A Framework of Media-Independent Pre-authentication (MPA) for Inter-domain Handover optimization draft-ohba-mobopts-mpa-framework-05.txt Ashutosh Dutta.

Slides:



Advertisements
Similar presentations
Network Research Lab. Sejong University, Korea Jae-Kwon Seo, Kyung-Geun Lee Sejong University, Korea.
Advertisements

1Nokia Siemens Networks Presentation / Author / Date University of Twente On the Security of the Mobile IP Protocol Family Ulrike Meyer and Hannes Tschofenig.
1 Mobility Management for All-IP Mobile Networks: Mobile IPv6 vs. Proxy Mobile IPv6 Ki-Sik Kong; Wonjun Lee; Korea University Youn-Hee Han; Korea university.
Dynamic Tunnel Management Protocol for IPv4 Traversal of IPv6 Mobile Network Jaehoon Jeong Protocol Engineering Center, ETRI
AAA Mobile IPv6 Application Framework draft-yegin-mip6-aaa-fwk-00.txt Alper Yegin IETF 61 – 12 Nov 2004.
A Seamless Handoff Approach of Mobile IP Protocol for Mobile Wireless Data Network. 資研一 黃明祥.
Inter-Subnet Mobile IP Handoffs in b Wireless LANs Albert Hasson.
Wireless Design for Voice Last Update Copyright 2011 Kenneth M. Chipps Ph.D.
1 IEEE : Media Independent Handover: Features, Applicability, and Realization 蔡喬偉 Kenichi Taniuchi, Toshiba Corporation Yoshihiro Ohba and Victor.
Formal Approach to Mobility Modeling IETF 78 – IRTF MOBOPTS Ashutosh Dutta Bryan Lyles Henning Schulzrinne 1.
67 th IRTF MOBOPTS – 1 Media Independent Pre-Authentication and Implementation (draft-ohba-mobopts-mpa-framework-03.txt) (draft-ohba-mobopts-mpa-implementation-03.txt)
Media-Independent Pre-Authentication (draft-ohba-mobopts-mpa-framework-01.txt) (draft-ohba-mobopts-mpa-implementation-01.txt) Ashutosh Dutta, Telcordia.
Introducing Reliability and Load Balancing in Home Link of Mobile IPv6 based Networks Jahanzeb Faizan, Mohamed Khalil, and Hesham El-Rewini Parallel, Distributed,
1 MIPv6 CN-Targeted Location Privacy and Optimized Routing draft-weniger-mobopts-mip6-cnlocpriv-01 IETF #68, Prague, March 2007.
Simultaneous Mobility: Problem Statement K. Daniel Wong, Malaysia University of Science & Technology
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Distributed Mobility Management using IEEE Date Submitted: March 16, 2011.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Problem Statement for Authentication Signaling Optimization Date.
Future Internet Presentation Kyung Hee University, Seok Hyun Hwang( 황석현 ) Seamless Handover in Proxy MIPv6 with AAA Server ( 이종망간 빠른 이동성 제공을.
August 1, 2005IETF63 PANA WG Pre-authentication Support for PANA (draft-ohba-pana-preauth-00.txt) Yoshihiro Ohba
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Proposal for IEEE Study Group on Security Signaling Optimization.
A Route Optimization Scheme Based on Roaming in PMIPv6 (pROR) S.-s. Oh, H.-Y. Choi, and S.-G. Min 1 in Fifth International Joint Conference on INC, IMS.
Convergence & Handoff Issues in Next-Generation Wireless Networks Jaydip Sen.
IEEE P802 Handoff ECSG Submission May 2003 Paul Lin, Intel Corp Proposed Problem and Scope Statements for Handoff ECSG Huai-An (Paul) Lin Intel Corp. May.
21-07-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxxx Title: IETF Liaison Report Date Submitted: July 19, 2007 Presented at.
Transient BCE for Proxy Mobile IPv6 draft-liebsch-netlmm-transient-bce-pmipv6-01.txt Oliver Marco
IEEE MEDIA INDEPENDENT HANDOVER Title: An Architecture for Security Optimization During Handovers Date Submitted: September,
1 IEEE MEDIA INDEPENDENT HANDOVER DCN: sec Title: Detailed analysis on MIA/MSA architecture Date Submitted: January 5, 2010 Present.
IETF 81: V6OPS Working Group – Proxy Mobile IPv6 – Address Reservations 1 Reserved IPv6 Interface Identifier for Proxy Mobile IPv6 Sri Gundavelli (Cisco)
