An Experimental Study of a Business Domain Independent Application Level and Internet Access Authentication and Authorization Concept

  • Authors:
  • Rainer Huber;Norbert Jordan

  • Affiliations:
  • Vienna University of Technology;Vienna University of Technology

  • Venue:
  • ICMB '05 Proceedings of the International Conference on Mobile Business
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

The movement of many business domains towards offering services via the Internet demands for convergent and extensible AAA (Authentication, Authorization and Accounting) concepts. This paper introduces a convergent access and application level AAA framework that ports the concepts of IEEE 802.1x and EAP to the application layer and utilizes SOAP as the transport medium for EAP messages. The requirements for the mobile network operator domain have been analyzed and as a prove of concept, an Internet shop application has also been implemented. It supports secure payment via EAP-SIM by utilizing the developed AAA framework. In addition, the integration into an IEEE 802.11i reference environment is described and EAP-SIM AAA characteristics on the WLAN access level have been investigated.