Why not EAP over PANA? Qualcomm, Inc. Vidya Narayanan, Dondeti, Lakshminath, Jun Wang, Pete Barany Notice: QUALCOMM Incorporated grants a free, irrevocable.

Slides:



Advertisements
Similar presentations
WLAN IW Enhancement for IMS Support
Advertisements

WLAN IW Enhancement for Multiple Authentications Support Notice: Contributors grant free, irrevocable license to 3GPP2 and its Organization Partners to.
Page 1 Title: Traffic Detection Function Extensions for cdma2000 1x and HRPD Networks Sources: Qualcomm Contact: George Cherian
Mobile IPv4 FA CoA Support in WLAN Interworking Raymond Hsu Qualcomm Inc. Notice: QUALCOMM Incorporated grants a free, irrevocable license.
Mobile IPv4 FA CoA Support in WLAN Interworking Raymond Hsu, Qualcomm Inc., Sanket S. Nesargi, Nortel, Nanying Yin,
Inter-AGW HO Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material.
Dynamic HA Assignment for MIPv4 in WLAN Interworking Raymond Hsu, Qualcomm Inc., Wing C. Lau, Qualcomm Inc., Notice:
MIP6-HA-Local-Assignment-Capability indication to MS Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners.
Tunneling Protocol Support for 1x CSFB from E-UTRAN
1 DSMIP6 Support QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota Notice.
IP Connectivity for E911 in HRPD/PDS Networks Page 1 IP Connectivity for Emergency Calls in HRPD/PDS Networks 3GPP2 Meeting, 1/07 IP Connectivity for Emergency.
XHRPD Example Scenario for MSS Masa Shirota Qualcomm Inc. July 15, GPP2 Dalian Meeting Recommendation: FYI Notice QUALCOMM Incorporated grants a.
3GPP2 A r0 3GPP2 C xxxr0 TSG-A WG3 and TSG-C WG2 Title: HRPD Redirect on EPC Unavailable Source: Mike DolanAlcatel-Lucent Dave.
HRPD Femto Local IP Access: Overview Peerapol Tinnakornsrisuphap Qualcomm October 27 th, GPP2 Seoul,
1 IP Service Authorization Support and Mobility Selection for X.S0011-E Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
1 UATI-IP address mapping Peerapol Tinnakornsrisuphap David Ott Qualcomm.
1 Title: Need for the Message Integrity of User traffic Abstract: From both: competitive and security standpoints, UMB standard should add the option of.
1 May 14, 2007 Zhibi Wang, Simon Mizikovsky – Alcatel-Lucent Vidya Narayanan, Anand Palanigounder – QUALCOMM ABSTRACT: Access authentication architecture.
1 cdma2000® Data Service Transition to NULL Support Jun Wang Ravi Patwardhan June 5, 2003 Recommendation -
Broadcast Area Based Management for BCMCS Quanzhong Gao Weidong Wu 04/05/2005.
Security Framework for (e)HRPD 1 S GPP2 TSG-S WG4 Source: QUALCOMM Incorporated Contact(s): Anand Palanigounder
1 IPsec-based MIP6 Security Qualcomm Inc. Starent Inc. Notice: Contributors grant free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
Authentication Profile for UICC- less eHRPD Terminals QUALCOMM Incorporated Contact(s): Anand Palanigounder Jun Wang.
QUALCOMM Incorporated 1 Protocol Options for BSN- BSMCS Controller Interface Jun Wang, Kirti Gupta 05/16/2005 Notice: Contributors grant a free, irrevocable.
Broadcast/Multicast Priority List JUNHYUK SONG SAMSUNG Incorporated grants a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
QUALCOMM PROPRIETARY 3GPP2 Network Evolution Architecture Dec. 04, 2006 Lucent Technologies Nortel Networks Qualcomm Inc. Hitachi, Ltd Huawei Technologies.
1 A13 Proxy for supporting HRPD Handout from femto AP to macro AN Peerapol Tinnakornsrisuphap David Ott
1 Flow Mobility Support QUALCOMM Inc. George Cherian, Jun Wang, Masa Shirota
C August 24, 2004 Page 1 SMS Spam Control Nobuyuki Uchida QUALCOMM Incorporated Notice ©2004 QUALCOMM Incorporated. All rights reserved.
1 SeGW Certificate profile (Revised) 3GPP2 TSG-S WG4 /TSG-X WG5 (PDS) S X xx Source: QUALCOMM Incorporated Contact(s): Anand.
Page 1 January 16, 2008 Source: 3GPP2 TSG-S WG4 (Security) Contacts: Anand Palanigounder, Chair, TSG-S WG4 ( Zhibi Wang,
Proposed 1x Device Binding Solution Based on SX & SX GPP2 TSG-SX WG4 SX Source(s): Qualcomm Incorporated.
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PMIP Comparison QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PCC Support for cdma2000 QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
Proposed Solution for Device Binding 3GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
