Securing Mobile IPv6 Route Optimization Using a Static Shared Key

정리 : 20070221 by 임헌정
http://www.4ellene.net
급하게 만든 허접 번역 입니다. 오역이 많습니다.



1. Introduction

This specification introduces an alternative, low-latency security

mechanism for protecting signaling related to the route optimization

in Mobile IPv6.

이 문서에서는 MIPv6의 RO과정에서 메시지 보호를 위한 low-latency한 보안 메커니즘을 소개 하려 한다.

The default mechanism specified in [1] uses a

periodic return routability test to verify both the "right" of the

mobile node to use a specific home address, as well as the validity

of the claimed care-of address. That mechanism requires no

configuration and no trusted entities beyond the mobile node's home

agent.

[1]의 방식은 주기적인 RR테스트를 통해서 MN를 점검하는 방식을 사용하였다.

이방식은 설정이나 MN의 HA에 대한 신뢰 엔티티가 필요 하지 않았다.

The mechanism specified in this document, however, requires the

configuration of a shared secret between mobile node and its

correspondent node.

이 문서에서 제안하는 메커니즘은 MN과 CN과의 공유키 설정이 필요하다.

As a result, messages relating to the

routability tests can be omitted, leading to significantly smaller

latency. In addition, the right to use a specific home address is

ensured in a stronger manner than in [1].

결과 적으로 RR테스트가 생략되어 레턴시가 줄어 들게 된다. 부가적으로 HoA를 사용할수 있는 권한도 [1]방식에 비해 stronger manner한다.

On the other hand, the

applicability of this mechanisms is limited due to the need for

preconfiguration. This mechanism is also limited to use only in

scenarios where mobile nodes can be trusted not to misbehave, as the

validity of the claimed care-of addresses is not verified.

반면에 사전 설정이 필요 하므로 활용도에 있어서는 제한적이다. 또한, MN가 잘못된 동작을 안한다는 가정하에서만 가능하다. 잘못된 동작이란 validity of the claimed care-of addresses is not verified.

The keywords "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",

"SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this

document are to be interpreted as described in RFC 2119 [2]. Other

terminology is used as already defined in [1].

2. Applicability Statement

This mechanism is useful in scenarios where the following conditions

are all met:

아래 내용은 이 메커니즘이 동작 하기 위한 요구 사항들을 정의한 것이다.

- Mobile node and correspondent node are administered within the

same domain.

mn과 cn은 같은 도메인 안에 있어야 함

- The correspondent node has good reason to trust the actions of

the mobile node. In particular, the correspondent node needs to

be certain that the mobile node will not launch flooding attacks

against a third party as described in [5].

CN은 MN의 동작을 무조건 신뢰하여야 한다. 구체적으로, CN은 MN가 [5]에서 설명하는 플러딩 공격을 하지 않는 다고 확신 해야 한다.

- The configuration effort related to this mechanism is acceptable.

Users MUST be able to generate/select a sufficiently good value

for Kcn (see [3])

이 메커니즘에서 필요한 설정을 당연히 수행 하여야 한다. 사용자는 Kcn에 충분한 값을 생성하거나 선택 하여야 한다.

- There is a desire to take advantage of higher efficiency or

greater assurance with regards to the correctness of the home

address offered via this mechanism.

이 메커니즘에 위해서 제공되는 HoA보다 효율적이고 정확성에 대해 보다 확실성을 가지는 것을 이용고자 하여야 한다.

- This mechanism is used only for authenticating Binding Update

messages (and not, e.g., data), so the total volume of traffic is

low (see RFC 4107 [4], and the discussion in section 4).

이 메커니즘은 BU메시지의 인증에만 사용되어야 한다.(데이터 인증에 사용 불가), 그래야만 전체적인 트래픽의 양이 줄어 든다.

This mechanism can also be useful in software development, testing,

and diagnostics related to mobility signaling.

이 메커니즘은 모빌리티 신호 전송 소프트웨어 개발이나 태스트, 진단에 유용하게 사용될수 있다.

Generally speaking, the required level of trust that the

correspondent node needs for enabling a precomputable Kbm with a

mobile node is more often found within relatively small, closed

groups of users who are personally familiar with each other, or who

have some external basis for establishing trustworthy interactions.

