WLAN IW Enhancement for Multiple Authentications Support QUALCOMM Inc.: Raymond Hsu, QUALCOMM Inc.: Masa Shirota,

Slides:



Advertisements
Similar presentations
WLAN IW Enhancement for IMS Support
Advertisements

WLAN IW Enhancement for Multiple Authentications Support Notice: Contributors grant free, irrevocable license to 3GPP2 and its Organization Partners to.
1 WLAN IW Enhancement for IMS Support QUALCOMM:Raymond Hsu, Masa Shirota, KDDI:Kazushi Imamoto,
Page 1 Title: Traffic Detection Function Extensions for cdma2000 1x and HRPD Networks Sources: Qualcomm Contact: George Cherian
Mobile IPv4 FA CoA Support in WLAN Interworking Raymond Hsu Qualcomm Inc. Notice: QUALCOMM Incorporated grants a free, irrevocable license.
Mobile IPv4 FA CoA Support in WLAN Interworking Raymond Hsu, Qualcomm Inc., Sanket S. Nesargi, Nortel, Nanying Yin,
Dynamic HA Assignment for MIPv4 in WLAN Interworking Raymond Hsu, Qualcomm Inc., Wing C. Lau, Qualcomm Inc., Notice:
MIP6-HA-Local-Assignment-Capability indication to MS Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners.
1 DSMIP6 Support QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota Notice.
IP Connectivity for E911 in HRPD/PDS Networks Page 1 IP Connectivity for Emergency Calls in HRPD/PDS Networks 3GPP2 Meeting, 1/07 IP Connectivity for Emergency.
XHRPD Example Scenario for MSS Masa Shirota Qualcomm Inc. July 15, GPP2 Dalian Meeting Recommendation: FYI Notice QUALCOMM Incorporated grants a.
1 Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained.
3GPP2 A r0 3GPP2 C xxxr0 TSG-A WG3 and TSG-C WG2 Title: HRPD Redirect on EPC Unavailable Source: Mike DolanAlcatel-Lucent Dave.
HRPD Femto Local IP Access: Overview Peerapol Tinnakornsrisuphap Qualcomm October 27 th, GPP2 Seoul,
1 IP Service Authorization Support and Mobility Selection for X.S0011-E Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
1 UATI-IP address mapping Peerapol Tinnakornsrisuphap David Ott Qualcomm.
1 Title: TDF support in cdma2000 1x and HRPD Networks Sources: China Telecom, ZTE, Huawei Contact: CT: Heng Nie ( ), Congjie Mao(
1 May 14, 2007 Zhibi Wang, Simon Mizikovsky – Alcatel-Lucent Vidya Narayanan, Anand Palanigounder – QUALCOMM ABSTRACT: Access authentication architecture.
3GPP2 Network Evolution: Inter-working Across Technologies January 08, 2007 QUALCOMM Inc Notice Contributors grant a free, irrevocable license to 3GPP2.
1 cdma2000® Data Service Transition to NULL Support Jun Wang Ravi Patwardhan June 5, 2003 Recommendation -
3GPP2 X xxx Title: SIP6 access and MIP6 Access Differentiation Sources: ZTE Contact: Rajesh Bhalla
Broadcast Area Based Management for BCMCS Quanzhong Gao Weidong Wu 04/05/2005.
Security Framework for (e)HRPD 1 S GPP2 TSG-S WG4 Source: QUALCOMM Incorporated Contact(s): Anand Palanigounder
1 IPsec-based MIP6 Security Qualcomm Inc. Starent Inc. Notice: Contributors grant free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
Authentication Profile for UICC- less eHRPD Terminals QUALCOMM Incorporated Contact(s): Anand Palanigounder Jun Wang.
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PCC Support for cdma2000 QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
1 Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained.
The contributing companies grant a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable.
QUALCOMM Incorporated 1 Protocol Options for BSN- BSMCS Controller Interface Jun Wang, Kirti Gupta 05/16/2005 Notice: Contributors grant a free, irrevocable.
Broadcast/Multicast Priority List JUNHYUK SONG SAMSUNG Incorporated grants a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
QUALCOMM PROPRIETARY 3GPP2 Network Evolution Architecture Dec. 04, 2006 Lucent Technologies Nortel Networks Qualcomm Inc. Hitachi, Ltd Huawei Technologies.
1 Flow Mobility Support QUALCOMM Inc. George Cherian, Jun Wang, Masa Shirota
X xxx China Telecom Requirements on Accounting at HA/LMA Title: Accounting at HA/LMA for cdma2000 (Work Item # 3GPP ) Sources: China Telecom.
Why not EAP over PANA? Qualcomm, Inc. Vidya Narayanan, Dondeti, Lakshminath, Jun Wang, Pete Barany Notice: QUALCOMM Incorporated grants a free, irrevocable.
C August 24, 2004 Page 1 SMS Spam Control Nobuyuki Uchida QUALCOMM Incorporated Notice ©2004 QUALCOMM Incorporated. All rights reserved.
