Tech-invite3GPPspaceIETFspace
21222324252627282931323334353637384‑5x
Top   in Index   Prev   Next

TR 33.980
Interworking of
Liberty Alliance Identity Federation Framework (ID-FF),
Identity Web Services Framework (ID-WSF) and GAA

V19.0.0 (PDF)  2025/09  42 p.
V18.0.0  2024/03  42 p.
V17.0.0  2022/03  42 p.
V16.0.0  2020/06  42 p.
V15.0.0  2018/06  41 p.
V14.0.0  2017/03  42 p.
V13.0.0  2016/01  42 p.
V12.0.0  2014/10  42 p.
V11.1.0  2013/12  42 p.
V10.0.0  2011/04  42 p.
V9.0.0  2009/12  41 p.
V8.0.0  2008/12  40 p.
V7.6.0  2007/09  40 p.
Rapporteur:
Dr. Holtmanns, Silke
Nokia Networks Oy

full Table of Contents for  TR 33.980  Word version:  19.0.0

each clause number in 'red' refers to the equivalent title in the Partial Content
Here   Top
0Introduction  p. 5
1Scope  p. 6
2References  p. 6
3Definitions, symbols and abbreviations  p. 7
3.1Definitions  p. 7
3.2Abbreviations  p. 8
4Interworking of Liberty Alliance ID-FF/ ID-WSF and Generic Authentication Architecture  p. 9
4.1Introduction  p. 9
4.2Architectural Description - Use of GBA within ID-FF / ID-WSF  p. 9
4.2.1Architecture for collocation of NAF with Liberty Alliance Authentication Function  p. 12
4.2.1.1Collocation of IdP/NAF in Liberty Alliance ID-FF (alternatively SAML v2.0)  p. 12
4.2.1.2Collocation of AS/NAF in Liberty Alliance ID-WSF  p. 13
4.2.2Architecture for collocation of BSF with Liberty Alliance authentication function  p. 15
4.2.2aLogical data model of the Liberty Alliance Authentication Function (IdP/AS)  p. 16
4.2.3User Registration to Interworking Service  p. 16
4.2.3.1Registration with Operator  p. 17
4.2.3.2Registration with IdP  p. 17
4.2.4Provisioning of User Data for Interworking Service  p. 17
4.2.4.1Service based on standard user data  p. 18
4.2.4.2Service based on pre-provisioned interworking data  p. 18
4.2.4.3Service based on explicitly added interworking data  p. 18
4.3Co-hosting of NAF and IdP  p. 18
4.3.1Federation Concept in GBA  p. 19
4.3.2Session Concept at IdP  p. 19
4.3.2aSingle-Logout Concept  p. 20
4.3.3SSO scenario: ID-FF with <lib:AuthnResponse> transfer  p. 20
4.3.3.1HTTPS with conventional TLS  p. 20
4.3.3.2HTTPS with PSK TLS  p. 22
4.3.4SSO scenario: ID-FF with artefact transfer  p. 23
4.3.5SSO scenario: ID-WSF Authentication Service  p. 25
4.3.6SSO scenario: SAML v2.0 with <samlp:Response> transfer  p. 27
4.3.6.1HTTPS with TLS  p. 27
4.3.6.2HTTPS with PSK TLS  p. 28
4.3.7SSO scenario: SAML v2.0 with artefact transfer (resolution)  p. 29
4.3aCo-hosting of BSF and IdP  p. 30
4.3a.1General  p. 30
4.3a.2UE behaviour  p. 31
4.3a.3IdP/BSF behaviour  p. 31
4.3a.4Federation Concept in GBA with IdP/BSF collocation  p. 31
4.3a.5Session Concept at the IdP  p. 32
4.3a.6SSO scenario: ID-FF with <samlp:AuthnResponse> transfer  p. 32
4.4Use of GUSS / USS in Support of ID-FF and ID-WSF  p. 34
4.4.1GAA-LAP Interworking Service  p. 35
4.4.2GAA-LAP Interworking USS  p. 35
4.4.2aGUSS / USS when IdP/AS is collocated with BSF  p. 35
4.5Liberty Alliance Authentication Context and GBA  p. 35
ADigest Authentication within SASL for Ua protocol between UE and AS/NAF  p. 37
A.1HTTPS deployment  p. 37
A.2Digest challenge  p. 37
A.3Digest response  p. 38
A.4Response auth  p. 38
A.5Subsequent authentication  p. 38
$Change history  p. 39

Up   Top