일반적으로 CN이 MN의 Kbm을 미리 계산하는데 필요한 신뢰의 요구 레벨은 상대적으로 작고, 사용자의 가까운 그룹이다.

A typical example scenario where this mechanism is applicable is

within a corporation, or between specific users. Application in the

general Internet is typically not possible due to the effort that is

required to manually configure the correspondent nodes.

이 메커니즘이 사용되기 적절한 곳은 회사나 특정한 두 개인 사이이다. 인터넷에서의 일반적 어플리케이션은 직접 CN을 수정하여야 하는 문제 때문에 적당하지 않다.

Application at a public network operator is typically not possible due to

requirements placed on the trustworthiness of mobile nodes.

공개 네트워크 오퍼레이터의 어플리케이션으로 사용하는 것도 적절하지 않은데 그 이유는 MN이 신뢰할만한 곳에 위치 하여야 하기 때문이다.

3. Precomputing a Binding Management Key (Kbm)

A mobile node and a correspondent node may preconfigure data useful

for creating a Binding Management Key (Kbm), which can then be used

for authorizing binding management messages, especially Binding

Update and Binding Acknowledgement messages. This data is as

follows:

MN과 CN은 바인딩 관리 키(Kbm)생성을 위해 미리 데이터를 설정해두어야 한다. 이 데이터는 BU, BUAck등의 바인딩 관련 메시지를 허가(=authorizing) 할때 사용한다. 이렇게 설정해야 하는 데이터는 아래와 같다.

- A shared key (Kcn) used to generate keygen tokens, at least 20

octets long

- A nonce for use when generating the care-of keygen token

- A nonce for use when generating the home keygen token

The keygen tokens MUST be generated from Kcn and the nonces as

specified in Mobile IPv6 [1] return routability. Likewise, the

binding management key Kbm must subsequently be generated from the

keygen tokens in the same way as specified in Mobile IPv6 [1].

키젠토큰은 MIPv6 RR에 정의된것처럼 Kcn과 nonces값을 가지고 생성되어야 한다.동시에 바인딩 메니져 키 Kbm도 MIPv6에서 정의된것처럼 키젠 토큰을 통해서 생성되어야 한다.

The

preconfigured data is associated to the mobile node's home address.

Kcn MUST be generated with sufficient randomness (see RFC 4086 [3]).

미리 설정할 데이터는 MN의 HoA와 연관되어서 설정되어야 한다. Kcn은 충분한 랜덤값으로 생성되어야 한다.

Replay protection for Binding Update messages using Kbm computed from

the preconfigured data depends upon the value of the Sequence Number

field in the Binding Update.

Kbm을 이용한 BU msg.재전송 방지는 미리 정의된 데이터를 가지고 구현하다. 이 데이터의의 값은 BU의 seq# 필드값을 참조하여 구한다.

If the correspondent node does not

maintain information about the recently used values of that field,

then there may be an opportunity for a malicious node to replay old

Binding Update messages and fool the correspondent node into routing

toward an old care-of address.

만약 CN이 필드의 최근 정보를 가지고 있다면, 악의적 노드가 이를 악용할 가능성이 있다.

For this reason, a correspondent node

that uses a precomputable Kbm also MUST keep track of the most recent

value of the Sequence Number field of Binding Update messages using

the precomputable Kbm value (for example, by committing it to stable

storage).

이러한 이유 때문에 미리 계산된 Kbm을 이용하는 CN은 BU메시지의 Seq# 필드의 최근 사용한 정보를 보관 하고 있어야 한다.

When a Binding Update is to be authenticated using such a

precomputable binding key (Kbm), the Binding Authorization Data

suboption MUST be present. The Nonce Indices option SHOULD NOT be

present. If it is present, the nonce indices supplied SHOULD be

ignored and are not included as part of the calculation for the

authentication data, which is to be performed exactly as specified in

[1].

