OpenFlow-based authorization mechanism for Wi-Fi roaming systems



Similar documents
eduroam in Asian countries - - benefits, and 4ps for opera4on - -

Software-Defined Networking for Wi-Fi White Paper

Software Defined Networking Seminar

Secure WiFi Access in Schools and Educational Institutions. WPA2 / 802.1X and Captive Portal based Access Security

Developing Network Security Strategies

IdentiFi and Eduroam Roaming Wireless Service Integration CONFIGURATION GUIDE

Belnet Networking Conference 2013

Design and Implementation Guide. Apple iphone Compatibility

Spotlight On Backbone Technologies

Penn State Wireless 2.0 and Related Services for Network Administrators

Chandelle: Principles of integration wireless controller and SDN controller. Sergey Monin, Alexander Shalimov, Ruslan Smeliansky

Wireless Technology Seminar

Deploying secure wireless network services The Avaya Identity Engines portfolio offers flexible, auditable management for secure wireless networks.

Trusting SDN. Brett Sovereign Trusted Systems Research National Security Agency 28 October, 2015

COMPSCI 314: SDN: Software Defined Networking

Fundamentals of Windows Server 2008 Network and Applications Infrastructure

Evolving Network Security with the Alcatel-Lucent Access Guardian

Software Defined Networking

Open Source Network: Software-Defined Networking (SDN) and OpenFlow

Software-Defined Networking for the Data Center. Dr. Peer Hasselmeyer NEC Laboratories Europe

Network Virtualization for Large-Scale Data Centers

VLANs. Application Note

APPENDIX 3 LOT 3: WIRELESS NETWORK

NXC5500/2500. Application Note. Captive Portal with QR Code. Version 4.20 Edition 2, 02/2015. Copyright 2015 ZyXEL Communications Corporation

RADIUS and WLAN Infrastructure Monitoring

Deploying Cisco Basic Wireless LANs WDBWL v1.1; 3 days, Instructor-led

SDN for Wi-Fi OpenFlow-enabling the wireless LAN can bring new levels of agility

Enabling Multiple Wireless Networks on RV320 VPN Router, WAP321 Wireless-N Access Point, and Sx300 Series Switches

A Presentation at DGI 2014 Government Cloud Computing and Data Center Conference & Expo, Washington, DC. September 18, 2014.

UTM10 in multi-ssid, multi-vlan network with WMS5316. Network diagram

WLAN Information Security Best Practice Document

Case Study - Configuration between NXC2500 and LDAP Server

eduroam(radius based Federation)

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

SDN and OpenFlow. Naresh Thukkani (ONF T&I Contributor) Technical Leader, Criterion Networks

Release: 1. ICANWK607A Design and implement wireless network security

Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure

The Ultimate WLAN Management and Security Solution for Large and Distributed Deployments

IPOP-TinCan: User-defined IP-over-P2P Virtual Private Networks

Securing Local Area Network with OpenFlow

Table of Contents. Cisco Wi Fi Protected Access 2 (WPA 2) Configuration Example

White Paper. SDN 101: An Introduction to Software Defined Networking. citrix.com

Course Content for Managing Cisco Wireless LANs (WMNGI 1.2) Duration : 4 Days

Using Cisco UC320W with Windows Small Business Server

Increasing robustness of Software-Defined Networks

Ten Things to Look for in an SDN Controller

LTE, WLAN, BLUETOOTHB

When SDN meets Mobility

Towards Software Defined Cellular Networks

CSCI-1680 So ware-defined Networking

1 Purpose Scope Roles and Responsibilities Physical & Environmental Security Access Control to the Network...

Routing Security Server failure detection and recovery Protocol support Redundancy

Microsoft Windows Server System White Paper

WiNG5 DESIGN GUIDE By Sriram Venkiteswaran. WiNG5 Wireless Association Filters. How To Guide

SSVVP SIP School VVoIP Professional Certification

RAD-Series RADIUS Server Version 7.1

BlackBerry Enterprise Server Version: 5.0. Upgrade Planning Guide

Industrial Network Security for SCADA, Automation, Process Control and PLC Systems. Contents. 1 An Introduction to Industrial Network Security 1

Boosting Business Agility through Software-defined Networking

How To Make A Vpc More Secure With A Cloud Network Overlay (Network) On A Vlan) On An Openstack Vlan On A Server On A Network On A 2D (Vlan) (Vpn) On Your Vlan

Cloud Networking Disruption with Software Defined Network Virtualization. Ali Khayam

OpenFlow: Concept and Practice. Dukhyun Chang

Simplify IT. With Cisco Application Centric Infrastructure. Roberto Barrera VERSION May, 2015

EAP-SIM Authentication using Interlink Networks RAD-Series RADIUS Server

Software Defined Network Application in Hospital

How To Pass The Information And Network Security Certificate

Disaster-Resilient Backbone and Access Networks

Agenda What can we do now? And 5 years from now we will still be current!