1 SeGW Certificate profile (Revised) 3GPP2 TSG-S WG4 /TSG-X WG5 (PDS) S X xx Source: QUALCOMM Incorporated Contact(s): Anand.
Proposed 1x Device Binding Solution Based on SX & SX GPP2 TSG-SX WG4 SX Source(s): Qualcomm Incorporated.
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PCC Support for cdma2000 QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
Proposed Solution for Device Binding 3GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
May 12, 2008 Alcatel Lucent, Cisco, Motorola, Nortel, Verizon ABSTRACT: Proposed is additional key hierarchy and derivation for EPS access over eHRPD.
X xxx ZTE Discussion on cdma2000 Charging with PCC Title: Discussion on PCC Charging for cdma2000 1x and HRPD Sources: China Telecom, ZTE Contact:
Mobility Management in WLAN IW Inma Carrion, Vijay DevarapalliNokia Raymond HsuQualcomm Inc. Pete McCann, Frank AlfanoLucent Serge ManningSprint Notice:
5 November Overview of Proposed Femtocell Architecture Alternatives presented at the 3GPP2 Femto Workshop Airvana 5 November 2007 cdma2000® is the.
1 Authentication and User Profile April 24, 2007 Jun Wang QUALCOMM Inc. Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
July 21, 2008 Alcatel Lucent ABSTRACT: Proposed is key derivation for eHRPD RAN Handoff. RECOMMENDATION: Review and approve. Notice Contributors grant.
Supporting Local Breakout in HRPD Femto Peerapol Tinnakornsrisuphap Qualcomm Doug Knisely
August 25, 2008 Alcatel Lucent ABSTRACT: 1x System Reliability is important in the face of major events, such as an earthquake. There are several ways.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
3GPP2 Network Evolution: UMB->HRPD Handoff October 16, 2007 Qualcomm Inc. Contact: Jun Wang Notice Contributors grant a free, irrevocable license to 3GPP2.
Remote access to Local IP network via Femto Peerapol Tinnakornsrisuphap Anand Palanigounder
X xxx ZTE Discussion on cdma2000 Charging with PCC Title: Inter-RAT RAN information management protocol Stack Sources: NSN Contact: Scott Marin,
Comment to Limited Idle Mode Nortel Networksgrants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable.
1 Remote IP Access - Stage 2 Architecture proposal for adoption Peerapol Tinnakornsrisuphap Anand.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
EHRPD-LTE Inter Technology Spectrum Optimization Source: Qualcomm Incorporated Contact: Jun Wang/George Cherian September 9, 2013 Notice ©2013. All rights.
EAP over HRPD Comments Qualcomm, Inc. Vidya Narayanan, Dondeti, Lakshminath, Jun Wang, Pete Barany Notice: QUALCOMM Incorporated grants a free, irrevocable.
X xx CT+ZTE PCC for cdma2000 MS Init Call Flows 1 1 Title: PCC for cdma2000 – MS-Init Call Flow Example Sources: CTC, ZTE Contact: CHINA TELECOM.
1 Title: Performance of Default Parameters for 1xEV-DO RTCMAC Source: Christopher Lott, QUALCOMM Incorporated , Date: Februrary.
1 HRPD Fast Handoff Jun Wang and Raymond Hsu Qualcomm Inc Notice: QUALCOMM Incorporated grants a free, irrevocable license to 3GPP2 and its Organization.
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PCC Support for cdma2000 QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
1 SAMSUNG BCMCS Security Architecture and Key Management JUNHYUK SONG SAMSUNG Incorporated grants a free, irrevocable license to 3GPP2 and its Organization.
1 PPP Free Operation Mobility Management January 16, 2006 Jun Wang, Pete Barany, Raymond Hsu Qualcomm Inc Notice: Contributors grant free, irrevocable.
1 On 3GPP2 Femto Security Anand Palanigounder Qualcomm Inc. Notice: Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
Signaling Packet Routing for Layer 3 approach in UMB-HRPD/1x interworking KDDI Corporation, Tsunehiko Chiba, Osamu.
C August 19, 2003 Page 1 SMS Push Teleservice Nobuyuki Uchida QUALCOMM Incorporated Notice ©2003 QUALCOMM Incorporated. All rights reserved.QUALCOMM.
1 MSI (Multiple Service Instances) Ravindra Patwardhan QUALCOMM Incorporated Review and approve for D Notice QUALCOMM.
Clarifications on Work Split among TSG-X/A for 3GPP2 Network Evolution March 26, 2007 Airvana/Alcatel-Lucent/CTC/Fujitsu/ Hitachi/KDDI/NEC/Qualcomm/ZTE.
1 IP Service Authorization Support and Mobility Selection Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
Source: Qualcomm Incorporated Contact: Jun Wang, George Cherian March 1, 2010 Page 1 3GPP2 Femtocell Phase II Femto Access Control Enhancement Notice ©
Presentation transcript:

