A Multi-Domain Access Control Infrastructure Based on Diameter and EAP
スポンサーリンク
概要
- 論文の詳細を見る
The evolution of Internet, the growth of Internet users and the new enabled technological capabilities place new requirements to form the Future Internet. Many features improvements and challenges were imposed to build a better Internet, including securing roaming of data and services over multiple administrative domains. In this research, we propose a multi-domain access control infrastructure to authenticate and authorize roaming users through the use of the Diameter protocol and EAP. The Diameter Protocol is a AAA protocol that solves the problems of previous AAA protocols such as RADIUS. The Diameter EAP Application is one of Diameter applications that extends the Diameter Base Protocol to support authentication using EAP. The contributions in this paper are: 1) first implementation of Diameter EAP Application, called DiamEAP, capable of practical authentication and authorization services in a multi-domain environment, 2) extensibility design capable of adding any new EAP methods, as loadable plugins, without modifying the main part, and 3) provision of EAP-TLS plugin as one of the most secure EAP methods. DiamEAP Server basic performances were evaluated and tested in a real multi-domain environment where 200 users attempted to access network using the EAP-TLS method during an event of 4 days. As evaluation results, the processing time of DiamEAP using the EAP-TLS plugin for authentication of 10 requests is about 20ms while that for 400 requests/second is about 1.9 second. Evaluation and operation results show that DiamEAP is scalable and stable with the ability to handle more than 6 hundreds of authentication requests per second without any crashes. DiamEAP is supported by the AAA working group of the WIDE Project.
- 2012-02-01
著者
-
Teraoka Fumio
Faculty Of Science And Technology Keio University
-
Ben Ayed
Graduate School Of Science And Technology Keio University
関連論文
- AMS : An Adaptive TCP Bandwidth Aggregation Mechanism for Multi-homed Mobile Hosts(New Technologies and their Applications of the Internet IV)
- PMPATH : A Policy Routing System for Multihomed End-Hosts(Policy Routing, New Technologies and their Applications of the Internet III)
- A Multi-Domain Access Control Infrastructure Based on Diameter and EAP
- PNEMO: A Network-Based Localized Mobility Management Protocol for Mobile Networks