Re: [Dime] Diameter ERP
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Dime] Diameter ERP



Hi, Sebastien and all:
----- Original Message ----- 
From: "Sebastien Decugis" <sdecugis at nict.go.jp>
To: <dime at ietf.org>
Sent: Thursday, October 15, 2009 2:34 PM
Subject: [Dime] Diameter ERP


> Hello DIME members,
> 
> FYI, draft-ietf-dime-erp-02.txt has been published. It is a small update
> from previous version, and does not contain new ideas.
> 
> As a reminder, some issues are still pending on this document and your
> comments would be appreciated. See section 10 of the document for more
> details on the following issues:
> 
> - do we use Diameter ERP (alone) to support re-authentication of the
> peer after a handover, or do we mandate the use of a mobility
> application (such as MIP6) in that case -- this mobility application
> could use Diameter ERP as an optimization.

[Qin]:  In my understanding, Diameter ERP is not mobility protocol but can reuse the similar mechanism specified in  the mobility application, e.g., Diameter user session mangement ,as described in the section 4.1 of RFC4004, the different sessions can be correlated with the Acct-Multi-Session-Id AVP like. 

Therefore the similar mechanism(i.e.,user Session correlation) can also be adopted, i.e., each time the peer  moves to the new NAS, the session-Id created from the new NAS will be  correlated with the user name or Acct-Multi-Session-Id corresponding to this given peer.
 
> - in case the home domain contains several EAP servers, how does ERP
> mechanism find the one that possess the EMSK for a given peer ?

[Qin]: Isn't EMSKname used to distinguish different EAP servers in the same home domain?
If EMSKname can not be used to do this, I think ERP/DER messages can be advertised to all the EAP 
servers in the home domain, the first EAP server who responds will be viewed as the EAP server that
 possess the EMSK for a given peer. Is it right?


> We are looking forward to your comments...
> 
> Best regards,
> Sebastien.
> 
> -- 
> Sebastien Decugis
> Research fellow
> Network Architecture Group
> NICT (nict.go.jp)
> 
> _______________________________________________
> DiME mailing list
> DiME at ietf.org
> https://www.ietf.org/mailman/listinfo/dime

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.