인증에 미리 계산된 바인딩 키(Kbm)을 이용한 바인딩 업데이트시 Binding Authorization Data의 옵션에 체크가 되어 있어야 한다. Nonce를 지칭하는 옵션은 설정되어 있으면 안된다. 만약 설정되어 있더라도 nonce값은 무시되며 인증데이터 계산시 고려 하지 않는다.

4. Security Considerations

A correspondent node and a mobile node may use a precomputable

binding management key (Kbm) to manage the authentication

requirements for binding cache management messages.

CN과 MN은 미리 계산된 바인딩 관리 키를 사용하여 binding cache management message를 필요한 인증 요구사항을 관리 한다.

Such keys must

be handled carefully to avoid inadvertent exposure to the threats

outlined in [5]. Many requirements listed in this document are

intended to ensure the safety of the manual configuration. In

particular, Kcn MUST be generated with sufficient randomness (see RFC

4086 [3]), as noted in Section 3.

이런 키 값들은 외부 침입자들에게 노출되지 않도록 조심 하여야 한다. 이 문서에서 정의하고 있는 많은 요구사항들은 설정들에 대해 안정하게 보관하는것에 초점을 두고 있다.

Manually configured keys MUST be used in conformance with RFC 4107

[4]. Used according to the applicability statement, and with the

other security measures mandated in this specification, the keys will

satisfy the properties in that document.

직접 설정된 키들은 rfc4170와 상응해야 한다. 또한 문서에서 요구하는 여러 요구사항을 만족 해야 한다.

In order to ensure

protection against dictionary attacks, the configured security

information is intended to be used ONLY for authenticating Binding

Update messages.

사전 공격을 방지하기 위해서는 설정된 보안 정보는 바인딩 업데이트 메시지 인증시만 사용되어야 한다.

A mobile node MUST use a different value for Kcn for each node in its

Binding Update List, and a correspondent node MUST ensure that every

mobile node uses a different value of Kcn.

MN는 자신이 가지고 있는 바인딩 업데이트 리스트의 각 노드마다 서로 다른 Kcn값을 사용해야 한다. 그리고 CN은 모든 MN이 서로 다른 Kcn을 가지고 있다고 확신 해야 한다.

This ensures that the

sender of a Binding Update can always be uniquely determined. This

is necessary, as this authorization method does not provide any

guarantee that the given care-of address is legitimate.

BU 전송자는 독특하게 선택 될수 이다는 점도 간과하지 말아야 한다. 왜냐 하면, 이런 authorization방식은 주어진 CoA주소가 합당한 것이진 확인할수 없다.

For the same

reason, this method SHOULD only be applied between nodes that are

under the same administration. The return routability procedure is

RECOMMENDED for all general use and MUST be the default, unless the

user explicitly overrides this by entering the aforementioned

preconfigured data for a particular peer.

이와 비슷한 이유로 이 방식은 동일한 관리 상에 있는 노드들 끼리에게만 적용될수 있다. RR 동작은 모든 일반적 사용시 적당하다. 그리고 특별한 이유가 없다면 기본 방식으로 설정되어야 한다.

Replay protection for the Binding Authorization Data option

authentication mechanism is provided by the Sequence Number field of

the Binding Update.

Binding Authorization 데이터 옵션의 인증 메커니즘에 대한 재전송 방지는 바인딩 업데이트의 Seq# 필드를 통해서 가능하다.

This method of providing replay protection fails

when the Binding Update sequence numbers cycle through the 16 bit

counter (i.e., not more than 65,536 distinct uses of Kbm), or if the

sequence numbers are not protected against reboots.

이런 재전송 방지도 실패할때가 있는데 바로 Seq# 16bit 카운터이상 오버 했을 경우이다. 또는 재 부팅으로 인해 seq# 정보가 지워 졌을 경우 이다.

If the mobile

node were to send a fresh Binding Update to its correspondent node

every hour, 24 hours a day, every day of the year, this would require

changing keys every 7 years.

만약 MN이 매시간 마다 새 바인딩 업데이트를 전송시 매 7년마다 키를 교환하여야 한다

Even if the mobile node were to do so

every minute, this would provide protection for over a month. Given

typical mobility patterns, there is little danger of replay problems;

만약 매 분마다 바인딩 업데이트를 한다면 한달동안은 protection을 할수 있다. 하지만 이런 패턴이 이라면 재전송관련 위험성을 가지고 있다.

nodes for which problems might arise are expected to use methods

other than manual configuration for Kcn and the associated nonces.

