Showing posts with label aaa server. Show all posts
Showing posts with label aaa server. Show all posts

Thursday, January 24, 2019

Radiator SIM support 2.4 released

We are pleased to announce release 2.4 of Radiator SIM support. This release includes support for SCTP multihoming and has a number of smaller enhancements and bug fixes.

Revision 2.4 detailed updates and fixes
  • 3GPPAutHSS now supports Peer-Auth-Application-Id as DiaPeerDef selector. Requires Carrier module 1.5 or later and Radiator 4.20 or later.
  • Added configuration parameter HSSRealm to 3GPPAuthHSS. This value for this parameter is typically the realm where HSS resides. If not set, messages’ realm is set from DestinationRealm parameter of DiaPeerDef used to forwarding messages to the HSS. Defaults to not set.
  • Subscription-Id AVP is now added to SWm DEA messages to relay MSISDN to ePDG.
  • Updated EAP-SIM, EAP-AKA and EAP-AKA’ permanent, pseudonym (TMSI) and fast re-authentication identity leading characters to match RFC 4186, 4187 and 5448, and 3GPP TS 23.003 suggestions and requirements. Because of historical reasons, EAP-SIM fast re-authentication and EAP-AKA TMSI leading characters were swapped. EAP-AKA’ non-permanent identifiers are now fully separate from the respective EAP-AKA identifiers.
  • Removed obsolete configuration parameters TestNoMAP and GetReauthQueryEAP. Support for TestClient and TestVectorFile were removed from AuthAKA.pm and related files because they are obsolete. Use AuthAKATEST or ServerWXMAP based configurations for testing.
  • A number of code clean up and maintenance changes were done based on Perl::Critic and other tools.
  • SCTP multihoming is now supported. Requires Radiator 4.22 and Radiator Radius::UtilXS package.
Also, for more information, please do not hesitate to contact us at info@radiatorsoftware.com . See also Radiator SIM Pack product page.

Tuesday, September 18, 2018

Radiator as a Cisco ACS replacement

Since Cisco announced the end of sale of their Secure Access Control System (Cisco ACS), customers have contacted Radiator Software looking for a replacement solution, and they have found Radiator AAA Server Software to be just the alternative they need. Radiator is a cost-effective, flexible solution that is known in the market as the “Swiss Army of AAA Servers”.

Radiator AAA Server Software is actively developed and it runs with a variety of platforms, including Linux, Windows, and others. You can be sure that you will have a supported, continuously developed AAA solution that is always kept up to date for years to come. Radiator has at least two releases per year, with interim patches made for security and other urgent needs.

Making it a flexible solution with multi-vendor support, key features of Radiator include:

  • Supports authentication by over 60 different types of methods
  • Interoperates with a huge range of devices, databases, billing packages, and tokens
  • Includes RadSec - secure, reliable RADIUS proxying
  • Includes Diameter - the RADIUS successor protocol used already by mobile operators
  • Includes TACACS+ - for infrastructure management
  • Integration with AD, LDAP, SQL databases among others
  • Accounting logs in variety of formats to be integrated with external systems
  • See also full feature list 

How migration to Radiator works?

When doing the migration to Radiator, you do not need to have new appliances; Radiator can be cost-efficiently fitted into your current infrastructure.

All you need is to install Radiator into your preferred platform, implement the initial configuration, and integrate Radiator to your preferred database. The use of a separate database enables your organization a secure way to store user credentials and data. Additionally, it is possible to include management and logging systems, which you may already have in use. When doing the migration, our team can provide you with assistance and experience from a wide range of use cases.

Typical Radiator set-up in a Wi-Fi authentication use case using RADIUS and TACACS+.

You do not need to worry about complicated licensing; all you need is a Radiator AAA Server Software license pack, available from one server license, two server license for high-availability, and unlimited server count license for large scale deployments. If you need an additional AAA server for a different use case within your organization, you can use a remaining available license, or upgrade your existing pack.

Would you like to know more?

With Radiator, you get direct professional technical support for configuration, deployment, and custom development. Our support packages range from basic email support to 24x7 telephone support.

