802.11 Fast BSS Transition (FT) Part 2 of 2

802.11 Fast BSS Transition (FT) Part 2 of 2

By CWNP On 08/22/2007 - 6 Comments

The IEEE 802.11r amendment introduces a new 3-tier AKM architecture and some new terminology such as Mobility Domain, Key Holders, RICs, and two tiers of Pairwise Master Keys (PMKs).  A Mobility Domain is a set of BSSs, within the same ESS, identified by a Mobility Domain Identifier (a numerical value).  Fast BSS Transition (FT) is not specified between Mobility Domains.  The definition of an authenticator is, under the new amendment, split into two pieces – each being responsible for certain tasks.  These two pieces are called the PMK-R0 Key Holder (R0KH) and the PMK-R1 Key Holder (R1KH).  These could, in many instances, be considered the WLAN controller (R0KH) and the lightweight AP (R1KH) though this is not a requirement of the amendment.

 

To contrast with the current AKM structure, the 802.11r authentication server (typically a RADIUS server) sends the Master Session Key (MSK), which is formed at the supplicant and authentication server during the “Initial Mobility Domain Association (IMDA)”, to the authenticator instead of the PMK that is currently sent using 802.11i AKM.  This MSK is used to derive the same PMK-R0 (the highest level PMK) on both the supplicant and authenticator.  From this PMK-R0, a set of unique-per-AP PMK-R1 keys (the second highest level PMK) is derived on the supplicant and authenticator.  The R0KH then distributes (through a mutually-authenticated and confidential connection) each PMK-R1 to the correct R1KH.  

Once the PMK-R1 keys are held by the R1KH and the supplicant (which is both an S0KH and S1KH), the FT 4-Way Handshake (performed only once, during the IMDA) can proceed for the purpose of establishing a PTK which will be used for data frame encryption.  From there, the FT reassociation mechanism is handled either over-the-DS as part of an FT Request/Response (using Action frames) or over-the-air as part of an authentication request/response procedure.  The 802.11r amendment additionally specifies the use of Resource Information Containers (RICs), which are sequences of information elements that include resource request and response parameters.  RICs are used as bolt-on parts of over-the-air and over-the-DS FT protocols allowing the supplicant to request resources from new APs for QoS purposes.

For more detailed information on IEEE 802.11r Robust Security Network (RSN) Fast BSS Transition (FT), refer to the CWNP whitepaper by the same name found here:
http://www.cwnp.com/learning_center/search_details.php?doc_id=j8s5


6 Responses to 802.11 Fast BSS Transition (FT) Part 2 of 2

Subscribe by Email
Durfee Jones Says:
05/29/2018 at 06:22am
Even so, the complying with short article defines the login procedure in detail. Chase Bank Login On your device's web internet browser, go to the mobile page for Chase Bank.

Kevinogi jhome Says:
04/18/2018 at 05:54am
Manfred said he didn't know that the Marlins' new owners planned to tear it washington nationals jersers down
In the early moments of atlanta braves jersers the interview, Le Batard asked Manfred whether he knew prior to the recent sale to the group oakland athletics jersers fronted by Bruce Sherman and Jeter whether the new owners planned to slash payroll. After some prodding (and Le Batard's saying that the commissioner was lying), Manfred answered, "We do not get involved in operating-level decisions in the ownership approval process."

"We did not have player-specific plans from the Miami Marlins or any other team that has been in the ownership miami marlins jersers process. Those are decisions that the individual owners make, and they do not have to be cleared by us or approved by us. ... Those are local decisions that really are not part of the approval process. Those are decisions that the individual owners make, and they do not have to be cleared with us or approved by us."

Manfred went on to say that he didn't receive a payroll plan from the Marlins until two days prior to his interview with Le Batard. More: "We don't get into, are you going to trade 'Player X' or 'Player Y' at a particular point in time, nor do we ask them to make a commitment to people before they even got in and made an evaluation of their talent level, their ability to win with the people that st. louis cardinals jersers they have. That's just not how the ownership process works."
wholesale baseball jersers

But some of that may not be true
Here's a key excerpt from a los angeles angels of anaheim jersers must-read Barry Jackson piece in the Miami Herald:

A source directly involved in the Marlins sales chicago white sox jersers process, after hearing the Le Batard cincinnati reds jersers interview, said, via text: "Commissioner said was not aware of [Jeter] plan to slash payroll. Absolutely not true. They request and receive the operating plan from all bidders.

"Project Wolverine [the name for Jeter's plan] called chicago white sox jersers on his group to reduce payroll to $85 million. This was vetted and approved by MLB prior to approval by MLB. Every [Jeter] investor and non investor has the Wolverine financial plan of slashing payroll to $85 million. Widely circulated."

