Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking

碩士 === 國立交通大學 === 資訊科學與工程研究所 === 95 === This thesis proposes a mechanism to integrate the authentication and key management scheme of the IEEE 802.11i standard with the WLAN Mesh environment. WLAN Mesh eliminates the need for cabling and provides a powerful routing mechanism, so that deployments of...

Full description

Bibliographic Details
Main Authors: Ho-Han Liu, 劉合翰
Other Authors: Chien-Chao Tseng
Format: Others
Language:en_US
Published: 2007
Online Access:http://ndltd.ncl.edu.tw/handle/96653347245940880553
id ndltd-TW-095NCTU5394099
record_format oai_dc
spelling ndltd-TW-095NCTU53940992015-10-13T16:13:48Z http://ndltd.ncl.edu.tw/handle/96653347245940880553 Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking 支援IEEE802.11s無線區域網狀網路整合式安全網域之機制 Ho-Han Liu 劉合翰 碩士 國立交通大學 資訊科學與工程研究所 95 This thesis proposes a mechanism to integrate the authentication and key management scheme of the IEEE 802.11i standard with the WLAN Mesh environment. WLAN Mesh eliminates the need for cabling and provides a powerful routing mechanism, so that deployments of the backbone network will be faster and less expensive than the wired counterpart. However, the security mechanism of the WLAN Mesh is isolated from 802.11i. This isolation of security mechanism introduces extra overhead in handoff handling and routing, and thus degrades the quality of real-time services. In order to improve the handoff performance while fulfilling the security requirement of 802.11i, the proposed mechanism makes the mesh portal (MPP), instead of the mesh access point (MAP), the IEEE 802.1X authenticator so that it can reduce the demand for performing the IEEE 802.1X authentication in handoffs. As a consequence, it not only reduces the handoff latency and message traffic but also improves the routing performance of the encrypted frame. Meanwhile, the mechanism is compatible with IEEE 802.11i and can be used by a station without any modification. Furthermore, the mechanism can also operate with IEEE 802.11s, affecting neither the original routing mechanism nor the security mechanism of IEEE 802.11s. We also propose an analytical model to evaluate the handoff latency and message traffic caused by the security procedures while a station roaming within a WLAN Mesh network. The results show that the proposed mechanism can reduce the handoff latency up to 245% and achieve the same performance as the one accomplished by the 802.11i preauthentication with a successful probability of 80%-90%. Moreover, this model can be further applied in analyzing the optimum number of APs managed by one authenticator in a centralized WLAN architec-ture, where authenticators and APs are implemented in distinct network entities. Chien-Chao Tseng 曾建超 2007 學位論文 ; thesis 77 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立交通大學 === 資訊科學與工程研究所 === 95 === This thesis proposes a mechanism to integrate the authentication and key management scheme of the IEEE 802.11i standard with the WLAN Mesh environment. WLAN Mesh eliminates the need for cabling and provides a powerful routing mechanism, so that deployments of the backbone network will be faster and less expensive than the wired counterpart. However, the security mechanism of the WLAN Mesh is isolated from 802.11i. This isolation of security mechanism introduces extra overhead in handoff handling and routing, and thus degrades the quality of real-time services. In order to improve the handoff performance while fulfilling the security requirement of 802.11i, the proposed mechanism makes the mesh portal (MPP), instead of the mesh access point (MAP), the IEEE 802.1X authenticator so that it can reduce the demand for performing the IEEE 802.1X authentication in handoffs. As a consequence, it not only reduces the handoff latency and message traffic but also improves the routing performance of the encrypted frame. Meanwhile, the mechanism is compatible with IEEE 802.11i and can be used by a station without any modification. Furthermore, the mechanism can also operate with IEEE 802.11s, affecting neither the original routing mechanism nor the security mechanism of IEEE 802.11s. We also propose an analytical model to evaluate the handoff latency and message traffic caused by the security procedures while a station roaming within a WLAN Mesh network. The results show that the proposed mechanism can reduce the handoff latency up to 245% and achieve the same performance as the one accomplished by the 802.11i preauthentication with a successful probability of 80%-90%. Moreover, this model can be further applied in analyzing the optimum number of APs managed by one authenticator in a centralized WLAN architec-ture, where authenticators and APs are implemented in distinct network entities.
author2 Chien-Chao Tseng
author_facet Chien-Chao Tseng
Ho-Han Liu
劉合翰
author Ho-Han Liu
劉合翰
spellingShingle Ho-Han Liu
劉合翰
Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking
author_sort Ho-Han Liu
title Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking
title_short Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking
title_full Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking
title_fullStr Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking
title_full_unstemmed Mechanism for Supporting Integrated Security Domain for IEEE 802.11s WLAN Mesh Networking
title_sort mechanism for supporting integrated security domain for ieee 802.11s wlan mesh networking
publishDate 2007
url http://ndltd.ncl.edu.tw/handle/96653347245940880553
work_keys_str_mv AT hohanliu mechanismforsupportingintegratedsecuritydomainforieee80211swlanmeshnetworking
AT liúhéhàn mechanismforsupportingintegratedsecuritydomainforieee80211swlanmeshnetworking
AT hohanliu zhīyuánieee80211swúxiànqūyùwǎngzhuàngwǎnglùzhěnghéshìānquánwǎngyùzhījīzhì
AT liúhéhàn zhīyuánieee80211swúxiànqūyùwǎngzhuàngwǎnglùzhěnghéshìānquánwǎngyùzhījīzhì
_version_ 1717770105704677376