Our consulting services are available to assist with migration projects. As we have had a wide range of customers with different needs migrating to Radiator, we can easily tailor a cost-effective consulting package for your needs. Thanks to our experience with similar projects, Radiator configuration can be adjusted to new environments without any extra hassle. Our customers include ISPs, enterprises, carriers, universities, public organizations, and utility companies.

If you would like to know more about Radiator, licensing options, and support, please contact our team at sales@radiatorsoftware.com

Blog post revised Feb 2nd 2022.

Tuesday, May 22, 2018

RAdmin version 1.16 is released

We are pleased to announce that RAdmin version 1.16 is now released. RAdmin is our tool for managing RADIUS users. With RAdmin you can check usage summaries, drill down to usage details and much more that is needed when managing your RADIUS traffic and users.

For this revision, we have implemented one key security fix, multiple bug fixes and and other enhancements. With 2-factor authentication, for example, support for using Yubikey 2-factor authentication tokens has now been updated. This release allows our customers to be sure that the software we provide is up-to-date and can be run on the current Windows, Linux and other platforms. 

For detailed list of enhancements, please see RAdmin revision history

New features

In addition of providing new bugfixes, version 1.16 also provides new enhancements for RAdmin UI. One example of these is providing a better way to listing usage of different users and sessions (see picture below). In addition other new usability and UI fixes are now available in order to provide a user-friendly way for managing network users.



Would you like to know more?

We are happy to provide RAdmin, like other Radiator products for evaluation.

RAdmin is designed especially for ISPs, CSPs and other companies or organizations that have the need to manage their RADIUS users. When contacting our sales team at info@radiatorsoftware.com we are happy to provide more info about use cases for Radiator and RAdmin. 

Wednesday, February 28, 2018

Radiator 4.20 now available!

We are happy to announce that Radiator 4.20 is published today!

The new version has dozens of improvements, new features, and bug fixes. Here are some examples:
– OCSP and OCSP stapling support, see the blog post
– Certificate check enhancements
– Better support for asynchronous operations
– Several security improvements
– Security fix for certificate validation for EAP-TLS and TLS-based Stream modules
– Possibility to include extra checks with new ServerTACACSPLUS AuthorizeGroups parameter
– TLS 1.3 awareness
– New module AuthBy RATELIMITSOURCE
– Improved LDAP functionality
– New hooks, such as EAPTLS_CertificateVerifyFailedHook and ForwardHook

For a detailed list of changes, see Radiator revision history page.

Friday, May 12, 2017

Radiator 4.18 now available!

We have published the updated version of Radiator, please meet brand new Radiator 4.18!

There are lots of enhancements and bugfixes in Radiator 4.18. Some are small, some bigger but nothing really major. The main improvements include:
  • Several security fixes
  • Enhanced logging and debugging features
  • New modules for accounting handling
  • Automatic rejection of empty passwords and some types of invalid user names
  • AuthenProto parameter for setting the allowed authentication methods
  • Several EAP enhancements

The detailed list of changes is available on Radiator revision history.

Thursday, September 29, 2016

Make your Radiator log data searchable, part 2

This is the second part of blog series that helps you to use the log data that Radiator generates.

In the first part of blog series, we configured Radiator to export data in JSON format. This part shows some basic examples about utilising that data.

The setup introduced in blog series part 1 is running and it produces log data in JSON format. The JSON data is forwarded to an analysis tool. In this case, we use Elastic Stack and its visualisation tool Kibana for analysing the sample data. For more information about Elastic Stack, see the Elastic Stack website, or an open source fork of Elastic Stack, OpenSearch. Configuring the data forwarding depends on the chosen tool and it is not discussed in this blog post.