First off, "Project Wolverine" is ludicrously self-important and sinister-sounding, as budget strategies go. That's the name of a secret NSA laboratory deep under the Caballo Mountains in New Mexico, not a financial schematic. Do better, Jeets. Anyhow, there's enough careful phrasing in Manfred's comments ("operating-level decisions," "'Player X' or 'Player Y'") to give him some plausible deniability. However, the idea that he didn't know about plans to engage in yet another demo job by Marlins owners strains credulity.

crothermbeme crothermbeme Says:
04/18/2018 at 02:48am
On Monday,NFL jersesys shop US local time, the New England Patriots began their first voluntary activity in the offseason. Many media have focused their attention on the absence of quarterbackShop NFL Jerseys By Team Tom Brady and near-fielder Rob Gronkowski. However, the return of a key player deserves the same level of attention. He is the wide receiver - JulianBuy Customized NFL Jerseys Edelman. On Monday, Edelman appeared in the Gillette Stadium. This was his first step toward a $500,000 training bonus.Shop NFL Hats
The amount Shop NFL T-Shirtsof this bonus ranks first in the Patriot team. The following is the comparison of Edelman's total training bonus with other players in the team: Edelman:Shop NFL Hoodie $500,000 in Glonnowski: $250,000 Kickback Goalbacker Kodarel Patterson: $250,000 in defense Endpoints Lawrence Guy: $200,000 kicker Stephen Gestkowski: $100,000Pittsburgh Steelers Jerseys security guard Patrick Bell (Clock family): $85,000 In addition to the bonus, Edelman's appearance is also A positive signal was Minnesota Vikings Jerseysreleased: He was recovering systematically from the anterior cruciate ligament tear injury on August 25 last year. With Brandine Cooks Customized Seattle Seahawks Jerseysbeing traded by the team, Danny Amundola joined the Miami Dolphins again through the free agency market. As Brady’s numberCustomized Carolina Panthers Jerseys one goal, Edelman’s return to health in the new season is The Patriots' top priority. As a rule, Brady and Edelman hadIndianapolis Colts Hats practiced many passes during this offseason.
In addition, Edelman’s move Tampa Bay Buccaneersto Gillette Stadium on Monday was also a balance between strength training and Brady’s personal trainer Alex Guerrero. Edelman, who willSeattle Seahawks Hoodie soon turn 32, is a frequent guest of the TB12 Sports Therapy Center founded by Guerrero.
It is reported that Brady may reduceLos Angeles Chargers Hoodie the frequency of participating in the Patriots training during this offseason, and will pay more attention to his training withBaltimore Ravens T-shirts Guerrero. From the current situation, Edelman does not seem to have similar ideas with Brady. (TB12 is Tom Brady's English initialsAtlanta Falcons T-shirts and jersey number.) If you don't remember what Elderman's Patriots lost last season, perhaps the following three facts can remind Denver Broncos T-shirtsyou of Edelman’s Importance: 1. He collected data in 89 postseason games, ranking third in NFL history, second only to Jerry Rice's 151Jacksonville Jaguars Hoodie and Reggie Wayne's 93.
This also means that as long as Edelman completed Los Angeles Rams Hatsfive postseason catches, he will surpass Wayne and rank second in history. 2. He was one of 14 players who completed at least 1000 yardsCustomized New England Patriots Jerseys of NFL postseason advancement and ranked 13th in NFL history with 1024 yards of data. As long as Edelman finished San Francisco 49ers Jerseyscatching the ball in the 39-yard playoffs, he will be ranked in the top ten in history. 3. In his career, a total of four postseasonArizona Cardinals Jerseys games have completed single-field catches and advanced over 100 yards. In this data, he and Dion - Blanche together, ranked first in the history of the Patriots.

Kr Ashwin Says:
01/11/2018 at 04:49am Attachment: Download 15170770_912148562254198_1554389680130230932_n.jpg

Here is all the ideas you need to get to permanently remove any of the web where is my computer windows 10 Browser History and becomes to know through this tutorial free of cost and online.Thank you to share this post.

Says:
08/04/2008 at 09:00am
Some answers:

1. Channels have no bearing on mobility domains. Both Single Channel Architectures and Multiple Channel Architectures will support 802.11r.

2. This information is not provided by the 802.11r draft standard. This information is left to the discretion of the vendor building the implementation.

3. R0KH and R1KH are not different APs. The R0KH will likely be the controller, and the R1KH will likely be the AP. Refer to this document for more information:
http://www.cwnp.com/learning_center/search_details.php?doc_id=j8s5

Says:
08/04/2008 at 02:41am
Some questions:
1.The BSSs in a Mobility Domain must be in the same channel or can be in different channels in 802.11r?

2.It said:"The R0KH then distributes (through a mutually-authenticated and confidential connection) each PMK-R1 to the correct R1KH."
I want to know how the R0KH distributes each PMK-R1 to the correct R1KH in details?

3.When in Initial Mobility Domain Association , R0KH and R1KH may be the same AP, but along with STA's roaming, R1KH(target AP) should be changed even not communicate with R0KH directly; Before reassociation, the new R1KH must communicate with R0KH(initial AP) to get PMK-R1. This communication must be in wireless or in wired network? This course is between R0KH and R1KH, how different with 802.11i(target-AP and authentication server) before reassociation?This can save roaming time?

Sincerely look forward to your answer! Thank you!

<< prev - comments page 1 of 1 - next >>

Leave a Reply

Please login or sign-up to add your comment.
Success Stories

I literally just came out of the testing centre having taken the CWDP exam. The certification process opened my mind to different techniques and solutions. This knowledge can only broaden your perspective. Great job, CWNP, you have a great thing going on here.

-Darren
Read More

Working through the CWNP coursework and certifications helped not only to deepen my technical knowledge and understanding, but also it boosted my confidence. The hard work it took to earn my CWNE has been rewarding in so many ways.

-Ben
Read More

I want to commend you and all at CWNP for having a great organization. You really 'raise the bar' on knowing Wi-Fi well. I have learned a ton of information that is helping my job experience and personal career goals, because of my CWAP/CWDP/CWSP studies. Kudos to all at CWNP.

-Glenn
Read More