srho 1 IEEE MEDIA INDEPENDENT HANDOVER DCN: xxx-00-srho Title: Overview of Single Radio Handover Procedures of WMF Date Submitted:
Transient BCE for Proxy Mobile IPv6 draft-ietf-mipshop-transient-bce-pmipv6-00.txt Oliver Marco
1 NetLMM Vidya Narayanan Jonne Soininen
Media-Independent Pre-Authentication (draft-ohba-mobopts-mpa-framework-00.txt) Ashutosh Dutta, Telcordia Technologies Yoshihiro Ohba (Ed.), Kenichi Taniuchi.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: L3 Transport for MIH Services Date Submitted: July 19, 2007 Presented at IEEE
Some use cases and requirements for handover Information Services Greg Daley MIPSHOP Session IETF 64.
MIPSHOP – November, 2005 Event Services and Command Services for Media Independent Handover Presentation prepared by: Srini Sreemanthula Presented by:
Cooperation between stations in wireless networks Andrea G. Forte, Henning Schulzrinne Department of Computer Science, Columbia University Presented by:
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Security Problems related to Transition Date Submitted: January.
2006/7/10IETF66 RADEXT WG1 Pre-authentication AAA Requirements Yoshihiro Ohba Alper Yegin
1 IEEE MEDIA INDEPENDENT HANDOVER DCN: DCN:21-07-xxx Title: Security Optimization During Handovers: SG Proposal Date Submitted: xx,
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: September 16, 2010 Presented at IEEE session.
IEEE MEDIA INDEPENDENT HANDOVER Title: An Architecture for Security Optimization During Handovers Date Submitted: September,
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Pre-authentication Activity Date Submitted: February 26, 2006.
Paris, August 2005 IETF 63 rd – mip6 WG Mobile IPv6 bootstrapping in split scenario (draft-ietf-mip6-bootstrapping-split-00) mip6-boot-sol DT Gerardo Giaretta,
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: May 14, 2009 Presented at IEEE session.
1 IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: EAP Pre-authentication Problem Statement in IETF HOKEY WG Date Submitted: September,
Software-Defined Networking in Heterogeneous Radio Access Networks TNC 2014 Conference, Dublin Hao Yu, DTU/NORDUnet May 21, 2014.
Service Flows Distribution and Handoff Technique based on MIPv6 draft-liu-dmm-flows-distribution-and-handoff-00
21-07-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxxx Title: MIH security issues Date Submitted: July, 02, 2007 Presented at.
Trend of Mobility Management Yen-Wen Chen Ref: 1.Draft IEEE Standard for Local and Metropolitan Area Networks: Media Independent Handover Services 2.Transport.
Introduction to “Tap – Dance ”. Company Proprietary Presentation Topics  Introduction  Handover scenarios  Inter-Network Handover consequences  Common.
Requirement for Proxy Mobile IP tunnel for AGW-eBS data tunnel Qualcomm, Inc. Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
IEEE MEDIA INDEPENDENT HANDOVER DCN:
Pre-authentication Problem Statement (draft-ohba-hokeyp-preauth-ps-00
Network Based Connectivity and Mobility Management for IPv4 draft-chowdhury-netmip4-00.txt Kuntal Chowdhury IETF-65.
Media-Independent Pre-authentication (MPA) Framework
Pre-authentication Overview
IEEE MEDIA INDEPENDENT HANDOVER DCN: srho
draft-corujo-ps-common-interfaces-lmm-00
IETF67 B. Patil, Gopal D., S. Gundavelli, K. Chowdhury
2002 IPv6 技術巡迴研討會 IPv6 Mobility
IEEE MEDIA INDEPENDENT HANDOVER DCN:
IEEE MEDIA INDEPENDENT HANDOVER
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: March 18, 2010 Presented at IEEE session.
IEEE MEDIA INDEPENDENT HANDOVER DCN: sec
IEEE MEDIA INDEPENDENT HANDOVER
Mobility Support in Wireless LAN
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: July 21, 2011 Presented at IEEE session.
Presentation transcript:

