Function Specification Layered IPWorks/AAA
Ericsson Dynamic Activation 1

Contents

1Introduction
1.1Purpose and Scope
1.2Target Group
1.3Typographic Conventions

2

Layered AAA Provisioning Solution
2.1Overview
2.2Data Model AAA
2.3Atomicity and Integrity Handling
2.4AAA Provisioning
2.4.1AAA User
2.4.2AAA Group
2.4.3AAA Policy
2.4.4AAA Massive Operation

Reference List

1   Introduction

This section is an introduction to this document. It contains information about the prerequisites, purpose, scope, and target group for the document. This section also contains explanations of typographic conventions used in this document.

1.1   Purpose and Scope

This document gives a brief introduction to the Layered Authentication, Authorization, and Accounting (AAA) Data in IPWorks provisioning solution, provided by Ericsson™ Dynamic Activation (EDA).

1.2   Target Group

The target group for this document is as follows:

For more information regarding the different target groups, see Library Overview Reference [1].

1.3   Typographic Conventions

Typographic conventions are described in Library Overview Reference [1]. In addition to the writing conventions mentioned above, the following applies:

2   Layered AAA Provisioning Solution

Data Layered Architecture (DLA) is an Ericsson architecture that provides a layered structure for network elements. This allows separation of traffic logic and data storage into different nodes.

2.1   Overview

An overview of the layered AAA provisioning and including nodes is shown in Figure 1. For detailed information about AAA FE configuration, refer to User Guide for Resource Activation, Reference [4] and Configuration Manual for Resource Activation, Reference [7].

Figure 1   DLA AAA Overview

2.2   Data Model AAA

The following figure shows the AAA provisioning data model in Centralized User Database (CUDB).

Figure 2   Data Model AAA

Dynamic Activation is responsible to:

2.3   Atomicity and Integrity Handling

Atomicity means ensuring that any operations performed on the system are either all completed successfully or all reversed successfully to keep the data consistency.

One CAI3G CSO can imply several LDAP orders towards the CUDB. Dynamic Activation will provide atomicity in AAA provisioning as below:

If rollback is still failed, the atomicity is not achieved; the CUDB integrity is not assured. Dynamic Activation raised an alarm and sends back error information about inconsistent data in the CUDB.

For more information about AAA alarm, see Event and Alarm Handling, Reference [5]

For more information about rollback failed error, see Layered IPWorks/AAA Provisioning over CAI3G Reference [2].

In case of data inconsistency, manual action is needed. For more information about AAA actions, see Function Specification Resource Activation, Reference [6].

Note:  
Simultaneously Create, Set and Delete the same subscriber can result in inconsistent data in the CUDB, reserve sufficient time duration, with consideration to retry behavior, between the different operations.

2.4   AAA Provisioning

CAI3G is offered for provisioning of Layered AAA data. Through the CAI3G provisioning interface, it is possible to perform the following Customer Service Orders (CSOs):

For more information, refer to Layered IPWorks/AAA Provisioning over CAI3G Reference [2].

CLI is offered for massive print and end of the AAA users, groups and the policies by using the following commands:

For more information, refer to Layered IPWorks/AAA Massive Provisioning over CLI , Reference [3].

2.4.1   AAA User

This MO is used to handle the provisioning of AAA User.

When initiating AAA User, following entries are created in CUDB:

When modifying AAA User, perform following operations in CUDB:

2.4.2   AAA Group

The MO is used to handle the provisioning of AAA Group.

When initiating AAA Group, following entries are created in CUDB:

When modifying AAA Group, do following operations in CUDB:

2.4.3   AAA Policy

The MO is used to handle the provisioning of AAA Policy.

When initiating AAA Policy, add policy name entry under Policies entry in mscCommonData object, with PolicyChecklist and PolicyReplylist attributes.

When modifying AAA Policy, modify policy name entry under Policies entry.

2.4.4   AAA Massive Operation


Reference List

Ericsson Documents
[1] Library Overview, 18/1553-CSH 109 628 Uen
[2] Layered IPWorks/AAA Provisioning over CAI3G, 19/155 19-CSH 109 628 Uen
[3] Layered IPWorks/AAA Massive Provisioning over CLI, 21/155 19-CSH 109 628 Uen
[4] User Guide for Resource Activation, 1/1553-CSH 109 628 Uen
[5] Event and Alarm Handling, 3/1553-CSH 109 628 Uen
[6] Function Specification Resource Activation, 3/155 17-CSH 109 628 Uen
[7] Configuration Manual for Resource Activation, 2/1543-CSH 109 628 Uen


Copyright

© Ericsson AB 2016. All rights reserved. No part of this document may be reproduced in any form without the written permission of the copyright owner.

Disclaimer

The contents of this document are subject to revision without notice due to continued progress in methodology, design and manufacturing.

Ericsson shall have no liability for any error or damage of any kind resulting from the use of this document.

Trademark List
All trademarks mentioned herein are the property of their respective owners. These are shown in the document Trademark Information.

    Function Specification Layered IPWorks/AAA         Ericsson Dynamic Activation 1