Page 49 / 141
DTUS065 rev A.7 – June 27, 2014
V.7.6
Authentication speed up
In the association task, the AP and the client must exchange several frames.
The number of frames increases with the security level.
In the WPA protocol, the PMK (Pairwise Master Key) is used to generate
the temporally keys which will be used to encrypt the data.
-
WPA/WPA2-PSK: The PMK is derived from the Pre-Shared Key.
-
WPA/WPA2-EAP: The PMK is distributed by the radius server.
The table below gives the number of frames vs the security level
Security policy
Number of frame
Open (without security)
4 frames
-
4 Authentication frames
WEP
4 frames
-
4 Authentication frames
WPA/WPA2-PSK
8 frames
-
4 Authentication frames
-
4 Key exchange frames
WPA/WPA2-EAP (with radius server)
> 8 frames
-
4 Authentication frames
-
Several radius authentication frames
-
4 key exchange frames
The “4 Authentication frames” are mandatory by the 802.11 protocol.
The “4 Key exchange frames” are necessary to exchange the temporally key.
The “several radius authentication frames” are necessary to authenticate the
Wi-Fi client with the radius server. The numbers of frame are depending of
the authentication method.
V.7.6.1
Pre-authentication / PMK caching
With this feature, the authentication with WPA/WPA2-EAP policy is
reduced to 8 frames (as in PSK mode).
The AP signals its pre-authentication / PMK caching capabilities in its
beacons. If a client supports at least of these, it can use the corresponding
ones.
The Wln products support both features and automatically use them if the
roaming is enabled.