Design Consideration/Goal MN authenticates itself to CN & sets up a key for secure BU Employs PKC, secure against powerful intruder No PKC operations performed at MNs Issue certificate for home link, not MNs (i. e., public key binds with home link, not with individual IP address) |