이런 문제점을 가진 노드는 직접 Kcn이나 관련 nonce를 설정하는 방식말고 다른걸 사용하여야 한다.

When the Sequence Number field rolls over, the parties SHOULD

configure a new value for Kcn, so that new Kbm values will be

computed.

Seq# 가 제한 값을 넘긴다면 parties는 새 Kcn값을 설정하여야 한다. 그래므로 새 Kbm값을 설정 하여야 한다.

If a correspondent node does NOT keep track of the sequence number

for Binding Update messages from a particular mobile node, then the

correspondent node could be fooled into accepting an old value for

the mobile node's care-of address.

만약 CN이 MN의 바인딩 업데이트 메시지의 seq#를 저장하고 있지 않는다면 CN은 MN의 과거의 CoA주소를 이용한 공격에 당할수 있다.

In the unlikely event that this

address was reallocated to another IPv6 node in the meantime, that

IPv6 node would then be vulnerable to unwanted traffic emanating from

the correspondent node.

일반적이지 않은 경우지만 이 주소가 다른 IPv6노드에게 재 할당될 수가 있다. 이렇게 되면 IPv6노드는 CN이 전송하는 원하지 않는 트래픽으로 인해 피해를 볼수 있다.

Note that where a node has been configured to use the mechanism

specified in this document with a particular peer, it SHOULD NOT

attempt to use another mechanism, even if the peer requests this or

claims not to support the mechanism in this document. This is

necessary in order to prevent bidding down attacks.

특정 노드와 통신하기 위해서 이 문서에서 제안하는 메커니즘을 원하는 노드가 있다면, 그 특정 노드가 다른 메커니즘을 원하더라도 다른 메커니즘과 병행하여서 사용하면 안된다. 이것은 bidding down 공격을 막기 위해서 이다.

There is no upper bound on the lifetime defined for the precomputable

Kbm. As noted, the key is very likely to be quite secure over the

lifetime of the security association and usefulness of applications

between a mobile node and correspondent node that fit the terms

specified in section 2.

미리 계산된 Kbm을 위해 정의된 Lifetime의 시간 제안은 없다. 이야기 했듯이 키정보는 SA의 lifetime동안 안전하게 관리 되어야 한다.


2007/02/23 01:47 2007/02/23 01:47
TAG
Trackback address :: http://4ellene.net/tt/trackback/1124
  1. Soma.

    Tracked from Soma online sales. 2008/06/18 02:43  삭제

    Soma without prescription. Effects of soma. Soma online sales. Soma. Coupons for soma by chicos. Soma medication. Soma online. Soma fm.

