TF-NGN AAA research Cees de Laat 1 of 10 Utrecht University.

Slides:



Advertisements
Similar presentations
Architecture of a shared-image electronic whiteboard in telemedicine
Advertisements

Authentication Authorization Accounting and Auditing
Session ID Georg Carle, John Vollbrecht, Sebastian Zander, Tanja Zseby San Diego, December 2000.
Policy-based Accounting Draft Version 01 Policy-based Accounting Draft Version 01 Georg Carle, Sebastian Zander, Tanja Zseby GMD FOKUS - German National.
Broadband Networks, Integrated Management & Standardization Nobuo FUJII ITU-T SG4 Vice Chairman NTT Network Innovation Laboratories
M2M middleware service Inge Grønbæk, Telenor R&I ETSI Workshop on RFID and The Internet Of Things, 3rd and 4th December 2007.
All rights reserved © 2005, Alcatel Grid services over IP Multimedia Subsystem  Antoine Pichot, Olivier Audouin, Alcatel  GridNets ’06.
Communicating over the Network
1 Communication in Distributed Systems REKs adaptation of Tanenbaums Distributed Systems Chapter 2.
Application Server Based on SoftSwitch
Fraunhofer Institute FOKUS
44212: Web-site Development
The Anatomy of the Grid: An Integrated View of Grid Architecture Carl Kesselman USC/Information Sciences Institute Ian Foster, Steve Tuecke Argonne National.
8/10/2001GGF - 3 / Leon Gommans - UvA1 Observations on the CAS architecture made from the Generic AAA perspective. 3rd Global Gridforum Oct. 7-10th 2001.
Omniran TG 1 Cooperation for OmniRAN P802.1CF Max Riegel, NSN (Chair OmniRAN TG)
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: J. Vollbrecht and C. de Laat RFC 2903, 2904, 2905,
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903, 2904, 2905,
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: J. Vollbrecht and C. de Laat RFC 2903, 2904, 2905,
User-Level Performance Monitoring Programme Cees de Laat Hans Blom 1 of 6 Utrecht University.
Authorization of a QoS path based on Generic AAA SC2002 Baltimore NOV Bas van Oudenaarde Advanced Internet Research Group University of Amsterdam.
Policy-based Accounting Tanja Zseby, Georg Carle, Sebastian Zander GMD FOKUS - German National Research Institute for Information Technology Competence.
QoS Auditing Sebastian Zander, Tanja Zseby GMD FOKUS - German National Research Institute for Information Technology Competence Center Global Networking.
Generic AAA Architecture draft-delaat-aaa-generic-00 C. de Laat Utrecht University G. Gross Lucent Technologies L. Gommans Cabletron Systems EMEA J. Vollbrecht.
Generic AAA based provisioning Of Network Elements Status update EVL 9/10/03 Leon Gommans University of Amsterdam.
EEC-484/584 Computer Networks Lecture 3 Wenbing Zhao
Layer 7- Application Layer
Protocols and the TCP/IP Suite Chapter 4 (Stallings Book)
DRIVER Step #1 towards a Pan-European Digital Repository Infrastructure Yannis Ioannidis University of Athens, Hellas IST 2007 Networking Session: Future.
Examples for Policy-based Accounting in the AAA Framework Georg Carle, Sebastian Zander, Tanja Zseby GMD FOKUS German National Research Institute for Information.
Policy-based Accounting Draft Sebastian Zander, Tanja Zseby GMD FOKUS - German National Research Institute for Information Technology Competence Center.
AAA-ARCH IRTF-RG Authentication Authorisation and Accounting ARCHitecture chairs: C. de Laat J. Vollbrecht 1 of 16.
AAA-ARCH IRTF-RG Authentication Authorisation and Accounting ARCHitecture Research Group chairs: C. de Laat J. Vollbrecht Content of this talk has contributions.
1 Pertemuan 7 Communication Protocols for E-Business Matakuliah: M0284/Teknologi & Infrastruktur E-Business Tahun: 2005 Versi: >
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903, 2904, 2905,
Policy-based Accounting: Accounting Issues Georg Carle, Sebastian Zander, Tanja Zseby GMD FOKUS - German National Research Center for Information Technology.
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: J. Vollbrecht and C. de Laat RFC 2903, 2904, 2905,
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903,
Accounting, billing & payment Support for financial exploitation of network-based services Henk Jonkers Telematica Instituut Enschede, the Netherlands.
1 Directories and Policy-Based Networking - Strassner Directories & Policy-Based Networking 0827_02F8_c1 John Strassner Cisco Systems.
The IRTF Promoting Research for the Evolution of the Future Internet Cees de Laat chair AAAARCH-Research Group Utrecht University.
1 Computer Communication & Networks Lecture 27 Application Layer: Electronic mail and FTP Waleed.
Chapter 2 Network Models
Layer Architecture of Network Protocols
Computer Networks.  The OSI model is a framework containing seven layers that defines the protocols and devices used at each stage of the process when.
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903, 2904, 2905,
Networks – Network Architecture Network architecture is specification of design principles (including data formats and procedures) for creating a network.
Internet Protocol B Bhupendra Ratha, Lecturer School of Library and Information Science Devi Ahilya University, Indore
1 End-user Protocols, Services and QoS. 2 Layering: logical communication application transport network link physical application transport network link.
Application Layer Khondaker Abdullah-Al-Mamun Lecturer, CSE Instructor, CNAP AUST.
Real-time Flow Management 2 BOF: Remote Packet Capture Extensions Jürgen Quittek NEC Europe Ltd, Heidelberg, Germany Georg Carle GMD.
Chapter 2 Protocols and the TCP/IP Suite 1 Chapter 2 Protocols and the TCP/IP Suite.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Application Layer Functionality and Protocols Network Fundamentals.
Protocols COM211 Communications and Networks CDA College Olga Pelekanou
1 Chapters 2 & 3 Computer Networking Review – The TCP/IP Protocol Architecture.
The concepts of Generic AAA are described in RFC2903 [1] (Generice AAA Architecture) and RFC2904 [2] (Authorization Framework). Several.
Middleware Solution for What Problem? Cees de Laat Faculty of Physics and Astronomy Utrecht University.
Authorization GGF-6 Grid Authorization Concepts Proposed work item of Authorization WG Chicago, IL - Oct 15 th 2002 Leon Gommans Advanced Internet.
Cisco Discovery Semester 1 Chapter 6 JEOPADY RouterModesWANEncapsulationWANServicesRouterBasicsRouterCommands RouterModesWANEncapsulationWANServicesRouterBasicsRouterCommands.
Computer Network Architecture Lecture 6: OSI Model Layers Examples 1 20/12/2012.
EGEE is a project funded by the European Union under contract IST JRA4 Overview Javier Orellana JRA4 Coordinator EGEE Kick Off Meeting SA2.
The OSI Model An ISO (International standard Organization) that covers all aspects of network communications is the Open System Interconnection (OSI) model.
Communication Networks NETW 501 Tutorial 2
Georg Carle, Sebastian Zander, Tanja Zseby
EA C451 Vishal Gupta.
Implementing TMG Server Publishing
Lecture 6: TCP/IP Networking By: Adal Alashban
IS 4506 Server Configuration (HTTP Server)
AAA: A Survey and a Policy- Based Architecture and Framework
Networking for Home and Small Businesses – Chapter 6
IS 4506 Configuring the FTP Service
Presentation transcript:

TF-NGN AAA research Cees de Laat 1 of 10 Utrecht University

Contents of this talk This space is intentionally left blank 2 of 10

Physics-UU to IPP-FZJ => 7 kingdoms –Netherlands »Physics dept »Campus net »SURFnet –Europe »TEN 155 –Germany »WINS/DFN »Juelich, Campus »Plasma Physics dept Multi Kingdom Problems 3 of 10 USA line 3 ms Jülich 17 ms 2.5 ms

The need for AAA End user RRRR Remote service management 4 of 10 Kingdom NKingdom N+1 BB AAA BB management ? ? AAA $$$ See IRTF AAA-ARCH Research group

Policy based networking example 5 of 10 Experiment Camera Pc Macintosh Policy based networking switch with > layer 4 AAA functionality AAA

ASP Layer 3/4 Switch Internet User Content Server AAA Content Server AAA Content Server AAA Bandwidth Broker AAA User-Home Organisation AAA Financial Organisation AAA Service Profiles AAA ASPISP's 6 of 11

Roles 7 of 12 SURFnet Portals Brokers ContentCustomers Universit y NOBLibrary Hogescho ol

Roles GEANT/DANTE SURFnetDFN SWITCH REDIRIS USERUSER USERUSER USERUSER USERUSER UNI USERUSER USERUSER USERUSER USERUSER USERUSER USERUSER USERUSER USERUSER 8 of 13

Generic AAA server Rule based engine Application Specific Module Auth rulesEvents API AAA Server building block Types of communication: 1: “The” AAA protocol 2: interface (API) to app specific module (addressing!) 3: interface (API or connection) to repositories (e.g. LDAP) 9 of 13 Rule example: Auth_A = (B>9).or. C.and. D

Generic AAA server Rule based engine Application Specific Module PolicyEvents Service 5 Types of communication: 5: Towards service (f.e. COPS, CLI, SNMPv3) Pushing the buttons 10 of 13

Generic AAA server Rule based engine Application specific Module Policy Events Accounting/ Metering Service 5 Acct Data 3 5 AAA Server with Accounting as Part of the Service 11 of 13

AAA Server with Accounting as Separate Service Generic AAA server Rule based engine Application Specific Module Policy Events Accounting Module Service 5 Metering 6 Acct Data of 13

Questions Resource discovery AAA discovery Is AAA high or low in middleware? All A's together or not? Should AAA be visible in the app or only stay in middleware and this way solve its user interface problem Transport TCP/UDP/IPApplications AAAAAA R1R2 CORBACORBA LDAPLDAP BB... Middle ware GUI 12b of 13

Stretching the OSI model Netwerk Diensten bandwidth complexity t au t t Netwerk Applications Middleware 12b' of 13

RG-Goals-1 Specific goals of the RG are: develop generic AAA model by specifically including Authentication and Accounting develop audibility framework specification that allows the AAA system functions to be checked in a multi- organization environment develop a model that supports management of a "mesh" of interconnected AAA Servers define distributed policy framework, coordinate with policy framework WG and others develop an accounting model that allows authorization to define the type of accounting processing required for each session 12c of 13

RG-Goals-2 Specific goals of the RG are: implement a simulation model that allows experimentation with the the proposed architectural models (also work on an emulation) describe interdomain issues using generic model work with AAA WG to align short term AAA protocol requirements with long term requirements as much as possible complete the work in Q (ambitious) RFC !!!! 12d of 13

Research Group - info 12e of 13 Research Group Name: AAAARCH - RG Chair(s) –John Vollbrecht -- –Cees de Laat -- Web page – – Mailing list(s) –For subscription to the mailing list, send to with content of message subscribe aaaarch end –will be archived, retrieval with frames and in plain ascii: » » »ftp://ftp.fokus.gmd.de/pub/glone/mail-archive/aaaarch-current

Research TF-NGN Use European research net as testbed for AAA VLL type of service Top-down –Application –Middleware - AAA –BB –Policy push –Diffserv Focus on techniques and products Concentrate on Authentication, aggregation Authorisation SLA - policy - metering - verification Simulation/emulation 13 of 13