|
|
|
|
Ȩ
¼Ö·ç¼Ç |
|
|
|
|
|
|
| |
| |
|


|
| |
|
|
| |
 |
TRIPLE-EYE´Â À¯¹«¼± À̵¿ÀÎÅÍ³Ý È¯°æ¿¡¼ °¡ÀÔÀÚ¿¡ ´ëÇÑ ¾ÈÀüÇÏ°í ½Å·Ú¼º ÀÖ´Â ÀÎÁõ(Authentication),
±ÇÇѰËÁõ(Authorization), ±×¸®°í °ú±Ý(Accounting) ¼ºñ½º¸¦ Á¦°øÇÏ´Â DIAMETER ÇÁ·ÎÅäÄÝ ±â¹ÝÀÇ Â÷¼¼´ë AAA ¼Ö·ç¼ÇÀÔ´Ï´Ù.
|
| |
| |
Authentication : ¸Á Á¢±ÙÀ» Çã¿ëÇϱâ Àü¿¡ »ç¿ëÀÚÀÇ ½Å¿øÀ» °ËÁõ
|
| |
Authorization : ¸Á »ç¿ëÀÌ Çã°¡µÈ »ç¿ëÀÚ¿¡ ´ëÇÑ ¾î¶² ±ÇÇѰú ¼ºñ½º¸¦ Çã¿ëÇÒ °ÍÀÎÁö¸¦ Á¤ÇÏ´Â °Í
|
| |
Accounting : »ç¿ëÀÚÀÇ ¸Á ÀÚ¿ø »ç¿ë¿¡ ´ëÇÑ Á¤º¸¸¦ ¸ðÀ¸´Â ¹æ¹ýÀ» Á¦°ø (Billing, Auditing,
Capacity-
|
| |
planning¿¡ »ç¿ë) |
|
 |
| |
CDMA2000 1x/EVDO ¹× IMT-2000
|
| |
Public WLAN(Wireless LAN)
|
| |
2.3GHz HPi Network
|
| |
SIP(Session Initiation Protocol) Based VoIP Service
|
|
 |
 |
|
 |
IETFÀÇ Â÷¼¼´ë ÀÎÁõ ÇÁ·ÎÅäÄÝ - " DIAMETER
"
DIAMETER´Â »õ·Î¿î Á¤Ã¥°ú ·Î¹Ö, Mobile IP °°Àº »õ·Î¿î ±â¼ú¿¡ ´ëÇÑ
AAA ¼ºñ½º¸¦ Á¦°øÇϱâ À§ÇÑ °¡º¿ì¸é¼µµ È®Àå °¡´ÉÇÑ, Peer ±â¹ÝÀÇ AAA
ÇÁ·ÎÅäÄݷμ RADIUS ¹× TACACS+°¡ °¡Áö°í ÀÖ´Â ±â¼úÀû ÇѰ踦 º¸¿Ï
Çϱâ À§ÇØ °³¹ßµÇ¾úÀ¸¸ç, IETF¿¡¼´Â Â÷¼¼´ë AAA ÇÁ·ÎÅäÄÝ·Î DIAMETER¸¦
¼±Á¤ÇÏ¿© DIAMETER AAA¿¡ ´ëÇÑ »õ·Î¿î Ç¥ÁØÀ» Á¤ÀÇÇÏ¿´½À´Ï´Ù
DIAMETER ÇÁ·ÎÅäÄÝÀº ±âÁ¸ RADIUS ÇÁ·ÎÅäÄݺ¸´Ù °³¼±µÈ ±â´É, RADIUS
ÇÁ·ÎÅäÄݰúÀÇ È£È¯¼º(Compatibility) ¹× RADIUS ÇÁ·ÎÅäÄÝ¿¡¼ DIAMETER
ÇÁ·ÎÅäÄÝ·ÎÀÇ ½¬¿î À̵¿¼º(Migration)ÀÌ °¡´É Çϵµ·Ï ¼³°èµÈ Â÷¼¼´ë ÀÎÁõ
ÇÁ·ÎÅäÄÝÀÔ´Ï´Ù.
