Abstract—With an increasing number of personalized information and services offered on the Internet, especially the World Wide Web, effective identity management solutions are demanded by application providers. Instead of a web-based stand-alone approach, we extend existing network-based AAA mechanisms to be useable for identity management by web applications. Our proposal, Diameter WebAuth, allows to seamlessly integrate webbased services into a Diameter infrastructure for authentication, authorization, credit-control and identity management purposes. Diameter WebAuth offers comparable features to web-based identity management solutions, benefits from the maturity and wide deployment of the Diameter protocol, and takes advantage of existing AAA setups.