Doc.: IEEE 802.11-11/01047r2 Submission NameAffiliationsAddressPhoneemail Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin.

Slides:



Advertisements
Similar presentations
Doc.: IEEE /1160 Submission NameAffiliationsAddressPhone George CherianQualcomm 5775 Morehouse Dr, San Diego, CA, USA
Advertisements

Using Upper Layer Message IE in TGai
Doc.: IEEE /0032r0 Submission NameAffiliationsAddressPhone Hitoshi MORIOKAAllied Telesis R&D Center Tenjin, Chuo-ku, Fukuoka
Doc.: IEEE /1436r0 Submission NameAffiliationsAddressPhone Robert Sun Huawei Technologies Co., Ltd. Suite 400, 303 Terry Fox Drive, Kanata,
Doc.: IEEE /0780r1 Submission NameAffiliationsAddressPhone Ping Fang Zhiming Ding Phillip Barber Rob Sun Huawei Technologies Co., Ltd. Bldg.
Doc.: IEEE /0041r1 Submission NameAffiliationsAddressPhone Robert Sun; Yunbo Li; Edward Au; Phillip Barber Huawei Technologies Co., Ltd.
Doc.: IEEE /0567r1 Submission May 2012 Huawei Slide 1 Multiple Frequency Channel Scanning Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE / ai Submission NameAffiliationsAddressPhone Phillip BarberHuawei Technologies Co., Ltd Alma Rd, Ste 500 Plano,
Submission doc.: IEEE ai May 2012 InterDigital, KDDI, Nokia, Huawei, Intel, Qcomm Slide 1 Proposed SFD Text for ai Passive Scanning.
Doc.: IEEE /0976r1 Submission July 2011 Hitoshi Morioka, ROOT INC.Slide 1 TGai Authentication Protocol Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /933r6 Submission July 2012 Fang Xie (CMCC)Slide 1 Access Control Mechanism for FILS Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1042r3 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /1042 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang, Kyungki,
Doc.: IEEE /0249r0 Submission March 2012 Slide 1Lin Cai et al,Huawei. Differentiated Association Service Provisioning in WiFi Networks Date: 03/02/2012.
Doc.: IEEE /1054r0 Submission Sep Santosh Pandey (Cisco)Slide 1 FILS Reduced Neighbor Report Date: Authors:
Submission doc.: IEEE /1003r2 July 2011 Hiroki Nakano, Trans New Technology, Inc.Slide 1 Upper Layer Data on Management frames Date:
Submission doc.: IEEE 11-11/1414r2 November 2011 Katsuo Yunoki, KDDI R&D LaboratoriesSlide 1 Probe Request and Response in TGai Date: Authors:
Doc.: IEEE /0067r0 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 Active Scanning Time Notification Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0977r2 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA ROOT INC Tenjin, Chuo-ku, Fukuoka JAPAN
Submission doc.: IEEE ai March 2012 InterDigital, KDDI, Nokia, Huawei, IntelSlide 1 Proposed SFD Text for ai Passive Scanning Improvement.
Doc.: IEEE /0897r0 SubmissionJae Seung Lee, ETRISlide 1 Active Scanning considering Operating Status of APs Date: July 2012.
Doc.: IEEE / ai Submission Nov 2011 Huawei Technologies Co. LtdSlide 1 Broadcast Probe Response in TGai Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0547r1 Submission May 2012 Dapeng Liu, China MobileSlide 1 Extend 802.1X for higher layer configuration in FILS Date:
Doc.: IEEE /0158r2 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 Proposed Additions to SFD Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE / ai Submission NameAffiliationsAddressPhone Phillip BarberHuawei Technologies Co., Ltd Alma Rd, Ste 500 Plano,
Submission doc.: IEEE /1034r4 September 2012 Jeongki Kim, LG ElectronicsSlide 1 Enhanced scanning procedure for FILS Date: Authors:
Doc.: IEEE /1233r3 Submission Sep 2011 Slide 1 Passive Scanning Improvement Date: Authors:
Submission doc.: IEEE ai September 2012 Lei Wang, InterDigital CommunicationsSlide 1 Ad Hoc Discussions of ai Passive Scanning during.
Submission doc.: IEEE ai May 2012 Lei Wang, InterDigital CommunicationsSlide 1 Proposed SFD Text for ai AP/STA Initiated FILS Optimizations.
Doc.: IEEE /1042r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /0275r3 Submission March 2012 Hitoshi Morioka, Allied Telesis R&D CenterSlide 1 Higher Layer Configuration Function for TGai SFD Date:
Doc.: IEEE /0977r1 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA ROOT INC Tenjin, Chuo-ku, Fukuoka JAPAN
Doc.: IEEE /278r0 Submission NameAffiliationsAddressPhone Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin.
Doc.: IEEE /0080r0 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 AP Admission Control in TGai Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1000r1 Submission July 2011 Jihyun Lee, LG ElectronicsSlide 1 TGai FILS Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0568r0 Submission May 2012 Young Hoon Kwon, Huawei Slide 1 AP Discovery Information Broadcasting Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0263r1 SubmissionJae Seung Lee, ETRI Spec Framework Proposal: Selection of the AP for Scanning Date: Slide 1 March 2012.
Submission doc.: IEEE ai May 2012 InterDigital Slide 1 Passive Scanning Improvement Ad Hoc Report Date: Authors:
Doc.: IEEE /0896r0 SubmissionJae Seung Lee, ETRISlide 1 Probe Request Filtering Criteria Date: July 2012.
Doc.: IEEE /01047r4 Submission NameAffiliationsAddressPhone Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin.
Doc.: IEEE /1426r00 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi- tech District,
Doc.: IEEE /0059r1 SubmissionJae Seung Lee, ETRI Selection of the AP for Scanning Date: Slide 1.
Doc.: IEEE /0977r4 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA Allied Telesis R&D Center Tenjin, Chuo-ku, Fukuoka
Doc.: IEEE /0158r0 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 Proposed Additions to SFD Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1244r0 Submission Sep 2011 Hiroshi Mano, Root, Inc.Slide 1 11ai overview (PAR, Scope and current status) Date: Authors:
Doc.: IEEE /1426r02 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District,
Doc.: IEEE /1017r1 July 2011 Huawei Submission July 2011 Discussion for 11ah Functional Requirements Date: NameCompanyAddressPhone .
Doc.: IEEE /0269r1 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,
Access Control Mechanism for FILS
Month Year doc.: IEEE yy/xxxxr0 May 2012
AP discovery with FILS beacon
Proposed SFD Text for ai Link Setup Procedure
Discussions on FILS Authentication
FILS presentation on High Level Security Requirements
AP Discovery Information Broadcasting
Fast Authentication in TGai
EAP based Message Flow Optimization for FILS
Using Upper Layer Message IE in TGai
Scanning from Specific Channel
Access Control Mechanism for FILS
Listen to Probe Request from other STAs
Using Upper Layer Message IE in TGai
Discussion for 11ah Functional Requirements
Access Control Mechanism for FILS
Fast Authentication in TGai
Access Control Mechanism for FILS
Performance Analysis of authentication and authorization
Differentiated Association Service Provisioning in WiFi Networks
Month Year doc.: IEEE yy/xxxxr0 May 2012
Scanning from Specific Channel
Presentation transcript:

doc.: IEEE /01047r2 Submission NameAffiliationsAddressPhone Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin Sourth 9, Nanshan District, Shenzhen, Guangdong, China, Zhiming Ding Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin Sourth 9, Nanshan District, Shenzhen, Guangdong, China, om Phillip Barber Huawei Technologies Co., Ltd Alma Rd, Ste 500 Plano, Texas USA Using Upper Layer Message IE in TGai Date: Aug 2011 Slide 1 Authors: Ping Fang, Huawei.

doc.: IEEE /01047r2 Submission Aug 2011 Slide 2 Abstract This document describes a technical proposal for TGai. In this proposal, Upper Layer Message IEs are proposed for EAP and DHCP; Association, authentication and 4- Way handshake are carried out concurrently to improve efficiency. Ping Fang, Huawei.

doc.: IEEE /01047r2 Submission Conformance w/ Tgai PAR & 5C Aug2011 Ping Fang, HuaweiSlide 3 Conformance QuestionResponse Does the proposal degrade the security offered by Robust Security Network Association (RSNA) already defined in ? No Does the proposal change the MAC SAP interface?Yes, possible Does the proposal require or introduce a change to the architecture?No Does the proposal introduce a change in the channel access mechanism?No Does the proposal introduce a change in the PHY?No Which of the following link set-up phases is addressed by the proposal? (1) AP Discovery (2) Network Discovery (3) Link (re-)establishment / exchange of security related messages (4) Higher layer aspects, e.g. IP address assignment 3,4

doc.: IEEE /01047r2 Submission Why do we need FILS? Aug 2011 Slide 4Ping Fang, Huawei. If a dual mode MS makes a seamless handoff from cellular network to WiFi network, the time of WiFi ILS should be minimized. 3GPP TS23.327(Mobility between 3GPP-WLAN, not support seamless HO yet) and WMF T37 (WiMAX WiFi Interworking, support seamless HO but effect is not proved, using pre-authentication) have supported this scenario. Internet Dual mode MS WiFi interface Cellular interface BS Cellular core HA AAA Cellular access AP WiFi access –Hot-Spot Pass-Through Internet Access: Users on vehicle/train passing near an AP with a mobile phone must have the ability to access various Internet services in a few seconds to his/her e- mail/twitter/facebook or to offload traffic carried by other networks e.g. 3G.

doc.: IEEE /01047r2 Submission Usual WiFi network architecture & initial link setup Aug 2011 Slide 5 AP STA DHCP Server AS Router Internet User DeviceWiFi Access NetworkInternet 1 Discovery & Association 2 EAP authentication 3 IP address Assignment 4 After link setup 5 Move in WiFi ESS 6 Possible Fast transition 11r Interface Ping Fang, Huawei. Here too many message exchanges

doc.: IEEE /01047r2 Submission How to reduce the time of ILS? Aug 2011 Slide 6Ping Fang, Huawei MIH could be used by cellular network to help DM-MS to find vicinal WiFi AP (location technology needed). –This is out of scope of this proposal. To reduce message exchanges on air interface. To reduce message exchanges on network side (e.g. AP is configured an IP address pool and works as DHCP proxy) and reduce workload of calculating (e.g. prepared authentication vectors in AKA method). Don’t use methods based on certificate.

