<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.calhoun-diameter-strong-crypto" target="https://datatracker.ietf.org/doc/html/draft-calhoun-diameter-strong-crypto-07">
   <front>
      <title>DIAMETER Strong Security Extension</title>
      <author initials="P. R." surname="Calhoun" fullname="Pat R. Calhoun">
         <organization>Sun Microsystems</organization>
      </author>
      <author initials="W." surname="Bulley" fullname="William Bulley">
         <organization>Merit Network</organization>
      </author>
      <author initials="S." surname="Farrell" fullname="Stephen Farrell">
         <organization>Baltimore Technologies</organization>
      </author>
      <date month="March" day="6" year="2001" />
      <abstract>
	 <t>The DIAMETER base protocol defines message integrity and AVP
encryption using symmetric transforms to secure the communication
between two DIAMETER nodes. The base protocol also defines a DIAMETER
proxy server, that forwards requests to other servers when it detects
that a given request cannot be satisfied locally.
The ROAMOPS Working Group has defined a requirement that allows for
the DIAMETER servers communicating through the proxy to be able to
provide for end-to-end AVP integrity and confidentiality, making it
difficult for the proxy to be able to modify, and/or be able to view
sensitive information, within the message. The Mobile-IP and NASREQ
Working Groups have stated that strong authentication is a
requirement for AAA data, such as accounting records, for the
purposes of non-repudiation.
This DIAMETER extension specifies how strong AVP authentication,
integrity and encryption can be done using asymmetric transforms, by
encapsulating Cryptographic Message Syntax (CMS) data into DIAMETER
AVPs. The CMS data can also be used to carry X.509 certificates.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-calhoun-diameter-strong-crypto-07" />
   
</reference>
