User's Manual
Mobile WiMAX Outdoor RAS SPI-2210 System Description/Ed.05
© SAMSUNG Electronics Co., Ltd. 4-4
4.1.2 Authentication
At the Time of Initial Access
The MS authentication procedure performed in ‘4.1.1 Initial Access’ is as follows:
Figure 4.2 Authentication Procedure (At the time of initial access)
Classification Description
(0)~(2) When the ACR receives MS_PreAttachment_Req_Ack for SBC-RSP from the
RAS, the ACR includes the EAP Request/Identity payload in the AuthRelay-EAP-
Transfer message and transmits the message to the RAS to start the EAP
authentication. The RAS relays the received EAP payload to the MS by using the
PKMv2 EAP-Transfer/PKM-RSP message.
(3)~(5) The MS sends the RAS a PKMv2 EAP-Transfer/PKM-REQ message with the
NAI included in the EAP Response/Identity. The RAS relays it to the ACR using
the AuthRelay-EAP-Transfer message. The authenticator of the ACR then
analyzes the NAI and sends the MS the Diameter DEAP Request (DER)
message (when the Diameter protocol is used) or the Access Request message
(when the RADIUS protocol is used).
(6)~(11) The subscriber authentication procedure is performed between the MS and AAA
server using the EAP-method. The authentication procedure is performed using
the Diameter EAP Request (DER)/Diameter EAP Answer (DEA) message (when
the Diameter protocol is used) or the Access-Challenge/Access-Request
message (when the RADIUS protocol is used).
(PKMv2 EAP-Transfer)
MS RAS ACR
AAA
Repeat
2) PKM-RSP
(PKMv2 EAP-Transfer)
3) PKM-REQ
8) PKM-RSP
(PKMv2 EAP-Transfer)
9) PKM-REQ
(PKMv2 EAP-Transfer)
14) PKM-RSP
(PKMv2 EAP-Transfer)
17) PKM-RSP
18) PKM-REQ
(PKMv2 SA-TEK-Request)
19) PKM-RSP
20) PKM-REQ
(PKMv2 Key Request)
21) PKM-RSP
(PKMv2 Key Reply)
(PKMv2 SA-TEK-Challenge)
(PKMv2 SA-TEK-Response)
0) MS_PreAttachment_Ack
1) AuthRelay-EAP-Transfer
4) AuthRelay-EAP-Transfer
7) AuthRelay-EAP-Transfer
10) AuthRelay-EAP-Transfer
15) Key_Change_Directive
16) Key_Change_Directive_Ack
5) Diameter: DER/RADIUS: Access Request
6) Diameter: DEA/RADIUS: Access Challenge
11
)
Diameter: DER
/
RADIUS: Access Re
q
uest
12) Diameter: DEA/RADIUS: Access Accept
13) AuthRelay-EAP-Transfer