This image shows how the log data is processed when using Elastic Stack for analysing:

radpwtst to Elastic stack.png

radpwtst tool, which is included in Radiator distribution, is used as a RADIUS client. Thus, it authenticates via RADIUS and Radiator logs authentication attempts as entries to authlog.json file. Here is a sample of one authentication entry as shown in the JSON file:



{"nas_port":"1234","source_host":"osc-dev-3","time":"1463404359","type":"authentication","timestamp":"2016-05-16T16:12:39Z","nas_identifier":"203.63.154.1","nas_ip_address":"203.63.154.1","calling_station_id":"987654321","result":"accept","username":"mikem","called_station_id":"123456789","trace_id":"43efcbe2"}



The name-value pairs are not ordered in any way so they are hard to read as such. To get a better idea of the data, it must be parsed. One option is to use configuration variable for the plaintext output, it is feasible to use, at least in the testing phase. This helps to verify that the data is correctly interpreted by Elastic Stack.

Visualising log data with Kibana

Elastic Stack parses the data so we can explore the contents in Kibana. Part of our sample data looks like this in Kibana:




By clicking each entry open, we can verify that all name-value pairs are distinguished. By default, each name-value pair is indexed and searchable, and if you add new fields to the JSON data, Elastic Stack indexes them automatically. They are parsed and usable in your searches without need for other modifications. This enables searching of wide variety of name-value pairs and their combinations.



Kibana shows the amount of entries in each time window. By filtering everything else but authentication-related entries, we see trends in amount of authentication attempts.



Similarly, we can create visualisation of access/reject rate within a certain time frame.



Do you want to know more?

There will be examples of more detailed JSON use cases in the blog. If you have questions, contact Radiator team at sales(a.t.)radiatorsoftware.com – we are happy to help you to have more benefits of your log data.

Monday, July 18, 2016

Flexible M2M/IoT service with Radiator and Private APN

M2M (Machine to Machine) communications, IoT (Internet of Things), and Industrial Internet are constantly bringing new connected devices, things, to the Internet. Operators and other companies already use Radiator AAA Server Software to create M2M, IoT, and Industrial Internet services to customers. Using Radiator with Private APN (access point name) is an important use case.

Figure 1: Radiator RADIUS server and Private APN service architecture

Most mobile operators provide, in addition to their own APNs, also a Private APN service for companies interested of separating their data traffic from operators’ generic subscriptions. The Private APN service utilises operator’s SIM cards for radio network access, but separates the data traffic in operator’s GGSN (gateway GPRS support node) by the access point name (e.g. internet.company instead of operator’s own access point name). These separate private access points may have their own parameters for authentication, accounting, IP networks, IP address allocation, connection parameters, traffic accounting, priorities, and other functionalities. Depending on the GGSN capabilities, it is possible to move some of these functionalities and information to a separate RADIUS service, which is provided either by the operator or company utilising the Private APN.

With the Private APN and Radiator AAA Server Software as a RADIUS service, our customers have successfully deployed M2M, IoT, and Industrial Internet solutions. Some examples are:
  • Fixed IPv4 and IPv6 address allocation for mobile operator M2M/IoT service based on MSISDN (phone number) with the option of returning any GGSN-supported subscription parameters from RADIUS to GGSN
  • Ensuring that the Australian state-wide network of water measurement devices are active and sending measurement data, and working as AAA service for VPN connection authentication for devices
  • Tracking truck locations, and authenticating, accounting, and authorising GPS tracking devices for fleet tracking service operating across several operators and European countries

Would you like to know more?

This use case is one of the many, where Radiator can be used to provide additional and complementary functionality to mobile network and Internet of Things/Industrial Internet solutions. Contact our team at sales(a.t.)radiatorsoftware.com to set up a meeting, where we can discuss how Radiator could help you in building and deploying mobile network or IoT/Industrial Internet services and solutions.

Friday, June 17, 2016

Radiator SIM Pack, Carrier Pack and Telco Pack releases

We are happy to announce we have now new releases of Radiator SIM Pack and Telco Pack  and also the first release (v. 1.0) of Radiator Carrier Pack, which is designed to address the needs of carriers.