|
 |
| |
Better Transport
|
| |
- ½Å·Ú¼º ÀÖ´Â Àü¼Û ÇÁ·ÎÅäÄÝ »ç¿ë(TCP,
SCTP)
- °¢ Hop ¸¶´Ù ÆÐŶ ÀçÀü¼Û °¡´É
- Application-levelÀÇ heartbeat ¸Þ½ÃÁö(Watchdog
message) ¿¬°áÀ» ÅëÇÑ Àü¼Û°èÃþ º¹±¸(Failover) Áö¿ø |
| |
Better Proxying
|
| |
- Hop-by-Hop Àü¼Û Failure
°ËÃâÀ» ÅëÇÏ¿© Proxy°¡ ¸Þ½ÃÁö¸¦ ´Ù¸¥ next-HopÀÇ Peer·Î
Àü¼Û °¡´ÉÇϵµ·Ï
º¹±¸(Failover) Áö¿ø
- Proxy´Â º¹±¸(Failover)¿¡ µû¶ó¼ ÀÚµ¿ÀûÀ¸·Î Pending
¿äû ¸Þ½ÃÁö¸¦ ÀçÀü¼Û |
| |
Better Session Control
|
| |
- Session °ü¸®´Â °ú±Ý¿¡ µ¶¸³Àû
- Session Á¾·á ¶Ç´Â Àç ÀÎÁõ/Àç ±ÇÇѰËÁõÀ» ¿äûÇϱâ À§Çؼ
¼¹ö¿¡¼ ¸Þ½ÃÁö¸¦ Initiate °¡´É |
| |
Better Security
|
| |
- Hop-by-hop º¸¾ÈÀº TLS ¶Ç´Â IPsec¸¦ »ç¿ëÇÏ¿©
Á¦°ø
- PKI¸¦ ÅëÇÑ End-to-end º¸¾ÈÀº Áß°³ Proxy¸¦ ÅëÇÑ
Áß¿äÇÑ AVPµéÀÇ ¹«°á¼º(Integrity)°ú ±â¹Ð¼º
(Confidential)À» Á¦°ø |
|
 |
 |
|
|
 |
 |
 |
|
 |
 |
|
±¸ºÐ
|
±âº»±â´É
|
¼¼ºÎ±â´É
|
DIAMETER
Base
ÇÁ·ÎÅäÄÝ |
ÇϺÎ
Àü¼Û°èÃþ°ú ¿¬µ¿ÇÏ¿© °¢ DIAMETER ³ëµå°£ÀÇ Àü¼Û°èÃþ
¿¬°áÀ» ¼³Á¤, ÇØÁö ¹× °ü¸®Çϰí,
»óÀ§ ÀÀ¿ë°èÃþµéÀÌ ¾ÈÀüÇϰÔ
¸Þ½ÃÁö¸¦ ¼Û¼ö½ÅÇÒ ¼ö ÀÖ´Â
AAA ¼ºñ½ºÀÇ FrameworkÀ» Á¦°ø |
|
| DIAMETER
Mobile IPv4ÀÀ¿ë |
DIAMETER
Base ÇÁ·ÎÅäÄÝÀÇ Inter-domain°ú °áÇյǾî À̵¿
´Ü¸»(MN)¿¡ ´ëÇÑ ÀÎÁõ ¹× ±ÇÇÑ
°ËÁõÀ» ¼öÇàÇÏ¿© À̵¿´Ü¸»(MN)¿¡ À̵¿¼º Áö¿ø ±â´ÉÀ» Á¦°ø |
°¡ÀÔÀÚ(Mobile Node) ÀÎÁõ ¹× ±ÇÇÑ °ËÁõ
- Mobile IPv4 Extension¿¡¼ Á¤ÀÇÇÏ´Â AAA
½ÅÈ£(AMR/AMA, HAR/HAA) ó¸®
- HMAC-MD5, SHA -1 ÀÎÁõ ¾Ë°í¸®Áò
- °¡ÀÔÀÚ NAI(network access interface) Áö¿ø
- °í°´¼¾ÅÍ(CS) ¿¬µ¿À» ÅëÇÑ °¡ÀÔÀÚ
ÇÁ·ÎÆÄÀÏ ¹× ±ÇÇѰü¸®
ºÎ°¡
±â´É
- µ¿Àû ¼¼¼ÇŰ »ý¼º ¹× ºÐ¹è(KDC)
- µ¿Àû HA ÇÒ´ç ½Åȣó¸®
