Thư viện tri thức trực tuyến
Kho tài liệu với 50,000+ tài liệu học thuật
© 2023 Siêu thị PDF - Kho tài liệu học thuật hàng đầu Việt Nam

Chapter 6 - AAA on the Internet ppt
Nội dung xem thử
Mô tả chi tiết
Chapter 6
AAA on the Internet
6.1 Authentication, Authorization, and Accounting
The term AAA has been traditionally used to refer to Authentication, Authorization, and
Accounting activities. All of those activities are of crucial importance for the operation of
an IP network, although typically they are not so visible to the end user.
The importance of AAA functions lies in the fact that they provide the required protection
and control in accessing a network. As a consequence, the administrator of the network can
bill the end user for services used. By services we are referring to any type of services related
to the access of the network, such as high bandwidth, provision of routing services, gateway
services, etc.
Before we proceed with this chapter, let us agree on a common terminology.
Authentication. This is the act of verifying the identity of an entity (subject).
Authorization. This is the act of determining whether a requesting entity (subject) will
be allowed access to a resource (object) (e.g., network access, certain amount of
bandwidth, etc.).
Accounting. This is the act of collecting information on resource usage for the purposes of
capacity planning, auditing, billing, or cost allocation.
All of these concepts are intimately linked. For instance, it is not feasible to record the
usage of a resource when the entity (subject) making usage of the resource (object) is not
yet known. Therefore, in order to account for the usage of a resource the entity has to be
authenticated. Once the subject is authenticated, it can be authorized to access the resource.
Here, we are speaking generically. A resource could be access to a network, a radio resource,
or access to a conference bridge.
The rest of this chapter describes the Internet architecture needed to provide the network
functions of AAA. We will learn about the protocols that the IETF has developed to provide
the mentioned functions.
6.2 AAA Framework on the Internet
At the beginning of 1997 the IETF defined the Remote Authentication Dial In User Service
(RADIUS, RFC 2058 [260]) as the protocol to perform AAA functions on the Internet.
ıa- ´ Martın´
The 3G IP Multimedia Subsystem (IMS): Merging the Internet and the Cellular Worlds Third Edition
Gonzalo Camarillo and Miguel A. Garc
© 2008 John Wiley & Sons, Ltd. ISBN: 978- 0- 470- 51662- 1