May 12, 2008 Alcatel Lucent, Cisco, Motorola, Nortel, Verizon ABSTRACT: Proposed is additional key hierarchy and derivation for EPS access over eHRPD.
1 1xBCMCS – Registration for Paging Ragulan Sinnarajah QUALCOMM Incorporated September 15 Notice.
Mobility Management in WLAN IW Inma Carrion, Vijay DevarapalliNokia Raymond HsuQualcomm Inc. Pete McCann, Frank AlfanoLucent Serge ManningSprint Notice:
1 Authentication and User Profile April 24, 2007 Jun Wang QUALCOMM Inc. Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
Dec GPP2 TSG-X PDS 1 BCMCS Higher-Layer Encryption Raymond Hsu, Jun Wang Qualcomm Inc. Dec Notice QUALCOMM Incorporated grants a free, irrevocable.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
UMB AIS Document Structure Ravi Patwardhan, Qualcomm QUALCOMM Incorporated grants a free, irrevocable license to 3GPP2 and its Organizational.
Background Both RoHCv1 and RoHC v2 are supported in 3GPP LTE R8 and R9
Supporting Local Breakout in HRPD Femto Peerapol Tinnakornsrisuphap Qualcomm Doug Knisely
August 25, 2008 Alcatel Lucent ABSTRACT: 1x System Reliability is important in the face of major events, such as an earthquake. There are several ways.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
3GPP2 Network Evolution: UMB->HRPD Handoff October 16, 2007 Qualcomm Inc. Contact: Jun Wang Notice Contributors grant a free, irrevocable license to 3GPP2.
X xxx ZTE Discussion on cdma2000 Charging with PCC Title: Inter-RAT RAN information management protocol Stack Sources: NSN Contact: Scott Marin,
Comment to Limited Idle Mode Nortel Networksgrants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable.
1 Remote IP Access - Stage 2 Architecture proposal for adoption Peerapol Tinnakornsrisuphap Anand.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
EAP over HRPD Comments Qualcomm, Inc. Vidya Narayanan, Dondeti, Lakshminath, Jun Wang, Pete Barany Notice: QUALCOMM Incorporated grants a free, irrevocable.
X xx CT+ZTE PCC for cdma2000 MS Init Call Flows 1 1 Title: PCC for cdma2000 – MS-Init Call Flow Example Sources: CTC, ZTE Contact: CHINA TELECOM.
1 Title: Performance of Default Parameters for 1xEV-DO RTCMAC Source: Christopher Lott, QUALCOMM Incorporated , Date: Februrary.
1 HRPD Fast Handoff Jun Wang and Raymond Hsu Qualcomm Inc Notice: QUALCOMM Incorporated grants a free, irrevocable license to 3GPP2 and its Organization.
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PCC Support for cdma2000 QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
1 Notice (c) ZTE CORPORATION. ZTE Corporation, grants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other.
0 软交换应用的探讨 赵慧玲 2004 年 05 月 Dynamically Coverage Management By Caiqin Zhu(Catherine Zhu) China Telecom Apr © GPP2 China Telecom.
1 PPP Free Operation Mobility Management January 16, 2006 Jun Wang, Pete Barany, Raymond Hsu Qualcomm Inc Notice: Contributors grant free, irrevocable.
1 On 3GPP2 Femto Security Anand Palanigounder Qualcomm Inc. Notice: Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
Signaling Packet Routing for Layer 3 approach in UMB-HRPD/1x interworking KDDI Corporation, Tsunehiko Chiba, Osamu.
Benefits of eBS for UMB Qualcomm Inc. January 08, 2007 Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners.
1 MSI (Multiple Service Instances) Ravindra Patwardhan QUALCOMM Incorporated Review and approve for D Notice QUALCOMM.
WLAN IW Enhancement for Multiple Authentications Support QUALCOMM Inc.: Raymond Hsu, QUALCOMM Inc.: Masa Shirota,
Clarifications on Work Split among TSG-X/A for 3GPP2 Network Evolution March 26, 2007 Airvana/Alcatel-Lucent/CTC/Fujitsu/ Hitachi/KDDI/NEC/Qualcomm/ZTE.
1 IP Service Authorization Support and Mobility Selection Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
Inter-RAT Measurement Control Jungsoo Jung Samsung Electronics Samsung Electronics grants a free, irrevocable license to 3GPP2 and.
Source: Qualcomm Incorporated Contact: Jun Wang, George Cherian March 1, 2010 Page 1 3GPP2 Femtocell Phase II Femto Access Control Enhancement Notice ©
Requirement for Proxy Mobile IP tunnel for AGW-eBS data tunnel Qualcomm, Inc. Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
E-UTRAN - HRPD rev B Interworking
Presentation transcript:

Why not EAP over PANA? Qualcomm, Inc. Vidya Narayanan, Dondeti, Lakshminath, Jun Wang, Pete Barany Notice: QUALCOMM Incorporated grants a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained in the contribution and any modifications thereof in the creation of 3GPP2 publications; to copyright and sell in Organizational Partner’s name any Organizational Partner’s standards publication even though it may include portions of the contribution; and at the Organization Partner’s sole discretion to permit others to reproduce in whole or in part such contributions or the resulting Organizational Partner’s standards publication. QUALCOMM Incorporated is also willing to grant licenses under such contributor copyrights to third parties on reasonable, non- discriminatory terms and conditions for purpose of practicing an Organizational Partner’s standard which incorporates this contribution. This document has been prepared by QUALCOMM Incorporated to assist the development of specifications by 3GPP2. It is proposed to the Committee as a basis for discussion and is not to be construed as a binding proposal on QUALCOMM Incorporated. QUALCOMM Incorporated specifically reserves the right to amend or modify the material contained herein and nothing herein shall be construed as conferring or offering licenses or rights with respect to any intellectual property of QUALCOMM Incorporated other than provided in the copyright statement above.

Introduction and Outline PANA is complex at many levels  Too many documents  Too many protocols Unnecessarily too deep in the stack  Need IP address to operate Complex Architecture More susceptible to DoS attacks Configuration Complexity Fundamental issues raised at the IETF Not a coincidence that it is not used anywhere yet!

PANA Document List WG Documents  draft-ietf-pana-cxtp draft-ietf-pana-cxtp  draft-ietf-pana-mobopts draft-ietf-pana-mobopts  draft-ietf-pana-preauth draft-ietf-pana-preauth  draft-ietf-pana-snmp draft-ietf-pana-snmp  draft-ietf-pana-statemachine draft-ietf-pana-statemachine  draft-ieft-pana-aaa-interworking draft-ieft-pana-aaa-interworking  draft-ietf-pana-framework draft-ietf-pana-framework  draft-ietf-pana-ipsec draft-ietf-pana-ipsec  draft-ietf-pana-pana draft-ietf-pana-pana  RFC 4058 RFC 4058 RFC 4058  RFC 4016 RFC 4016 RFC 4016  draft-ietf-pana-usage-scenarios draft-ietf-pana-usage-scenarios Related documents  draft-anjum-pana-location-requirements-00.txt draft-anjum-pana-location-requirements-00.txt  draft-bournelle-pana-mobopts-analysis-00.txt draft-bournelle-pana-mobopts-analysis-00.txt  draft-forsberg-pana-skc-00.txt draft-forsberg-pana-skc-00.txt  draft-marin-pana-ieee80211doti-00.txt draft-marin-pana-ieee80211doti-00.txt Evidently, a long list of documents to even parse, let alone implement!

