can therefore imply either no router change or a cross-router handover.
The distinction lives in configuration outside the measurement. Someone has to know which sector belongs to which access network, which PDSN currently serves it, which prefix that router will advertise and whether the mapping is still current. Calling the pilot “the target router” skips the decisive join.
Three identifiers, three coordinate systems
RFC 5271 offers several pieces of handover-assist information because no single identifier carries the whole topology.
SectorID is a 128-bit identifier associated with a radio sector and its pseudo-noise-code offset. The document notes that it can be represented in IPv6 address form. That visual resemblance is dangerous in an operations system: an IPv6-shaped SectorID is not thereby a router's IPv6 address.
ANID is different. It combines System ID, Network ID and Packet Zone ID into an operator-administered five-octet access-network identifier. Crossing an ANID region is relevant to re-registration. It describes a network domain, not a globally stable access router.
Pilot sets are different again. They are measurements and candidates, often with signal estimates. They describe what the radio can hear at a time. They do not state what the operator's topology database will return.
RFC 5271 groups these with cell information, RAN serving nodes, location when available and subnet information under “handover assist information.” The phrase is exact. These values assist discovery. They do not replace discovery.
The option transports evidence; it does not certify an interpretation
When a 3G CDMA point of attachment cannot be represented by the link-layer address expected in the generic fast-handover model, RFC 5271 defines the Handover Assist Information Option. Mobility option Type 29 carries an option code, an explicit value length and the value itself. Code 1 denotes ANID; code 2 denotes SectorID.
An implementation that does not understand the option should treat it as opaque and must not drop the containing message for that reason. This is good extensibility. It is not semantic validation.
An opaque field can survive a proxy, a queue or an older node without corruption while still being unusable for a safe decision. A consumer needs the namespace, operator domain, observation time, topology generation and mapping policy. Otherwise identical bytes can be joined against the wrong tenant or a table that changed after a rehoming.
The correct audit object is not targetRouter = X. It is a relation: these observations, in this namespace, evaluated under this topology generation at this time, produced candidate X with these alternatives and this expiry.
Predictive mode spends a limited amount of time
Fast handover has predictive and reactive modes. In predictive mode, the mobile sends a Fast Binding Update and receives its acknowledgment while it is still on the previous router's link. The previous router can contact the new router, establish forwarding and let the new router buffer packets before the radio move completes.
That optimization requires advance knowledge of both place and time. RFC 5271 says network-controlled cellular systems are a good fit when the next router can be identified promptly. If the network cannot do that in time, reactive mode is better.
The R flag in the proxy router advertisement says what the network supports. When set, only reactive handover is supported; when clear, predictive and reactive modes are available. Capability is not a verdict on the current prediction. A network can support predictive handover and still lack sufficient evidence for this move.
The mobile must send its predictive FBU before the old connection closes. Missing that boundary is not an invitation to relabel a late request. It is the trigger to fall back.
One reversed arrow cancels the story
The most revealing rule in RFC 5271 concerns congestion. A mobile can send the FBU at the intended time, yet the previous router may receive it late. Its Handover Initiate message can then reach the candidate new router only after that router has already received the mobile's Unsolicited Neighbor Advertisement.
The messages can all be well formed. The identifiers can match. The protected links assumed by the RFC can be intact. Yet the prediction has failed as a prediction. The event that HI was supposed to prepare has already announced itself.
RFC 5271's answer is operationally disciplined: the new router should return a handover-not-accepted acknowledgment and behave reactively. It does not preserve the “predictive” label merely because a workflow started earlier.
This is causal authorization. The authority of HI depends on arriving before the readiness event it is meant to prepare. A database that stores each message with a valid flag but loses receive order can reconstruct a false success. Remote timestamps are not enough; clock error and retries can scramble them. The new router's local receive and processing sequence is part of the proof.
Identification still precedes attachment
In the predictive flow, the mobile sends a proxy-router solicitation with handover-assist evidence to the previous router. The previous router uses that evidence to identify a candidate new router and returns its address and prefix. The mobile formulates a prospective new care-of address and sends the FBU. The previous router sends HI, and the new router can prepare and buffer.
