Users roaming is an important feature to be provided by current ISPs. The goal is to allow users to access to the Internet from everywhere without the need to have multiple subscriptions.A suitable authentication and key distribution mechanism between different domains involved is required to provide a secure network access service. The IETF solution for this is the Extensible Authentication Protocol (EAP) which supports various authentication methods while defining a keying framework. However, this framework suffers from some limitations in roaming scenario, specially in a mobility context. The reason is that each time the visited network needs to reauthenticate the client, the home domain must be contacted. This may introduce some consequent delay if the client is far from it. This paper proposes a new design which improves the current EAP keying distribution framework. The basic idea is to allow the visited domain to play a more active role in the key distribution. For this, we introduce a new level in the key hierarchy defined in the EAP keying framework. Thanks to this one, a new key can be used between the mobile and the visited network. This brings better performance during reauthentication as the home domain is no longer solicited.
In commercial and enterprise deployments, Mobile IPv6 can be a service offered by a Mobility Services Provider (MSP). In this case, all protocol operations may need to be explicitly authorized and traced, requiring the interaction between Mobile IPv6 and the AAA infrastructure. Integrating the Authentication, Authorization, and Accounting (AAA) infrastructure (e.g., Network Access Server and AAA server) also offers a solution component for Mobile IPv6 bootstrapping. This document describes various scenarios where a AAA interface for Mobile IPv6 is required. Additionally, it lists design goals and requirements for such an interface. Status of This Memo This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.