Fundamental Issues with PANA IETF Security AD Evaluation of PANA:  “The PANA WG seems to have a fundamental misunderstanding about i. I believe that the people involved in the PANA WG have been told about their misunderstanding by the editor of i (Jesse Walker from Intel), and it seems that this input was ignored this input. As a result the PANA specification that will not work at all in wireless LANs that deploy i.”

Fundamental Issues with PANA IETF Security AD Evaluation of PANA:  “An Access Point that implements i will silently discard all PANA traffic, and as a result, the PANA usage scenarios i (either TKIP or CCMP, which are called WPA and WPA2 by the WiFi Alliance) cannot work as described.”

PANA Architecture PaCPAAAS EP PANA AAA/LDAP/API SNMP/ API IKE/ 4-way HS

Protocols Involved in PANA EAP over PANA  EAP (RFC3748)  IPsec  PANA-SNMP  CxTP  PANA-AAA EAP Method Secure Association Protocol  i 4-way exchange  e 3-way exchange  IKE  Key management still separate and diverse for different access technologies

Protocols Involved – EAPoHRPD EAP over HRPD  EAP (RFC3748) EAP Method GEE

Protocol Layering HRPD EAP Layer Peer Layer Method1Method2 GEE Layer UDP EAP Layer Peer Layer Method1Method2 IPLower LayerPANA EAPoPANA Peer Stack EAPoHRPD Peer Stack

DoS Impacts Worst case impact on system (EAP over PANA)  L2 AND L3 equipment!  More layers to launch DoS attacks  DHCP-based attacks possible Worst case impact on system (EAPoHRPD)  L2 equipment only!

Comparison (1 of 2) EAP over HRPD EAP over PANA Number of OTA messages required  7 7 7 7  7 (not counting AT obtaining IP address) NOTE: If not optimized via piggybacking,  13 EAP methods supported AllAll Integrity protection of EAP messages Yes (dependent upon EAP method) Yes Encryption of attributes in EAP messages Yes (dependent upon EAP method) Reliable, in-order delivery Yes (via EAP retransmission and RLP retransmission/sequence numbers) Yes (via PANA retransmission/sequence numbers, EAP retransmission, and RLP retransmission/sequence numbers) Fragmentation Yes (via RLP or specific EAP method) IP address required No Yes (e.g, link-local)

Comparison (2 of 2) EAP over HRPD EAP over PANA Reliable indication that EAP exchange has completed successfully or failed Yes (dependent upon the EAP method) Yes Separate access authentication (NAP) and service authentication (ISP) supported YesYes Identity privacy supported Yes (dependent upon the EAP method) Bandwidth efficient Yes Requires UDP/IP header (maybe use ROHC to help) LightweightYes Not really 3GPP2 standards work required Yes (about the same as for EAPoPANA … see next slide) Yes (about the same as for EAPoHRPDRLP … see next slide) IETF momentum/industry adoption Yes (meaning EAP over a specific link-layer, not EAP over HRPD per se) Questionable … also, 3GPP2 dependent upon IETF to publish PANA RFCs in timely manner

PANA Timeline 2001 Start of PANA work ?? Original Deadline Fundamental Issues Raised; Still in last call Start of EAPoHRPD work Start Of GEE GEE to IESG EAPoHRPD/GEE Timeline EAPoHRPD Completion

Timeline EAPoHRPD  4Q of 2005 GEE  Submission to IESG by 5/1/06 PANA  Last call in progress  Fundamental issues raised by security AD No clear resolution seems possible  Work in progress for 5 years now; could prolong much longer

Conclusion Stating the obvious, no reason to use PANA  EAPoHRPD is simpler  EAPoHRPD with GEE does everything we need