Only later does the old radio connection close and a new traffic channel get assigned. RFC 5271 then places an access-technology-specific attachment procedure in the sequence. Its example includes PPP Link Control Protocol, CHAP or PAP authentication, AAA exchange, IPv6CP interface-identifier negotiation, link-local address creation, Router Advertisement and care-of-address configuration. DHCPv6 may supply bootstrap information. A normal Mobile IPv6 Binding Update with the home agent follows.
None of those later facts is contained in the pilot report. None is proved by the previous router's mapping answer. Even the early prefix can be provisional: where the new router selects the real per-link prefix, it must assign the correct NCoA after attachment.
Preparation is valuable precisely because attachment is unfinished. Conflating them makes a fast path look more certain than the ordinary path it is trying to anticipate.
An identifier can correlate a node without proving a person
The generic handover messages expect link-layer addresses. A point-to-point 3G CDMA link may not provide the same object. RFC 5271 therefore defines Mobile Node Identifier option Type 30, with codes for NAI and IMSI, and allows it to substitute in specified places.
That substitution solves a protocol correlation problem. It does not turn an IMSI into evidence that PPP completed, that a proposed address is correct, that a packet reached the mobile or that a human approved a transaction. The document describes the MN ID as unique within the operator's network; it is not a universal subject identifier.
Subscriber identifiers also create a surveillance surface. A handover trace should expose the minimum protected reference needed to correlate protocol events, not spray the raw value into dashboards, logs and downstream analytics. Retention must be tied to the handover purpose and accompanied by deletion evidence.
“Authenticated on attachment” remains a later fact. Back-projecting it into the earlier router prediction would reverse the proof chain.
Current operation requires a historical map
RFC 5271 is Informational and was written against RFC 5268 and the Mobile IPv6 specification then in RFC 3775. RFC 5568 later obsoleted RFC 5268; RFC 6275 replaced RFC 3775. The technology-specific observations remain instructive, but an implementation has to read them beside the current base specifications and current IANA assignments.
RFC 4907 supplies the architectural warning: link indications are hints with particular semantics, confidence and filtering requirements. Their usefulness depends on what the consumer actually does with them. A lower-layer signal does not inherit IP-layer meaning merely because it arrives sooner.
This historical layering matters in procurement. A product can truthfully say it implements an RFC 5271 option while using stale topology, flattening namespaces or treating a late HI as preparation. Compliance with a message format and correctness of the running evidence chain are different claims.
Running code is the sequence, not the green badge
Lu Heng's Running-Code Primacy asks what happened in the system that ran. For this handover, the answer is a chain: a radio observation, a namespaced sector or ANID, one topology generation, a candidate NAR, a mode decision, an FBU, local HI/UNA order, actual link establishment, address configuration and packet release.
Reality-layer discipline prevents each step from borrowing authority from the next. Signal strength is physical evidence. SectorID is a radio-topology name. ANID is an operator-network name. The NAR is a mapping result. The Mobile Node identifier is a correlation value. PPP authentication is an attachment event. A configured NCoA is an address state. Packet receipt is an outcome.
The abstraction stays reversible only if “target router” can lead back to the observation, namespace, table generation, alternatives and expiry that produced it. The moment the trail stops at prediction=true, uncertainty has been laundered into authority.
Sources
- RFC 5271: Mobile IPv6 Fast Handovers for 3G CDMA Networks
- RFC Editor record for RFC 5271
- RFC 5568: Mobile IPv6 Fast Handovers
- RFC 4907: Architectural Implications of Link Indications
- RFC 4260: Mobile IPv6 Fast Handovers for 802.11 Networks
- RFC 6275: Mobility Support in IPv6
- RFC 4283: Mobile Node Identifier Option
- IANA Mobility Parameters
- Lu Heng: Running-Code Primacy
- Lu Heng: On Reality Layers
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
