1 AAA Framework for Multicasting draft-ietf-mboned-multiaaa-framework-01.txt July 11, 2006 Hiroaki Satou Hiroshi Ohta

Slides:



Advertisements
Similar presentations
Akihiro Tanabe, Daisuke Andou, Kaori Izutsu, Tsunemasa Hayashi and Hiroshi Tohjo NTT Access Network Service Systems Laboratories {atanabe, dandou,
Advertisements

IETF 77, March 2010, Anaheim Updates on Requirements for Multicast AAA coordinated between CPs and NSPs draft-ietf-mboned-maccnt-req-09 & AAA and Admission.
Encrypting Wireless Data with VPN Techniques
Geneva, 15 May 2009 Status of NGN architecture related studies in ITU-T SG13 Olivier Le Grand WP 3/13 chairman France Telecom JOINT ITU-T SG13 - IEEE NGSON.
All rights reserved © 2005, Alcatel Grid services over IP Multimedia Subsystem  Antoine Pichot, Olivier Audouin, Alcatel  GridNets ’06.
Push Technology Humie Leung Annabelle Huo. Introduction Push technology is a set of technologies used to send information to a client without the client.
Always Best Connected Architecture and Design Rajesh Mishra Ericsson Berkeley Wireless Center.
Quality of Service Update
CPSC Network Layer4-1 IP addresses: how to get one? Q: How does a host get IP address? r hard-coded by system admin in a file m Windows: control-panel->network->configuration-
Supercharging PlanetLab A High Performance,Multi-Alpplication,Overlay Network Platform Reviewed by YoungSoo Lee CSL.
CMPE208 Presentation Terminal Access Controller Access Control System Plus (TACACS+) By MARVEL (Libing, Bhavana, Ramya, Maggie, Nitin)
1 Discussion Issues on Receiver Access Control in the Current Multicast Protocols (Update) draft-ietf-mboned-rac-issues-01.txt November 9th, 2005 Tsunemasa.
Workflow & Event Derivation Workshop
6 The IP Multimedia Subsystem Selected Topics in Information Security – Bazara Barry.
Rev BMarch 2004 The ABC Service as a Research Infrastructure Rajesh Mishra Per Johansson Cahit Akin Salih Ergut.
Ubiquitous Access Control Workshop 1 7/17/06 Access Control and Authentication for Converged Networks Z. Judy Fu John Strassner Motorola Labs {judy.fu,
Internet Telephony Helen J. Wang Network Reading Group, Jan 27, 99 Acknowledgement: Jimmy, Bhaskar.
1 Extending SIP Speaker: Hsuan-Ming Chen Adviser: Ho-Ting Wu Date: 2005/04/26.
By: Alena Newcomb.  What is a WI-FI hotspot?  Wireless Local Area Network location that provides broadband Internet access.  Use of laptops, PDA, or.
Chapter 16 AAA. AAA Components  AAA server –Authenticates users accessing a device or network –Authorizes user to perform specific activities –Performs.
Workflow & Event Derivation Workshop
1 An overview Always Best Connected Networks Dênio Mariz Igor Chaves Thiago Souto Aug, 2004.
Cellular IP: Proxy Service Reference: “Incorporating proxy services into wide area cellular IP networks”; Zhimei Jiang; Li Fung Chang; Kim, B.J.J.; Leung,
Session Policy Framework using EAP draft-mccann-session-policy-framework-using-eap-00.doc IETF 76 – Hiroshima Stephen McCann, Mike Montemurro.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 9 Network Policy and Access Services in Windows Server 2008.
Virtual Private Networks (Tunnels). When Are VPN Tunnels Used? VPN with PPTP tunnel Used if: All routers support VPN tunnels You are using MS-CHAP or.
CIS679: RTP and RTCP r Review of Last Lecture r Streaming from Web Server r RTP and RTCP.
1 Kyung Hee University Prof. Choong Seon HONG Network Control.
Framework & Requirements for an Access Node Control Mechanism in Broadband Multi-Service Networks ANCP WG IETF 70 – Vancouver draft-ietf-ancp-framework-04.txt.
Client-controlled QoS Management in Networked Virtual Environments Patrick Monsieurs, Maarten Wijnants, Wim Lamotte Expertise Center for Digital Media.