  2. online poker

    Tracked from strip poker 2009/03/30 14:09  삭제

    free strip poker

  3. natural viagra

    Tracked from buying viagra online 2009/04/02 03:49  삭제

    discount viagra

  4. viagra cialis levitra

    Tracked from viagra uk 2009/04/03 17:13  삭제

    viagra

  5. Tracked from extreme sex 2009/04/13 05:20  삭제

    extreme pussy torture

  6. Tracked from underage rape 2009/04/13 10:48  삭제

    true rape stories

  7. Tracked from rape survivor stories 2009/04/14 06:46  삭제

    rape storys

  8. extreme close up

    Tracked from extreme cumshots 2009/04/14 15:39  삭제

    extreme bondage

  9. secretary bondage

    Tracked from self bondage 2009/04/15 05:07  삭제

    rubber bondage

  10. violent rape

    Tracked from rape bbs 2009/06/29 04:20  삭제

    rape asain

  11. gary roberts rape

    Tracked from stories of rape 2009/06/29 04:59  삭제

    movies with rape scenes

  12. rape in high school

    Tracked from forced white wife 2009/06/29 19:11  삭제

    bondage + forced + sex

  13. lesbian rape porn

    Tracked from crime rape 2009/06/30 04:03  삭제

    gang rapes

  14. forced womanhood stories

    Tracked from rape stories 2009/06/30 11:02  삭제

    forced to fuck

  15. woman rape

    Tracked from young ape anal rape 2009/06/30 21:15  삭제

    forced fuck

  16. father rape

    Tracked from porno rape 2009/07/01 02:09  삭제

    brutal fucking

  17. brutal anal sex

    Tracked from brutal facesitting 2009/07/01 09:13  삭제

    illegal rape

  18. rape fantasy porn

    Tracked from rape thumbs 2009/07/01 11:15  삭제

    pedo rape stories

  19. hardcore rape porn

    Tracked from extreme board rape 2009/07/01 16:34  삭제

    rape pics

  20. forced rough sex stories

    Tracked from extreme anal 2009/07/01 20:49  삭제

    what is rape

  21. schoolgirl rape

    Tracked from rape thumbs 2009/07/01 21:12  삭제

    father daughter rape

  22. ghost rape

    Tracked from virgin rape 2009/07/02 01:33  삭제

    rape porn vids

  23. underground rape porn

    Tracked from forced lesbian sex 2009/07/03 05:32  삭제

    forced sex fantasy

  24. sex rape

    Tracked from forced to fuck 2009/07/03 16:18  삭제

    sublime date rape

  25. underground rape porn

    Tracked from rape fetish porn 2009/07/03 16:40  삭제

    forced fucking

  26. extreme torture

    Tracked from rape teen 2009/07/04 13:01  삭제

    woman rape

  27. extreme dildo

    Tracked from sickest rape sites 2009/07/05 15:02  삭제

    forced deepthroat

  28. rape scenes

    Tracked from brutal torture sex 2009/07/08 05:35  삭제

    outdoor rape

  29. top casino

    Tracked from download online casino games 2009/07/10 09:40  삭제

    1 hour free us online casinos

  30. usa casino gaming

    Tracked from internet casino gambling 2009/07/10 10:21  삭제

    us online casinos

  31. casino games

    Tracked from online casino usa 2009/07/10 12:50  삭제

    free online casino cash

  32. casino money

    Tracked from play free casino games 2009/07/10 23:49  삭제

    free online casino games

  33. casino game onlino

    Tracked from casino betting 2009/07/11 05:51  삭제

    online casino craps

  34. online free casino games

    Tracked from casino gaming table 2009/07/11 19:21  삭제

    casino betting

  35. online casinos

    Tracked from uk online casinos 2009/07/12 02:53  삭제

    free casino games online

  36. new online casino

    Tracked from internet casino 2009/07/12 06:31  삭제

    online casinos accepting us

  37. online casinos for us players

    Tracked from online casino deposit 2009/07/12 09:35  삭제

    online casino game

  38. free cash online casino

    Tracked from vip online casino 2009/07/12 19:55  삭제

    free casino

  39. online no deposit casinos

    Tracked from online casinos no deposit bonus 2009/07/12 20:28  삭제

    online casino code

  40. online casino

    Tracked from new online casinos 2009/07/13 08:36  삭제

    no deposit online casinos

  41. casino web sites

    Tracked from casino directory 2009/07/13 17:44  삭제

    online casino bonus

  42. casino

