Wireless Network Architecture to Support Mobile Users

In this paper we propose a compound method for user authentication in a public access wireless LAN when the latter requires separate authorization to access internal network services and the Internet. The approach we develop aims to minimize a risk of attacks at network nodes conducted by unauthenticated users provides key establishment and strong encryption between a mobile node and an access point and decreases overall handover latency. An authorized user is granted network and Internet access as a result of a single authentication process that combines 802.11i and PANA operations.