Radiator Carrier Pack is targeted especially for carriers: it provides the interoperability, flexibility, and performance of Radiator, and it also includes Radiator Carrier Module. This module consists of advanced Radiator Diameter server software and Diameter relay software. These provide the platform for other Radiator carrier products: Radiator SIM Pack, Radiator Telco Pack and Radiator GBA/BSF Pack.

Initial release of Radiator Carrier Pack includes following features (and more can be found from revision history):

  • The existing and new modules are reorganised. Base components from Radiator Telco Module are now included in Radiator Carrier Module.
  • DiameterTelcoConnection now calls DiaPeer's send_reply() instead of calling send() directly. This is preferred to keep the peer state machine up to date.
  • OriginHost and OriginRealm in DiaPeerDef support special formatting.
  • Diameter initiator connections are now activated after the configuration has been loaded instead of during configuration loading.

Do you want to know more?

If you like to know more about Radiator Carrier Pack and other Radiator carrier products, please do not hesitate to contact our sales team at sales(a.t.)radiatorsoftware.com

Monday, June 6, 2016

Make your Radiator log data searchable

This is the first part of blog series that helps you to use log data that Radiator generates. Jump to second part.


Radiator exports AAA (authentication, authorisation, accounting) data to various formats. You can process the log data further by other log collection systems, such as Splunk and Elasticsearch. In this article, we briefly describe how to export data in JSON format. The common use case is to record the metrics that best describe your environment, for example, authentication, and authorisation messages.

The image below shows you an example of visualised Radiator worker statistics. The graphics were created with Grafana. Click the image for a larger view.





Adding a new field
With Radiator, it is possible to export log data in JSON format (for more information, see JSON.org). Basically, JSON is a set of name-value pairs. The values can also be ordered lists and it is possible to nest lists inside other lists. This makes it possible to express complex data structures in an universal manner with JSON.

Usually, the hardest part in modifying configuration is to figure out how to synchronise modifications everywhere, especially if the logs are centrally collected and parsed. For example, if Client-Identifier or some other RADIUS attribute is added to a log message when authentication fails, you have to ensure the log parser engine understands the new field.

This is an example of AuthLog FILE, which has date, username, and result.

Wed May 18 15:48:44 2016:mikem:FAIL

If you add a new field, the log entry looks like this:

Wed May 18 15:48:44 2016:mikem:client-1:FAIL

Here is the same information as a default JSON message without the new field:

{"timestamp":"2016-05-18T15:48:44Z","result":"reject","source_host":"osc-dev-3","username":"mikem","type":"authentication"}

Here is the JSON message with the new field: {"timestamp":"2016-05-18T15:48:44Z","result":"reject","source_host":"osc-dev-3","username":"mikem","type":"authentication", “client”:”client-1”}
With JSON, it is easy to add the new field to Radiator log message. Usually, there is no need to modify the parser configuration since the fields are just a group of name-value pairs and not fixed together in any way.

Configuring Radiator

The configuration process is straightforward: add Log <FILE, SYSLOG, ...> clause and use it in the same way as existing ones to your Radiator config and you are done. With Radiator, you can customise your own LogFormatHook and add, remove, or modify the fields. This is how Radiator extends the log usage possibilities even further.

Note: The following configuration example needs Radiator 4.16 with latest patches. You must have JSON module installed. JSON::XS module is recommended (see https://metacpan.org/pod/JSON and https://metacpan.org/pod/JSON::XS).


Configuration example: JSON output to radius.cfg (source goodies/logformat.cfg):



# This logger logs events in JSON format. It requires the Perl JSON
# module. Note the specific requirement for loading the logger module.
<Log FILE>
       Identifier mylogger-json
       Trace 4
       Filename %L/logfile.json
       LogFormatHook sub { Radius::LogFormat::format_log_json(@_); }
</Log>


# This auth logger logs both successes and failures to a JSON file.
<AuthLog FILE>
       Identifier myauthlogger-json
       Filename %L/authlog.json
       LogFormatHook sub { Radius::LogFormat::format_authlog_json(@_); }
       LogSuccess 1
       LogFailure 1
</AuthLog>


# This is the Handler-clause.
<Handler>
   <AuthBy FILE>
       Filename %D/users
   </AuthBy>
   AuthLog myauthlogger-json
   # Log accounting messages in JSON format.
   AcctLogFileName %L/acctlog.json
   AcctLogFileFormatHook sub { Radius::LogFormat::format_acctlog_json(@_); }
</Handler>



In this example configuration, all log data is saved into a single file. This may cause problems in the real configuration because of increasing log data file size. You can avoid this by using log rotation tools, for example, logrotate in Unix-based systems. Rotating log files can safely be done without restarting Radiator. Radiator also supports the special characters in the file names.

