After reading I agree with some of the divisions that occur, but think that if more layer splitting happens it will be laterally (with defined interfaces in a 'meta' protocol layer).
* IP shouldn't fragment
* Connections should only exist in higher layers
Connections probably should be divided in to different logical parts, but interact as closely related components of a validated and reliable "pipe". Supporting mobile endpoints (in my mind) clearly means dropping the implicit authentication of an interface address and instead using a stronger cryptographic one. That's also why the connection layer needs to remain unified, even if the components within it are distinct: attacks on the connection are equivalent to packets that failed checksum.