T-Mobile Rolls Out Strong Security at Wi-Fi Hot Spots

By Carol Ellison  |  Posted 2004-10-07 Print this article Print

Aiming to provide a "tipping point" for corporate Wi-Fi adoptions, the U.S. wireless carrier brings strong 802.1x security with authentication and encryption to its 4,700 hot spots.

In a move it expects will allay the concerns of enterprise customers, T-Mobile is introducing strong, 802.1x-based authentication and encryption across its network of 4,700 hot spots. The move, which appears to be the first use of advanced 802.1x-based security by a national mobile carrier in U.S. hot spots, leverages the existing 802.1x infrastructure used to authenticate GSM (Global System for Mobile Communications)/GPRS (General Packet Radio Service) cell-phone users. "CIOs across the country have been asking for enhanced security, and were the first U.S. wireless carrier to deliver it," said Joe Sims, vice president and general manager of T-Mobile HotSpot.
"The rollout of 802.1x across our network will enable IT managers and business professionals to use T-Mobile HotSpot as a more secure virtual extension of their corporate networks and offices," Sims said.
"One of the final barriers to significant corporate adoption of Wi-Fi was removed for professionals and companies looking to enhance their mobility strategy." The announcement is also likely to come as good news to mobile and Wi-Fi industries, which have struggled with questions of how to support 802.1x-based security schemes in hot spots that lack the IT staffs to manage them. 802.1x provides the authentication and encryption framework used in the advanced Wi-Fi security specifications 802.11i and WPA (Wi-Fi Protected Access), which were developed to address vulnerabilities identified in WEP (Wired Equivalent Protocol), the original security mechanism for 802.11 WLANs. WPA was adopted by the Wi-Fi Alliance last year. 802.11i with AES (Advanced Encryption Standard) security was ratified by the IEEE in July. Even before the adoption of those standards, 802.1x was used in "dynamic WEP" (Wired Equivalent Privacy) to bring additional layers of security to WLANs. Read more here about the ratification of the 802.11i standard. "Our advanced security is really our implementation of WPA," said Mark Bolger, director of brand marketing for T-Mobile HotSpot. Strong security in WPA and 802.11i—also known as WPA2—speeded the adoption of Wi-Fi networks in the enterprise, where the market has traditionally lagged behind the home due to security concerns. Enterprises remained wary of the use of hot spots, which were largely unsecured because of the difficulty of managing the IT infrastructure in coffee shops, restaurants and other public venues that lack on-site IT staffs. Looking for a Wi-Fi hot-spot? Click here to use eWEEK.coms Hot-Spot Finder. 802.1x networks require an authentication server (usually RADIUS) or database to store user credentials, as well as the installation on client devices of a "supplicant"—a small software program that establishes communications with the server using an EAP (Extensible Authentication Protocol) type. Paul Lopez, senior manager of advanced technologies at T-Mobile, said the company is addressing that problem in an upgrade to its T-Mobile Connection Manager software. The software includes the client supplicant and can be downloaded for free from the T-Mobile Web site. Current T-Mobile Wi-Fi customers will be prompted to upgrade when they connect to the network. The software is also available on CD at many local T-Mobile stores and hot spots. EAP protocols, already widely used in the mobile environment, are the mechanism in the SIM (Simple Identity Management) cards used to handle authentication and accounting across GSM/GPRS mobile-phone networks. T-Mobile plans to leverage the 802.1x infrastructure already in place for its wide area GSM/GPRS network to extend 802.1x authentication to the hot-spots. Bolger of T-Mobile HotSpot said he expects that this ability to centrally secure and monitor performance at each hot-spot location will be "a tipping point for corporate adoptions" of the companys phone/Wi-Fi services. Kevin Walsh, director of product management at Funk Software, a developer of remote authentication technologies that works with a number of GSM/GPRS carriers, said GPRS operators have been looking at introducing 802.1x authentication to hot spots for some time. The hurdle has always been "the burden of supporting the end-user machine," Walsh said. "Im excited about T-Mobiles interest in this because now we have a world-class operator saying, This is the best way to do this." Check out eWEEK.coms Mobile & Wireless Center at http://wireless.eweek.com for the latest news, reviews and analysis.

Be sure to add our eWEEK.com mobile and wireless news feed to your RSS newsreader or My Yahoo page

Carol Ellison is editor of eWEEK.com's Mobile & Wireless Topic Center. She has authored whitepapers on wireless computing (two on network security–,Securing Wi-Fi Wireless Networks with Today's Technologies, Wi-Fi Protected Access: Strong, Standards-based Interoperable Security for Today's Wi-Fi Networks, and Wi-Fi Public Access: Enabling the future with public wireless networks.

Ms. Ellison served in senior and executive editorial positions for Ziff Davis Media and CMP Media. As an executive editor at Ziff Davis Media, she launched the networking track of The IT Insider Series, a newsletter/conference/Web site offering targeted to chief information officers and corporate directors of information technology. As senior editor at CMP Media's VARBusiness, she launched the Web site, VARBusiness University, an online professional resource center for value-added resellers of information technology.

Ms. Ellison has chaired numerous industry panels and has been quoted as a networking and educational technology expert in The New York Times, Newsday, The Los Angeles Times and The Wall Street Journal, National Public Radio's All Things Considered, CNN Headline News, WNBC and CNN/FN, as well as local and regional Comcast and Cablevision reports. Her articles have appeared in most major hi-tech publications and numerous newspapers and magazines, including The Washington Post and The Christian Science Monitor.

Submit a Comment

Loading Comments...
Manage your Newsletters: Login   Register My Newsletters

Rocket Fuel