A method for enabling a mobile node to transmit encrypted data over a path
including a wireless link and an untrusted link, while avoiding double
encryption on any link. The data on the end-to-end path is encrypted
using an application specific security mechanism, or an L2 mechanism is
used for encrypting the data on the wireless link as mandated by the
wireless standards, and an application specific security mechanism is
used for encrypting the data on the untrusted link. By avoiding redundant
double encryption, the method of the invention results in optimizing the
use of network resources in bandwidth-limited wireless networks and
increases the life of the mobile node battery.