Do you want to know more?
Your JSON files are now ready, the next step is to use them efficiently. In the next part of the series, we will introduce the more detailed use cases, which will help you get the most out of Radiator logging.

Wednesday, January 20, 2016

Radiator 3GPP AAA Server white paper published

We are happy to announce that Radiator 3GPP AAA Server white paper (pdf) has now been published. 3GPP AAA Server white paper, as well as our previous white papers about Radiator SIM support and Radiator Policy and Charging support, can be found from OSC website.

If you are in a need for 3GPP AAA Server solution, you can always contact us at sales(a.t.)radiatorsoftware.com

Monday, December 28, 2015

Implementing VoLTE supplementary services with Radiator GBA/BSF

Generic Bootstrapping Architecture (GBA) is a technology that enables the authentication of a user. This authentication is possible if the user owns a valid identity on an HSS (Home Subscriber Server). GBA is standardised at the 3GPP. The user authentication is instantiated by a shared secret, for example, a SIM card inside the mobile phone and the other is on the HSS.

With GBA, it is possible to provide VoLTE Supplementary Services, for example, Call Forwarding in VoLTE. Call Forwarding is an example of use case that cannot be pre-configured for all the subscribers because users want to configure their own forwarding number. With Radiator GBA/BSF module, this is possible to done in your VoLTE network – without the need to drop the user from VoLTE to other network.

How this is done with Radiator?

One of our customers had a need for VoLTE Supplementary Services in their network, and as a part of product development, a new Radiator GBA/BSF module was introduced to meet their needs.

GBA_AP.png
One example architecture when using Radiator GBA/BSF module for VoLTE Supplementary Services


As it is shown in picture above, Radiator GBA/BSF module will work as a authentication proxy between the end-user UE and HSS. It will authenticate user requests, and also separate the authentication procedure and the Application Specific server (AS) specific application logic to different logical entities – such as VoLTE Supplementary Services.

After the authentication procedure has been completed, Radiator GBA/BSF module assumes the role of a reverse proxy, i.e. the AP forwards HTTP requests originating from the UE to the correct AS, and returns corresponding HTTP responses from the AS to the originating UE.

Need for VoLTE Supplementary Services in your own network?

In case you need VoLTE Supplementary Services, such as Call Forwarding, in your own network, please do not hesitate to contact our team at sales(a.t.)radiatorsoftware.com. Our team of experts is happy to assist with your project.

Monday, November 9, 2015

Using Radiator for Wi-Fi offloading: how to make savings in mobile packet core network

With Wi-Fi offloading, mobile operators can transfer traffic from their Evolved Packet Core network to Wi-Fi networks. One of the key reasons for this is cost savings - as an example from Radiator customer can demonstrate.Our customer has currently 50,000 public hotspots in their country - the best Wi-Fi coverage in the nation.

Hotspots in the country by operator

In order to get the most out of their Wi-Fi network, a solution was needed for automatic SIM authentication for mobile users. For this, our regional partner implemented a solution with Radiator SIM Pack for the customer. This enabled them to increase the network usage from 1 M usages  per month to over 70 million usages per month. A key component, in addition to Radiator SIM Pack, was iPhone Carrier Bundle with auto connect - that provides automatic authentication to the end-user.

After the initial surge, customer still sees growth of 13 % per month.

The current progress of WiFi Auto Connect usage
Because of the solution, customer is now offloading almost 600 TBytes of data from evolved mobile packet core (EPC) each month - and the amount is still growing. If cost of each GByte to the EPC is around USD $4, the customer is saving over USD $2M per month - and over $24M per year!

