150 likes | 327 Views
PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt). Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com) Basavaraj Patil (basavaraj.patil@nokia.com) Hesham Soliman (hesham.soliman@era.ericsson.se). Objective.
E N D
PANA Usage Scenarios Updates(draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com) Basavaraj Patil (basavaraj.patil@nokia.com) Hesham Soliman (hesham.soliman@era.ericsson.se) IETF54 PANA WG
Objective • Illustrate examples/scenarios where PANA can be applied IETF54 PANA WG
Contents • A set of usage scenarios to which PANA could be applied • Mobile IPv6 • CDMA2000 • DSL/Cable modem • Limited scope access network IETF54 PANA WG
PANA for Mobile IPv6 • Mobile IPv6 does not have the equivalent of an FA • Access network needs to authenticate the user before the MN can send BUs to the HA or CN • Access authentication can be accomplished via PANA IETF54 PANA WG
HA AAA PANA PaC PAA Binding Update ASP IETF54 PANA WG
Packet Data Network Authentication in CDMA2000 using PANA • Authentication in CDMA2000 for packet data access is based on multi-layer authentication • Cellular systems’ authentication for device authentication • In addition, higher layer authentication is performed for user authentication (via PPP and Mobile IP) • PANA can be used for authentication in the case of Simple IP service in lieu of PPP • Becomes even more compelling if PPP is substituted by some other protocol for carrying IP IETF54 PANA WG
Cellular systems’ authentication MSC/HLR BSC PDSN PaC PAA RAN PANA IETF54 PANA WG
Authentication in Broadband Networks (DSL/Cable Modem) using PANA • PANA could be used for DSL/cable modem instead of PPPoE • More efficient than PPPoE • Since PANA is supposed to be L2-agnostic, it would transparently work with any intermediary L2 devices (hubs or switches) between PaC and PAA IETF54 PANA WG
PANA DSL modem DSLAM PAA PaC Home DSL provider IETF54 PANA WG
Limited scope access networks using PANA • Limited scope access is unrestricted • Access to Internet initiates PANA exchange for authentication IETF54 PANA WG
PANA Campus map/ flight schedule, etc. Edge subnet WLAN AP PaC PAA Local web server PaC Free access Charged access IETF54 PANA WG
Thank you! IETF54 PANA WG
Why PANA? • Need for network access authentication at higher layer when L2 that does not have authentication mechanism • Not all L2 technologies support carrying EAP (not all IEEE 802 devices implement 802.1X) • Assuming every L2 to carry EAP is not realistic • Using PPP authentication for shared media is inefficient • Need for higher layer authentication on top of L2 authentication • Multi-layer authentication is widely used and common higher layer authentication carrier protocol needs to be standardized • Web-based authentication that is widely used in hot-spot network access is known to be proprietary hack IETF54 PANA WG
802.1X with dynamic key distribution PANA PANA WLAN AP hub/ switch DSL modem DSLAM Home DSL provider IETF54 PANA WG
802.1X with dynamic key distribution PANA WLAN AP Router DSL modem DSLAM Home DSL provider IETF54 PANA WG