1. A method comprising:
generating a plurality of second-level derived authentication keys at one of a plurality of network access servers based on a first-level derived authentication key, each of the plurality of second-level derived authentication keys being associated with one of the plurality of network access servers within a mobility domain, and
generating a plurality of key names, at least one of the plurality of key names corresponding to one of the plurality of second-level derived authentication keys.
2. A method as defined in claim 1, wherein generating the plurality of second-level derived authentication keys comprises generating a second-level pairwise master key based on at least one of a first-level pairwise master key, a key derivation function, a service set identifier, a network access server identifier, a separator, or a sender protocol address.
3. A method as defined in claim 1, wherein generating the plurality of key names comprises generating at least one of the plurality of key names based on at least one of a hash function, a service set identifier, a network access server identifier, a separator, or a sender protocol address.
4. A method as defined in claim 1 further comprising:
receiving a master authentication key from an authentication server;
generating the first-level derived authentication key based on the master authentication key; and
generating a key name corresponding to the first-level derived authentication key.
5. A method as defined in claim 1 further comprising:
generating a first-level pairwise master key at the one of the plurality of network access servers based on at least one of a master secret key, a service set identifier, a mobility domain identifier, a network access server identifier, a separator, or a sender protocol address; and
generating a key name corresponding to the first-level pairwise master key based on at least one of the service set identifier, the mobility domain identifier, the network access server identifier, the separator, the sender protocol address, or a nonce value.
6. A method as defined in claim 1 further comprising receiving the first-level derived authentication key and a key name from an authentication server, wherein the key name corresponds to the first-level derived authentication key.
7. A method as defined in claim 1 further comprising providing at least one of the plurality of second-level derived authentication keys to at least one of the plurality of network access servers.
8. A method as defined in claim 1 further comprising:
generating a session key for a session with a subscriber station based on one of the plurality of second-level derived authentication keys; and
generating a key name corresponding to the session key.
9. A method as defined in claim 1 further comprising:
generating a pairwise temporal key based on at least one of a second-level pairwise master key, a key derivation function, a first nonce value, a second nonce value, a first network access server identifier, a second network access server identifier, a basic service set identifier, or a sender protocol address; and
generating a key name corresponding to the pairwise temporal key based on at least one of a secure hash function, the first nonce value, the second nonce value, the basic service set identifier, or the sender protocol address.
10. An article of manufacture including content, which when accessed, causes a machine to:
generate a plurality of second-level derived authentication keys at one of a plurality of network access servers of a mobility domain based on a first-level derived authentication key, each of the plurality of second-level derived authentication keys being associated with one of the plurality of network access servers; and
generate a plurality of key names, at least one of the plurality of key names corresponding to one of the plurality of second-level derived authentication keys.
11. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to generate the plurality of second-level derived authentication keys by generating a second-level pairwise master key based on at least one of a first-level pairwise master key, a key derivation function, a service set identifier, a network access server identifier, a separator, or a sender protocol address.
12. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to generate the plurality of key names by generating at least one of the plurality of key names based on at least one of a hash function, a service set identifier, a network access server identifier, a separator, or a sender protocol address.
13. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to:
generate the first-level derived authentication key at the one of the plurality of the network access servers based on a master authentication key from an authentication server; and
generate a key name corresponding to the first-level derived authentication key.
14. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to:
generate a first-level pairwise master key at the one of the plurality of network access servers based on at least one of a master secret key, a service set identifier, a mobility domain identifier, a network access server identifier, a separator, or a sender protocol address; and
generate a key name corresponding to the first-level pairwise master key based on at least one of the service set identifier, the mobility domain identifier, the network access server identifier, the separator, the sender protocol address, or a nonce value.
15. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to receive the first-level derived authentication key and a key name from an authentication server, and wherein the key name corresponds to the first-level derived authentication key.
16. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to forward at least one of the plurality of second-level derived authentication keys to at least one of the plurality of network access servers.
17. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to:
generate a session key for a session with a subscriber station based on one of the plurality of second-level derived authentication keys; and
generate a key name corresponding to the session key.
18. An article of manufacture as defined in claim 10, wherein the content, when accessed, causes the machine to:
generate a pairwise temporal key based on at least one of a second-level pairwise master key, a key derivation function, a first nonce value, a second nonce value, a first network access server identifier, a second network access server identifier, a basic service set identifier, or a sender protocol address; and
generate a key name corresponding to the pairwise temporal key based on at least one of a secure hash function, the first nonce value, the second nonce value, the basic service set identifier, or the sender protocol address.
19. An apparatus comprising:
a first network access server to generate a plurality of second-level derived authentication keys based on a first-level derived authentication key, at least one of the plurality of second-level derived authentication keys being associated with a second network access server; and
a key name generator coupled to the network access server to generate a plurality of key names, at least one of the plurality of key names corresponding to one of the plurality of second-level derived authentication keys,
wherein the first and second network access servers are associated with a plurality of network access servers of a mobility domain.
20. An apparatus as defined in claim 19, wherein the first network access server generates the first-level derived authentication key based on a master authentication key from an authentication server, and wherein the key name generator generates a key name corresponding to the first-level derived authentication key.
21. An apparatus as defined in claim 19, wherein the first network access server receives the first-level derived authentication key and a key name from an authentication server, and wherein the key name corresponds to the first-level derived authentication key.
22. An apparatus as defined in claim 19 further comprising a communication interface to securely forward at least one of the plurality of second-level derived authentication keys to the second network access server.
23. An apparatus as defined in claim 19 further comprising an authenticator to generate a session key for a session with a subscriber station based on one of the plurality of second-level derived authentication keys, wherein the key name generator generates a key name corresponding to the session key.
24. An apparatus as defined in claim 19, wherein the first network access server is integrated within a controller of at least one of an access point or a base station.
25. A system comprising:
an omni-directional antenna; and
a processor coupled to the omni-directional antenna to generate a plurality of second-level derived authentication keys at one of a plurality of network access servers of a mobility domain based on a first-level derived authentication key and to generate a plurality of key names,
wherein each of the plurality of second-level derived authentication keys is associated with one of the plurality of network access servers, and
wherein at least one of the plurality of key names corresponds to one of the plurality of second-level derived authentication keys.
26. A system as defined in claim 25, wherein the processor generates the first-level derived authentication key based on a master authentication key from an authentication server, and generates a key name corresponding to the first-level derived authentication key.
27. A system as defined in claim 25, wherein the processor receives the first-level derived authentication key and a key name from an authentication server, and wherein the key name corresponds to the first-level derived authentication key.
28. A system as defined in claim 25, wherein the processor forwards at least one of the plurality of second-level derived authentication keys to at least one of the plurality of network access servers.
29. A system as defined in claim 25, wherein the processor generates a session key for a session with a subscriber station based on one of the plurality of second-level derived authentication keys, and generates a key name corresponding to the session key.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1-3. (canceled).
4. A salicide butting contact structure comprising:
a contact region including a first area of a first conductivity type and a second area of a second conductivity type opposite to said first conductivity type surrouding and adjacent to said first area;
and contacting said first and second areas;
a second insulator covering said salicide;
a contact window formed in said second insulator and exposing a surface of said salicide; and
a conductor filled in said contact window and contacting said surface of said salicide.
5. A salicide butting contact structure of claim 4, wherein said first and second areas are heavily doped.
6. (canceled).
7. A butting contact method comprising the steps of:
forming a first area of a first conductivity type and a second area of a second conductivity type opposite to said first conductivity type and surrounding and adjacent to said first area;
forming a salicide by using a first insulator as a mask and contacting said first and second areas;
depositing a second insulator on said salicide;
etching a contact window in said second insulator and exposing a surface of said salicide; and
filling a conductor in said contact window and contacting said surface of said salicide.