The present invention provides network-layer authentication protocols for
authenticating mobile client and access router to each other. The present
invention uses Router Discovery as a carrier to implement the
authentication protocols. In an embodiment of the present invention, a
mobile client sends out a solicitation message to request connectivity
service. The solicitation message contains a proof of identity of the
mobile client. An access router that receives the solicitation message
will not respond to it until the proof of the identity is verified. Only
when the proof of identity of the mobile client is verified, will the
access router respond and return an advertising message to the mobile
client, thereby preventing unauthorized mobile clients from obtaining
network access.