    Tracked from online casino for south dakota 2009/07/14 05:20  삭제

    casino online apuestas

  43. online casino poker

    Tracked from casino online games 2009/07/14 17:14  삭제

    online casino games

  44. casino money

    Tracked from casino games online 2009/07/15 08:20  삭제

    online casino gaming

  45. casino gaming online

    Tracked from casino guide http 2009/07/16 12:57  삭제

    casino money

  46. online casino game

    Tracked from online casino news 2009/07/16 13:46  삭제

    tops casino

  47. beating internet casino

    Tracked from online casino reviews bonuses 2009/07/16 18:07  삭제

    topgame online casinos

  48. casino guide http

    Tracked from casino game onlino 2009/07/16 23:57  삭제

    online casinos no deposit bonus

  49. free online casino

    Tracked from no deposit online casinos 2009/07/17 18:05  삭제

    free casinos online

  50. casino party usa

    Tracked from web casino 2009/07/17 22:42  삭제

    casino casinos online

  51. online casinos in usa

    Tracked from online internet casino 2009/07/18 05:39  삭제

    casino casinos online

  52. online gambling casinos

    Tracked from the online casino 2009/07/19 00:57  삭제

    online casino games http

  53. online casinos for us players

    Tracked from vip casin 2009/07/19 07:28  삭제

    online no deposit casinos

  54. tranny cum

    Tracked from shemale vids 2009/07/20 02:47  삭제

    hentai tranny

  55. asian ladyboys dp

    Tracked from transvestite bdsm 2009/07/20 07:58  삭제

    shemale escorts

  56. ladyboy gangbang

    Tracked from japanese ladyboy 2009/07/20 22:39  삭제

    las vegas transvestite

  57. transvestite diva

    Tracked from shemale private 2009/07/21 01:25  삭제

    tranny movies

  58. transvestite clips

    Tracked from ladyboy hentai 2009/07/21 10:06  삭제

    transvestite dating

  59. dickgirl futanari

    Tracked from sexy transvestites 2009/07/22 05:39  삭제

    shemale bondage

  60. shemale on shemale

    Tracked from las vegas transvestite 2009/07/22 10:09  삭제

    ladyboy escorts

  61. chinese ladyboys

    Tracked from transexual dating 2009/07/22 17:58  삭제

    black transsexual

  62. black transexual

    Tracked from shemale stories 2009/07/22 18:24  삭제

    beautiful transexuals

  63. tranny fucks guy

    Tracked from transvestite stories 2009/07/23 07:13  삭제

    shemale private

  64. tranny cumming

    Tracked from lesbian shemale 2009/07/23 23:39  삭제

    black ladyboys

  65. transexual galleries

    Tracked from transvestite dating 2009/07/24 02:24  삭제

    tranny hentai

  66. transsexual sex

    Tracked from shemale yum 2009/07/24 09:10  삭제

    futanari galleries

  67. transvestite video

    Tracked from nancy ladyboy 2009/07/25 03:50  삭제

    transvestites porn

  68. hot transexual

    Tracked from tranny seduction 2009/07/25 04:16  삭제

    pattaya ladyboy

  69. oriental ladyboys

    Tracked from ladyboy cock 2009/07/25 04:52  삭제

    futanari girls

  70. brother sister incest

    Tracked from brother on sister porn 2009/09/06 04:05  삭제

    brother sister sex

  71. daughter nude

    Tracked from daughter incest incest 2009/09/06 11:04  삭제

    daughter sex

  72. mom son sex

    Tracked from mom son fucking 2009/09/06 11:26  삭제

    mom strips for son

  73. mom son fucking

    Tracked from mom mature son gallery 2009/09/07 20:41  삭제

    mom son sex

  74. dad and daughter incest

    Tracked from daddies fucking daughters 2009/09/08 01:18  삭제

    dad with sis son sex mom

  75. gay incest

    Tracked from daddies and sons gay 2009/09/08 01:53  삭제

    brother gay incest

  76. incest mother and daughter

    Tracked from incest forum 2009/09/08 08:46  삭제

    incest pictures

  77. mom son sex

    Tracked from mom son fucking 2009/09/08 13:36  삭제

    mom strips for son

  78. family porn

    Tracked from family orgy 2009/09/08 23:30  삭제

    family sex clips

  79. dad fucking son

    Tracked from sibling incest 2009/09/09 08:35  삭제

    father son sex

  80. incest cartoon

    Tracked from incest art 2009/09/09 13:13  삭제

    incest comics

