Technical Specs

Table Of Contents
The following figure shows the Cisco Resilient Mesh authentication overview:
Figure 8: Cisco Resilient Mesh Authentication Overview
Stages of Authentication
The Cisco Resilient Mesh meter must go through five stages of authentication before it connects with the CGR:
Stage 1: Key information exchange
Stage 2: 8021X/EAP-TLS authentication (ECC cipher suite certificate)
Stage 3: 802.11i four-way handshake—Pairwise Master Key (PMK) confirmation, Pairwise Transient Key (PTK) derivation,
and Group Temporal Key (GTK) distribution
Stage 4: Group key handshake
Stage 5: Secure data communications
Figure 9: Four-Way Handshake
25
REVIEW DRAFT - CISCO CONFIDENTIAL