A Framework of Media-Independent Pre-authentication (MPA) for Inter-domain Handover optimization draft-ohba-mobopts-mpa-framework-05.txt Ashutosh Dutta Victor Fajardo Yoshihiro Ohba Kenichi Taniuchi Henning Schulzrinne (See also draft-ohba-mobopts-mpa-implementation-04.txt for performance results)

Media-independent Pre- Authentication (MPA) MPA is a mobile-assisted higher-layer authentication, authorization and handover scheme that is performed before establishing L2 connectivity to a network where mobile may move in near future MPA provides a secure and seamless mobility optimization that works for Inter-subnet handoff, Inter-domain handoff and Inter-technology handoff MPA works with any mobility management protocol Time Conventional Method AP Discovery AP Switching MPA Pre-authentication IP address configuration & IP handover Time Client Authentic ation Packet Loss Period

MPA Phases 1.Pre-authentication: EAP pre-authentication to CTN (Candidate Target Network) 2.Pre-configuration: Proactive IP address acquisition from CTN 3.Pre-switching: L3 HO execution over MN-nAR tunnel 4.Switching: L2 handover 5.Post-switching: Tunnel deletion Not all MPA phases have to be executed and can be replaced with other mechanisms MPA Operation can stop at phase 1 (pre-auth only) or at phase 2 (pre-auth + pre-authorization),

Proactive Handover Tunnel in pre-switching phase Home Network HA AR Serving NetworkTarget Network CN BU Tunneled Data MN

Agreement in IETF68 Revise MPA framework draft to focus on inter-domain handover problem Specific changes are explained in next slides

“Inter-domain Handover” Section Added Definition of an administrative domain (or a domain): –Networks that are managed by a single administrative entity –An administrative entity may be a service provider, an enterprise and any organization. An Inter-domain handover will by-default be subjected to inter-subnet handover and in addition it may be subjected to either inter-technology or intra-technology handover. Inter-domain handover will be subjected to all the transition steps a subnet handover goes through and in addition it will be subjected to authentication and authorization process as well. It is also likely that type of mobility support in each administrative domain will be different. For example, administrative domain A may have MIPv6 support, while administrative domain B may use Proxy MIPv6.

Inter-domain Handover between CMIPv6 & PMIPv6 domains HA PMA MN AR MPA PMIPv6 domain CMIPv6 domain LMA

“Detailed Issues” Section split MPA Operations (Section 7) –7.1 Discovery –7.2 Pre-authentication in multiple CTN environment –7.3 Proactive IP address acquisition –7.4 Address resolution –7.5 Tunnel management –7.6 Binding Update –7.7 Preventing packet loss –7.8 Link-layer security and mobility –7.9 IP layer security and mobility –7.10 Authentication in initial network attachment MPA Deployment Issues (Section 8) –8.1 Considerations for failed switching and switch-back –8.2 Pre-allocation of QoS resources –8.3 Resource allocation issue during pre-authentication MPA Case Studies for Inter-Domain Handoff (Section 9) –9.1 Homogeneous Mobility Protocol in each domain (MIPv6, SIP Mobility, MIPv4 FA-CoA, PMIPv6) MPA for PMIPv6: –9.2 Diverse Mobility Protocol in each domain –9.3 Multicast mobility –9.4 Coexistence of MPA with other optimization technique

“Applicability Statement” Section moved to earlier section (Section 4) MPA is categorized as a proactive handover optimization mechanism. In other words, MPA is more applicable where an accurate prediction of movement can be easily made Even if accurate prediction of movement is easily made, effectiveness of MPA may be relatively reduced if the network employs network- controlled localized mobility management in which the MN does not need to change its IP address while moving within the network. Effectiveness of MPA may also be relatively reduced if signaling for network access authentication is already optimized for movements within the network, e.g., when simultaneous use of multiple interfaces during handover is allowed In other words, MPA is most viable solution for inter-administrative domain predictive handover without simultaneous use of multiple interfaces

Performance result: MPA with L2sec bootstrapping Use of MPA to bootstrap L2 security, e.g., IEEE 80211i, required for candidate networks, before handover Handover performance between network-layer assisted pre-authentication and i pre-authentication is similar Network-layer assisted pre-authentication works across multiple subnets/domains/media whereas i pre-authentication works only within the and in the same ESS. Type of authentication i post- authentication i pre- authentication Network-layer assisted pre-authentication OperationNon- roaming RoamingNon- roaming RoamingNon- roaming Roaming Authentication and authorization delay 61ms599ms99ms636ms177ms831ms Configuration delayN/A 17ms Secure association18m17ms16ms17ms Total79m616ms115ms655ms211ms865ms Handover Delay79m616ms16ms17ms

Performance result: MPA with multiple Mobility Management Protocols

Summary MPA framework draft has been presented 5 times since IETF62 The draft has been revised to focus on inter- domain handover and it’s in a good shape The draft is fully ready to be a RG draft

Thank You!

MPA for L2 Pre-auth & bootstrapping: Scenario