Home > Articles > Centralized Authentication: a Critical need to Secure Wi-Fi Networks
Articles
Centralized Authentication: a Critical need to Secure Wi-Fi Networks
Posted on Wednesday, March 10, 2010 - Nikhil Jain, Cyberoam
Print this Page Print  Email this Post Email
Centralized Authentication: a Critical need to Secure Wi-Fi Networks

While Wi - Fi makes information much more accessible and does away with the complexities of wiring and cabling, it brings along with it a plethora of security issues that need attention. Wi-Fi Networks are usually open and can be accessed by non registered users easily. Due to this any hacker can gain access to the internal network leading to data loss and theft through eavesdropping, interception and modification of data in transit, spoofed e-mail messages for social engineering and malware insertion attacks, service disruption, bandwidth loss etc. The lax security measures on part of users as well as Internet service providers, present cyber criminals with a cakewalk. Basically they take advantage of the fact that there are no proper security systems and practices, all of which help them erase their trails.

The deployment of security through different Wi-Fi settings, be it home, businesses or hotspots, is the first step towards ensuring security. However there is a need to have greater security measures taken at the operators end.

It is now mandatory by law to offer secure Wi-Fi services via 802.1x and WPA/ WPA2 based methods and keep track of wifi usage.

Looking into these security issues it is now mandatory by law to offer secure Wi-Fi services via 802.1x and WPA/ WPA2 based methods and keep track of Wi-Fi usage. Service providers offering Wi-Fi services at public places such as hotels, restaurant, airport malls, railway stations, shops or residential use and enterprise network on leased lines need to have a Central Authentication Mechanism Provisioning and subscriber management for secure Wi-Fi networks.

The Government of India - has introduced significant new compliance requirements for all ISPs providingWi-Fi services at

  • Public hotspots including airports, Malls, cafes, schools, hotels, etc
  • Enterprises and offices that use leased lines and install their own Wi-Fi routers also need to be secured
  • Residential & Retail Subscribers

Rolling out a secure Wi-Fi Network as perDOTRequirements

Public Wi-Fi
All public Wi-Fi access points whether offered free or paid need to be encrypted and secured, the user can register and login through a temporary username password auto generated from the system for that session or till the expiration of numbers of hours purchased.

The ssdervice provider also needs to ensure a controlled distribution of service through pre creation of login ids at each Wi-Fi hotspot, which get authenticated at the centralized server.

The registration and tracking of usage will happen at a central authentication server, centrally for all the hotspots by the service provider. It is mandatory to keep photo identity and mobile number for records.

For Enterprise & Residential Wi-Fi
Service providers must offer central authentication mechanism - Each subscriber (Office, Residential) must be able to access Wi-Fi service through their unique login id & password that will be authenticated at the centralized server deployed by the ISP.

The system should be able to track each subscriber's sessions and usage with records that must include IP address & location where / when an authorized user accessed a specified Internet resource which need to be maintained for a year.

As per the new law multiple logins cannot be issued to a single user, But can be give for different accounts to same subscriber. For new subscribers, service activation would happen only after registration for central authentication.

These guidelines issued by DoT will definitely secure the network and stop unlawful use by anti social elements. Elitecore Offers EliteAAA to centrally manage the subscriber's authentication & authorizes them for appropriate level of service, and centralized subscriber management. EliteAAA for Wi-Fi is vendor agnostic and standards-based solution offering encryption and key rotation based on IEEE 802.1x and Wi-Fi Protected Access (WPA/ WPA2). EliteAAA supports EAP TLS, EAP TTLS, EAP FAST, EAP MD5 and PEAP – MS – CHAPv2 security methods. A lot of Service providers have realized the importance of secure Wi-Fi, We are working on various cases related to Wi-Fi Security offering a centralized authentication server and other security features that are needed to protect the Wi-Fi Networks as per guidelines laid down by DoT. A secure Wi-Fi service experience is paving way for the next revolution of internet experience.

Rating : ( average: 0 out of 5)

2010: Aug | Jul | Jun | May | Apr | Mar | Feb | Jan
2009: Dec | Jul | Jun | May | Apr | Mar
2008: Dec | Nov | Oct | Sep | Aug | Jul | Jun | May | Apr | Mar
2007: Dec | Nov | Oct | Sep | Aug | Jul | Jun | May | Apr | Mar
IAMAI
Run your advertorial
Developed by Finesse Interactive