WLAN IW Enhancement for Multiple Authentications Support QUALCOMM Inc.: Raymond Hsu, QUALCOMM Inc.: Masa Shirota, KDDI: Kazushi Imamoto, KDDI: Ryuhei Munakata, Notice: Contributors grant free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained in the contribution and any modifications thereof in the creation of 3GPP2 publications; to copyright and sell in Organizational Partner’s name any Organizational Partner’s standards publication even though it may include portions of the contribution; and at the Organization Partner’s sole discretion to permit others to reproduce in whole or in part such contributions or the resulting Organizational Partner’s standards publication. Contributors are also willing to grant licenses under such contributor copyrights to third parties on reasonable, non-discriminatory terms and conditions for purpose of practicing an Organizational Partner’s standard which incorporates this contribution.This document has been prepared by the contributors to assist the development of specifications by 3GPP2. It is proposed to the Committee as a basis for discussion and is not to be construed as a binding proposal on the contributors. The contributors specifically reserves the right to amend or modify the material contained herein and nothing herein shall be construed as conferring or offering licenses or rights with respect to any intellectual property of the contributors other than provided in the copyright statement above.

Introduction The approved WLAN Enhancement WID [X r3] includes the multiple authentications support: –External AAA Support: Based on CDMA2000 wireless IP standards architecture, authentication consists of 2-phases. The 1st phase is authenticated by HLR or AN-AAA, the 2nd phase is an IP service authentication which can be authenticated by external AAAs using PAP or CHAP. The mechanism which allows the latter authentication in addition to the current EAP authentication over IKE session is required. –IPv4 and IPv6 Simultaneous Operation: It is required that the MS and the PDIF support simultaneous packet data session which can be authenticated and authorized independently.