Amount of offloaded data by month

Interested in Wi-Fi offloading?

If you have interest in Radiator solutions for Wi-Fi offloading - please do not hesitate to contact our sales team at info@open.com.au

Wednesday, June 17, 2015

Radiator Interoperating with Hotel Management Systems

One of the widely seen use cases for Radiator is interoperating with different hotel property management systems (PMS). Radiator is used between the hotel’s PMS and the network equipment that controls internet access in hotel rooms. One of the commonly used systems is Micros Opera that is used by both independent hotels and hotel chains.

For Opera, we have implemented support in Radiator that is easy to deploy with your own team or with the help of our experts. When Radiator starts up, it will receive hotel customer information from Opera. This information is used for Wifi network authentication. The basic information received from Opera is name, room and customer id of the guest. When the hotel guests check in or check out, the information Radiator maintains is updated by Opera. Radiator support is not limited to Opera: it supports any PMS that provides a FIAS interface.

Many hotels require guests to log in with their name and room number. Radiator then gives access based on customer information it has received from Opera. This functionality is shown in the picture below.


In addition to simply offering unpoliced, complimentary internet access, Radiator provides you more advanced options for revenue generating services. Radiator can, for example, give policy instructions, such as the speed given to the customer - based on the price customer is willing to pay for the internet access. Also, Radiator can pass information to network equipment (such as Mikrotik controllers) about how long the customer can use the internet with their current login without having go through the login process again.

Same need in your own hotel or hotel chain?

If you need a smart and flexible internet access service for your business, just contact our sales team at sales@radiatorsoftware.com. Our experts at Radiator Software can provide you with competitive service package suited just for your needs.

Friday, May 22, 2015

Reduce the time to market of your products with Radiator

 
Photo by Egan Snow

Time to market is one of the key issues when you want to provide new services and products to your customers. When competition is though, new ideas should be easy implement in your customer’s operating environment.

One of the strengths of Radiator charging and policy pack is its flexibility in order to test and create new products. As a policy controller, Radiator is often much more flexible than many options on the market.

Flexibility for authentication or database testing

One example of this flexibility are the SIM cards that can be used to create and fully test new products.  In some of our projects, our customers have at first used the dedicated Radiator SIM cards (available freely from us) before switching over to the production environment. Piloting the customer experience for SIM authentication was made as realistic as it gets.

And it doesn't end here: in a similar way telcos or other operators can first test their new services, for example, new data plans, in a safe environment before going live.

Another example where flexibility comes in handy are the different types of databases. Since Radiator Policy charging and rules function (PCRF) and Online charging system (OCS) have been tested against sqlite, MySQL, PostgreSQL and Oracle SQL Database, it is possible for you or your customer to choose from different options that fit best to your needs and existing environments and the data within.

How to speed up your product and service development with Radiator?

Our team has gained experience with Radiator for different use cases over multiple years. We have wide experience of different kind of product solutions. When you are thinking about use cases, such as SIM authentication or policy and charging issues, please do not hesitate to contact our sales team at sales@open.com.au

Tuesday, May 12, 2015

Scalable customer data plan - customize with Radiator

Different customers have different needs. Photo by Jenny Downing (cc)
As different uses of data roaming are still expanding rapidly, telecommunications companies (telcos) and other operators need different ways to provide the best value to their customers. Price and the maximum data quota offered are not the best or the only ways to compete. Customer loyalty can be achieved with customized offers that make the customer feel that this service is provided just to him or her. Because of this, customers want to optimize their data roaming use with flexible pricing and a telco needs to address these demands.

Radiator can be used to create these kind of solutions with data plans - a monthly subscription to a service that delivers database content, real-time data, news or other information. For different kind of data plans, advanced policy and charging support is needed. In this blog Radiator is being used to create different kind of data plans for different kind of customers.

