NIS Chapter 06 Flashcards
What is roaming?
is when a STA switches APs while maintaining network connectivity for the upper layer applications
In what layer does roaming happen?
It happens in layer 2 and is known as the reassociation service
What causes the client station to roam?
propriety rules written into the AP that are defined as the received signal strength indicator threshold. With that it will initiate the roaming process.
What is the primary tasks of the AP to AP handoff?
- target ap tells original that the client is roaming
- target asks original for buffered client packets
What are 2 problems with the autonomous AP-AP?
- back end communication depend on the vendor since it is propierty. AP comm not very effective
- handoffs very slow
WHat does RSNA say about roaming clients?
New and unique keys must be generated every time a client roams
What are the 3 steps that lead to the creation of a PMK (regardless of PSK or 802.1X/EAP
- discovery
- create PMK
- 4 way handshake
Recap all the pre to the generation of PTK
3 steps
What is PMKSA?
this is the result of a successful authentication success between supplicant and AS
Name the types of OMKSA that an PMKID can reference
- PMK association from a PSK from the target AP
- cached PMKSA from 802.1X/EAP
- Cahsed and obtained through preauth w
What is preauth?
A client can use preauth to establish a new PMKSA . It allows a STA to initiate a 802.1X/EAP exchange with a radius server while it is still associated with the original AP
What is PMK caching
- this is a method used by AP and STA to maintain a PMKSA while a client roams . Where the client and authenticator cache PMKs. The PMKIDs are then used to skip the 802.1X authentication and go to the 4 way handshake. The PMK that already exists will then be used as seeding for 4 way.
Why is OKC (oppurtinistic key caching) the preffered method?
PMK caching and preauth dp not scale well
What makes OKC scale better?
caching PMK amongst multiple APs under some admin control
what is the formula for the P<KID of the OKC?
hmac-sha1-128(PMK, pmk name || AA|| SPA)
summarise the process of OKC
-
what are the advantages of OKC over preauth and cache?
- reduce load on radius sever
- only one PMK