Mobile VPN: Delivering Advanced Services in Next Generation Wireless Systems

Similar documents
Contents. Preface. Acknowledgement. About the Author. Part I UMTS Networks

UMTS/GPRS system overview from an IP addressing perspective. David Kessens Jonne Soininen

The 3GPP and 3GPP2 Movements Towards an All IP Mobile Network. 1 Introduction

VPN. Date: 4/15/2004 By: Heena Patel

Table of Contents. Introduction

COPYRIGHTED MATERIAL. Contents. Foreword. Acknowledgments

U.S. Patent Appl. No. 13/ filed September 28, 2011 NETWORK ADDRESS PRESERVATION IN MOBILE NETWORKS TECHNICAL FIELD

Networking. Systems Design and. Development. CRC Press. Taylor & Francis Croup. Boca Raton London New York. CRC Press is an imprint of the

Security and Authentication Concepts

Mobile Wireless Overview

SpiderCloud E-RAN Security Overview

White Paper. Telenor VPN

5.0 Network Architecture. 5.1 Internet vs. Intranet 5.2 NAT 5.3 Mobile Network

ALCATEL-LUCENT 7750 SERVICE ROUTER NEXT-GENERATION MOBILE GATEWAY FOR LTE/4G AND 2G/3G AND ANCHOR FOR CELLULAR-WI-FI CONVERGENCE

Cisco Which VPN Solution is Right for You?

The Shift to Wireless Data Communication

Introduction. Acknowledgments Support & Feedback Preparing for the Exam. Chapter 1 Plan and deploy a server infrastructure 1

Cisco Networking Professional-6Months Project Based Training

The Architecture of a Novel Tool for Network Management Using GSM/GPRS Mobile Devices

Introduction. Assessment Test

Co-existence of Wireless LAN and Cellular Henry Haverinen Senior Specialist Nokia Enterprise Solutions

IP Core Network Realization

GPRS Network Security

Best practices on cellular M2M deployment. Paul Bunnell November 2014

GPRS and 3G Services: Connectivity Options

Designing and Developing Scalable IP Networks

Technical White Paper

ICTTEN6172A Design and configure an IP- MPLS network with virtual private network tunnelling

INTELLIGENT NETWORK SERVICES MIGRATION MORE VALUE FOR THE

White Paper. Mobility and Mobile IP, Introduction. Abstract

HRPD Support for Emergency Services

IMT-2000 Network Architecture

Contents. Biography. Acknowledgments. List of Abbreviations. List of Symbols

Cisco CCNP Optimizing Converged Cisco Networks (ONT)

Internet, Part 2. 1) Session Initiating Protocol (SIP) 2) Quality of Service (QoS) support. 3) Mobility aspects (terminal vs. personal mobility)

Designing a Windows Server 2008 Network Infrastructure

MOC 6435A Designing a Windows Server 2008 Network Infrastructure

Network Services Internet VPN

DATA SECURITY 1/12. Copyright Nokia Corporation All rights reserved. Ver. 1.0

Module 1: Overview of Network Infrastructure Design This module describes the key components of network infrastructure design.

TS-3GB-S.R0103-0v1.0 Network Firewall Configuration and Control (NFCC) - Stage 1 Requirements

IP-based Mobility Management for a Distributed Radio Access Network Architecture. helmut.becker@siemens.com

Course Description. Students Will Learn

Wireless Local Area Networks (WLANs)

Course Outline: Designing a Windows Server 2008 Network Infrastructure

GSM v. CDMA: Technical Comparison of M2M Technologies

Inter-Domain QoS Control Mechanism in IMS based Horizontal Converged Networks

Building VPNs. Nam-Kee Tan. With IPSec and MPLS. McGraw-Hill CCIE #4307 S&

Industrial Network Security for SCADA, Automation, Process Control and PLC Systems. Contents. 1 An Introduction to Industrial Network Security 1

