An in-band signaling method that enables secure updates of a care-of-IP
address for a mobile host that roams between access networks. In the
illustrative embodiment described herein, a mobile host includes an
intelligent interface that handles IP networking functions and tunnels IP
packets between the mobile host and the mobile host's home agent/remote
access server (HA/RAS) transparently, as if the mobile host established a
connection to a communicating or destination host (DST) from the home
network (where the HA/RAS resides). In accordance with an aspect of the
invention, there is provided an in-band signaling method that employs
encrypted three-way handshake signaling messages that are embedded in
encapsulated IP packets to enable care-of IP address updates. This method
can effectively protect mobile hosts from denial-of-service attacks and
is transparent to NAT/NAPT firewalls. The signaling messages are
communicated between the home agent and the mobile host, in a manner
transparent to any NAT/NAPT firewall in the network.