doc.: IEEE /01047r2 Submission Our scope and essential principle Aug 2011 Slide 7 AP STA DHCP Server AS Router Internet User DeviceWiFi Access NetworkInternet 11r Interface We work on here Key hierarchy must not be changed! Ping Fang, Huawei. IEEE r may be deployed if mobility in WiFi network is supported. Usually RADIUS or DIAMETER protocol is here. No changes here would be better.

doc.: IEEE /01047r2 Submission How to reduce rounds on air interface? Aug 2011 Slide 8Ping Fang, Huawei. This can not be as a part of ILS. The whole flow of ILS according to current specification and mobility is considered. Other IP address allocation approach could be used. To carry out EAP procedure, IP address allocation procedure, 4-Way handshake and AID assigning concurrently. –EAP messages and DHCP messages are encapsulated into Upper Layer Message IEs and included in Authentication frames if the FILS procedure is indicated. –The fields of 4-way handshake messages are included into the Authentication frames and 4-way handshake steps must be in step with EAP steps. –The Association frames are removed. AID is delivered together with the GTK through the third step of the 4-way handshake.

doc.: IEEE /01047r2 Submission Could EAP be ignored? Aug 2011 Slide 9Ping Fang, Huawei. In 3GPP TS ( SAE Security aspects of non-3GPP accesses ), it is specified: –Access authentication for non-3GPP access in EPS shall be based on EAP-AKA (IETF RFC 4187) or on EAP-AKA’ (IETF RFC 5448). In WiMAX NWG T37(WiMAX WiFi Interworking), EAP is also conducted by AAA server in WiMAX CSN during WiFi ILS. Considering the MIP keys are derived from EMSK which is an outcome of an EAP procedure in current network specifications (see 3GPP TS and WMF T32), the EAP should be kept in FILS.

doc.: IEEE /01047r2 Submission Could DHCP be ignored? Aug 2011 Slide 10Ping Fang, Huawei. DHCP is the main protocol for IP address allocation even in IPv6 (DHCPv6). DHCP is not only used to assign an IP address, but also used to deliver many other information. –An very important example is that in BBF TR069 a CPE identifies itself to the DHCP server as supporting ACS Discovery method defined in TR069 by including the string “dslforum.org” in DHCP option 60 (in DHCP Discovery/Request) and then the DHCP server includes an ACS URL and a provisioning code in DHCP option 43 in its response (DHCP Offer/ACK). IF a STA uses FILS and has to acquire some information in extra steps, then FILS is not complete. Problems are just left for the following steps. So, we may not use DHCP to assign IP address in FILS, but we can not ignore DHCP in FILS. How to assign IP address is the choice of network operator.

doc.: IEEE /01047r2 Submission Possible Protocol Detail July 2011

doc.: IEEE /01047r2 Submission Upper Layer Message IE New Upper Layer Message IE can be defined as below Aug 2011 Slide 12 Upper layer message IE element format Ping Fang, Huawei. Element IDlengthUpper layer message ULM body ULM Type 1:EAP 2:DHCPv4 3:DHCPv6 … 1 bit 7bits e.g Oct. Flag 0: No more segment 1:More segment

doc.: IEEE /01047r2 Submission How to be compatible with legacy STAs Authentication frames must be kept. Add a new enumerative value to the field Algorithm in Authentication frame to indicate using FILS procedure. Definitions in 11mb: Aug 2011 Slide 13Ping Fang, Huawei. 1 = Open System 2 = Shared Key 3 = FT (first defined in 11r) 4 = FILS (first defined in 11ai)

doc.: IEEE /01047r2 Submission How to be compatible with other possible FILS? More AKM suite selectors (suite type) could be defined. Aug 2011 Slide 14Ping Fang, Huawei. Authentication algorithm = 4 (FILS) “And FILS” Suite type = 1, 802.1x Suite type = 2, PSK (mean only 4-way HS without EAP, PMK is PSK) Suite type = 3, FT over 802.1x Suite type = 4, FT over PSK … Suite type = 8, FILS over 802.1x Suite type = 9, FILS over PSK (maybe not use current 4-way HS)

doc.: IEEE /01047r2 Submission Modifications Maximum length of IE is limited to 256 octet. So one EAP or DHCP message may be divided into multiple IEs. Association frames are ignored if FILS is called. 4-Way handshake procedure is concurrently carried out with EAP procedure in Authentication frames if FILS is called. IP address can be allocated in Authentication frames with standard DHCP or only with fields under some special circumstance. Aug 2011 Slide 15Ping Fang, Huawei.

doc.: IEEE /01047r2 Submission Questions & Comments Aug 2011 Slide 16Ping Fang, Huawei.