Showing posts with label 3GPP Radius. Show all posts
Showing posts with label 3GPP Radius. Show all posts

Sunday, August 2, 2009

3GPP Radius Part2

Some time back I wrote about 3GPP Radius. This is continuation of it.

What I said in the previous post was UE sends the authentication details in PCO field of Create PDP context/Create default bearer to GGSN/PGW. GGSN/PGW looks at that field and creates a Radius Access Request and sends it to a AAA server. AAA server can accept or reject the request. Its plain and simple. Lets look a little further.

IP address allocation: It would be interesting to see if Radius server can assign IP addresses to the UE. When a GGSN sends access request to AAA server, AAA server can respond to the request with access accept by placing an IP address in the Framed-IP field. This way we will not have to maintain a IP pool in GGSN, some processing reduced. GGSN can send the IP address received in Access accept to UE in PDP response message. So radius server will maintain a pool of ip addresses to be assigned to each UE and I believe it would be easy to maintain too.

The IP address can be returned to the radius server in Accounting Stop message. Once AAA server receives accounting stop it can free that ip address and assign it to other UE.

Accounting: I am quite not sure about it but I think accounting is done based on MSISDN. If so AAA server can maintain a table mapping MSISDN, IP address allocated, number of packets/octets in and out. Charging can be done based on this data. More over we can have static values of IP addresses to be assigned based on MSISDN. Assign this IP address to this MSISDN. Basically MSISDN becomes a kind of MAC address (?).

I believe most of the service providers do the way I mentioned above, if not I would be happy to know the other techniques.

FreeRadius : I am impressed. Simply superb is the word. I used Free Radius extensively in past few days and my god its just sweet. 100 requests at a time and still counting. What I did was create a local ip pool and when ever there is access request, reply with an IP address. It works superb. What I dint do was SQL Ip pool. I believe we can do Accounting scenario mentioned above pretty easily. (Log MSISDN, IP address, Accounting Packets/Octets in and out). The only problem with local IP pool was returning the IP addresses. IP addresses were not released when accounting stop was received. I tried every possible way but nope, it dint work. But Sql IP pool is supposed to work fine, I havent tested it but I believe it works fine. I dint try assigning IP addresses based on MSISDN too. Hope it works.

Thats pretty much it. Comments are always welcome.

Oh! Wish you all a very happy friendship day!

Wednesday, May 6, 2009

LTE : Wishlist

Off-late work is keeping me busy and I am not finding time to do much except for logging and verifying bugs. :) I have jotted down few things which I feel are pretty important to understand LTE technology much better. I call it the "Wishlist". These are my priority now.

  • QoS : QoS is top in my list. I had tried posting something before but I still need to work more. There are acronyms like TFT , TAD's to understand. I still have couple of questions from readers to answer.
  • Dedicated Bearers: I still dont get the dedicated bearers completely. I am almost there. I wrote two posts on dedicated bearers sometime back and I almost understand how they work now. (Post 1 and Post 2)
  • 3GPP Radius: I think I have got this one. There is not much difference in LTE and UMTS/GSM implementation of Radius authentication except for changes in few acronyms. If you pick up the free radius from freeradius.org you might just be able to authenticate user in GSM/UMTS domain as the dictionary for 3GPP is already available. But for LTE you might need to tweek something to make free radius work. I wrote something on Radius sometime back but more to follow.
  • Interop with 3GPP/Non 3GPP: LTE is all about convergence. So lots of networks will be coming together. There is need to understand how this will happen. This is not a high priority on the list but interop with 3G is definitely on the charts.
  • LTE Security aspects : I am still taking baby steps here. A lot needs to be done. :)

There is an event coming up on LTE. LTE World Summit in Germany from May 18th to 20th. Its one even that anyone working in LTE should watch out for. Unfortunately I cannot attend it. I am neither rich to afford a flight ticket nor my company is ready to sponsor. So attending one of these events is in my wish list too. :) There will be another LTE world summit in Asia, even that will be held in Hongkong in month september. It is very disheartening to see that nothing is happening in India. I know there are lot of people working on various LTE projects in India but 4G is not going to be deployed any sooner in India. I wish somebody takes up and initiative and arrange a meet in India where people from various companies can share their interests and show case their products. If I am unaware of any such events please enlighten me.

