MOBIKE

IKEv2 Mobility and Multihoming Protocol

Protocol →
Introduced in Rel-8

MOBIKE is an extension to the IKEv2 protocol that enables an IPsec Security Association to survive changes in endpoint IP addresses, crucial for seamless mobile VPN connectivity during network handovers.

Category
Protocol
Introduced
Rel-8
Where
Security
Specifications
3 specs
MOBIKE Description Purpose Related Classification Detected Changes Specifications

Description

MOBIKE (IKEv2 Mobility and Multihoming Protocol) is a standards-based protocol defined by the IETF and adopted within 3GPP systems. It extends the core IKEv2 protocol, which is responsible for mutual authentication and establishment of IPsec Security Associations (SAs). The primary function of MOBIKE is to enable an established IKEv2 session and its associated IPsec Child SAs to remain active even when the IP addresses of one or both endpoints change. This is achieved through a lightweight update mechanism rather than a full re-negotiation.

Architecturally, MOBIKE operates within the IKEv2 protocol stack. The MOBIKE-enabled peers exchange new informational payloads, namely the UPDATE_SA_ADDRESSES notification. When a mobile node detects a change in its IP address (e.g., due to a handover), it sends this UPDATE_SA_ADDRESSES message to its peer, informing it of the new address. The peer acknowledges the update, and both sides then redirect the IPsec ESP/AH traffic to the new source/destination addresses. The IKEv2 SA itself, which contains the cryptographic keys and identities, remains unchanged. This process preserves the session state and avoids the computational overhead and service interruption of a full IKE_SA_INIT and IKE_AUTH exchange.

Key components in a MOBIKE transaction are the MOBIKE-supported IKEv2 initiator and responder. The protocol includes mechanisms for path testing (using return routability checks) to ensure the new address is reachable and to prevent flooding attacks. It also supports Network Address Translation (NAT) traversal scenarios. Within 3GPP, MOBIKE is particularly relevant for scenarios such as Non-3GPP access (e.g., untrusted WLAN) integration with the 5G Core, where a UE uses IPsec tunnels via a N3IWF. As the UE moves, MOBIKE allows the IPsec tunnel between the UE and the N3IWF to be maintained seamlessly across IP address changes, ensuring continuous secure access to 5G core network services.

Purpose & Motivation

MOBIKE was created to solve a fundamental problem with traditional IPsec VPNs: they are brittle in mobile environments. Standard IKEv2 binds Security Associations to specific IP addresses. If a client's IP address changes—a common occurrence for a device moving between Wi-Fi networks or performing a cellular handover—the existing IPsec SAs become invalid, and the VPN connection drops. This forces a full VPN reconnection, causing service disruption, increased signaling load, and poor user experience.

The protocol addresses the limitations of previous approaches by decoupling the IKEv2 security association from the specific endpoint IP addresses. Before MOBIKE, workarounds involved using stable virtual IP addresses or Mobile IP, which added complexity. MOBIKE integrates mobility support directly into IKEv2, providing a standardized, lightweight solution. Its adoption in 3GPP, notably from Release 8 for early EPS/SAE architectures and reinforced in later releases for 5G, was motivated by the need for secure, seamless mobility across heterogeneous access networks. It enables always-on VPNs for corporate access and is essential for the 5G architecture's convergence of 3GPP and non-3GPP access, allowing a UE to maintain a persistent secure connection to the core network regardless of access technology changes.

Classification

Part ofIPSec
Related approachesN3IWF

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (1 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-17 1 change

In Release 17, 3GPP introduced clarifications to the MOBIKE (IKEv2 Mobility and Multihoming Protocol) function. This update focused on refining the existing protocol specifications to improve implementation understanding. The change did not introduce new procedures or capabilities but provided necessary clarifications to the established MOBIKE framework.

Explore further

Broader topics and technologies where MOBIKE plays a role.

Defining Specifications

3GPP specifications that define or reference MOBIKE, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 24.554 vj40 5G Proximity Services (ProSe) Protocols Rel-19
TS 33.822 v1800 Security Architecture for Inter-Access Mobility Rel-8
TR 33.938 vj10 3GPP Cryptographic Inventory for 5G Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.