Re: [Dime] DiME ERP - Getting the message flows right
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Dime] DiME ERP - Getting the message flows right



Hmmm. Interesting. 

From your description I would go for a direct exchange between local ERP
server and home EAP server. 


>-----Original Message-----
>From: dime-bounces at ietf.org [mailto:dime-bounces at ietf.org] On 
>Behalf Of ext Sebastien Decugis
>Sent: 17 March, 2009 08:28
>To: Hannes Tschofenig
>Cc: dime at ietf.org; hokey at ietf.org
>Subject: Re: [Dime] DiME ERP - Getting the message flows right
>
>Hi again,
>
>After trying to capture the new mechanism (based on a new application
>id) in a document, I have encountered an issue and I am not 
>sure what is the proper way to solve it.
>
>When the local ER server (aka HOKEY server in the visited 
>domain) needs to retrieve the rDSRK material (i.e. it was not 
>bootstrapped already) this material can not be provided 
>directly by the Home ER server, because of the key hierarchy:
>
>EMSK (in Home EAP server)
>|
>+- rRK (in Home ERP server)
>|
>+- DSRK (in Home EAP server or a local server)
>    |
>   +- rDSRK (in local ERP server)
>
>There are two ways to get this material:
>- through the home ERP server (in this case the home ER server 
>receives visited domain specific keying material, which may 
>not be good)
>- directly with an exchange between local ERP server and home 
>EAP server.
>
>This second option would be shown as follow ( exchange (c) ):
>
>>   Diameter EAP +-------------+   Diameter EAP   +-------------+
>>                |             |                  |             |
>>  <------------>| Local       |<---------------->| Home        |
>>                | Diameter    |                  | Diameter    |
>>                | EAP Proxy   |                  | EAP Server  |
>>                |             |            ----->|             |
>>                +-------------+           /      +-------------+
>>                       ^                 /              ^
>>                    (a)| proprietary   (c)  proprietary |(b)
>>                       v               /                v
>>                +-------------+ <-----/          +-------------+
>>   Diameter ERP |             |                  |             |
>>                | Local       |    Diameter ERP  |  Home       |
>>  <------------>| Diameter    |<---------------->|  Diameter   |
>>                | ERP Server  |                  |  ERP Server |
>>                |             |                  |             |
>>                +-------------+                  +-------------+
>>   
>
>Note that the exchange (b) is needed anyway for the case when 
>the peer is in its home domain.
>
>
>Does anybody have some comments on this?
>
>Thank you,
>Sebastien.
>
>
>--
>Sebastien Decugis
>Research fellow
>Network Architecture Group
>NICT (nict.go.jp)
>
>_______________________________________________
>DiME mailing list
>DiME at ietf.org
>https://www.ietf.org/mailman/listinfo/dime
>

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.