Inter-domain Authentication and Authorization Mechanisms for Roaming SIP Users

To enable users to utilize the services of various providers of multimedia services based on the session initiation protocol (SIP), some kind of interaction is required between the foreign provider and the home provider of the users. Such interaction is required for example to allow a user to utilize services provided by a foreign service provider while the user is on travel. In this paper we describe two possible approaches for exchanging authentication, authorization and accounting (AAA) information between foreign and home providers, namely: SIP dependent and independent inter-domain AAA communication. In the SIP dependent scenario, SIP is used as the communication protocol between the interacting providers and for carrying any information that needs to be exchanged between the providers. With the SIP independent scenario a special AAA protocol is used between the domains for exchanging AAA related information. Both approaches will be described in terms of message sequences that would be exchanged and will be analyzed in terms of their efficiency, flexibility and security. The here described scenarios present an overview of various efforts currently being followed in the standardization groups and are based on standardized protocols. Our contribution is to provide the details of the currently discussed concepts and compare between them. 1 This paper describes work undertaken in the context of the IST FP6/2002/IST/1 ‘My personal Adaptive Global Net’ IST-MAGNET project, WP3 Adaptive and Scalable Air-Interfaces for Personal Area Networks. The IST program is partially funded by the EC. The authors would like to acknowledge the contributions of their colleagues from the MAGNET Consortium

[1]  Victor Fajardo,et al.  Diameter Base Protocol , 2003, RFC.

[2]  王家志 Technical Specification Group Services and System Aspects ; 3 G Security ; Specification of the MILENAGE Algorithm Set : An example algorithm set for the 3 GPP authentication and key generation functions , 2001 .

[3]  Allan C. Rubens,et al.  Remote Authentication Dial In User Service (RADIUS) , 1997, RFC.

[4]  Gonzalo Camarillo,et al.  Integration of Resource Management and SIP , 2002 .

[5]  Stephen Thomas,et al.  QoS and AAA Usage with SIP Based IP Communications , 2001 .

[6]  J. Rosenberg,et al.  Session Initiation Protocol , 2002 .

[7]  Allan C. Rubens,et al.  Remote Authentication Dial In User Service (RADIUS) , 2000, RFC.

[8]  K. Ramakrishnan,et al.  Integration of Resource Management and SIP , 2000 .

[9]  Charles E. Perkins,et al.  Mobile IP Authentication, Authorization, and Accounting Requirements , 2000, RFC.

[10]  William Marshall,et al.  Private Session Initiation Protocol (SIP) Extensions for Media Authorization , 2003, RFC.

[11]  Leon Gommans,et al.  AAA Authorization Application Examples , 2000, RFC.

[12]  Henning Schulzrinne,et al.  Dynamic Host Configuration Protocol (DHCP-for-IPv4) Option for Session Initiation Protocol (SIP) Servers , 2002, RFC.

[13]  Dean Willis,et al.  Session Initiation Protocol (SIP) Extension Header Field for Service Route Discovery During Registration , 2003, RFC.

[14]  K.K. Tam,et al.  Session Initiation Protocol , 2002, 2002 IEEE International Conference on Industrial Technology, 2002. IEEE ICIT '02..