IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht www.aaaarch.org RFC 2903, 2904, 2905,

Slides:



Advertisements
Similar presentations
Authentication Authorization Accounting and Auditing
Advertisements

Session ID Georg Carle, John Vollbrecht, Sebastian Zander, Tanja Zseby San Diego, December 2000.
Policy-based Accounting Draft Version 01 Policy-based Accounting Draft Version 01 Georg Carle, Sebastian Zander, Tanja Zseby GMD FOKUS - German National.
AAA Architecture Use of a AAA Server Application Specification to Support Generic AAA Applications Across a Mesh of Interconnected AAA Servers With Policy.
Whos who in the IETF Zoo? Geoff Huston Executive Director, Internet Architecture Board.
802.1AF - directions define requirements to find and create connections in terms of Discovery - Authentication - Enable 1.Discover of what can be done.
Web Services Architecture An interoperability architecture for the World Wide Service Network.
TF-NGN AAA research Cees de Laat 1 of 10 Utrecht University.
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: J. Vollbrecht and C. de Laat RFC 2903, 2904, 2905,
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903, 2904, 2905,
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: J. Vollbrecht and C. de Laat RFC 2903, 2904, 2905,
Virtual Ticketing Agents using Web Services and J2EE Advisor: Dr. Chung-E-Wang Date: 05/06/03 Naveen Repala.
Connect. Communicate. Collaborate Click to edit Master title style MODULE 1: perfSONAR TECHNICAL OVERVIEW.
Authorization of a QoS path based on Generic AAA SC2002 Baltimore NOV Bas van Oudenaarde Advanced Internet Research Group University of Amsterdam.
Policy-based Accounting Tanja Zseby, Georg Carle, Sebastian Zander GMD FOKUS - German National Research Institute for Information Technology Competence.
QoS Auditing Sebastian Zander, Tanja Zseby GMD FOKUS - German National Research Institute for Information Technology Competence Center Global Networking.
Generic AAA Architecture draft-delaat-aaa-generic-00 C. de Laat Utrecht University G. Gross Lucent Technologies L. Gommans Cabletron Systems EMEA J. Vollbrecht.
Draft-irtf-aaaarch-aaa-pol-00.txt Joe Salowey Guus Sliepen David Spence
Generic AAA model in Grids IRTF - AAAARCH meeting IETF 52 – Dec 14 th Salt Lake City Leon Gommans Advanced Internet Research Group.
November IPsec Remote Access BOF Washington D.C. November
Generic AAA based provisioning Of Network Elements Status update EVL 9/10/03 Leon Gommans University of Amsterdam.
An authorization control framework to enable service composition Takashi Suzuki, Randy H. Katz EECS Department University of California, Berkeley {tsuzuki,
A Model for Grid User Management Rich Baker Dantong Yu Tomasz Wlodek Brookhaven National Lab.
Examples for Policy-based Accounting in the AAA Framework Georg Carle, Sebastian Zander, Tanja Zseby GMD FOKUS German National Research Institute for Information.
Policy-based Accounting Draft Sebastian Zander, Tanja Zseby GMD FOKUS - German National Research Institute for Information Technology Competence Center.
AAA-ARCH IRTF-RG Authentication Authorisation and Accounting ARCHitecture chairs: C. de Laat J. Vollbrecht 1 of 16.
AAA-ARCH IRTF-RG Authentication Authorisation and Accounting ARCHitecture Research Group chairs: C. de Laat J. Vollbrecht Content of this talk has contributions.
Policy-based Accounting: Accounting Issues Georg Carle, Sebastian Zander, Tanja Zseby GMD FOKUS - German National Research Center for Information Technology.
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: J. Vollbrecht and C. de Laat RFC 2903, 2904, 2905,
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903,
Accounting, billing & payment Support for financial exploitation of network-based services Henk Jonkers Telematica Instituut Enschede, the Netherlands.
Slide #1IETF 64 Ops Area Meeting – 07/11/05 Issues in Provisioning Internet-wide VPN Services Christian JACQUENET
The IRTF Promoting Research for the Evolution of the Future Internet Cees de Laat chair AAAARCH-Research Group Utrecht University.
IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903, 2904, 2905,
OASIS ebXML Registry Standard Open Forum 2003 on Metadata Registries 10:30 – 11:15 January 20, 2003 Kathryn Breininger The Boeing Company Chair, OASIS.
1 OPSAWG Agenda Items 7,8, 9 Juergen Quittek, John Parello, Benoit Claise 78th IETF Meeting, Maastricht, Energy Management Framework / Architecture.
DCN: March 7, 2005 IETF 62 - Minneapolis, MN Media Independent Handover Services and Interoperability Ajay Rajkumar Chair, IEEE
1 OSG Accounting Service Requirements Matteo Melani SLAC for the OSG Accounting Activity.
WEIRD Hot Topic: Wireless Chris Burke WEIRD Working Group
EAI WG meeting IETF-65, March 20, Agenda 17:40 Welcome, blue sheet, scribe, agenda bashing 17:50 Review of WG charter (approved) 17:55 Problem/framing:
Web Services Presented By : Noam Ben Haim. Agenda Introduction What is a web service Basic Architecture Extended Architecture WS Stacks.
AAA WG 47 th IETF Adelaide, Australia. Agenda Thursday Agenda, 3:30 – 5:30 PM –Agenda bashing –Document status Network access AAA requirements (AAA WG.
1 Policy-based architecture. 2 Policy management view of the architecture IP MMed domain is a converged services domain where voice, video, data are provided.
OGF DMNR BoF Dynamic Management of Network Resources Documents available at: Guy Roberts, John Vollbrecht.
The concepts of Generic AAA are described in RFC2903 [1] (Generice AAA Architecture) and RFC2904 [2] (Authorization Framework). Several.
Middleware Solution for What Problem? Cees de Laat Faculty of Physics and Astronomy Utrecht University.
Authorization GGF-6 Grid Authorization Concepts Proposed work item of Authorization WG Chicago, IL - Oct 15 th 2002 Leon Gommans Advanced Internet.
XCON BOF IETF 57 Vienna, Austria July 15, Administriva Conscripting a Scribe Note Well announcement (Read Section 10 of RFC 2026) Blue Sheets.
Access Node Control Protocol (ANCP) IETF 66, Montreal Wojciech Dec Matthew Bocci
Introducing WI Proposal about Authorization Architecture and Policy Group Name: WG4 Source: Wei Zhou, Datang, Meeting Date: Agenda Item:
Introducing WI Proposal about Authorization Architecture and Policy Group Name: WG4 Source: Wei Zhou, Datang, Meeting Date: Agenda Item:
GRID ANATOMY Advanced Computing Concepts – Dr. Emmanuel Pilli.
Moving towards an IRS WG Charter Ross Callon IETF 85, Atlanta.
Slide 1 2/22/2016 Policy-Based Management With SNMP SNMPCONF Working Group - Interim Meeting May 2000 Jon Saperia.
Policy Framework WG Agenda 49 th IETF, San Diego Co-chairs: Joel Halpern, Ed Ellesson,
Access Node Control Protocol (ANCP) IETF 68, Prague Wojciech Dec Matthew Bocci
WREC Working Group IETF 49, San Diego Co-Chairs: Mark Nottingham Ian Cooper WREC Working Group.
May 2010 Slide 1 SG Communications Boot Camp Matt Gillmore 11/1/2010.
RADIUS By: Nicole Cappella. Overview  Central Authentication Services  Definition of RADIUS  “AAA Transaction”  Roaming  Security Issues and How.
Page 1 R2AD *** DAY 1 (May 23) *** 10:00 Agenda bashing, role call, note taker & time keeper. (KF; 30 min) 10:40 ACS Overview (10 minutes) 11:00 Security.
GGF - © Birds of a Feather - Policy Architecture Working Group.
SIP Working Group IETF Chairs -- Rohan MAHY Dean WILLIS.
GGF-Process WG Administrative Information Process Working Group:ggf-proc-wg Chairs:"Tony Genovese" "Cees de Laat" Secretary/Webmaster:"Stacey Bruno"
Georg Carle, Sebastian Zander, Tanja Zseby
SDN RG State of the Nation
Joseph JaJa, Mike Smorul, and Sangchul Song
Agenda and Status SIP Working Group
IETF 57 Vienna, Austria July 15, 2003
AAA: A Survey and a Policy- Based Architecture and Framework
3GPP and SIP-AAA requirements
Presentation transcript:

IRTF - AAAARCH - RG Authentication Authorisation Accounting ARCHitecture RG chairs: C. de Laat and J. Vollbrecht RFC 2903, 2904, 2905, 2906

Contents of this talk This space is intentionally left blank 2 of 14

History & Charter Authorization subgroup of AAA-WG Commonality in authorization space Tie in policy from all WG's IRTF-RG chartered in Dec 1999 This RG will work to define a next generation AAA architecture that incorporates a set of interconnected "generic" AAA servers and an application interface that allows Application Specific Modules access to AAA functions. 3 of 14

From charter The architecture's focus is to support AAA services that: can inter-operate across organizational boundaries are extensible yet common across a wide variety of Internet services enables a concept of an AAA transaction spanning many stakeholders provides application independent session management mechanisms contains strong security mechanisms that be tuned to local policies is a scalable to the size of the global Internet 4 of 14

Basic AAA Service perspective: –Who is it who wants to use my resource »Establish security context –Do I allow him to access my resource »Create a capability / ticket /authorization –Can I track the usage of the resource »Based on type of request (policy) track the usage User perspective –Where do I find this or that service –What am I allowed to do –What do I need to do to get authorization –What does it cost Intermediaries perspective –Service creation –Brokerage / portals Organizational perspective –What do I allow my people to do –Contractual relationships (SLA’s)

