欢迎来到天天文库
浏览记录
ID:19427332
大小:597.50 KB
页数:36页
时间:2018-10-02
《a proposal for next generation cellular network ...》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、AProposalforNextGenerationCellularNetworkAuthenticationandAuthorizationArchitectureJamesKempfResearchFellowDoCoMoUSALabskempf@docomolabs-usa.comDIMACS,November4,2004OutlineExistingsolutionsforauth/authzandtheirproblemsPre-IPL2.5UniversalAccessMethod(UAM)SENDandPANAADifferentWay-HyperoperatorObst
2、aclestoAcceptanceSummary6/27/20212Existingsolutionsforauth/authzandtheirproblemsPre-IPLayer2.5TerminalandnetworkauthenticateeachotherpriortoestablishingIPserviceTypicallythruaLayer2.5flowbetweentheterminalandanetworkaccessserverPPPforsomecellularprotocolsProprietaryforothers802.1xEAPOLfor802.11N
3、etworkaccessserverroutesauthrequestbackintothehomenetworkvialocalAAAserverRadiusorDiameteracrosstheInternetHomenetworkAAAserverauthenticatesAuthorizationfornetworkaccessfromhomenetworkAAAservertolocalAAAserverIfaterminalisauthenticated,thenitisauthorizedforIPserviceIfthenetwork/basestationisauth
4、enticated,thenitisauthorizedtotaketheterminal’straffic6/27/20214Example:802.1xBorderRouterARAP/NASAccessNetworkMobileTerminalInternetAAA-HAAA-FEAP+EAPoL+802.11/3EAP+Radius+IPEAP+Radius+IPPMKpushedtoAP6/27/20215802.1xTerminaltoAccessNetworkDetail802.1X/EAP-RequestIdentity802.1X/EAP-ResponseI
5、dentity(EAPtypespecific)RADIUSAccessRequest/IdentityEAPtypespecificmutualauthentication(e.g.TLS)802.1X/EAP-SUCCESSAPSTA802.1XRADIUSAP802.1XblocksportfordatatrafficSTA802.1XblocksportfordatatrafficASDerivePairwiseMasterKey(PMK)DerivePairwiseMasterKey(PMK)RADIUSAccept+PMK6/27/20216ProblemsHandover
6、requireslengthyPMKrekeying,delayinghandoverImplicitauthorizationmodelfornetworkaccessisdifficulttoextendtootherservicesExample:multicastAuthenticatedandauthorizedterminalsthatarecompromisedorotherwisedecidetobehavebadly6/27/20217UniversalAccessMethodTerminalestablishesrestrictedIPaccessCan’trout
7、etotheInternetOnlyHTTPHTTPGETredirectedtoPublicAccessControl(PAC)GatewayPACpushesloginpagetoterminalUsertypesinlogin/passwordforaccountaccessorcreditcardnumberforonetimeaccessPACroutesauthrequestbackintothehomenetworkvialoca
此文档下载收益归作者所有