Mobile IPv6 deployment opportunities in next generation 3GPP networks. I. Guardini E. Demaria M. La Monaca

Securing Networks with Cisco Routers and Switches ( )

Continued improvement in semiconductor and computing. technologies brought exponential growth to wireless industry. The

Chapter 3: WLAN-GPRS Integration for Next-Generation Mobile Data Networks

Contents. Acknowledgments

Network System Design Lesson Objectives

MOBILE VIDEO WITH MOBILE IPv6

Course Contents CCNP (CISco certified network professional)

Verizon Wireless White Paper. Verizon Wireless Broadband Network Connectivity and Data Transport Solutions

VPN Technologies: Definitions and Requirements

Impact of IP on Mobile Communications THIS IS CISCO ON THE MOVE

Product Description. HUAWEI E5220s-81 Mobile WiFi V100R001 HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date

Diameter in the Evolved Packet Core

Next Generation Networks Convergence, evolution and roadmaps

Tech Brief. Enterprise Secure and Scalable Enforcement of Microsoft s Network Access Protection in Mobile Networks

I. What is VPN? II. Types of VPN connection. There are two types of VPN connection:

Deploying IPv6 in 3GPP Networks. Evolving Mobile Broadband from 2G to LTE and Beyond. NSN/Nokia Series

Chapter 5. Data Communication And Internet Technology

Chapter 1 The Principles of Auditing 1

A SEAMLESS MOBILE VPN DATA SOLUTION FOR UMTS AND WLAN USERS

Southern Methodist University. Department of Electrical Engineering. Telecommunications (EETS) Course Descriptions

Mobility and cellular networks

End-to-End QoS Network Design

Supporting Municipal Business Models with Cisco Outdoor Wireless Solutions

12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust

CompTIA Exam N CompTIA Network+ certification Version: 5.1 [ Total Questions: 1146 ]

Authentication, Authorization and Accounting (AAA) Protocols

The GSM and GPRS network T /301

Security. AAA Identity Management. Premdeep Banga, CCIE # Cisco Press. Vivek Santuka, CCIE # Brandon J. Carroll, CCIE #23837

! encor e networks TM

3GPP TS V6.3.0 ( )

GPRS / 3G Services: VPN solutions supported

Design and Implementation Guide. Apple iphone Compatibility

GSM services over wireless LAN

EAP-SIM Authentication using Interlink Networks RAD-Series RADIUS Server

CCIE Routing and Switching Written and Lab Exam Content Updates

How To Configure L2TP VPN Connection for MAC OS X client

Toolkit for vulnerability assessment in 3G networks. Kameswari Kotapati The Pennsylvania State University University Park PA 16802

Implementing LTE International Data Roaming

Authentication and Security in IP based Multi Hop Networks

Internet Protocol: IP packet headers. vendredi 18 octobre 13

Voice over IP Implementation

D2-01_37. WAN Network Communications Architectures for Smartgrids: Case Study comparison

Verizon Managed SD WAN with Cisco IWAN. October 28, 2015

Advanced Higher Computing. Computer Networks. Homework Sheets

1 Introduction Services and Applications for HSPA Organization of the Book 6 References 7

Contents. Foreword. Acknowledgments

CIS 175 NETWORK TECHNICIAN JACKSON STATE COMMUNITY COLLEGE COURSE SYLLABUS

Transcription:

Mobile VPN: Delivering Advanced Services in Next Generation Wireless Systems Alex Shneyderman and Alessio Casati Wll Y Wiley Publishing, Inc.