Having said 4G is far far away in India, 3G isn't coming any sooner too. THe spectrum auction again has been postponed. As elections are going on we might have to wait for the new government to form for spectrum to released. But BSNL has launched its 3G services which is not used by corporates. Lets hope we can have 3G at least by this year end.

I have a big question. Now that release 8 has free-zed how will any work on it will continue. Say something needs to changed in spec how will it be done. All changes go in Rel 9? That shouldn't be. Any ideas?

Right now all I can think of is LTE. But the question is pursuing it as career is a good idea? 3G took 7 years to deploy and work properly. LTE might 10 years. What after it? New technology? I dont know? Still thinking in that aspect as I have to move on with my career too.

I am in desperate need of tool using which I can make notes. I use windows PC in office and publish all my blogs from mac. So if I have to make a quick note on Mac which needs to be accessed on my office PC is getting difficult for me. I am right now using Google Notebook but I would really like to see some think like sticky which can used to make notes from any where and can be accessed any where. I am planning on buying a smart phone soon. So I will have three devices to make notes. I would really appreciate if any you know of any tool or service.

And finally I should say that my blog is not well maintained. Information is spread all over the blog and there is redundancy or lack of info in some posts. I apologize for that and will get better as the time passes by.

As always comments and emails are greatly welcome.

Friday, April 10, 2009

3GPP Radius

Radius is the authentication and accounting server used in Rel 7. I have been reading a lot about it as my job demands to create a test plan and cases for testing a AAA server. I thought of blogging about it.

Ok, so authentication is important in mobile world. You need to know if the mobile subscriber is allowed to access packet core or not. So how this is done in Rel 7? Here it its.


3GPP Radius.jpg

This feature is explained in 3GPP TS 29.061. So mobile terminal sends out an PDP context activate request to SGSN. SGSN create a PDP context request and send it to GGSN. Now if you look at PDP context request there is and IE called PCO ( Protocol Configuration Options). SGSN creates the request with authentication details put in PCO field and forwards it to GGSN.

PCO contains : Type of authentication protocol, user name and password. (PAP/CHAP)

GGSN before granting the pdp responses creates a radius access request with user name and password in PDP request and sends it to AAA server. AAA server grants or rejects the access. Once AAA sever gives ok, GGSN creates PDP response and sends it to SGSN. GGSN may send Accounting start request to AAA server before sending the PDP response. This is nice, simple and easy way for authentication.

If you have a cisco 7200, a AAA server and SGSN, try creating a network for your selves. What I did in my lab was configured a Cisco 7200 as GGSN. Believe me its very simple. Our tool can act as SGSN. It can send out tens of thousands of PDP context requests. Then I pulled a Free radius server from internet. Wala! I have my network. I configured out tool acting as SGSN to send out PDP requests, Cisco 7200 process the PDP request and sends out radius requests to free radius. Free radius says ok and I have PDP response from router.

So this is how network operators create their network. Now going to Rel 8, I see that PCO is still present in GTP v2. But I am guessing authentication has to be much more stronger since its all IP. We can compare a Rel 8 network to WLAN network, just for understanding the authentication better. So in WLAN we have EAP authentication methods. Now Consider EAP TLS with certificate based security. A laptop in WLAN network has certificate to attach to a particular network. Access points in WLAN are configured to talk to AAA server for authentication. So lets consider that laptops as Mobile subscribers and Access point as the core network. AAA servers remain the same in both. Once a mobile node request access, it uses it certificate to get validated. Core network talks to AAA server to authenticate the mobile node. Just like the way it is done in WLAN. After that data may flow encrypted. I havent read much about this in Rel 8, but will post something in this security section soon.

Comments are welcome.