MWI Mobile and Wireless Internet Group Copyright © i2CAT Virtual APs (vAPs) for eduroam GN4 – JRA1-T2 Prague, TNC’16, 15/06/2016 Daniel Camps (i2CAT),

Slides:



Advertisements
Similar presentations
Doc.:IEEE /1523r4 Submission November 2011 Access Delay Reduction for FILS: Network Discovery & Access congestion Improvements Slide 1 Authors:
Advertisements

IEEE INFOCOM 2004 MultiNet: Connecting to Multiple IEEE Networks Using a Single Wireless Card.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Confidential 1 IEEE u Overview Klaas Wierenga TF-Mobility Loughborough, May 7, 2009.
3G WLAN handover Gabor Bajko Nokia. Experiment Upstream-router DSMIP6-HA V6 V4 V6 Internet WiFi HSPA DSMIP6 Home Agent.
Fast L3 Handoff in Wireless LANs Andrea G. Forte Sangho Shin Henning Schulzrinne.
Doc.: IEEE /0598r0 Submission May 2012 Steve Grau, Juniper NetworksSlide 1 Layer 3 Setup with Dynamic VLAN Assignment Date: Authors:
VGO 2 May 2003 Online Gaming by VGO2 Philippe Villeneuve Gustavo Basilio Niklas Åbrink Kristoffer Sjögren Nrip Nihalani Gunnar Wretlind.
Application Guide For Mesh AP – MAP-3120 How to setup VLAN for different services in MAP-3120? F/W:
Omniran IEEE 802 Enhanced Network Detection and Selection Date: Authors: NameAffiliationPhone Max RiegelNSN
TNC 2003 Wireless Campus project Coletta Elisa Marchioro -
Doc.: IEEE /1000r0 Submission July 2011 Jihyun Lee, LG ElectronicsSlide 1 TGai FILS Proposal Date: Authors: NameAffiliationsAddressPhone .
Self-Management in Chaotic Wireless Deployments A. Akella, G. Judd, S. Seshan, P. Steenkiste Presentation by: Zhichun Li.
Wireless Networking WAN Design Module-06
Peer WLAN Consortium: A P2P Case Study Mobile Multimedia Laboratory Department of Informatics Athens University of Economics & Business Athens MMAPPS Meeting,
Networking Components
Cisco Confidential © 2010 Cisco and/or its affiliates. All rights reserved. 1 MSE MSAP Functional Specifications Presenter Name: Patrick Nicholson.
Omniran OmniRAN Wi-Fi Hotspot Roaming Use Case Date: Authors: NameAffiliationPhone Max RiegelNSN
Doc.: IEEE /0034r0 Submission NameAffiliationsAddressPhone Hitoshi MORIOKAAllied Telesis R&D Center Tenjin, Chuo-ku, Fukuoka
January 2005Rudolf, Kwak, Worstell1 VoIP in WLANs and E911 support Marian Rudolf, Joe Kwak, InterDigital; Harry Worstell, AT&T doc: IEEE /0014r0.
21-07-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: MIH Protocol Security Date Submitted: December, 2007 Presented.
Unrestricted Connection manager MIF WG IETF 78, Maastricht Gaëtan Feige, Cisco (presenter) Pierrick Seïté, France Telecom -
Interworking (802.11u) Scott Armitage.
Towards Programmable Enterprise WLANs With Odin
CWNA Guide to Wireless LANs, Second Edition
A Mobile-IP Based Mobility System for Wireless Metropolitan Area Networks Chung-Kuo Chang; Parallel Processing, ICPP 2005 Workshops. International.
1 C-DAC/Kolkata C-DAC All Rights Reserved Computer Security.
Standard for a Convergent Digital Home Network for Heterogeneous Technologies Zhimeng Du 12/5/2013.
NETWORKING COMPONENTS AN OVERVIEW OF COMMONLY USED HARDWARE Christopher Johnson LTEC 4550.
Wireless II. Frames Frames – Notes 3 Frame type ▫Management  Beacons  Probes  Request  Response  Associations  Request  Response  Disassociate.
Submission doc.: IEEE 11-11/1414r2 November 2011 Katsuo Yunoki, KDDI R&D LaboratoriesSlide 1 Probe Request and Response in TGai Date: Authors:
Submission doc.: IEEE 11-12/0281r0 March 2012 Jarkko Kneckt, NokiaSlide 1 Recommendations for association Date: Authors:
IEEE MEDIA INDEPENDENT HANDOVER DCN: MISU Title: Proposal on new MIH service for Proximity Service Communications Date Submitted:
Doc.: IEEE /0638r0 Submission May 2004 Bernard Aboba, MicrosoftSlide 1 Network Selection Bernard Aboba Microsoft
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Doc.: IEEE /1280r1 Submission Jan 2006 Bin Wang, ZTE CorporationSlide 1 Frequent Handover Notice: This document has been prepared to assist IEEE.
Doc.: IEEE /1019r0 Submission September 2004 Soohong Daniel Park & Jaehwan Lee Access Router Identifier (ARID) for supporting L3 mobility Soohong.
Performance Validation of Mobile IP Wireless Networks Presented by Syed Shahzad Ali Advisor Dr. Ravi Pendse.
SOCIAL HOUSEKEEPING THROUGH INTERCOMMUNICATING APPLIANCES AND SHARED RECIPES MERGING IN A PERVASIVE WEB-SERVICES INFRASTRUCTURE WP8 – Tests Ghent CREW.
Submission doc.: IEEE 11-12/0553r4 May 2012 Jarkko Kneckt, NokiaSlide 1 Response Criteria of Probe Request Date: Authors:
SubmissionSlide 1Dwight Smith, Motorola Mobility Nov 2012doc.: IEEE 11-12/1332r0 Other Service Discovery Concepts Date: Authors:
Submission doc.: IEEE 11-12/535r1 May 2012 Jarkko Kneckt, NokiaSlide 1 Scanning and FILS requirements Date: Authors:
Cooperation between stations in wireless networks Andrea G. Forte, Henning Schulzrinne Department of Computer Science, Columbia University Presented by:
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Support for Load Balancing in v
Doc.: IEEE /1259r0 SubmissionYunlu Liu (China Mobile)Slide 1 Measurement Reporting in WLAN Date: Authors: Nov 2012.
Doc.: IEEE /1000r1 Submission July 2011 Jihyun Lee, LG ElectronicsSlide 1 TGai FILS Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0568r0 Submission May 2012 Young Hoon Kwon, Huawei Slide 1 AP Discovery Information Broadcasting Date: Authors: NameAffiliationsAddressPhone .
Doc.:IEEE /1503r1 November 2011 Short Beacon Slide 1 Authors:
Doc.: IEEE /1436r0 Submission November 2004 Mike Moreton, STMicroelectronicsSlide 1 L2 Domain Indication Mike Moreton, STMicroelectronics 15 th.
Doc.:IEEE /1523r1 Submission November 2011 Access Delay Reduction for FILS: Network Discovery & Access congestion Improvements Slide 1 Authors:
Easy 802.1X Onboarding with EAPConfig files and Supplicant Configuration Automatic Discovery (SCAD) Gareth Ayres (Speaker) Stefan.
Doc.:IEEE /0129r1 January 2012 S.Abraham, Qualcomm Inc Short Beacon Slide 1 Authors:
Improving the eduroam experience with Interworking (802.11u)
Overlapping eduroam networks operated by different organizations
By Sachin Kumar Korenga & Rochita Thakkallapally
Wireless Technologies
Wireless II.
5G MOBILE TECHNOLOGY By J.YOGESH 08M31A0425.
AP Discovery Information Broadcasting
Response considerations in Active Scanning
Maryna Komarova (ENST)
Local Administrator Advertisements
Network Selection Bernard Aboba Microsoft
Month Year doc.: IEEE yy/xxxxr0
Discovery Assistance for ay
Mobile IP Outline Homework #4 Solutions Intro to mobile IP Operation
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Cooperative AP Discovery
Month Year doc.: IEEE yy/xxxxr0
What’s New In WatchGuard Wi-Fi Cloud v8.6
Presentation transcript:

MWI Mobile and Wireless Internet Group Copyright © i2CAT Virtual APs (vAPs) for eduroam GN4 – JRA1-T2 Prague, TNC’16, 15/06/2016 Daniel Camps (i2CAT), Ilker Demirkol (UPC), Raimundas Tuminauskas (KUT), Zbigniew Oltustyk (PSNC), Silvia Surroca (UPC)

Copyright © i2CAT 2 1.Problem Statement 2.Proposed Solution 3.Performance Evaluation (with demo video) 4.Conclusions and next steps Outline

MWI Mobile and Wireless Internet Group Copyright © i2CAT 3 1. Problem Statement (1/3) eduroam is too successful … Different entities offering eduroam services may operate in close proximity Eduroam providers around i2CAT’s office in Barcelona

Copyright © i2CAT 4 1. Problem Statement: Issue 1 - Mobility (2/3) eduroam was not designed to have multiple providers operating in the same area was originally designed assuming that the SSID would convey a service name … operated by a single provider devices perform cell selection based on SSID and signal strength  select the “eduroam” AP with the best signal If the “eduroam” APs belong to different providers, IP address changes  Some applications may be affected

Copyright © i2CAT 5 1. Problem Statement: Issue 2 - Policing (3/3) eduroam providers compete against each other, and against other Wi-Fi networks for ISM bandwidth QoE is jeopardized as Wi-Fi usage increases eduroam providers may want to have tools to police bandwidth usage upon congestion e.g. police bandwidth according to eduroam realm Note: fairness is not at stake

Copyright © i2CAT 6 2. Proposed Solution Instantiate “per-realm” vAPs in physical APs. vAP (multi-SSID) has wide cross-vendor support Not quite … vAPs introduce OTA overhead: Instantiate vAPs representing providers in a geographical area A default vAP for users of other realms default_vap vap_upcvap_ub vap_i2cat ssid = eduroam