Ix Contents Foreword Preface Parti Chapter 1 Wireless Data Fundamentals Introduction to MVPN The Era of Pervasive Mobility Pervasive Mobility Drivers Increase in Productivity Mobile Device Evolution Cellular Systems Advances Mobile Lifestyles and Workplaces Background on VPN MVPN Business Case Moving to Mobile VPN Wireless Communications with MVPN MVPN as a Differentiation Tool Mobile VPN Market and Stakeholders MVPN Service Providers MVPN Customers Small Businesses Enterprises Institutions Application Service Providers XV xvii 1 3 5 6 6 7 7 7 8 9 10 10 11 12 12 13 14 14 15 16

Contents Wireless Data Standards Regional Standards Organizations 17 3GPP 18 3GPP Documents and Standardization Process 21 3GPP2 21 3GPP2 Documents and Standardization Process 23 Internet Engineering Task Force 24 IETF Documents and Standardization Process 25 IEEE 802 LAN/MAN Standards Committee 26 IEEE Documents and Standardization Process 29 Finding Standards Documents Online 30 Summary 30 Chapter 2 Data Networking Technologies 31 Tunneling and Labeling Technologies 32 Layer Two Tunneling Protocol 33 IP in IP Tunneling 36 GRE Protocol 37 Mobile IP 38 Implementing Mobile IP 39 GPRS Tunneling Protocol 42 Addressing Security 46 IPSec 46 Public Key Infrastructure 50 SSLandTLS 53 Labeling with Multi-Protocol Label Switching 54 Quality of Service and VPN 59 Per-Hop Behavior Types 59 QoS and Tunnels 60 QoS and MPLS 63 Authentication, Authorization, and Accounting 63 User Authentication and Authorization 64 Accounting Data Collection 65 AAA and Network Access Services: RADIUS 67 Authentication Methods for Network Access 67 AAA and Roaming: The Network Access Identifier 69 AAA Evolution: DIAMETER 70 Network Services 71 Address Management 71 DHCP Protocol 72 Host Naming 74 Domain Name System 74 Network Address Translation 77 Summary 79 16

Contents xi Chapter 3 Wireless Systems Overview: A Radio Interface Perspective 81 Three Wireless Generations 82 1G Cellular Systems 85 AMPS 85 Nordic Mobile Telephone and Total Access Communication System 86 2G Cellular Systems 87 North American TDMA (IS 136) 88 Global System for Mobile Communications (GSM) 89 High-Speed Circuit-Switched Data 90 cdmaone 90 3G Cellular Systems 92 CDMA2000 92 CDMA2000-lxEV 93 CDMA2000-3x 94 Universal Mobile Telecommunications System 94 UMTS Standardization 95 UMTS Radio Interface 96 Enchased Data Rate for Global Evolution 98 EDGE Classification 98 The Future of EDGE 100 Wireless LAN 100 WLAN Technology 101 Summary 102 Chapter 4 Wireless Systems Overview: Data Services Perspective 103 Circuit versus Packet 104 Data Services in 1G, 2G, and 3G Systems 106 1G Systems Circuit Data 106 Circuit-Switched Data in 2G and 3G Systems 107 CDMA and TDMA Circuit-Switched Data 107 GSM and UMTS Circuit-Switched Data 109 GSM / UMTS CSD Service Capabilities 110 CDMA2000 Packet Data 112 CDMA2000 Packet Data Architecture 113 Mobile Station Perspective 117 Dormancy 117 Mobile Station Types 118 CDMA2000 Mobility Levels 119 CDMA2000 Mobile AAA 121 GSM and UMTS Packet Data: General Packet Radio Service and UMTS PS Domain 123 GPRS Elements 124 UMTS Elements 125 GPRS and UMTS PS Domain System Architecture 126 GPRS and UMTS PS Domain Service Capabilities 131 GPRS and UMTS PS Domain Terminal 131 Summary 133