- µ¿Àû MNÀÇ È¨ ÁÖ¼Ò ÇÒ´ç
- Co-Located À̵¿ ´Ü¸»ÀÇ MIP µî·Ï |
| DIAMETER
EAP(Extensible Authentication Protocol)ÀÀ¿ë |
EAP
ÀÀ¿ëÀº Wireless-LAN(WLAN) ¹× ÈÞ´ë ÀÎÅͳÝ(HPi)¿¡¼
Legacy Protocol(PAP, CHAP)ÀÇ ´ÜÁ¡°ú ¹®Á¦Á¡À» º¸¿ÏÇÏ¿©
ID/Password¸¦ ÅëÇÑ »ç¿ëÀÚ ±â¹ÝÀÇ ´Ù¾çÇÑ ÀÎÁõ¹æ½ÄÀ» Á¦°ø
(PAP, CHAP, MS-CHAP, MS-CHAPv2¸¦ Áö¿øÇϸç EAP¸¦
ÀÌ¿ëÇÑ ÀÎÁõ¹æ½ÄÀÎ EAP-MD5, EAP-TTLS, PEAPÀ» Á¦°ø)
|
»ç¿ëÀÚ
ÀÎÁõ
- IEEE 802.1x Framework ±â¹Ý,
»ç¿ëÀÚ ID/Password ±â¹Ý ÀÎÁõ
- EAP-MD5, EAP-TLS, EAP-TTLS, PEAP
ÀÎÁõ Áö¿ø
- ±âŸ MAC µîÀÇ ÀÎÁõ Áö¿ø
º¸¾È
±â´É
- ¾ç¹æÇâ ÀÎÁõ ¸ÞÄ¿´ÏÁò Áö¿ø
- Transport Layer : TLS, IPSec¹«¼±±¸°£
(´Ü¸»°ú AP»çÀÌ) : µ¿Àû ¼¼¼ÇŰÀÇ »ý¼º ¹×
ºÐ¹è ±â´É
- Application Layer : DIAMETER CMS Security
ÀÀ¿ëÀ» ÅëÇÑ E2E(End-to-End)
º¸¾È Á¦°ø |
| DIAMETER
NASREQÀÀ¿ë |
CDMA2000
1X, 1xEVDO »ç¿ëÀÚÁß Simple IP¸¦ ÀÌ¿ëÇÑ ¼ºñ½º¸¦
¹Þ´Â °¡ÀÔÀÚ¿¡ ´ëÇØ¼ DIAMETER NASREQ(PAP/CHAP)
ÀÎÁõÀ»
Á¦°øÇÑ´Ù. |
Simple
IP Service
PAP/CHAP
ÀÎÁõ
RADIUS/DIAMETER
Translator G/W¸¦
ÀÌ¿ëÇÑ Legacy ¸Á°ú ¿¬µ¿ |
| DIAMETER
°ú±Ý |
AAA
¼¹ö°¡ AAA Ŭ¶óÀÌ¾ðÆ®·ÎºÎÅÍ °ú±Ý Á¤º¸¸¦ ¼öÁýÇÏ¿© ¾ÈÀüÇÏ°í ½Å·Ú¼º
ÀÖ°Ô »óÈ£ Àü´ÞÇϰí
º¸°üÇÏ´Â ±â´ÉÀ» Á¦°ø |
|
|
 |
 |
|
|
|
 |
 |
 |
| |
IETF AAA WGÀÇ Ãֱ٠ǥÁØ ±Ô°Ý
|
| |
RFC Ç¥ÁØÀ» ¸¸Á·
|
|
|
| |
Unix ¹× Linux ¼¹ö ±â¹Ý
|
| |
Database : MMDB(Main Memory DB), ORACLE
|
|
 |
| |
TCP / SCTP
|
|
 |
| |
°í°´¼¾ÅÍ(CS) ¿¬µ¿À» ÅëÇÑ °¡ÀÔÀÚ Ã³¸®
|
| |
ºô¸µ¼¹ö(BS) ¿¬µ¿À» ÅëÇÑ °ú±Ý µ¥ÀÌÅÍ Ã³¸®
|
| |
LDAP ¹× DHCP ¿¬µ¿ ±â´É
|
|
 |
| |
°í°¡¿ë¼º(Highly Availability) ±¸Á¶: Active/Active, Active/Standby
|
|
 |
| |
|
|
|
|
|