Asian Journal of Information Technology

Year: 2007
Volume: 6
Issue: 1
Page No. 47 - 53

Design and Implementation of an AAA-Enabled Access Management System for Wireless Networks

Authors : Fu-Min Chang , Chih-Mou Shih and Shang-Juh Kao

Abstract: In the current wireless network environment, Remote Access Dial-In User Service (RADIUS) protocol was mainly adopted to provide the services of Authentication, Authorization and Accounting (AAA), which was proposed by IETF. With this protocol support, a secure environment for wireless users is provided while the usage of network resources can also be monitored and managed by system administrator. However, not all wireless access points support the RADIUS protocol, which causes the difficulty of building a universal wireless security environment. Furthermore, the accounting policy of RADIUS protocol takes into account the idle time of a wireless user whenever he is in the connection state, which is obviously unfair to the user. To overcome these deficiencies, in this study, we propose a wireless network access management system which directs the processes of authentication, authorization and accounting to back-end servers. In the system, by employing the approach similar to the webpage authentication, the wireless access point is not necessary in verification of legal access but simply transfers the messages to the back-end authorization and authentication server. Consequently, the AAA features are satisfyingly accomplished with a better accounting strategy. Specifically, the NetFlow protocol is applied to collect the wireless network usage for each user. Based on the collection, the time or the traffic each user actually utilizes is accounted for. Four accounting alternatives, which are time-prepaid, flow-prepaid, time-postpaid and flow-postpaid, are proposed and demonstrated.