xii Contents Part 2 MVPN and Advanced Wireless Data Services 135 Chapters Mobile VPN Fundamentals Defining VPN 138 VPN Building Blocks 138 Access Control I 41 Policy Provisioning and Enforcement 142 Captive Portal 142 Authentication 1^ Security 144 Tunneling as the VPN Foundation 1 4! > Labeling (MPLS) and VPN 147 Service Level Agreements 1^ MVPN SLA 149 Classifying VPN Technology 150 Tunneling Taxonomy 150 Voluntary VPN 151 Compulsory VPN 153 Chained Tunnel VPN 155 Architecture Taxonomy: Site-to-Site and Remote Access VPN 156 Site-to-Site VPN 156 Remote Access VPN 159 Moving from Wireline to Wireless and Mobile 162 Wireless versus Mobile 162 Significance of VPN in the Wireless Packet Data Environment 164 Voluntary MVPN 165 Compulsory MVPN 166 Summary 168 Chapter 6 GSM/GPRS and UMTS VPN Solutions 169 GSM and UMTS Circuit-Switched Data Solutions 170 CSD Solutions Technologies 171 CSD Deployment Scenarios 171 Packet Data Solutions 173 Packet Data Technology Solutions 173 IPPDPType 176 Simple IP 177 IP with Protocol Configuration Options 179 DHCP Relay and Mobile IPv4 181 PPPPDPType 182 PPP Relay 184 PPP Terminated at the GGSN 185 Service Level Agreements 187 Charging and Billing 188 Roaming 189 Case Study: ACME Wireless 194 Summary 200 137

Contents xiii Chapter 7 Chapter 8 CDMA2000 VPN Solutions Overview of CDMA2000 Private Network Access Simple IP: A True Mobile VPN? Simple IP VPN Architecture Simple IP VPN Call Scenario Mobile IP-Based VPN Public HA VPN Option Public HA VPN Security Private HA VPN HA Allocation in the Network Private HA Allocation Relative to the PDSN Collocated PDSN/HA Centrally Located HA Dynamic HA Allocation CDMA2000 IP Address Management Simple IP VPN Address Assignment Mobile IP VPN Address Assignment Authentication, Authorization, and Accounting for MVPN Service CDMA2000 AAA Architecture CDMA2000 AAA Brokerage Mobile IP VPN Perspective Simple IP VPN Perspective Case Study Summary Mobile VPN Equipment MVPN Clients MVPN Client Implementation MVPN Client Functions Software-Based Clients Hardware-Based Clients MVPN Client Design Issues Limited Platform Resources Unreliable Physical Environment Support and Distribution Security Requirements MVPN Gateways MVPN Gateway Implementation MVPN Gateways and Wireless Data Platforms General-Purpose Computing Platforms Routers and IP Switches Summary 201 202 204 205 207 209 210 211 213 217 217 218 219 220 222 223 224 225 225 227 228 229 230 233 235 235 236 236 237 238 240 240 240 242 244 245 248

xiv Contents Chapter 9 The Future of Mobile Services 249 Current Wireless Systems Industry and Evolution of 3G Systems 251 Service Aspects ^ IP-Based Mobility 255 Billing for Wireless Data Services 256 The Future of Wireless Service and Systems 258 Person-to-Person Services 259 Person-to-Machine Services 261 Machine-to-Machine Services 264 Mobile Virtual Network Operator 265 Lightweight MVNO 265 Full-Scale MVNO 266 MVPN in an MVNO Environment 266 WLAN/Cellular Convergence and MVPN 267 WLAN and Cellular Integration 268 WLAN Integration Methods 268 IMSI-Based Authentication for WLAN Integration 270 NAI-Based Authentication and Mobile IP 271 Summary 273 Appendix A Mobile IP Extensions 275 Challenge/Response Extensions 275 NAI Extension 277 Private Extensions 278 Appendix B CDMA2000 RADIUS Accounting Attributes 279 Accounting Container 280 IKE Attributes 280 Security Level, HA, Reverse Tunnel, and DiffServ Attributes 281 Appendix C RADIUS Usage in 3GPP 283 Possible Network Configurations 284 RADIUS for Authentication 285 RADIUS for Accounting 285 RADIUS for Interaction with Application Servers 286 Acronyms 291 Bibliography 309 Index 315