Top-Down Network Design

Software Defined Networking (SDN)

How To Manage A Network From A Microsoft Lab

Networking Basics for Automation Engineers

Deploying the ShoreTel IP Telephony Solution with a Meru Networks Wireless LAN

NOS for Network Support (903)

Defining SDN. Overview of SDN Terminology & Concepts. Presented by: Shangxin Du, Cisco TAC Panelist: Pix Xu Jan 2014

Intelligent WLAN Controller with Advanced Functions

A Look at the New Converged Data Center

How To Understand The Power Of The Internet

Windows Server 2012 Hyper-V Virtual Switch Extension Software UNIVERGE PF1000 Overview. IT Network Global Solutions Division UNIVERGE Support Center

Software Defined Networks

software networking Jithesh TJ, Santhosh Karipur QuEST Global

HP and IPv6 Deployment. Bill Medlin HP-UX IPv6 Project Manager

SDN/Virtualization and Cloud Computing

VLAN 802.1Q. 1. VLAN Overview. 1. VLAN Overview. 2. VLAN Trunk. 3. Why use VLANs? 4. LAN to LAN communication. 5. Management port

EE4367 Telecom. Switching & Transmission. Prof. Murat Torlak

Chapter 12 Homework CIT J001/02/04/06. Name: Date: Course: Test:

Is Your Network Ready for the ipad?

SDN CONTROLLER. Emil Gągała. PLNOG, , Kraków

AC1200 Multi-Function Concurrent Dual-Band Gigabit Wi-Fi Router

What is OpenFlow? What does OFELIA? An Introduction to OpenFlow and what OFELIA has to do with it

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview

Transcription:

29th TF-MNM Meeting Nov. 22, 2012, Belgrade, Serbia OpenFlow-based authorization mechanism for Wi-Fi roaming systems Hideaki Goto NII / Tohoku University, Japan 1

contents Policy-based authorization for WLAN roaming systems What s OpenFlow Network? OpenFlow-based authorization and access control mechanism for eduroam 2

A challenge in Wireless LAN roaming Basic access policy in eduroam User-type SP s local Internet resources Home users Allowed Allowed Guest users Forbidden Allowed More flexible access control using users attributes Allows the access to local resources Forbids the access to some Internet sites upon request Guest user Guest user Access Allowed Access Forbidden SP SP SP s local resources SP s local resources 3

Access controls using users attributes Background Demands for network access control based on the user s attributes such as affiliation, role, grade. Needs to allow the guests to gain access to the local resources such as printers and file servers in lectures, meetings, etc. Needs to derive Access Control Rules by combining the Policies of both home and visited institutions. We would like to build a simple yet powerful system based on the standard technologies. 4

Policy-based authorization for WLAN roaming Policy example at the home institution No access control except logging at Firewall for local staff/students. Students should not be allowed to use some notorious (troublesome) websites. (as a request to the visited institutions) Allows the professors to use local resources freely at the visited institutions. (as a request to the visited institutions) 5

Policy-based authorization for WLAN roaming Policy example at the visited institution For visitor students, block the accesses to some troublesome websites. Guests basically cannot use the local resources, while guest professors are allowed to use them. At a conference, for example, the secretariat can allow the participants to use the local resources onsite. 6

What s OpenFlow Network? OpenFlow Network consists of some OpenFlow Switches (OFSs) and one (or more) OpenFlow Controller (OFC) Packet flows are controlled by the flow information (L1-L4 header contents) 3. Indicate the process 4. Save the process to OFC 2. Inquire the process for the packet flow OFS OFS 1. Receive a packet 5. Forward packets accept or drop?, nexthop, etc. 7

Advantages of OpenFlow Network Conventional system: Highly dependent on network hardware topology Configuration is required on every network device (high maintenance labor/cost) #VLANs is limited up to 4,096 with IEEE802.1q OpenFlow Network: SDN: Software-Defined Network Dynamically configurable routing, access controls, etc. Simple hardware configuration on a centralized controller Quite simple configuration on switches Inter-operable across different vendors Scalable dynamic VLAN 8

Access Control mechanism using OpenFlow Policy DB is connected to the IdP at the home institution. The policy and the attributes are sent to the SP over RADIUS protocol. Switch control rules are derived from the IdP/SP policies, and the access control is performed. OpenFlow Controller NW printer file server [access privilege] [Calling-Station-ID] setting OpenFlow Switches SP-side AP Access-Control function RADIUS server A Roaming user [User-category] [Access-policy] RADIUS proxies [realm] [Calling-Station-ID] Policy DB RADIUS server B IdP-side 9

Technical details T. Watanabe, S. Kinoshita, J. Yamato, H. Goto, and H. Sone, Flexible Access Control Framework Considering IdP-side s Authorization Policy in Roaming Environment, COMPSAC2012 Workshop MidArch2012, pp.76-81, 2012. S. Kinoshita, T. Watanabe, J. Yamato, H. Goto, and H. Sone, Implementation and Evaluation of an OpenFlowbased Access Control System for Wireless LAN Roaming, COMPSAC2012 Workshop MidArch2012, pp.82-87, 2012. 10

What do we need? Well-defined, common attribute representations. Standardization of popular Access Control rules. Inter-operability with backward compatible RADIUS packet definition. Middleware (Open Source) 11