Download as pdf or txt
Download as pdf or txt
You are on page 1of 7

Data Sheet V-6.

Empowering Networks for Business


-Next Generation Sterlite Tech AAA

Overview
A robust AAA server is a preliminary requirement to propel the growth that comes with the launch of new
services and an increasing subscriber base. Sterlite Tech AAA offers an access agnostic Carrier grade
AAA. It supports deployments from 10K concurrent sessions scalable and expandable to more than 1
million concurrent sessions. It can be deployed as a centralized AAA for multiple networks LTE, 3G,
WiMAX, GPRS, EDGE, EV-DO, CDMA2000 1x,UMTS, WiFi, Dialup / ISDN, and VoIP/ NGN, DSL, Cable,
Key Highlights FTTX or as standalone for each services. Sterlite Tech AAA centrally manages the authentication of
subscribers, devices & authorizes them for appropriate level of service and ensures reliable accounting
› Ubiquitous AAA for multiple of usage. Sterlite Tech AAA competently manages the busiest of networks, easily scales to
networks accommodate growing business needs.
› 150+ Deployments
› Support of multiple Sterlite Tech AAA is a part of Sterlite Tech CSM – Core Session Management platform that offers a
business models flexible framework to CSP's for Diameter and RADIUS stack. It offers a pre-integrated platform that
› Carrier Grade Scalability allows operators with a wider choice, greater flexibility, and facilitates tighter product integration and
and Reliability addresses a wide range of access networks. Sterlite Tech AAA is compliant to the latest 3GPP/3GPP2,
› Broad multi-vendor IPV4 & IPV6, Wi-FI, WiMAX NWG specifications with approved standards of IETF, ETSI, ANSI and other
interoperability governing communication standards.
› Configurable Service Flow
› RADIUS, Diameter & Wi-Fi Calling Multiple VoD Plans LTE WiFi Internetworking
RDBMS Server integration Shared Data Plan Bandwidth Boost Authentication of Network Components

› Built in support for RADIUS Analytics & Reports Access Method & Control Authorization Concurrency Check

& Diameter eliminates need Mobile Data offload Time based plans IPoE

for custom mediation Captive Portal Authentication Session Management Load balancer
solution Fraud Detection
› Personalized services and
Use cases
management
Next Generation - Sterlite Tech AAA

