A communication network system has a plurality of interconnected
sub-networks, at least one mobile node having a care-of address dependent
on a sub-network currently connected thereto and a home address
independent of the connected sub-network, and a home agent. Upon
detection of a sub-network connected to the mobile node, the latter
determines a security method corresponding to the sub-network held in a
node-side security application management table as a security method for
ensuring the security for user data communicated between the mobile node
and a home agent associated therewith. Then, the sub-network is notified
to the home agent through a mobile node network signal. The home agent
determines a security method corresponding to the sub-network from among
security methods held in an agent-side security application management
table as a security method used for ensuring the security for user data
communicated between the home agent and the mobile node managed thereby.