Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts

Monday, July 8, 2019

WIMAX Authentication, Authorization, and Accounting (AAA)


AAA refers to a framework based on IETF protocols, Remote Authentication Dial-in User Service (RADIUS) or Diameter , which specify the procedures for authentication, authorization, and accounting associated with the user terminal’s subscribed services across different access technologies. As an example, AAA includes mechanisms for secure exchange and distribution of authentication credentials and session keys for data encryption. The AAA protocols provide the following services:  

• Authentication including device, user, or combined device and user authentication; 

• Authorization including delivery of information to configure the session for access, mobility, QoS, and other applications; 

• Accounting including delivery of billing information and other information that can be used to audit session activity by both the H-NSP and V-NSP. 

The AAA framework supports global roaming across operator networks, including support for reuse of credentials and consistent use of authorization and accounting. It further supports roaming between H-NSP and V-NSP. The AAA framework is based on use of RADIUS or Diameter in ASN and CSN. The AAA framework accommodates both Mobile IPv4  and Mobile IPv6  Security Association (SA) management. It further accommodates various network operation scenarios from fixed to full mobility. The AAA framework provides support for deploying MS authorization, user and mutual authentication between MS and the NSP, based on Privacy Key Management (PKMv2). In order to ensure interoperability, the AAA framework supports Extensible Authentication Protocol (EAP)-based authentication mechanisms that include passwords, Subscriber Identity Module, Universal Subscriber Identity Module, Universal Integrated Circuit Card, Removable User Identity Module, and X.509 digital certificates. The AAA framework is capable of providing the V-CSN or ASN with a temporary identifier that represents the user without revealing the user’s identity.

The NAP may deploy an AAA proxy between two NASs in ASN and the AAA in CSN in order to provide security and enhanced manageability. The AAA proxy will also allow the NAP to regulate the AAA attributes received from the visited CSN, and to add additional AAA attributes that may be required by the NASs in the ASN. Note that the CSN hosts the AAA server, whereas the ASN hosts one or more NASs. The PKMv2 protocol is used to perform over-the-air user authentication. The PKMv2 transfers EAP messages over R1 reference point (i.e., the IEEE 802.16-2009 air interface or its evolution) between the MS and the BS in ASN. 


Saturday, June 19, 2010

PKM Version 2: Mutual Authentication

Mutual authentication can take place in one of the two modes of operation. In the first mode, only mutual authentication is used. In the other mode, mutual authentication is followed by EAP authentication. In this second mode, the mutual authentication is performed only for initial network entry and only EAP authentication is performed in the case that authentication is needed for re-entry. SS mutual authorization, controlled by the PKMv2 authorization state machine, is the process of:

1.  Add a Note HereThe BS authenticating a client SS's identity.
2.  Add a Note HereThe SS authenticating the BS's identity.
3.  Add a Note HereThe BS providing the authenticated SS with an AK, from which a KEK and message authentication keys are derived.
4.  Add a Note HereThe BS providing the authenticated SS with the identities (i.e., the SAIDs) and properties of primary and static SAs for which the SS is authorized to obtain keying information.
Add a Note HereAfter achieving initial authorization, an SS should periodically seek reauthorization with the BS. This reauthorization is also managed by the SS's PKMv2 authorization state machine. An SS must maintain its authorization status with the BS to be able to refresh aging TEKs and GTEKs. TEK state machines manage the refreshing of TEKs. The SS or BS may run optional authenticated EAP messages for additional authentication.
Add a Note HereThe SS sends an authorization request message to its BS immediately after sending the authentication information message. This is a request for an AK, as well as for the SAIDs identifying any static security SAs that the SS is authorized to participate in. The authorization request includes:

§  Add a Note HereA manufacturer-issued X.509 certificate.
§  Add a Note HereA list of cryptographic suite identifiers, each indicating a particular pairing of packet data encryption and packet data authentication algorithms that the SS supports.
§  Add a Note HereThe SS's basic CID. The basic CID is the first static CID that the BS assigns to an SS during initial ranging—the primary SAID is equal to the basic CID.
§  Add a Note HereA 64-bit random number generated in the SS.
Add a Note HereIn response to an authorization request message, a BS validates the requesting SS's identity, determines the encryption algorithm and protocol support it shares with the SS, activates an AK for the SS, encrypts it with the SS's public key, and sends it back to the SS in an authorization reply message. The authorization reply includes:

§  Add a Note HereThe BS's X.509 certificate.
§  Add a Note HereA pre-PAK encrypted with the SS's public key.
§  Add a Note HereA 4-bit PAK sequence number, used to distinguish between successive generations of AKs.
§  Add a Note HereA PAK lifetime.
§  Add a Note HereThe identities (i.e., the SAIDs) and properties of the single primary and zero or more static SAs for which the SS is authorized to obtain keying information.
§  Add a Note HereThe 64-bit random number generated in the SS.
§  Add a Note HereA 64-bit random number generated in the BS.
§  Add a Note HereThe RSA signature over all the other attributes in the auth-reply message by BS, used to assure that the authenticity of the earlier PKMv2 RSA-Reply messages.
Add a Note HereAn SS must periodically refresh its AK by reissuing an authorization request to the BS. Reauthorization is identical to authorization. To avoid service interruptions during reauthorization, successive generations of the SS's AKs have overlapping lifetimes. Both SS and BS must be able to support up to two simultaneously active AKs during these transition periods. The operation of the authorization state machine's authorization request scheduling algorithm, combined with the BS's regimen for updating and using a client SS's AKs, ensures that the SS can refresh TEK keying information without interruption.

Related Posts with Thumbnails