Server manager Authentication & Authorization


Analytics EMS
(GUI) EAP, PAP , CHAP MS Chapv2, LDAP, Credit based, Location

Accounting Session Manager Quota Manager CDR Management

3GPP AAA Proxy AAA Elite CG MAP GW

Configurable Service Flow | SNMP| Programmable AAA I VSA I Single SPR

RADIUS + DIAMETER STACK

COTS Virtualization layer

COTS Hardware & Storage

Gateways

BNG/BRAS PDSN LI WAG/Controller ASN

DPI HLR/HSS P-GW GGSN CMTS

Networks

Fixed Line CDMA WIFI WiMAX 2G, 3G LTE


Sterlite Tech AAA Data Sheet

Key Features Session Parameters & Profile, IPOE based on Option 82


› Transparent Authentication for all the Network Elements with
— Flexible Authentication Methods
Single AAA Instance with single SPR entry.
Sterlite Tech AAA authenticates remote usernames and
passwords against a wide range of authentication databases
— Efficient Authorization based on
(subscriber repository) to ensure compatibility with the network.
› Access Policy based on time, concurrent policy based on user
identity, policy group
› LDAP-based Authentication
› Diameter/RADIUS Policy based on any Diameter/RADIUS
Sterlite Tech AAA support authentication against subscriber
attributes such as NAS-IP, MAC, BSID, time-of-day, days-of-
credentials stored in LDAP directories, Sterlite Tech AAA can
weeks
integrate with multiple LDAP servers to support load balancing
› Check Item based on any Diameter/RADIUS attribute such as
and failover scenarios.
NAS-IP-Address, BSID, MAC or combination of them
› Calling-station-ID based checking where user can be restricted
› RDBMS-based Authentication
to specific list of MAC-addresses
Sterlite Tech AAA supports authentication against credentials
stored in SQL databases from Oracle and any rich set of Java
— Real time Accounting
Database Connectivity (JDBC) or ODBC 2.0-compliant
databases (Oracle, MySQL, and , PostgreSQL, MS-SQL Sterlite Tech AAA offers a scalable carrier-grade platform to
Server). handle thousands of accounting requests per second in realtime,
on suitable hardware, and caters to the busiest of networks. It's
- Sterlite Tech AAA authenticates users based on the type of
highly reliable accounting capabilities, eliminates duplicate
service
usage records ensures delivery of all accounting data to your
- Authentication based on a group of customers
billing systems.
- The subscribers can also be authenticated based on their
access source like DHCP Option-82 parameters
› Export CDRs
Sterlite Tech AAA can seamlessly integrate with the accounting
› HSS/ HLR Based Authentication
and billing systems. RADIUS accounting log files can be
Sterlite Tech AAA enables Diameter Communication with HSS
exported in spreadsheets, xml, pdf and database formats using
(Home Subscriber Server). HSS and HLR Authentication
the reports Tool
supported over 3GPP SWx and Gr'/ D' interface respectively.

› Header Support in Accounting Request Packets and CSV File


› Credit-based Authentication
Sterlite Tech AAA provides an option of including the header
Sterlite Tech AAA can authenticate subscribers based on their
packet with all standard attributes and required vendor-specific
Credit Limit using the Credit Limit attribute in LDAP or the
attributes in the accounting request packet and CSV files. It also
database. The authentication will succeed only if the subscriber
provides a configurable option to choose specific attributes to
has credit balance.
be written in the CSV file and delimiter for the attributes. CSV
creation is very flexible in terms of managing order of attribute
› PAP /CHAP Support and naming convention of CSV files.
Sterlite Tech AAA supports PAP / CHAP protocols for
authentication through LDAP, database and users file. On › Forward Accounting Data to Database, and CSV file
enabling CHAP support, Sterlite Tech AAA encrypts the plain
Sterlite Tech AAA provides support for multiple storage types
text password stored in LDAP, the database or the users file. It
such as database and csv file. It stores all accounting requests
compares it with the encrypted password received in the
in all configured storages. The accounting data stored in these
RADIUS packet.
can be pulled into a central billing system for charging
customers based on their usage.
› EAP Authentication
Sterlite Tech AAA supports RADIUS and Diameter Multi- › Rollover capabilities for CDRs
Extensible authentication protocol (EAP) and attribute
Sterlite Tech AAA offers extensive support of file rolling based
definitions with support for vendor specific attributes in
on combination of size & time based file rolling or combination of
authentication packet. It support following EAP methods - EAP-
size & no. of records based or time based rolling greatly helps
TLS , EAP-TTLS , EAP-TTLS with MS-CHAP, PAP & MSCHAP V2
manageability of CDRs.
,EAP AKA ,EAP SIM, , EAP-AKA', EAP-PEAP.

— Policy Management
› Authentication based on parameters
Policies can be defined at the driver level, system level, rate plan
MSISDN, IMSI, Username / Password, APN, MAC, Location,
level, and the account level for authenticating and authorizing
users. For this Sterlite Tech AAA supports:
Sterlite Tech AAA Data Sheet

configurable options for including header information in the CSV


› Check, Reject, and Reply Items for authentication file. The CSV format allows to store both standard and vendor-
RADIUS Policies can be configured with check, reject and reply specific attributes. CSV files can be classified based on the NAS-
items for authenticating users based on RADIUS standard or IP-address. CSV files are rotated on a daily basis . Eliminates the
vendor specific attributes. Checks can be implemented on the need for custom mediation solutions
origination of the authentication request, called station ID,
calling station ID and type of service. Necessary responses can Sterlite Tech AAA supports RADIUS & Diameter in the same
be given using reply items and requests can be turned down instance so there is no need of any custom mediation for protocol
using reject items in the RADIUS Policy. conversion.

