Network World

research center:

Security

Search / DocFinder:
Advanced search
Research Centers
Vendor Solutions
Site Resources
Special Issues

Signature SeriesEnterprise All-Stars
Enterprise All-Stars NEW

You in action
You in action

New Data Center The New Data Center: Wireless & Mobility
Wireless & Mobility NEW

The New Data Center: Server Virtualization
Server Virtualization

Diameter

An IETF peer-to-peer protocol for authenticating remote users across a network. Intended as a supplement or replacement for RADIUS, which was designed for authentication over dial-up connections.

Like RADIUS, Diameter is a "triple-A" protocol - it authenticates and authorizes users and performs basic back-end accounting services for bookkeeping purposes.

Also like RADIUS, the basic Diameter transaction involves what are called attribute value pairs (AVP). For example, an AVP might be "user ID" and "Joe Smith," or "password" and "goldfish."

Upon receiving an authentication request, a RADIUS or Diameter server typically issues the user ID attribute as a challenge, to which the requesting user system responds with the user value - the ID. Then the server issues the password attribute. If the user value response is correct, the user is considered authentic.

But the AVP exchange goes beyond simple authentication, and this is where authorization comes in. Through its other value pairs, the server can further qualify the user to determine the specific resources to which the user will be granted access. For instance, access to a high-security application might require the user to supply a private-key code.

This is possible with RADIUS but easier to implement with Diameter because Diameter lets a remote server send unsolicited messages to a client. This way, if the user sends only the password, the Diameter-equipped server sends another message, requesting the private-key code.

Perhaps the most important difference between Diameter and RADIUS involves the scope of AVP use. The RADIUS address space is limited to 256 value pairs. However, Diameter features a 32-bit AVP address space, enough for a million or more pairs. This AVP potential is what gives Diameter extensibility. The more powerful Diameter value pairs are also able to serve mobile, nondial-up users.

For instance, one Diameter value pair involves "home-agent-address" as the attribute and uses an IP address as the value. A mobile user calling from a cell phone might use this to pass through to the Diameter server of his or her home agent ISP in order to authenticate the user ID and password value pairs. This is how Diameter liberates users from the SLIP or PPP dial-up tethers.

From Diameter extends remote authentication, Network World Tech Update, 01/31/00.

Additional resources

DIAMETER
Site with the latest Diamter RFCs and drafts, along with links to relevant software.

Comments:

Radius
by Debra Cross

I found this to be a very informational site for IT consultants, help desk, enginners, and various other It specialist. I will be forwarded this to my friends

Thanks

debra



Add a comment

NOTE: Comments are reviewed by an editor before being posted.

Your rating of this resource (with 5 the best)
1 2 3 4 5

Subject:

Your user name (what other users will see on the review):

Your real name (for our records only):

Your e-mail (ditto):

Your comments (Use a blank line to separate paragraphs):

TOP STORIES OF 2009 | MOST DUGG STORIES

  1. Is this the year the proprietary CMS dies?
  2. Microsoft lowers Windows licensing costs for virtual desktops
  3. Top 12 tech knockoffs
  4. Windows XP: No IE9 for you
  5. Mobile developers take measure of Windows Phone 7
  6. Wireless router basics
  7. Comcast, ISC offer IPv6 transition tool
  8. New Cisco Ethernet switches to play a broader video, security roles
  9. Cisco defends its Borderless
  10. Doing the laptop drive of shame, Part III

Newsletters
Sign up for one of NWW's Network Security newsletters.

Security in Practice
Virus and Bug Patch Alert
Security Strategies
Security News Alert
VPNs
Messaging
View all newsletters

Email Address:

Vendor Solutions

White Papers

IDC White Paper - Reducing IT Downtime & Business Loss
- PC Mall & HP

Secure Your Wireless LAN: How to protect against security breaches
- PC Mall

Building a Successful Security Operations Center
- ArcSight

More...

Whitepaper

IDC White Paper - Reducing IT Downtime & Business Loss - PC Mall & HP
System Downtime. Network Outages. Security Breaches. Whether your company experiences a power outage, natural disaster or security threat, it is vital to keep your business applications up. Download to learn how to manage your IT risks, keep your hardware and software up and your business running.


Research Centers: Applications | Application Development | Applications-Standards | Applications Vendor Solutions | Collaboration | CRM / ERP | Databases | Directories | Grid Computing | Java | Messaging | .Net | RFID | SOAP | Web Services | XML | Convergence & VoIP | Convergence Regulatory | Convergence Services | Convergence Standards | Convergence VoIP Vendor Solutions | Video | IP PBX | SIP | VoIP | VoIP Services | E-Business | DNS | RFID | Supply Chain | Web security LANs & Routers | Acceleration | Gigabit Ethernet | Lans-Standards | Routers | Wireless LANs | Network Management | Application Management | Desktop Management | Management Test Patch Management | Operating Systems | Linux | NetWare | Unix | Windows Outsourcing | Managed Services | Offshoring Security | Firewalls - VPN - Intrusion | Identity management | Patch Management | Microsoft Security | Privacy | Security Standards | Spam & Phishing | Viruses & worms | Web Security | Wireless Security | Servers & Desktop | Backup-Recovery | DataCenter | Desktops | Desktop Management | Grid | Servers | Server Blades | Servers Desktops | Utility Computing | Small & Medium Business | Broadband | Telework | Handhelds & PDAs | Home Networking | Security | Storage | Compliance | Infiniband | Network-Attached Storage | SANs | Storage Management | Storage Virtualization | Virtualization | Vendor News | Bankruptcy | Earnings | Lawsuits | Layoffs | Standards | Start Ups | Vendor Markets | Education | Financial | Healthcare | HIPAA | Manufacturing | Retail | Wide Area Network | Broadband | Carriers | Frame Relay | Metro Ethernet | MPLS | Service providers | Wireless services | Wireless & Mobile | Wireless LANs | PDAs & handhelds | Wireless Security | Wireless Services | Wireless Standards | Wireless Switches | All Company Profiles