User Guide

Radio Interface
6-75
6
the cipher used for broadcast frames is always TKIP. WEP encryption is not
allowed.
Key Caching: WPA2 provides fast roaming for authenticated clients by retaining
keys and other security information in a cache, so that if a client roams away from
an access point and then returns, re-authentication is not required. When a WPA2
client is first authenticated, it receives a Pairwise Master Key (PMK) that is used to
generate other keys for unicast data encryption. This key and other client
information form a Security Association that the access point names and holds in
a cache.
Preauthentication: Each time a client roams to another access point it has to be
fully re-authenticated. This authentication process is time consuming and can
disrupt applications running over the network. WPA2 includes a mechanism,
known as pre-authentication, that allows clients to roam to a new access point and
be quickly associated. The first time a client is authenticated to a wireless network
it has to be fully authenticated. When the client is about to roam to another access
point in the network, the access point sends pre-authentication messages to the
new access point that include the client’s security association information. Then
when the client sends an association request to the new access point, the client is
known to be already authenticated, so it proceeds directly to key exchange and
association.