Multiple Authentications by Home & External AAA Usage scenario: When MS accesses PDIF, MS is required to be authenticated by both HAAA and an external AAA. Proposal: Use RFC4739 (Multiple Authentication Exchanges in the Internet Key Exchange (IKEv2) Protocol) for multiple EAP authentications in single IKE session. –The first authentication exchange is between MS and HAAA via PDIF. HAAA is the EAP authentication server. Use either EAP-AKA or EAP-TLS/PSK [X.P ]. –The second authentication exchange is between MS and external AAA via PDIF. External AAA authenticates CHAP response or PAP password. For CHAP support, EAP-MD5 is used to exchange CHAP challenge and response between MS and PDIF. For PAP support, EAP-GTC is used to carry PAP password from MS to PDIF. PDIF does not pass-through EAP messages to external AAA because it’s not EAP server. PDIF needs to place CHAP response or PAP password in RADIUS or Diameter message sent to external AAA. –IKE session is authenticated only if both authentications are successful.

Multiple Authentications with Single IKE Session MSPDIFHAAA Ext AAA IKE_SA_INIT Request (Ni, …) EAP-AKA or EAP/TLS-PSK over IKE_AUTH CHAP or PAP over RADIUS or Diameter IKE_SA_INIT Response (Multiple_Auth_Supported, Nr, …) EAP-AKA or EAP/TLS-PSK over RADIUS or Diameter IKE_AUTH Request (AUTH, Another_Auth_Followed) IKE_AUTH Response (AUTH) EAP-MD5 or EAP-GTC over IKE_AUTH IKE_AUTH Request (AUTH) IKE_SAUTH Response (AUTH, SA, …) IKE_AUTH Request (Multiple_Auth_Supported, IDi, SA, …)

Multiple Authentications of IPv4 & IPv6 Sessions Usage scenario: –Initially, MS accesses PDIF via IPv6. IPv6 session is authenticated by HAAA. IPv6 session is for IMS terminated- or originated calls and is long-lived. –Later, MS accesses PDIF via IPv4. IPv4 session is authenticated by external AAA. IPv4 session is for packet data services (e.g., download) and is short-lived (to conserve IPv4 addresses resource). Proposal: Use separate IKE sessions

Multiple Authentications with Separate IKE Sessions IPv6 session establishment authenticated by home network: –MS and HAAA perform mutual authentication using EAP-AKA or EAP- TLS/PSK exchange via PDIF. –MS and PDIF perform mutual authentication of the IKE session using MSK generated from the EAP exchange. IPv4 session establishment authenticated by both home (same as IPv6 session) and external networks: –RFC4739 is used for multiple authentication. –First, the home network authentication is performed using a PSK derived from the MSK of the first IKE session associated with the long- lived IPv6 session. The nonces exchanged via IKE_SA_INIT can provide the freshness for the PSK derivation. This is an optimization to speed-up the home network authentication without requiring EAP exchange between MS and HAAA. –Second, the external network authentication is performed via (EAP- MD5) or PAP (EAP-GTC), between the MS and external AAA via PDIF.

Multiple Authentications with Separate IKE Sessions MSPDIFHAAA Ext AAA IKE_SA_INIT Exchange EAP-AKA or EAP/TLS-PSK over IKE_AUTH CHAP or PAP over RADIUS or Diameter EAP-AKA or EAP/TLS-PSK over RADIUS or Diameter EAP-MD5 or EAP-GTC over IKE_AUTH Start IPv6 session IKE_AUTH Exchange (use MSK to verify AUTH) Derive MSK Obtain MSK from HAAA Start IPv4 session IKE_SA_INIT Exchange (nonces, Multiple_Auth_Supported) Derive PSK from MSK and nonces IKE_AUTH Exchange (use PSK to verify AUTH) IKE_AUTH (IDi) IKE_AUTH Request (AUTH, Another_Auth_Followed) IKE_AUTH Response (AUTH)

Recommendation Discuss and Adopt the proposals for the WLAN IW enhancements.