Mechanism to support establishment of charging policies Group Name: WG2-ARC Source: InterDigital Meeting Date: TP8 Agenda Item:
1 Accounting, Authentication and Authorization Issues in “Well Managed” IP Multicasting Services November 9, 2005 Tsunemasa Hayashi
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Othman Othman M.M., Koji Okamura Kyushu University 1.
Skeeve Stevens APNIC 29, Kuala Lumpur Alternative criteria for subsequent IPv6 allocations Prop-083v002.
OmniRAN Specification – Structuring the effort Document Number: Omniran Date Submitted: Source: Max Riegel
Module 11: Remote Access Fundamentals
Group Communications at Concordia J. William Atwood High Speed Protocols Laboratory Concordia University Montreal, Quebec, Canada.
Ethernet Basics - 5 IGMP. The Internet Group Management Protocol (IGMP) is an Internet protocol that provides a way for an Internet computer to report.
NTT 2005 © 1 AAA Framework for Multicasting draft-satou-multiaaa-framework-00.txt November 9th, 2005 Hiroaki Satou Hiroshi.
QUALCOMM Incorporated 1 Protocol Options for BSN- BSMCS Controller Interface Jun Wang, Kirti Gupta 05/16/2005 Notice: Contributors grant a free, irrevocable.
A Conference Gateway Supporting Interoperability Between SIP and H.323 Jiann-Min Ho (Presenter) Jia-Cheng Hu Information Networking Institute Peter Steenkiste.
Real Time Protocol (RTP) 김 준
Identity Management: A Technical Perspective Richard Cissée DAI-Labor; Technische Universität Berlin
11 December, th IETF, AAA WG1 AAA Proxies draft-ietf-aaa-proxies-01.txt David Mitton.
NATIONAL INSTITUTE OF SCIENCE & TECHNOLOGY VOICE OVER INTERNET PROTOCOL SHREETAM MOHANTY [1] VOICE OVER INTERNET PROTOCOL SHREETAM MOHANTY ROLL # EC
1 Integrating security in a quality aware multimedia delivery platform Paul Koster 21 november 2001.
輔大資工所 在職研一 報告人:林煥銘 學號: Public Access Mobility LAN: Extending The Wireless Internet into The LAN Environment Jun Li, Stephen B. Weinstein, Junbiao.
CS460 Final Project Service Provider Scenario David Bergman Dong Jin Richard Bae Scott Greene Suraj Nellikar Wee Hong Yeo Virtual Customer: Mark Scifres.
Switch Features Most enterprise-capable switches have a number of features that make the switch attractive for large organizations. The following is a.
MOBILITY Beyond Third Generation Cellular Feb
AAAv6 Charles E. Perkins Patrik Flykt Thomas Eklund.
Security Mechanisms for Delivering Ubiquitous Services in Next Generation Mobile Networks Haitham Cruickshank University of Surrey workshop on Ubiquitous.
Skeeve Stevens APNIC 31, Hong Kong Alternative criteria for subsequent IPv6 allocations Prop-083v003.
ETE Framework for QoS guarantee in Heterogeneous Wired-cum-Wireless Networks (cont.) 홍 석 준
1 MPLS Architectural Considerations for a Transport Profile ITU-T - IETF Joint Working Team Dave Ward, Malcolm Betts, ed. April 16, 2008.
IP Multicast Receiver Access Control draft-atwood-mboned-mrac-req draft-atwood-mboned-mrac-arch.
Admission Control in IP Multicast over Heterogeneous Access Networks
(ITI310) By Eng. BASSEM ALSAID SESSIONS 9: Dynamic Host Configuration Protocol (DHCP)
WREC Working Group IETF 49, San Diego Co-Chairs: Mark Nottingham Ian Cooper WREC Working Group.
Omniran CF00 1 Key Concepts of Association and Disassociation Date: Authors: NameAffiliationPhone Max RiegelNokia
Enabling Secure Internet Access with TMG
Zueyong Zhu† and J. William Atwood‡
IEEE 802 OmniRAN Study Group: SDN Use Case
Local MAC Address Protocol
Chapter 8: Monitoring the Network
AAA: A Survey and a Policy- Based Architecture and Framework
Designing IIS Security (IIS – Internet Information Service)
DHCP: Dynamic Host Configuration Protocol
Editors: Bala’zs Varga, Jouni Korhonen
Presentation transcript:

1 AAA Framework for Multicasting draft-ietf-mboned-multiaaa-framework-01.txt July 11, 2006 Hiroaki Satou Hiroshi Ohta Tsunemasa Hayashi Haixiang He

2 Introduction Background –Purpose of I-D: provide a generalized framework for solution standards to meet requirements defined in draft-ietf-mboned-maccnt-req-04.txt (MACCNT-REQ) Agenda –Updates from satou01 -->mboned01

3 Major Changes Addition to description of roles –Notification of reason for rejection of user access Addition to Accounting –NSP should manage and log multicast states on user basis for user based accounting Addition of roles and mechanisms for “Caching of AAA Results” –AAA results from CP may be cached in NSP Removed mention of “commercial” to reflect a comment

4 Conclusion Define building blocks in a framework. Facilitate which WGs own which building blocks. Which building blocks need to be created/ modified. Goal is to achieve operational capabilities such as access control, admission control & user based accounting. Help solutions study with collaboration with appropriate WGs. Any Comments

5 Extra Slides

6 Network Models Content Server User Content Provider (CP) Network Provider (NP) User CP (TV Broadcaster) NP User (a) Single-Entity Model (b) Multiple-Entity Model AAA Server Content Server AAA Server NP provides content CPs and NPs are different entities (companies) Multicast Router

7 Functional Roles of Multiple-Entity Networks CP is responsible for authentication of content request NP’s edge routers control multicast packets and collect J/L based accounting information NP is responsible for packet level QoS (if necessary) edge NP NNI CP (A) AAA Server CP (B) AAA Server NNI Authentication Multicast Control Accounting QoS management NP= Network Provider CP= Content Provider User

8 Users CP assigned userID NP selection (e.g. fixed line or mobile) Access Request Content Providers UserID assignment Authentication A New Framework Network Providers CP selection Forward request to appropriate CP Bandwidth (QoS) Management Accounting Access Request Accounting Info. Response (Authentication Results) NP= Network Provider CP= Content Provider Response (Authentication Results) Multicast Packets

9 Proposed Framework (overview) NP- AAA CP-AAA User Edge Router Auth. Info. on IGMP/MLD (may be encrypted between user and CP- AAA) Forwarding Auth. Info. Notifying user access port CP selection Access ID management User access port detection Forwarding Auth. Info. With access ID Authentication Result With access ID Knowing corresponding access port by access ID Virtual session control for user-based accounting Framework for multicast AAA and QoS Management

10 Major changes (satou00->satou01) Added roles for each entity –The USER selects a CP and a NSP (This may be automatically; e.g. a fixed line NSP for STB or a mobile NSP for mobile terminal) –The CP is responsible for Authentication and Authorization of user's access –The NSP is responsible for managing its network resources –If TP (Transit Provider) is used, the TP transfers multicast stream from the CP to the NSP. TP is responsible for managing its network resources USER NSP (e.g. fixed line) NSP (e.g. mobile) TP (if existing) CP

11 Major changes (satou00->satou01 Cont.) Added section 4, "Network Connection Model and Functional Components“ Added modularity: fully enabled versions and partially enabled versions USER NSP Manage network resources (optional) Request Content (and Network Resources ) CP Authentication AAA Proxy Request Content Access Authorization Accounting Authorization Accounting information Resource Allocation