EAP-based Mediating Network Selection Copyright © 2003, The Internet Society Farid Adrangi Intel Corporation ( ) ACKNOWLEDGEMENTS:

Slides:



Advertisements
Similar presentations
Inter WISP WLAN roaming
Advertisements

Doc.: IEEE /039 Submission January 2001 Haverinen/Edney, NokiaSlide 1 Use of GSM SIM Authentication in IEEE System Submitted to IEEE
© 2012 Cisco and/or its affiliates. All rights reserved. 1 Eduroam and IEEE u Dave Stephenson Wireless Networking Business Unit Strategic Initiatives.
Omniran IEEE 802 Enhanced Network Detection and Selection Date: Authors: NameAffiliationPhone Max RiegelNSN
1 Role of Authorization in Wireless Network Security Pasi Eronen Jari Arkko November 3, 2004 This document has been produced partially in the context of.
Carrying Location Objects in RADIUS Hannes Tschofenig, Farid Adrangi, Avi Lior, Mark Jones.
Chapter 18 RADIUS. RADIUS  Remote Authentication Dial-In User Service  Protocol used for communication between NAS and AAA server  Supports authentication,
SP Wi-Fi Services over Residential Architectures (draft-gundavelli-v6ops-community-wifi-svcs) IETF 84 - August, 2012 Authors: Sri Gundavelli(Cisco) Mark.
Microsoft Windows Server 2003 TCP/IP Protocols and Services Technical Reference Slide: 1 Lesson 20 RADIUS and Internet Authentication Service.
ERP for IKEv2 draft-nir-ipsecme-erx-01. Why ERP for IKEv2? RFC 5296 and the bis document define a quick re- authentication protocol for EAP. ERP requires.
Lecture 12: WLAN Roaming Communities EDUROAM TM. eduroam TM eduroam (education roaming) is the secure, world-wide roaming access service developed for.
2007 © SWITCH TNC2007 Extending SWITCH Public Wireless LAN with EAP-SIM Kurt Baumann SWITCHmobile Project Leader
Interworking Architecture Between 3GPP and WLAN Systems 張憲忠, 何建民, 黃瑞銘, 紀嘉雄, 李有傑.
Interworking (802.11u) Scott Armitage.
Report about the Design Team on "Diameter Routing" (Tina Tsou)
Doc: Submission September 2003 Dorothy Stanley (Agere Systems) IETF Liaison Report September 2003 Dorothy Stanley – Agere Systems IEEE.
1 © 1999, Cisco Systems, Inc. AAA/Mobile IP For 3G CDMA Systems Gopal Dommety and Allen Long.
Doc.: IEEE /223r0 Submission March 2004 Eleanor Hepworth, Siemens Roke ManorSlide 1 Interworking Requirements Eleanor Hepworth Siemens Roke Manor.
Identities and Network Access Identifier in M2M Page 1 © GPP2 3GPP2 and its Organizational Partners claim copyright in this document and individual.
Cellular Access Control and Charging for Mobile Operator Wireless Local Area Networks H. Haverinen, J. Mikkonen and T. Takamaki, Nokia Wei-Jen, Lin Advanced.
EAP Key Framework Draft-ietf-eap-keying-01.txt IETF 58 Minneapolis, MN Bernard Aboba Microsoft.
March 15, 2005 IETF #62 Minneapolis1 EAP Discovery draft-adrangi-eap-network-discovery-10.txt Farid Adrangi ( )
1 RADIUS Attribute Harmonization and Informational guidelines for PWLAN Farid Adrangi Intel Corporation ( )
Carrying Location Objects in RADIUS Hannes Tschofenig, Farid Adrangi, Avi Lior, Mark Jones.
Common NAI/Password Fraud Issue 7/27/2005 Bryan Cook
Doc.: IEEE /0638r0 Submission May 2004 Bernard Aboba, MicrosoftSlide 1 Network Selection Bernard Aboba Microsoft
March 17, 2003 IETF #56, SAN FRANCISCO1 Compound Authentication Binding Problem (EAP Binding Draft) Jose Puthenkulam Intel Corporation (
Pascal Urien Slide 1/6 55th IETF Atlanta, GA, November 17-21, 2002 “EAP support in smartcards” My name is Pascal Urien Draft-urien-EAP-smartcard-00.txt.
1 HRPD Roamer Authentication Zhibi Wang, Sarvar Patel, Simon Mizikovsky, Nancy Lee.
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential.
1 Bandwidth Profile Negotiation over AAA Farid Adrangi, Paul Congdon, Chuck Black, Avi Lior, Farooq Bari draft-adrangi-radius-bandwidth-capability-01.txt.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Doc.: IEEE /0027r0 Submission January 2006 Slide 1 WiNOT Consortium: Proposal for online enrollment cluster Notice: This document has been prepared.
Carrying Location Objects in RADIUS Presentation written by: Hannes Tschofenig, Allison Mankin Draft Authors: Hannes Tschofenig, F. Adrangi, A. Lior, M.
Doc.: IEEE /109r1 Submission July 2002 J. Edney, H. Haverinen, J-P Honkanen, P. Orava, Nokia Slide 1 Temporary MAC Addresses for Anonymity Jon.
1 Network Selection Problem Definition Draft-ietf-eap-netsel-problem-01.txt Jari Arkko Bernard Aboba.
IETF #65 Network Discovery and Selection Problem draft-ietf-eap-netsel-problem-04 Farooq Bari Jouni Korhonen.
1 Remote IP Access - Stage 2 Architecture proposal for adoption Peerapol Tinnakornsrisuphap Anand.
Cisco Discovery Home and Small Business Networking Chapter 7 – Wireless Networking Jeopardy Review v1.1 Darren Shaver Kubasaki High School – Okinawa,
Extended QoS Authorization for the QoS NSLP Hannes Tschofenig, Joachim Kross.
NSIS QoS NSLP Authorzation Issues Hannes Tschofenig.
Doc.: IEEE /0448r0 Submission March, 2007 Srinivas SreemanthulaSlide 1 Joiint TGU : Emergency Identifiers Notice: This document has been.
Extensions to the Emergency Services Architecture for dealing with Unauthenticated and Unauthorized Devices draft-ietf-ecrit-unauthenticated-access-03.txt.
Nov 10, EAP-based Mediating Network Discovery and Selection Copyright © 2003, The Internet Society Farid Adrangi Intel Corporation (
1 Extensible Authentication Protocol (EAP) Working Group IETF-57.
Doc.: IEEE /827r0 Submission November 2003 Eleanor Hepworth, Siemens Roke ManorSlide 1 Co-existence of Different Authentication Models Eleanor.
August 4, 2004EAP WG, IETF 601 Authenticated service identities for EAP (draft-arkko-eap-service-identity-auth-00) Jari Arkko Pasi Eronen.
Port Based Network Access Control
Improving the eduroam experience with Interworking (802.11u)
November 18, 2002 IETF #55, ATLANTA1 Problem with Compound Authentication Methods Jesse Walker Intel Corporation (
Discussion on DHCPv6 Routing Configuration
RADEXT WG RADIUS Attributes for WLAN Draft-aboba-radext-wlan-00.txt
Access Network Information Option for Proxy Mobile IPv6
Hokey Architecture Deployment and Implementation
Teleconference Agenda
Carrying Location Objects in RADIUS
Jari Arkko Bernard Aboba
Report about the Design Team on "Diameter Routing" ietf
Network Selection Issues
MAC Address Hijacking Problem
Network Selection Bernard Aboba Microsoft
3GPP2-WLAN Interworking update
Considerations about Network Selection
Network Selection Bernard Aboba Microsoft
Initial Network Selection Concept
IETF Network Discovery and Selection Overview
3GPP and SIP-AAA requirements
3GPP WLAN interworking requirements
3GPP2-WLAN Interworking update
Access Network Information Option for Proxy Mobile IPv6
Presentation transcript:

EAP-based Mediating Network Selection Copyright © 2003, The Internet Society Farid Adrangi Intel Corporation ( ) ACKNOWLEDGEMENTS: JOE SALOWEY MARK GRAYSON – Cisco VICTOR LORTZ, JOSE PUTHENKULAM, - INTEL CORPORATION, MARCO SPINI – Telecom Italia MARK WATSON – Nortel, PASI ERONEN – NOKIA, FAROOQ BARI – AT&T Wireless JOHANNA WILD – MOTOROLA, BLAIR BULLOCK – iPass, ADRIAN BUCKLEY - Rim JARI ARKKO – ERICSSON, BERNARD ABOBA - Microsoft draft-adrangi-eap-network-discovery-and-selection-01.txt

Use-case 1 – WLAN client moves into a Hotspot advertising the client’s HSN SSID T-mobile Hotspot HSN T-mobile Orange - WLAN client is subscribed with T-mobile HSN - WLAN client moves into a hotspot with T-mobile and Orange ANs - WLAN client recognizes the HSN SSID (e.g., T-Mobile) - WLAN client associates with the HSN SSID, and then authenticates with its HSN by using its root NAI and home credential T-Mobile Subscriber

Use-case 2 – WLAN client moves into a Hotspot advertising one or more of WLAN client’s HSN Roaming Partner SSID(s) but not its HSN SSID Hotspot HSN T-mobile Orange - WLAN client is subscribed with T-mobile HSN - WLAN client moves into a hotspot with an ANs owned/managed by Orange & Wayport - WLAN client recognizes that its HSN SSID is not present, however it recognizes that the Orange and Wayport SSIDs have direct roaming relationship with its HSN - WLAN associates with the preferred AN, and authenticates with its HSN by using its root NAI and home credential Wayport T-Mobile Subscriber