  81. gay family incest

    Tracked from gay incest stories 2009/09/09 13:34  삭제

    boy incest

  82. free incest porn stories

    Tracked from free incest porn 2009/09/09 19:59  삭제

    daughter fucking incest porn

  83. daughter incest incest

    Tracked from daddy fucks daughter 2009/09/09 22:05  삭제

    daughter nude

  84. daddy fuck me

    Tracked from daddy and little girl fantasy 2009/09/10 06:17  삭제

    daddy fucks daughter

  85. sex slave punishment

    Tracked from sex slave 2009/09/11 05:22  삭제

    sex slaves

  86. bondage fuck

    Tracked from bondage fix 2009/09/12 03:12  삭제

    bondage fucking

  87. witch torture

    Tracked from whipped slave girl 2009/09/12 04:06  삭제

    women in bondage

  88. gay bdsm

    Tracked from feminine domination 2009/09/12 11:42  삭제

    gay bondage

  89. bondage orgasm

    Tracked from bondage movies 2009/09/12 12:36  삭제

    bondage pics

  90. bondage fuck

    Tracked from bondage fix 2009/09/12 12:38  삭제

    bondage fucking

  91. torture stories

    Tracked from torture sex 2009/09/12 22:27  삭제

    torture vaginal

  92. bdsm books

    Tracked from bdsm bondage 2009/09/13 00:31  삭제

    bdsm bound

  93. worst tortures

    Tracked from world domination 2009/09/13 01:55  삭제

    xxx bondage

  94. bdsm books

    Tracked from bdsm bondage 2009/09/13 05:57  삭제

    bdsm cafe

  95. bondage paper

    Tracked from bondage orgasm 2009/09/13 20:35  삭제

    bondage pics

  96. panty domination

    Tracked from outdoor bondage 2009/09/13 22:24  삭제

    public bdsm

  97. dungeon torture

    Tracked from drawing torture 2009/09/14 07:26  삭제

    electro torture

  98. bondage fix

    Tracked from bondage fairies 2009/09/14 12:46  삭제

    bondage fuck

  99. outdoor bdsm

    Tracked from orgasm torture 2009/09/15 20:53  삭제

    outdoor bondage

  100. domination

    Tracked from dick torture 2009/09/15 21:42  삭제

    domination porn

  101. bondage directory

    Tracked from bondage comics 2009/09/16 08:07  삭제

    bondage fairies

  102. tools of torture

    Tracked from toilet torture 2009/09/16 09:02  삭제

    torture

  103. bdsm ws

    Tracked from bdsm vids 2009/09/16 11:19  삭제

    bedroom bondage

  104. bdsm story

    Tracked from bdsm stories 2009/09/17 19:17  삭제

    bdsm tgp

  105. Amateur Incest Family Porn

    Tracked from Family Incest Galleries 2009/09/27 11:12  삭제

    family orgy

  106. daddies and sons gay

    Tracked from family rape 2009/09/27 13:24  삭제

    gay incest

  107. father daughter porn

    Tracked from father fucks daughter 2009/09/28 11:45  삭제

    incest porn

  108. mother daughter lesbian sex

    Tracked from lesbian mother daughters 2009/09/28 12:28  삭제

    incest mother and daughter

  109. fathers fucking daughters

    Tracked from dad and daughter 2009/09/28 15:23  삭제

    dad fucking virgin daughter

  110. boy incest

    Tracked from gay incest stories 2009/09/29 09:53  삭제

    gay family incest

  111. brother sister incest

    Tracked from little sister 2009/10/03 08:17  삭제

    brother and sister sex stories

  112. nude sister

    Tracked from nude family 2009/10/03 13:24  삭제

    simpsons family sex

  113. family nude

    Tracked from family incest 2009/10/04 09:14  삭제

    family incest galleries

  114. mom son fucking

    Tracked from mom mature son gallery 2009/10/04 10:28  삭제

    mom son sex

  115. bdsm for all

    Tracked from bdsm free 2009/10/21 12:12  삭제

    bdsm free videos

  116. bdsm video

    Tracked from bdsm videos 2009/10/21 13:16  삭제

    bdsm vids

  117. japanese bondage

    Tracked from latex bondage 2009/10/21 15:26  삭제

    lesbian bondage

  118. bondage games

    Tracked from bondage gear 2009/10/22 12:49  삭제

    bondage girl

  119. bondage gear

    Tracked from bondage girl 2009/10/22 13:29  삭제

    bondage girls

  120. black fox bondage

    Tracked from bondage anal 2009/10/23 17:11  삭제

    bondage and discipline

Comments List

  1. zoophilia wikipedia 2008/05/23 07:08

  2. teen japan posing 2008/05/24 01:28

Write a comment.

[로그인][오픈아이디란?]