| Based on In proxy mobile IPv6environment and authentication, authorization, Accounting (AAA) platform, We use the network access authentication protocol (Protocol for carrying Authentication for Network Access, PANA) and EAP-PSK authentication algorithm to design and realize the system of authentication and authorization in PMIPv6environment.At first, the paper discusses the background and current situation of the Diameter protocol, proxy mobile IPv6and various access authentication technology.Secondly, the paper describes the idea of RFC5779. Based on RFC5779, the paper is mainly carried out from the two parts of the mobile node access authentication and service authorization. Then the paper describes the PMIPv6protocol, the principle of AAA, and a variety of access authentication technology. Because this paper uses PANA protocol, the PANA protocol is introduced in detail.Thirdly, the paper presents the design of the system of authentication and authorization in PMIPv6environment. Based on RFC5779, the paper put forward two subsystems of authentication and authorization, introducing the system model, information flow, and specific message format and communication module.Fourthly, the paper presents the implementation of the system of authentication and authorization in PMIPv6environment based on the design. The authentication subsystem is implemented based on PANA protocol and Diameter protocol. The authorization subsystem is implemented based on PMIPv6protocol and Diameter protocol. The paper expounds the realization of each module principle and process. Software is implemented in the kernel system of Linux-2.6.29.5.At last, the test environment is set up for this software. The test focuses on testing EAP-PSK algorithm authentication of authentication subsystem and the implementation of authorization subsystem in the prototype system. The analysis of test’s results is also presented.This paper is supported by major national science and technology programs " new generation broadband wireless mobile communication network"--mobile Internet network and information security technology research. |