Use-case 3 – WLAN client moves into a Hotspot advertising only Unrecognized SSIDs (Continued) Hotspot T-mobile McDonalds Mediating Network 2 Mediating Network 3 Wayport Orange AnyISP Mediating Network 1 ORANGE: The Unrecognized SSID belongs to a Roaming partner of HSN that was not provisioned into the WLAN client McDonalds The Unrecognized SSIDs belong to an operator that does not have a direct or indirect business relationship with the WLAN client’s HSN. In this case the WLAN client can not be authenticated through this SSID. Wayport: The Unrecognized SSID belongs to an operator who is a roaming partner of HSN’s roaming partner and.AN T-Mobile Subscriber

Problem Scope Access Network Selection –How does a WLAN client choose a SSID to associate with an AN where there are more than one available SSID in the hotspot? Mediating Network Selection –How does WLAN client influence routing of AAA packets through a roaming partner where the Access Network is not owned by the HSN, and it does not have a direct roaming relationship with the HSN?

Solution For each Scenario Use-casesAN SelectionMediating Network Selection 1 – WLAN client moves into a Hotspot advertising the client’s HSN SSID Home SSID NA 2 – WLAN client moves into a Hotspot advertising one or more of WLAN client’s HSN Roaming Partner SSID(s) but not its HSN SSID Roaming Partner SSIDNA 3 – WLAN client moves into a Hotspot advertising only Unrecognized SSIDs Associate with each available SSID and perform mediating network discovery with the available SSIDs until an SSID that has direct connection to HSN has been found If an SSID that has direct connection to HSN is not found, then the WLAN UE shall attempt to select an SSID that has connection to one of the Mediating Networks in the preferred mediating Network lists.

Proposed Solution for Mediating Network Selection Using EAP-based signaling

Solution Properties Complies with RFC 2284bis and uses RFC 2486bis bang syntax It may not require any changes to Access Points (AP) already deployed in Access Networks (AN) Uses the EAP-Identity Request to deliver Network Information, preferably from the local AAA proxy/server Type-Data Field of Identity Request: \0 Realms=gric.com;mnc123.mcc334.3gppnetwork.org

Backup Slides

Agenda Use-case scenarios for network selection Problem Scope Solution for use-case scenarios Proposed Solution for Mediating Network Selection Next Steps

WLAN Client WLAN client has been provisioned by its Home Service Network (HSN) for the following: –Username and Initial Credential –HSN SSIDs and Roaming partners SSIDs –Preferred Mediating Network names

EAP-Identity Request There are three possible options of delivering Network Information using an EAP- Identity Request : –Use the initial EAP-Identity Request issued by the PWLAN AP –Use a subsequent EAP-Identity Request issued by the PWLAN RADIUS proxy –Use the initial EAP-Identity Request issued by PWLAN RADIUS proxy

Initial EAP-Identity Request issued by the PWLAN AP Subscriber AP PWLAN RADIUS Proxy MN RADIUS Proxy HSN RADIUS Server EAP-Identity Req (Network Info) EAP-Identity Resp (Decorated NAI ) Access-Req (EAP-Identity Resp+ Decorated NAI) Access-Req (EAP-Identity Resp+ Decorated NAI) Access-Req (EAP-Identity Resp+ Normal NAI) More EAP Over RADIUS Exchanges Access-Accept EAP-Success

Subscriber AP PWLAN RADIUS Proxy MN RADIUS Proxy HSN RADIUS Server EAP-Identity Req EAP-Identity Resp (Normal NAI) Access-Req (EAP-Identity Resp+ Normal NAI) Access-Challenge (EAP-Identity Req+ Network Info) EAP-Identity Req (Network Info) EAP-Identity Resp (Decorated NAI) Access-Req (EAP-Identity Resp+ Decorated NAI) Access-Req (EAP-Identity Resp+ Decorated NAI) Access-Req (EAP-Identity Resp+ Normal NAI) More EAP Over RADIUS Exchanges Access-Accept EAP-Success Subsequent EAP-Identity Request issued by the PWLAN RADIUS Proxy

Subscriber AP PWLAN RADIUS Proxy MN RADIUS Proxy HSN RADIUS Server Association Access-Req (EAP-Start) Access-Challenge (EAP-Identity Req+ Network Info) EAP-Identity Req (Network Info) EAP-Identity Resp (Decorated NAI) Access-Req (EAP-Identity Resp+ Decorated NAI) Access-Req (EAP-Identity Resp+ Decorated NAI) Access-Req (EAP-Identity Resp+ Normal NAI) More EAP Over RADIUS Exchanges Access-Accept EAP-Success Initial EAP-Identity Request issued by the PWLAN RADIUS Proxy

NAI Construction for Mediating Network Selection Complies with RFC-2486bis Uses mediating REALM, instead of WLAN client’s home REALM. Examples, given a user’s NAI : Then, the constructed NAI can be represented as :

Next Steps How should we proceed with this draft?