The need for AAA End user RRRR Remote service management Kingdom NKingdom N+1 BB AAA BB management ? AAA $$$ 9 of 14

Roles GEANT/DANTE SURFnetDFN SWITCH REDIRIS USERUSER USERUSER USERUSER USERUSER UNI USERUSER USERUSER USERUSER USERUSER USERUSER USERUSER USERUSER USERUSER

USERUSER UHO AAA Provider AAA Service Authorization Models AGENT USERUSER UHO AAA Provider AAA Service PULL USERUSER UHO AAA Provider AAA Service PUSH

Generic AAA server Rule based engine Application Specific Module Policy Data Service 5 Starting point PDP PEP 4 Accounting Metering 3 4’ 5 Acct Data API Policy Data 3

Multi domain case

Agenda 50th IETF CHAIRS: Cees de Laat John Vollbrecht Cees de Laat Agenda bashing, FNT and opening remarks Cees de Laat draft-irtf-aaaarch-generic-struct-00.txt John Vollbrecht draft-irtf-aaaarch-session-id-00.txt Sebastian Zander draft-irtf-aaaarch-pol-acct-02.txt Guus Sliepen draft-irtf-aaaarch-aaa-pol-01.txt Guus Sliepen draft-taal-aaaarch-generic-pol-01.txt Steven Tuecke security in the grid, overview Bob Morgan Shibboleth update Bob Morgan OASIS security-services TC Henk Jonkers Accounting Examples chairs closing remarks, next steps, summary, collect pink sheets

Agenda 51th IETF CHAIRS: John Vollbrecht Cees de Laat Cees de Laat 10 : Agenda bashing, FNT and opening remarks Cees de Laat 10 : Status, drafts and ongoing activities Christian Hesselman 10 : Content and QoS Policies in Multi-domain Heterogeneous Mobile Systems Walter Weiss 40 : draft: draft-ietf-rap-access-bind-00.txt title: "Framework for Binding Access Control to COPS Provisioning" John Vollbrecht 20 : discussion: next steps AUTH-PIB see memo on mailing list Arie Taal 29 : draft: draft-irtf-aaaarch-generic-pol-00.txt title: A grammar for Policies in a Generic AAA Environment Guus Sliepen 1 : draft: draft-irtf-aaaarch-aaa-pol-01.txt title: Policies in AAA Bob Morgan 15 : Shibboleth and related projects update, impact of Globus chairs 15 : closing remarks, next steps, summary, === collect colored sheets 150

Opening remarks since San Diego: –interim meeting in Utrecht -> draft –3 new drafts –2 reworked –2 teleconferences »About 8 participants –Discussion started with Grid-Forum Participation/contribution –Apart from about 3 or 4 places -> POOR! Evening meeting Re-charter (or not)

Opening remarks since Minneapolis: –1 new draft in AAAARCH, 1 (AUTH) in RAP –1 AUTH related interim meeting in Utrecht –0 reworked –0 teleconferences in AAAARCH –About 10 teleconferences related to AUTH Participation/contribution –Apart from about 3 or 4 places -> POOR! Re-chartered

Charter - research items develop generic AAA model by specifically including Authentication and Accounting UNDERWAY develop auditability framework specification that allows the AAA system functions to be checked in a multi-organization environment NJET develop a model for management of a "mesh" of interconnected AAA Servers NJET describe interdomain issues using generic model NJET define in a high level and abstract way the interfaces between the different components in the architecture UNDERWAY define distributed AAA related policy framework ON THE TABLE develop an accounting model that allows authorization to define the type of accounting processing required for each session ON THE TABLE implement a simulation model that allows experimentation with the proposed architecture UNDERWAY work with RAP-WG to develop an Authentication Information management model ON THE TABLE work with GRID-Forum to align the security and AAA architectural ideas UNDERWAY √

Current drafts 1. draft-irtf-aaaarch-aaa-pol-01.txt Title: Policy in AAA 2. draft-spence-aaaarch-objmsg-00.txt Title: Data Objects and Message Types in the Generic AAA Architecture 3. draft-irtf-aaaarch-session-id-00.txt Title: Session ID 4. draft-irtf-aaaarch-generic-struct-00.txt Title: Structure of a Generic AAA Server 5. draft-taal-aaaarch-generic-pol-01.txt (superceded by 6) Title: Policies in a Generic AAA Environment 6. draft-irtf-aaaarch-generic-policy-00.txt Title: A grammar for Policies in a Generic AAA Environment 7. draft-irtf-aaaarch-pol-acct-03.txt SUBMITTED FOR RFC Title: Policy-based Accounting

Research Group - info Research Group Name: AAAARCH - RG Chair(s) –John Vollbrecht -- –Cees de Laat -- Web page – – Mailing list(s) –For subscription to the mailing list, send to with content of message subscribe aaaarch end –will be archived, retrieval with frames and in plain ascii: » » »ftp://ftp.fokus.gmd.de/pub/glone/mail-archive/aaaarch-current