Different data plan settings for different customers

In the basic setup, the customer’s device interacts with operator’s border network gateway (BNG) - for example a router. The BNG interacts in it’s with Radiator Radius that gets customer’s data plan from operator’s other systems. This is how we have done things for our customers many times over.

However, there are more modern ways to do create data plans for customers. Another advantage that is gained with Radiator, is possibility for deep packet inspection (DPI). With DPI it is possible to create advanced data plans. Advanced data plans can for example include reserved quota for certain services (such as Spotify or others) that you can market to your customers. Another typical use for advanced data plans is dividing data quota between different SIMs - then the data can be divided between different members of family.

For telco or other service provider the advantage is scalability - differentiated data plans can be done with greater ease. See the picture below for the configuration that can be adjusted to your needs.

 
Same need in your own network?

The right solutions for you is Radiator Policy and Charging Support. Please contact our sales team sales ( a t ) radiatorsoftware.com

Friday, May 8, 2015

Radiator Connects - from Machine to Machine to the Internet of Things

Our customer, a telecommunication company, had a pressing need in their network. They needed to replace their outdated Radius solution with a new design that allowed their M2M (Machine-to-Machine) network to function automatically as a integrating solution between the network controlled devices and the operator’s network.

In addition to telcos, the same kind of solution can be provided for power companies, logistical companies and others who have a need for an IoT-solution where devices interact with each other. Devices can be either pre-provisioned in batches (such as contactless electricity meters) or they can be uploaded to the system one device at a time via the user portal operated by the company. The basic functionality is shown below.


 
In this kind of operating environment, it is essential that the Radius server used for authentication and provisioning is compatible with and able to adapt different systems and devices - some dated while back. You may have, for example, a need to use database of some specific vendor (Oracle etc) in the future as well. From Radius server you then need interoperability and flexibility - and Radiator can be easily integrated to your operating environment. 


Same need in your own network?

For this kind of configuration, the right solution for you is Radiator, possibly with Radiator EAP-SIM Pack  - with an IoT-solution it is often convenient to use SIM authentication. To complement Radiator capabilities, our team of Radiator experts, making it easy for you to just deploy Radiator as the solution or the replacement for less flexible system. Please contact our sales team sales@radiatorsoftware.com,  when figuring out the best solution for your needs.


The Radiator EAP-SIM Pack is now known as Radiator SIM Pack.

Wednesday, May 6, 2015

Preventing Bill Shock with Radiator

Photo by Thomas Fano
Unexpected bill shock - a huge bill accumulated from roaming - can be a nasty surprise for your customers. It is also one that can be avoided, both in domestic and in global use. One of the most known use cases is based on EU roaming regulations.

When your client uses mobile phone in other EU countries to go online, there's a limit on what an operator can charge them. The limit is based on EU regulations. To protect the client against excessive data roaming bills, the monthly cost of downloaded data on mobile device is capped, worldwide, at €50, unless something else has been agreed on. Following the EU regulations, a warning is sent when the usage reaches 80 % of the quota.

In addition to EU regulations, a system for warning and limiting data use is needed for global roaming to ensure that your clients will not have a bill shock from their worldwide data usage.

With Radiator, we have already done these kind of solutions for our operator customers who have in turn provided it for their virtual operators. In this post, we will tell you how to do it.

How to use Radiator to prevent Bill Shock

The basic layout of operator infrastructure

Radiator keeps track on the data used by the customer. To do so, Radiator interacts with the billing system where the data plans and client information is stored.

Customer's SIM is used to lookup information about the customer’s current quota usage, data plan, phone number for SMS alerts and possible other information, such as custom limit for data usage. One data plan is typically used for most of the customers, another for enterprise customers and another for customers of a virtual operator.

The client’s updated quota is then stored in the database. When the quota limit is reached, an automated SMS message is sent to the customer. After each month, the data quota is reset in the database and the usage monitoring will start from the beginning.

Customers are happy when their roaming quota is monitored reliably, and operator does not have to allocate any resources to this task. 

What do you need?

The functionality can be done with Radiator Policy and Charging Support. Contact our sales team at sales (a.t) radiatorsoftware.com.