Download presentation
Presentation is loading. Please wait.
Published byMarsha Moody Modified over 9 years ago
1
Diameter Mobile IPv6: HA-to-AAAH support draft-ietf-dime-mip6-split-01.txt Julien Bournelle (Ed.) Gerardo Giaretta Hannes Tschofenig Madjid Nakhjiri
2
Design Choice Long discussion on the DiME ML: –Diameter EAP for network access AAA –Reuse of 4072 would lead to update Separate Authentication from Authorization and Accounting –Authentication: 4072 (AUTHENTICATE_ONLY) –Authorization/Accounting: new Application
3
IKEv2 AUTHZ/ACCTG Diameter MIP6 (AUTHENTICATE_ONLY) Diameter EAP Architecture Home Agent AAA-EAP Server AAA-MIP6 Server MSP MSA
4
A New Application Authorization: 2 New messages: –MIP6-Authz-Request –MIP6-Authz-Answer Accounting: RFC 3588 (+ new AVPs) Session Management: –STR/STA –ASR/ASA
5
Authorization Token Authentication and Authz/Accounting are decorrelated –AAA-MIP6 has no proof that MN has been correctly authenticated (by AAA-EAP) Do we want/need a mechanism for this ? (General mechanism not only applicable to MIP6)
6
HA as single physical device IKEv2 responder may act as: –VPN concentrator –Home Agent How the IKEv2-R know that IKEv2-I want MIP6 service ?
7
Triggering MIP6-Authz App Two applications are used: 4072 and MIP6-App to perform AAA for mip6. When do MIP6-App is used ? –During 4072 Linked to previous issue (if we wait for BU to differentiate) –After 4072 Can’t request for HoA authorization
8
RFC 4285 support 4285 another mechanism to secure mip6 signaling between MN and HA. (no IKEv2) Do/Can we support this in current document ?
9
Acknowledgments Yoshihiro Ohba ENABLE project Orange-FT
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.