15
July 15, 2002 IETF54 PANA WG 1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba ([email protected]) Subir Das ([email protected]) Basavaraj Patil ([email protected] om) Hesham Soliman ([email protected] son.se)

July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba ([email protected]) Subir Das ([email protected])

Embed Size (px)

Citation preview

Page 1: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 1

PANA Usage Scenarios Updates(draft-ietf-pana-usage-scenarios-02.txt)

Yoshihiro Ohba ([email protected])

Subir Das ([email protected])

Basavaraj Patil ([email protected])

Hesham Soliman ([email protected])

Page 2: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 2

Objective

• Illustrate examples/scenarios where PANA can be applied

Page 3: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 3

Contents

• A set of usage scenarios to which PANA could be applied

– Mobile IPv6– CDMA2000– DSL/Cable modem– Limited scope access network

Page 4: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 4

PANA for Mobile IPv6

• Mobile IPv6 does not have the equivalent of an FA

• Access network needs to authenticate the user before the MN can send BUs to the HA or CN

• Access authentication can be accomplished via PANA

Page 5: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 5

HA

ASP

PANA

Binding Update

PaC PAA

AAA

Page 6: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 6

Packet Data Network Authentication in CDMA2000 using PANA

• Authentication in CDMA2000 for packet data access is based on multi-layer authentication– Cellular systems’ authentication for device authenticati

on– In addition, higher layer authentication is performed for

user authentication (via PPP and Mobile IP)

• PANA can be used for authentication in the case of Simple IP service in lieu of PPP – Becomes even more compelling if PPP is substituted by

some other protocol for carrying IP

Page 7: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 7

PDSN

RAN

PANA

Cellular systems’ authentication

BSC

MSC/HLR

PaC PAA

Page 8: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 8

Authentication in Broadband Networks (DSL/Cable Modem) using PANA

• PANA could be used for DSL/cable modem instead of PPPoE– More efficient than PPPoE– Since PANA is supposed to be L2-agnostic, it

would transparently work with any intermediary L2 devices (hubs or switches) between PaC and PAA

Page 9: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 9

DSLAMDSLmodem

Home DSL provider

PANA

PAAPaC

Page 10: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 10

Limited scope access networks using PANA

• Limited scope access is unrestricted

• Access to Internet initiates PANA exchange for authentication

Page 11: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 11

WLAN AP

PANA

Edgesubnet

Free access

Local web server

Campus map/ flight schedule,

etc.

Charged access

PaC

PaC

PAA

Page 12: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 12

Thank you!

Page 13: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 13

Why PANA?• Need for network access authentication at higher layer whe

n L2 that does not have authentication mechanism– Not all L2 technologies support carrying EAP (not all IEEE 802 d

evices implement 802.1X)– Assuming every L2 to carry EAP is not realistic– Using PPP authentication for shared media is inefficient

• Need for higher layer authentication on top of L2 authentication– Multi-layer authentication is widely used and common higher laye

r authentication carrier protocol needs to be standardized– Web-based authentication that is widely used in hot-spot network

access is known to be proprietary hack

Page 14: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 14

DSLAMhub/switch

WLAN AP DSLmodem

Home DSL provider

PANA

802.1X with dynamic key di

stribution PANA

Page 15: July 15, 2002IETF54 PANA WG1 PANA Usage Scenarios Updates (draft-ietf-pana-usage-scenarios-02.txt) Yoshihiro Ohba (yohba@tari.toshiba.com) Subir Das (subir@research.telcordia.com)

July 15, 2002 IETF54 PANA WG 15

DSLAMRouterWLAN AP DSLmodem

Home DSL provider

PANA

802.1X with dynamic key di

stribution