› Multiple Checks, Reject, and Reply Items for Authentication › Active Mediation
Sterlite Tech AAA can check for a single standard or vendor Sterlite Tech AAA supports Parlay, EJB and RADIUS Protocol.
specific attribute multiple times. This facilitates a check on an Sterlite Tech AAA can integrate with 3rd Party Rating and PPS
attribute for a list of values. The check will be made for all the (Prepaid Server) for Real time credit control and real time
values for the specified check item. Befitting responses can be accounting through Rating API.
given based on reject and reply items in the RADIUS Policy.
— Charging gateway
› Precedence Order and Logic Sterlite Tech AAA charging gateway integrates to operator OCS or
Multiple RADIUS Policies can be configured for a single Billing system over diameter or over JAVA RMI for real time
customer. There is a possibility here that there are multiple prepaid services.
check items created on the same attribute. The same applies to
reject and reply items. Sterlite Tech AAA has an inbuilt › Protocol conversions supported
precedence order and logic for handling such situations.
DIAMETER, JAVA API , HTTP/SOAP

— Static and Dynamic IP Pool Management — Hot-lining Support


Sterlite Tech AAA provides IP pool management to maintain a list
Supports redirecting users with no balance in their account or for
of used and free IP addresses. An IP pool can be bound with a
upgrading their balance. It helps prevent excessive- & fraudulent
network Access Server (NAS) and at Subscriber level. IP
service usage. A subscriber can be redirected at the start of the
Assignment can be configured based on group, realm, profile &
session or in mid session. Sterlite Tech AAA supports user profile
NAS. IP addresses are allocated to the end-user from selected
based hot lining, Rule based hot lining, mid session hot lining or
pool. Dynamic IP Address will be reserved/freed based on the
new session hot lining.
network attachment and detachment of subscriber.

— Multiple Protocol Support


— Advanced Proxy Capabilities
› RADIUS, Diameter, SIP, Parlay, Java, CORBA, SOAP/HTTP,
Proxy forwarding based on realm, ANI(Automatic number
XML, LDAP, Telnet
identification) , DNIS (Dialed Number Identification Service) and
› PAP,CHAP, MS-CHAPv2, EAP, MIP, MIPv6
NAS-IP-Address support. Sterlite Tech AAA provides an option to
› UAM, PPPoE, EJB, SNMP & TCP/IP, IPv6, GTPP
forward request to another AAA server based on any RADIUS
attribute. It also allows to select the matching pattern for the
— Carrier Grade Reliability
attribute. Strip Support including prepend/append & regex, with
choice of removing the realm pattern from a username with Sterlite Sterlite Tech AAA allows Operators to meet stringent uptime
Tech AAA. It also allows to configure whether to forward the requirements with reliable state-of-the-art features. These include
request to another AAA server or to authenticate locally after but are not restricted to the following features:
removing the username. Elite AAA supports broadcasting the
Authentication and Accounting request to multiple AAA Servers. › Failover Support
Sterlite Tech AAA supports Intelligent Load balancing & failover
Sterlite Tech AAA also supports Enhanced Proxy Communication with various aliveness checking. It enables configure LDAP and
for Sequential Proxy communication and co-relation with external proxy servers to keep your services up and running even in
systems, with adherence to RFC for proxy chaining and policy cases where a server fails or suffers a bottleneck. The requests
implementation in roaming. are diverted to an alternate server which handles the requests
until the failed server is up again. Timeout and number of
— Mediation request to determine a failure are also configurable.
The mediation features of Sterlite Tech AAA enables export CDRs
stored in proxy and main AAA server's local database, CSV file, › Connection Pooling
from where it can be fetched by the rating engine. It provides Sterlite Tech AAA supports cluster and connection pooling to
Sterlite Tech AAA Data Sheet

