针对IEEE802.11i协议中身份认证和主密钥协商造成认证时延过大的问题,提出了一种利用P2PChord技术管理无线局域网(WLAN)内认证信息的认证优化机制.站点在首次接入WLAN时将协商生成的认证信息发布至P2PChord环中.当站点在接入点(AP)间发生切换时,可从P2PChord环中查找出相应的认证信息以完成后续的协议交互,无需通过认证服务器重新认证,从而显著降低复杂认证引起的时延.理论推导及实验结果表明:该认证信息管理方案能够降低站点在AP间的切换时延,满足实时应用通信质量的需求;同时还可以减轻认证服务器的负担,在一定程度上防止单一故障点的存在.
To avoid the large authentication delay of IEEE 802. 11 i protocol for identity authentication and key agreement, an authentication optimizing mechanism based on peer to peer (P2P) chord technique is proposed. When the station joins the wireless local area network (WLAN) for the first time, it can send the authentication information to the Chord ring and find the authentication information between access points (APs) to finish the subsequent interaction of IEEE 802. 1 1i protocol. Without recertification, the solution reduces the authentication time of the complex authentication. The theoretical and experimental analyses show that this mechanism can reduce the handoff delay and satisfy the requirement of real-time applications. Besides, it can also lighten the burden of authentication server and avoid a single point of failure to a certain extent.