Presentation is loading. Please wait.

Presentation is loading. Please wait.

San Diego, August 2004 IETF 60 th – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-01) Gerardo Giaretta.

Similar presentations


Presentation on theme: "San Diego, August 2004 IETF 60 th – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-01) Gerardo Giaretta."— Presentation transcript:

1 San Diego, August 2004 IETF 60 th – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-01) Gerardo Giaretta Ivano Guardini Elena Demaria Telecom Italia Lab (TILab) Julien Bournelle Maryline Laurent-Maknavicius GET/INT

2 MIPv6 authorization and config. based on EAP August, 2004 IETF 60 th – mip6 WG draft-giaretta-mip6-authorization-eap-01 2 Overview Solution for bootstrapping Mobile IPv6 relying on a AAA infrastructure Bootstrapping is performed during the authentication phase for network access –the basic assumption is that network access and mobility services are provided by the same entity (i.e. Integrated ASP) –re-use of network access credentials The interaction between the MN and the Home AAA server is realized using EAP –exploits the capability of several EAP methods to carry arbitrary parameters together with authentication data

3 MIPv6 authorization and config. based on EAP August, 2004 IETF 60 th – mip6 WG draft-giaretta-mip6-authorization-eap-01 3 Protocol architecture Mobile Node Router or Access Point (pass through) AAA Server AAA Client Home Agent AAA-HA Protocol Configuration Data EAP Exchange L2/L3 Access Protocol (IEEE 802.1x, PANA) AAA Protocol (Diameter/RADIUS) Authentication for network access MIPv6 Authorization and Configuration

4 MIPv6 authorization and config. based on EAP August, 2004 IETF 60 th – mip6 WG draft-giaretta-mip6-authorization-eap-01 4 Advantages No changes needed on access equipment –easier deployment (particularly in roaming scenarios) –works with existing equipment (e.g. IEEE 802.1X APs) Both RADIUS and Diameter can be used between NAS and AAA infrastructure MN-HA IPsec SA can be setup from the keying material exported by the EAP method Could be used also over IKEv2 exploiting its support for EAP authentication –MIPv6 bootstrap from access networks with no EAP support (e.g. WLAN hotspots where initial logon occurs using HTTP)

5 MIPv6 authorization and config. based on EAP August, 2004 IETF 60 th – mip6 WG draft-giaretta-mip6-authorization-eap-01 5 Requirements on EAP methods Mutual Authentication Integrity Replay Protection Confidentiality (*) Exchange of arbitrary parameters PEAPv2 XXXXX EAP-FAST XXXXX EAP-TTLS XXXXX EAP-IKEv2 XXXXX EAP-SIM XXXXX EAP-AKA XXXXX EAP-TLS XXXX EAP-MD5 (*)Only if the secret for bootstrapping the IPsec SA is not derived from the EAP key hierarchy

6 MIPv6 authorization and config. based on EAP August, 2004 IETF 60 th – mip6 WG draft-giaretta-mip6-authorization-eap-01 6 Next steps Extension of the I-D with support for IKE authentication methods other than PSK –e.g. certificates Specification of the AAA-HA interface –a viable approach is the development of a new Diameter application –another solution might be the leverage of SNMPv3 –we should start with the collection of requirements (new I-D?) Definition of an AMSK for Mobile IPv6 –bootstrapping MN-HA IPsec SA from the EAP key hierarchy –a new I-D is probably needed


Download ppt "San Diego, August 2004 IETF 60 th – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-01) Gerardo Giaretta."

Similar presentations


Ads by Google