ensure that a connection is readily available when one is — Monitoring & Maintenance
needed. Instead of keeping a request on hold until it creates a › Sterlite Tech AAA supports SNMP. It provides with real time logs
connection on demand, it fetches an unused connection from & reports and real time stats through SNMP. It also offers
the pool, thus ensuring speedy processing. protection from SNMP trap flood. Operator team can view
system KPI from dashboard. It also supports HTTP Adapter in
› Virtualization Sterlite Tech AAA for KPIs all the MIBs are accessible through
- Supports OS Virtualization and multi-core architecture, where Web browser and JMX client like jconsole or NMS Systems.
multiple instances can run on same server
- Virtualization support with deployable in-premise and on › Dashboard Monitoring
cloud - TPS, Memory usage of system
- Authentication & accounting packets processed
› Supported Hypervisors - Authentication response messages
- RHEV, Hyper-V, CITRIX, Xen, VMWare, ESXi, KVM, Openstack - TRAP listener (errors on dashboard)
with KVM, Amazon AWS, Microsoft Azure - RADIUS client wise messages processed
• Graphical format
› Reliability to support rapid business expansion. With 99.999% • Numeric (No. of Requests / Responses)
availability. - Data source / drivers availability
• Status of each datasource available on GUI
— Subscriber Management - Dashboard personalization / ACL System
Centralized customer profile - Management of prepaid and
postpaid subscribers within common infrastructure. Subscriber — Secure Wired 802.1x Network Access
Profile information like QoS policy, static IP address, dynamic Sterlite Tech AAA provides network access to authorized users
p olicy checks, a uthorization configurations etc. can be authenticated against the designated database, when they are
configured with subscriber data. This subscriber information can connecting via wired 802.1X.
be updated by BSS systems using HTTP SOAP and/or HTTP
RESTful APIs.
Authentication in this case is based on user identity rather than on
the ethernet port to which they're plugged. It passes the required
— Server Manager information to the switch allowing it to dynamically configure the
Sterlite Tech CSM s erver m anager offers a centralized port's behaviour based on the user's authorization information.
configuratable GUI used to manage multiple Sterlite Tech AAA, The EAP-MD5 protocol it uses, beefs up credential security,
Sterlite Tech CG, Sterlite Tech DSC systems from centralized ensuring that users' login credentials are not stolen; mutual
location. authentication of client and server takes place, to prevent a user
Sterlite Tech AAA's Server manager helps from being duped into connecting to a rogue network; and ensures
› Centrally Manage Multiple Sterlite Tech AAA server instances data privacy. Sterlite Tech AAA supports secure access over
and multiple authentication, accounting and SNMP service HTTPS with X.509 certificate via SSL. Supports encryption and
instances through server manager GUI. key rotation based on IEEE 802.1x and Wi-Fi protected access
- Export/Import all Server Instances configuration. (WPA/WPA2)

- Roll Log based on Time & Volume.


— Access Policy, Group policy and Concurrent policy support
- Reload the Cache Configuration without stopping the server
With configurable concurrent sessions for each user. Different
—
rights & policies can be grouped in a number of ways to form
Resource Manager & Session Manager
different access groups
› Sterlite Tech AAA resource manager helps , centrally manage
› Enables operator to perform following actions
multiple resource manager server instances and IP pool
management services through server manager GUI - Creating access groups to grant access to modules

› Resource manager is used for protocol conversion from - Creating staff members to operate server manager
RADIUS to Diameter, RADIUS to JAVA-JMI - Staff management
› View, disconnect, purge and download active sessions details
through session manager. Search active session based on — Vo WiFi
several parameters like username, NAS IP address, group Sterlite Tech AAA 6.8 now supports VoWIFI business case with
name and idle time. release of Diameter 3GPP Service Policy support; it will enable the
› It supports SNMP counters &aAlerts for operators with below use case
- IP pool management
- RM charging services – counters available for charging › EAP-SIM, EAP-AKA and EAP-AKA' over 3GPP enabled SWm
service › Devices that do not support the EAP-SIM/AKA method
› Intelligent support for both HLR and HSS based hybrid networks
Sterlite Tech AAA Data Sheet

