2006/7/10IETF66 RADEXT WG1 Pre-authentication AAA Requirements Yoshihiro Ohba Alper Yegin

Slides:



Advertisements
Similar presentations
Doc.: IEEE /1186r0 Submission October 2004 Aboba and HarkinsSlide 1 PEKM (Post-EAP Key Management Protocol) Bernard Aboba, Microsoft Dan Harkins,
Advertisements

21-06-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxx Title: Pre-establishment of IP connectivity discussion Date Submitted:
AAA Mobile IPv6 Application Framework draft-yegin-mip6-aaa-fwk-00.txt Alper Yegin IETF 61 – 12 Nov 2004.
7/13/061 The Problem of Handover Keying IETF 66 Montreal.
Overview of the Mobile IPv6 Bootstrapping Problem James Kempf DoCoMo Labs USA Thursday March 10, 2005.
Chapter 16 AAA. AAA Components  AAA server –Authenticates users accessing a device or network –Authorizes user to perform specific activities –Performs.
Carrying Location Objects in RADIUS Hannes Tschofenig, Farid Adrangi, Avi Lior, Mark Jones.
AAA-Mobile IPv6 Frameworks Alper Yegin IETF Objective Identify various frameworks where AAA is used for the Mobile IPv6 service Agree on one (or.
Omniran IEEE 802 Scope of OmniRAN Date: Authors: NameAffiliationPhone Max RiegelNSN
Media-Independent Pre-Authentication (draft-ohba-mobopts-mpa-framework-01.txt) (draft-ohba-mobopts-mpa-implementation-01.txt) Ashutosh Dutta, Telcordia.
IETF DMM WG Mobility Exposure and Selection WT Call#4 Feb 24, 2015.
November st IETF MIP6 WG Mobile IPv6 Bootstrapping Architecture using DHCP draft-ohba-mip6-boot-arch-dhcp-00 Yoshihiro Ohba, Rafael Marin Lopez,
Doc: Submission September 2003 Dorothy Stanley (Agere Systems) IETF Liaison Report September 2003 Dorothy Stanley – Agere Systems IEEE.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Problem Statement for Authentication Signaling Optimization Date.
August 1, 2005IETF63 PANA WG Pre-authentication Support for PANA (draft-ohba-pana-preauth-00.txt) Yoshihiro Ohba
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Proposal for IEEE Study Group on Security Signaling Optimization.
21-07-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxxx Title: Secure Handover with QoS Support Date Submitted: November, 14,
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: March 17, 2011 Presented at IEEE session.
xxx IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Handover Procedure – Redraw of Annex Figure Date Submitted: January.
EAP Key Framework Draft-ietf-eap-keying-01.txt IETF 58 Minneapolis, MN Bernard Aboba Microsoft.
21-07-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxxx Title: IETF Liaison Report Date Submitted: July 19, 2007 Presented at.
11 December, th IETF, AAA WG1 AAA Proxies draft-ietf-aaa-proxies-01.txt David Mitton.
Transient BCE for Proxy Mobile IPv6 draft-liebsch-netlmm-transient-bce-pmipv6-01.txt Oliver Marco
IEEE MEDIA INDEPENDENT HANDOVER Title: An Architecture for Security Optimization During Handovers Date Submitted: September,
EAP Extensions for EAP Early Authentication Protocol (EEP) Hao Wang, Yang Shi, Tina Tsou.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: July 20, 2006 Presented at IEEE.
Transient BCE for Proxy Mobile IPv6 draft-ietf-mipshop-transient-bce-pmipv6-00.txt Oliver Marco
1 NetLMM Vidya Narayanan Jonne Soininen
ICOS BOF EAP Applicability Bernard Aboba IETF 62, Minneapolis, MN.
7/13/061 Handover Keying Reqs IETF 66 Montreal. 7/13/062 Problem scope requirements (1) MUST Support multiple access technologies MUST not require full.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: Security SG Report Date Submitted: September 20, 2007 Presented.
Mar 20, 2005IETF65 PANA WG Requirements for PANA support of location based services draft-anjum-pana-location-requirements-00.txt F. Anjum D. Famolari.
xxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxx Title: IETF Liaison Report Date Submitted: November 16, 2006 Presented.
IETF#83 Multimob DMM Proposal Summary Dapeng Liu China Mobile 1.
Washinton D.C., November 2004 IETF 61 st – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-02) Gerardo.
Nov. 9, 2004IETF61 PANA WG PANA Specification Last Call Issues Yoshihiro Ohba, Alper Yegin, Basavaraj Patil, D. Forsberg, Hannes Tschofenig.
August 2, 2005 IETF 63 – Paris, France Media Independent Handover Services and Interoperability Ajay Rajkumar Chair, IEEE WG.
1 IEEE MEDIA INDEPENDENT HANDOVER DCN: DCN:21-07-xxx Title: Security Optimization During Handovers: SG Proposal Date Submitted: xx,
A Framework of Media-Independent Pre-authentication (MPA) for Inter-domain Handover optimization draft-ohba-mobopts-mpa-framework-05.txt Ashutosh Dutta.
Minneapolis, March 2005 IETF 62 nd – mip6 WG Goals for AAA-HA interface (draft-giaretta-mip6-aaa-ha-goals-00) Gerardo Giaretta Ivano Guardini Elena Demaria.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: September 16, 2010 Presented at IEEE session.
IEEE MEDIA INDEPENDENT HANDOVER Title: An Architecture for Security Optimization During Handovers Date Submitted: September,
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Pre-authentication Activity Date Submitted: February 26, 2006.
August 2, 2005IETF63 EAP WG AAA-Key Derivation with Lower-Layer Parameter Binding (draft-ohba-eap-aaakey-binding-01.txt) Yoshihiro Ohba (Toshiba) Mayumi.
Paris, August 2005 IETF 63 rd – mip6 WG Mobile IPv6 bootstrapping in split scenario (draft-ietf-mip6-bootstrapping-split-00) mip6-boot-sol DT Gerardo Giaretta,
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: September 20, 2007 Presented.
1 IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: EAP Pre-authentication Problem Statement in IETF HOKEY WG Date Submitted: September,
Omniran IEEE 802 Scope of OmniRAN Date: Authors: NameAffiliationPhone Max RiegelNSN
IEEE MEDIA INDEPENDENT HANDOVER DCN:
Pre-authentication Problem Statement (draft-ohba-hokeyp-preauth-ps-00
<draft-ohba-pana-framework-00.txt>
Informing AAA about what lower layer protocol is carrying EAP
Media-Independent Pre-authentication (MPA) Framework
IEEE 802 OmniRAN Study Group: SDN Use Case
draft-ietf-dime-erp-02
Carrying Location Objects in RADIUS
Pre-authentication Overview
ERP extension for EAP Early-authentication Protocol (EEP)
IEEE MEDIA INDEPENDENT HANDOVER DCN: srho
CARD Designteam A. Singh, D. Funato, H. Chaskar, M. Liebsch
IETF Liaison Report November 2003 Dorothy Stanley – Agere Systems
IEEE MEDIA INDEPENDENT HANDOVER DCN:
IEEE MEDIA INDEPENDENT HANDOVER DCN:
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: March 18, 2010 Presented at IEEE session.
IEEE MEDIA INDEPENDENT HANDOVER
PMIP6 extensions for inter-access handovers and flow mobility
IEEE MEDIA INDEPENDENT HANDOVER DCN:
IEEE MEDIA INDEPENDENT HANDOVER DCN:
Dayong GUO Sheng JIANG (Speaker) Remi Despres
Presentation transcript:

2006/7/10IETF66 RADEXT WG1 Pre-authentication AAA Requirements Yoshihiro Ohba Alper Yegin

2006/7/10IETF66 RADEXT WG2 What is pre-authentication Pre-authentication is network access authentication by performing EAP authentication with a target authenticator via the serving network Pre-authentication was originally defined in IEEE i where the usage is intra-ESS transitions HOAKEY BOF (held in IETF65 and to be held in IETF66) is extending the notion of pre- authentication to work across multiple ESS ’ s and even across multiple access technologies

2006/7/10IETF66 RADEXT WG3 Basic pre-auth AAA requirements Requirements identified in IETF65 HOAKEY BOF –AAA needs to know that this is a pre-authentication not normal authentication User may only be allowed to have a single logon at the same time User may not be allowed pre-authentication Can pre-auth session timeout (see below) attribute serve as an indication of pre-auth or some other attribute is needed? –AAA needs to know how long to hold the session before timing out Session timeout for pre-auth may be different for normal session If the mobile moves after timeout then do normal authentication Addressed in draft-aboba-radext-wlan-03.txt What would signal that the host has successfully connected to a target network? Another round of (non-blocking) Access- Req/Accept? Or do we rely on accounting messages? If latter, then they must be mandated for pre-auth case

2006/7/10IETF66 RADEXT WG4 Other potential pre-authentication AAA requirements/issues

2006/7/10IETF66 RADEXT WG5 Extending pre-auth session lifetime Pre-authentication session lifetime may need to be extended –The MN may continue to stay in the serving network or move to some other network, while maintaining the pre-authentication session with a target authenticator Maximum pre-auth session lifetime may need to be defined in order to avoid unlimited attempts for extending pre-auth session lifetime - Is this a AAA protocol issue or a configuration issue?

2006/7/10IETF66 RADEXT WG6 Reverting to pre-auth state from full authorized state A session with a fully authorized state may need to be changed to a pre-auth state –This can happen when MN moves from network N1 to network N2, and goes back to N1 –MN may not want to perform pre-authentication again with N1 –Is this the same as key caching issue? Key caching lifetime management is not fully studied A complete solution for pre-authentication may solve key caching lifetime management issue as well

2006/7/10IETF66 RADEXT WG7 Maximum number of pre-auth sessions for different authenticators How many pre-authentication sessions for different authenticators are allowed per MN? Is this a AAA protocol issue or a configuration issue? –This may be a AAA protocol issue for indirect pre-authentication in which the serving authenticator is involved in pre-auth signaling

2006/7/10IETF66 RADEXT WG8 Information on the serving network AAA server may need information on the serving network from which a pre- authentication attempt is being made This information may affect the authorization decision made by AAA server This may apply to normal authentication and handover keying signaling as well

2006/7/10IETF66 RADEXT WG9 Calling-Station-Id What should Calling-Station-Id be in the case of inter-technology pre-authentication? –Should it be the MN’s address used for the serving network? In this case, a Calling-Station-Id may dynamically change if MN handovers to a new nerving network and still maintains the pre-authentication state with the target network –Should it be the MN’s address to be used for the target network? –Should it be null?

2006/7/10IETF66 RADEXT WG10 Network-initiated pre-authentication Are new AAA attributes needed to support network-initiated pre-authentication? –E.g., list of neighboring authenticators around the serving authenticator

2006/7/10IETF66 RADEXT WG11 Summary Pre-authentication for inter-technology handover requires thorough requirements work on both AAA and EAP lower-layer signaling –Pre-authentication is one work item of HOAKEY BOF