Fast 802.11 handovers with 802.1X reauthentications

Fast handovers of roaming stations (STAs) between access points (APs) require preauthentication or fast reauthentication within new serving APs. The current standards address only over‐the‐DS (Distribution System) preauthentications for 802.1X authentications. However, over‐the‐DS preauthentication...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Security and communication networks 2011-03, Vol.4 (3), p.267-283
Hauptverfasser: Marques, Rodolphe, Araújo, Edgar, Zúquete, André
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Fast handovers of roaming stations (STAs) between access points (APs) require preauthentication or fast reauthentication within new serving APs. The current standards address only over‐the‐DS (Distribution System) preauthentications for 802.1X authentications. However, over‐the‐DS preauthentication is not suitable for fast moving STAs, which may loose their connection with the currently serving AP before performing preauthentications in the neighbouring APs. This paper presents several ways to achieve fast 802.11 handovers while keeping the basic security features of 802.1X authentications. To do so, we designed a fast 802.1X reauthentication protocol. This protocol enables an STA to perform many fast 802.1X reauthentications after an initial, possible slow, 802.1X authentication. The reauthentication protocol requires little from the network environment, namely a new, central Reauthentication Service (RS) (possibly integrated with the local 802.1X Authentication Server). To speed up 802.1X reauthentications within handovers, the reauthentication protocol was piggybacked into 802.11 management frames that are ordinarily used during handovers. This way, we are able to perform 802.1X reauthentications while taking the normal, over‐the‐air 802.11 steps for performing handovers (network probing, authentication, and (re)association). Besides this over‐the‐air approach, we also show how the 802.1X reauthentication protocol can be implemented using an over‐the‐DS approach. A prototype implementation using over‐the‐air 802.1X reauthentication showed that handover delays can be dramatically reduced to 1.5 ms, while an 802.1X fast resume takes more than 150 ms. Copyright © 2010 John Wiley & Sons, Ltd. This paper presents a fast, generic 802.1x reauthentication protocol and its deployment using several 802.11 management frames, namely within network probing. This approach enables mobile nodes to install security associations on nearby APs while scanning for them. The main achievement is that handover latency can be reduced down to the latency of an 802.11 association with a very limited cooperation from the wireless network.
ISSN:1939-0114
1939-0122
1939-0122
DOI:10.1002/sec.184