An alternative WLAN security approach focuses on developing a framework for providing centralized authentication and dynamic key distribution.A proposal jointly submitted to the IEEE by Cisco Systems, Microsoft, and other organizations introduced an end-to-end framework using 802.1X and the EAP to provide this enhanced functionality.Central to this proposal are two main elements: •EAP allows wireless client adapters, which may support different authentication types, to communicate with different back-end servers such as Remote Access Dial-In User Service (RADIUS) •IEEE 802.1X, a standard for port-based network access control To support all popular operating systems, Cisco employees designed and implemented Lightweight Extensible Authentication Protocol (LEAP)—a network-EAP protocol based on 802.1x authentication framework—on Cisco Aironet WLAN products and solutions.Appendix B provides instructions for configuring EAP-TLS using demo certificates (for proof of concept testing).EAP provides a standard mechanism for supporting various authentication methods over wired and wireless networks.Since then, adoption of wireless LAN (WLAN) solutions in vertical (retail, education, health care, transportation, and so on) and horizontal markets has accelerated.

As standardized by the IEEE, security for 802.11 networks can be simplified into two main components: authentication and encryption.

And then claims are converted to a cookie and everything magically works -) This sparked another question.

At the moment Identity does not have open source, but what is the role of OWIN in Identity and how Claims work here? By default it adds a number of claims to a principal when user is logged in. You can make up your own claim types as you are pleased – this is just a string.

Sign In(new Authentication Properties , identity ); var claim2 = new Claim(Claim Types. Add Claim(claim2); After much digging I have discovered that Asp Net Identity framework does not set the cookie. And OWIN is part of Katana Project which has open source code.

In this case I have spent a few minutes navigating Katana project and how Authentication Manager works. It saves Identity objects into memory until time comes to set response cookies.

Figure 2-1 illustrates the mixed EAP protocol deployment in a WLAN network: Figure 2-1 Mixed 802.1x Protocol Deployment in a Wireless LAN Network As shown in Figure 2-1, either the Cisco Access Control Server (ACS) or the Cisco Access Registrar can be used for a combined LEAP and EAP-TLS protocol deployment in an enterprise network.