› Policy based information fetching and decision making from there by greatly reducing chances for errors and time for
existing PCRF configuration.
› Complete control for configuring a 3GPP business flow
› Multiple service handlers to customize service policy for business › Configurable Service Flow
requirement Sterlite Tech AAA also offers configurable service flow, it allows
operator to define the service flow from a single view through
— Enhanced Transaction Logging Architecture easy drag and drop handlers. Single Service Handlers can be
Sterlite Tech AAA offers enhanced transaction logger for RADIUS added multiple times to achieve Call Flow Requirement.
and Diameter packets with a simplified single line summary about
request and response processed by server. Scenarios of failure Sterlite Tech AAA now has support for both Diameter and
can now be understood with request & response logging reducing RADIUS support in the service flow handlers as mentioned
the time to solution for the problem. It also comes with highly below. The handler based architecture enables operational
customized logging architecture based on business requirement team to define the business service flow as required from a
with Multiple plugin configuration possibility for dynamic logging, single GUI.
Different logging format for different call flow design and separate › Authentication Service Handler
logging files for different service flows. › Diameter Proxy Handler
› Diameter Broadcast Handler
— System wide global Plug-In configuration support in AAA › CDR Handler
With Sterlite Tech AAA the plug-in configuration has been › Authorization Handler
centralized with global plug-in management this will enable with › Plugin Handler
the following:
› Profile Lookup Handler
› Diameter/RADIUS Broadcast Handler
› Single plug-in for multiple service moved to Global Configuration
from AAA Instance Level
› Advanced Translation Mapping
› Multiple universal plug-in managers for RADIUS and Diameter
Dynamic Mapping of Attributes from one to another with the
› Reusability of plug-in to multiple AAA instances
possibility to change the protocols either from RADIUS to
› Multiple plug-in configuration – to avoid lengthy configurations in Diameter, Diameter to Diameter, RADIUS to RADIUS, RADIUS to
single plugin WebService with an extensive use of Java Expression Libraries.
› Reduce configuration error and time

› Dashboard view of system performance


— GUI access for Custom Business logic via scripting Operator team can see the system performance from the same
Sterlite Tech AAA now comes with GUI for groovy plugins to easily GUI.
create, modify and support custom business logic or dynamic
business change into the network directly from the GUI. With — Smart Over load Protection with Priority Queue
newly developed GUI it would reduce time to market through ease
To ensure a consistent user experience operators need to ensure
of management, reuse of the groovy plugin from the centralised
to manage effectively the network fluctuations caused in the
GUI.
network, Sterlite Tech AAA offers multi levels of threshold
protection to handle TPS spikes in the network gracefully, which
— Operating System Support improve the service availability for the connected sessions and
Sterlite Tech AAA supports following Operating System. revenue assurance for the operators.
› Linux Red Hat
› Sun Solaris — Programmable Sterlite Tech AAA
To deal with unanticipated requirements of security and
— Key Deployment Features interworking, Sterlite Tech AAA is engineered with an advanced
› Deployment Architecture 1 + 1, N+1 Active-Active or Active scripting capability to customize special policy needs and solve
Stand by mode interoperability challenges, enabling network operators to
› Geographical cluster separation Active-Active program and automate policy-based configuration changes with
plug-in script support. Sterlite Tech AAA has specific built in
adaptor hooks which enable service providers with agile product
Why Sterlite Tech AAA based development, specific on site customization and flexibility
— Highly Flexible and Configurable system to configure in translating protocols for creating new services. This
feature is upgrade compatible, flexible, can easily drive custom
Sterlite Tech AAA is designed keeping the dynamic requirement of
logic and enables faster time to market
Operators, it offers great flexibility in configuration

— Broad Multi-vendor Support & Integration


› Single screen for defining Authentication and Accounting policy
Sterlite Tech AAA Data Sheet