Copyright © i2CAT 7 2. Proposed Solution – Solving Mobility Tunnel each vAP back to its home eduroam domain Note: We are talking about providers in close proximity  added delay is small default_vap vap_upcvap_ub vap_i2cat ssid = eduroam EoGRE

Copyright © i2CAT 8 2. Proposed Solution – Solving Mobility

Copyright © i2CAT 9 2. Proposed Solution – Solving policying Police bandwidth at the wireless and vAP levels vAPs broadcast a WMM Parameter Element containing Wi-Fi access priorities for each realm vAP1 ssid=eduroam WMM_QoS = Set_1 vAP2 ssid=eduroam WMM_QoS = Set_2 Beacon vAP1: {QoS_1} Beacon vAP2: {QoS_2}

Copyright © i2CAT Proposed Solution – Balancing STAs Main problem: How can we force STAs to associate to the vAP representing its eduroam realm? STAs only see SSID=„eduroam“ and a BSSID vAPs cannot be pre-provisioned with STA MACs Strategy: 1.A STA associates to a vAP, and we initiate authentication 2.We discover the STA’s realm Realm contained in the EAP response message 3.We move the STA to the proper vAP representing the realm … but how? 4.We proactively configure surrounding APs

Copyright © i2CAT Proposed Solution – Balancing STAs What we would have liked... Problem is the amost no adoption of this feature on the client side  We tried the hard way (Deauth) vAP1 vAP2 BSS Transistion Management Req (vap2) BSS Transistion Management Resp Assoc & Auth BSS Transistion Management defined in v

Copyright © i2CAT Proposed Solution – Balancing STAs default_vap uses blacklist Other vaps use whitelist New STAs associate to default_vap Realm is discovered White/Black lists are configured Deauth is sent STA reassociates through proper vAP

Copyright © i2CAT Performance Evaluation Testbed

Copyright © i2CAT Performance Evaluation Question 1: Assume white/black lists properly configured... do STAs connect to the proper vAP? how long does it take them? Observed behavior Always vAP with lowest BSSID Jiayu - G4 Jiayu - S3 BQ - Aquaris A4.5 Select a Random vAP Apple - MC603Y/A (Iphone 4) Jiayu - G3 One Plus – ONE A2003 Motorola - Moto G BQ – Aquaris E5 LG – Nexus 5 Samsung - GT-S5570I (Galaxy Mini) Samsung – SM-G7105 (Galaxy Grand 2) Samsung – SM-T705 (Galaxy Tab S) SM-G920F (Galaxy S6) MG482QL/A (Iphone 6)

Copyright © i2CAT Performance Evaluation Observed access times After receiving denied authentication from a vAP STAs behave differently Diverse client behavior: 1.Quickly try all vAPs in RR fashion (iphone) 2.Try with higher probability first vAP (Jiajyu G3) 3.Introduce timeout after Auth. Failed (Galaxy Mini)

Copyright © i2CAT Performance Evaluation Question 2: What happens the first time, i.e. black/white lists not setup? how do STAs behave after receiving a Deauth? Observed behavior Do not try to reconnect (unless user does it manually) One Plus – ONE A2003 Samsung – SM-T705 (Galaxy Tab S) MG482QL/A (Iphone 6) Jiayu - G4 Reconnect after timeout TIMEOUT (s) Apple - MC603Y/A (Iphone 4)2 Jiayu - G312 Motorola - Moto G7 BQ – Aquaris E510 LG – Nexus 513 Samsung - GT-S5570I (Galaxy Mini)2 Samsung – SM-G7105 (Galaxy Grand 2) 12 SM-G920F (Galaxy S6)15

Copyright © i2CAT Performance Evaluation Observed access times (TOTAL) In the worst case the user needs to tap twice Diverse client behavior due to different timeouts and random selection of correct vAP Note: This is only needed the first time Some connection managers often connect without user intervention

Copyright © i2CAT Performance Evaluation Question 3: What is the impact of the EoGRE tunneling on the eduroam connection setup? 100ms interdomain delay assumed Time until EAP success (s) IP acquisition time (s) eduroam (IP through visited domain)Tunneling to home domain Average

Copyright © i2CAT Performance Evaluation Question 4: What about handover? Short video here

Copyright © i2CAT Conclusions and next steps Introducing vAPs is feasible... but the main problem is steering STAs to the proper vAP Client ecosystem is very complex... but we should monitor adoption of features like BSS Transition Mngmt Advanced implementations could check the MAC OUI to infer capabilities of the devices... but maintenance is complex Proactive white/black list population is essential... requires interdomain interfaces Roaming models based on Hotspot 2.0 should also be studied Different vAPs could have different roaming agreement. Assume a custom SSID per realm, e.g. „eduroam-REALM“ STA connection manager would be configured to connect to „eduroam- REALM“ or default „eduroam“

MWI Mobile and Wireless Internet Group Copyright © i2CAT Mobile Wireless Internet Group