Sterlite Tech AAA ably fits into any network environment and works › Wi-Fi Calling (VoWi-Fi)
with the widest variety of network access equipment. The broad › Mobile Data Offload
multi-vendor support it provides allows easy integration of legacy › Shared Device plans
systems with new systems.
› IPoE based Authentication
› It supports most of the back-end authentication databases, and
› Volume on demand
is compatible with the latest authentication, provisioning, and
› Session Management
billing systems.
› Anti Fraud & Secure Access
› Sterlite Tech AAA easily interoperates with other AAA servers,
ensuring smooth communication with other service providers › QOS based Authorization
and enterprise customers. › Access Method Authorization
› Seamless interaction with multiple external AAA servers and › Access Control Authorization
roaming partners. › Monetary and Quota Re Authorization
› Standard based charging gateway, prepaid adapter modules to › Location Services
address prepaid charging. › Block Sites
› Pre-integrated SS7/Sigtran stack supporting MAP gateway › Restriction of User Login Based on MAC-Address (Calling-
allows integration with mobile network elements such as the Station-ID)
HLR.
› Restriction of User Login Based on BS-ID (Base Station)
› Support for 3GPP and non-3GPP interworking.
› Restriction of User Login Based on Time
› Supports simple IP (SIPv4) & Mobile IP (MIPv4), PMIPv4,
› Authentication & Redirection Policy for Factory Default User
CMIPv4, IPv4.
› DIAMETER Re-Authentication
› Seamless integration with BREW Gateway, WAP Gateway, IN
› Concurrent User Session Control
Platform, third party PPS and PDSN, ASN Gateway, GGSN/SGS/
wih multiple PDP Contexts & VPN and VPDN Support. › Multiple REALM Support
› Real-time session management to enable mobility, roaming, › Auto Session Closure for Stale Sessions
security, and usage tracking and r eal- t ime session › Redirection upon FUP
disconnection based on re-authorization functionality. › Midnight Bandwidth Boost Service
› Diameter based Wi-Fi Use Cases
— Multi Network Support › Authentication of Network Components
Sterlite Tech AAA supports multiple networks such as LTE, 3G, › Device based Policy
WiMAX/NWG, GPRS, EDGE, EV-DO, CDMA2000 1x,UMTS, WiFi, › Peak off Peak Plans
Dialup/ ISDN,VoIP/ NGN, DSL, Cable & FTTH.

— Performance
Compliance to Standards
Sterlite Tech AAA can be deployed on platform supporting JDK
1.6 version or above, it supports 1500 TPS on 8 Core CPU x 2 of › 3GPP , 3GPP2
2.4 Ghz & 64GB RAM. › IETF Enriched AAA RFC Compliance
› Femto AAA
— Use Cases supported › WiMAX NWG 1.3 & 1.5 Compliant
› Time of Day or Day of week Authorization › WiSpr 2.0
› LTE- Wi-Fi interworking › ETSI TISPAN

Sterlite Tech CSM Platform Products Include

AAA PCRF DSC CG


Sterlite Tech AAA Data Sheet

About Sterlite Technologies:


Sterlite Technologies Ltd [BSE: 532374, NSE: STRTECH], is a global technology leader in smarter digital
infrastructure. With a pure-play telecom focused business that develops & delivers optical communication
products, network & system integration services and OSS/BSS software solutions, Sterlite Tech has sales
network in six continents. The Company has manufacturing presence in India, China & Brazil, and aims to
transform everyday living by delivering smarter networks. With a strong portfolio of over 130 patents, Sterlite Tech
is home to India's only Centre of Excellence for broadband research. Projects undertaken by the company include
intrusion-proof smarter data network for the Armed Forces, rural broadband for BharatNet, Smart Cities'
development, and establishing high-speed Fibre-to-the-Home (FTTH) networks.

Office

STCC17/DS-AAA/0305
Sterlite Technologies Limited
Block 6, Magnet Corporate Park,
Nr. Sola Flyover, Thaltej, Ahmedabad - 380059 INDIA
Phone: +91 - 79 - 66065606 Fax: +91 - 79 - 26407640

Sales & Marketing


Mumbai Tel : + 91 - 22 - 61435100 Fax : + 91 - 22 - 61435151
Delhi Tel : + 91 - 11 - 47540400 Fax : + 91 - 11 - 41589760
Pune Tel : + 91 - 20 - 67083000
Dubai Tel : + 971 - 4 - 204 5391/5390/5392
Mauritius Tel : + 230 9481739

For queries or demo email us : sales@sterlite.com

www.sterlitetech.com

© Copyright 2017 Sterlite Technologies Ltd. All Rights Reserved.

You might also like