(LAN) enter the distribution system (DS) of an extended service set
(ESS).
Distribution System Service (DSS): The set of services provided by
the distribution system (DS) that enable the medium access control
(MAC) layer to transport MAC service data units (MSDUs) between
stations that are not in direct communication with each other over a
single instance of the wireless medium (WM). These services include
the transport of MSDUs between the access points (APs) of basic
service sets (BSSs) within an extended service set (ESS), transport
of MSDUs between portals and BSSs within an ESS, and transport of
MSDUs between stations in the same BSS in cases where the MSDU has a
multicast or broadcast destination address, or where the destination
is an individual address, but the station sending the MSDU chooses to
involve DSS. DSSs are provided between pairs of IEEE 802.11 MACs.
Integration: The service that enables delivery of medium access
control (MAC) service data units (MSDUs) between the distribution
system (DS) and an existing, non-IEEE 802.11 local area network (via
a portal).
Distribution: The service that, by using association information,
delivers medium access control (MAC) service data units (MSDUs)
within the distribution system (DS).
3.2. Terminology Used in This Document
One of the motivations in defining new terminology is to clarify
ambiguity and confusion surrounding some conventional terms. One
such term is "Access Point (AP)". Typically, when people talk about
"AP", they refer to the physical entity (box) that has an antenna,
implements 802.11 PHY, and receives/transmits the station (STA)
traffic over the air. However, the 802.11 Standard [1] describes the
AP mostly as a logical entity that implements a set of logical
services so that station traffic can be received and transmitted
effectively over the air. When people refer to "AP functions", they
usually mean the logical functions the whole WLAN access network
supports, and not just the subset of functions supported by the
physical entity (box) that the STAs communicate with directly. Such
confusion can be especially acute when logical functions are
implemented across a network instead of within a single physical
entity. To avoid further confusion, we define the following
terminology:
CAPWAP: Control and Provisioning of Wireless Access Points
IEEE 802.11 WLAN Functions: A set of logical functions defined by the
IEEE 802.11 Working Group, including all the MAC services, Station
Services, and Distribution Services. These logical functions are
required to be implemented in the IEEE 802.11 Wireless LAN (WLAN)
access networks by the IEEE 802.11 Standard [1].
CAPWAP Functions: A set of WLAN control functions that are not
directly defined by IEEE 802.11 Standards, but deemed essential for
effective control, configuration, and management of 802.11 WLAN
access networks.
Wireless Termination Point (WTP): The physical or network entity that
contains an RF antenna and 802.11 PHY to transmit and receive station
traffic for the IEEE 802.11 WLAN access networks. Such physical
entities were often called "Access Points" (AP), but "AP" can also
refer to the logical entity that implements 802.11 services. We
recommend "WTP" as the generic term that explicitly refers to the
physical entity with the above property (e.g., featuring an RF
antenna and 802.11 PHY), applicable to network entities of both
Autonomous and Centralized WLAN Architecture (see below).
Autonomous WLAN Architecture: The WLAN access network architecture
family in which all the logical functions, including both IEEE 802.11
and CAPWAP functions (wherever applicable), are implemented within
each Wireless Termination Point (WTP) in the network. The WTPs in
such networks are also called standalone APs, or fat APs, because
these devices implement the full set of functions that enable the
devices to operate without any other support from the network.
Centralized WLAN Architecture: The WLAN access network architecture
family in which the logical functions, including both IEEE 802.11 and
CAPWAP functions (wherever applicable), are implemented across a
hierarchy of network entities. At the lower level are the WTPs,
while at the higher level are the Access Controllers (ACs), which are
responsible for controlling, configuring, and managing the entire
WLAN access network.
Distributed WLAN Architecture: The WLAN access network architecture
family in which some of the control functions (e.g., CAPWAP
functions) are implemented across a distributed network consisting of
peer entities. A wireless mesh network can be considered an example
of such an architecture.
Access Controller (AC): The network entity in the Centralized WLAN
Architecture that provides WTPs access to the centralized
hierarchical network infrastructure in the data plane, control plane,
management plane, or a combination therein.
Standalone WTP: Refers to the WTP in Autonomous WLAN Architecture.
Controlled WTP: Refers to the WTP in Centralized WLAN Architecture.
Split MAC Architecture: A subgroup of the Centralized WLAN
Architecture whereby WTPs in such WLAN access networks only implement
the delay sensitive MAC services (including all control frames and
some management frames) for IEEE 802.11, while all the remaining
management and data frames are tunnelled to the AC for centralized
processing. The IEEE 802.11 MAC, as defined by IEEE 802.11 Standards
in [1], is effectively split between the WTP and AC.
Remote MAC Architecture: A subgroup of the Centralized WLAN
Architecture, where the entire set of 802.11 MAC functions (including
delay-sensitive functions) is implemented at the AC. The WTP
terminates the 802.11 PHY functions.
Local MAC Architecture: A subgroup of the Centralized WLAN
Architecture, where the majority or entire set of 802.11 MAC
functions (including most of the 802.11 management frame processing)
are implemented at the WTP. Therefore, the 802.11 MAC stays intact
and local in the WTP, along with PHY.
3.3. Terminology Used Historically but Not Recommended
While some terminology has been used by vendors historically to
describe "Access Points", we recommend deferring its use, in order to
avoid further confusion. A list of such terms and the recommended
new terminology is provided below:
Split WLAN Architecture: Use Centralized WLAN Architecture.
Hierarchical WLAN Architecture: Use Centralized WLAN Architecture.
Standalone Access Point: Use Standalone WTP.
Fat Access Point: Use Standalone WTP.
Thin Access Point: Use Controlled WTP.
Light weight Access Point: Use Controlled WTP.
Split AP Architecture: Use Local MAC Architecture.
Antenna AP Architecture: Use Remote MAC Architecture.
4. Autonomous Architecture
4.1. Overview
Figure 1 shows an example network of the Autonomous WLAN
Architecture. This architecture implements all the 802.11
functionality in a single physical device, the Wireless Termination
Point (WTP). An embodiment of this architecture is a WTP that
translates between 802.11 frames to/from its radio interface and
802.3 frames to/from an Ethernet interface. An 802.3 infrastructure
that interconnects the Ethernet interfaces of different WTPs provides
the distribution system. It can also provide portals for integrated
802.3 LAN segments.
+---------------+ +---------------+ +---------------+
| 802.11 BSS 1 | | 802.11 BSS 2 | | 802.11 BSS 3 |
| ... | | ... | | ... |
| +-----+ | | +-----+ | | +-----+ |
+----| WTP |----+ +----| WTP |----+ +----| WTP |----+
+--+--+ +--+--+ +--+--+
|Ethernet | |
+------------------+ | +------------------+
| | |
+---+--+--+---+
| Ethernet |
802.3 LAN --------------+ Switch +-------------- 802.3 LAN
segment 1 | | segment 2
+------+------+
Figure 1: Example of Autonomous WLAN Architecture
A single physical WTP can optionally be provisioned as multiple
virtual WTPs by supporting multiple SSIDs to which 802.11 clients may
associate. In some cases, this will involve putting a corresponding
802.1Q VLAN tag on each packet forwarded to the Ethernet
infrastructure and removing 802.1Q tags prior to forwarding the
packets to the wireless medium.
The scope of the ESS(s) created by interconnecting the WTPs will be
confined by the constraints imposed by the Ethernet infrastructure.
Authentication of 802.11 clients may be performed locally by the WTP
or by using a centralized authentication server.
4.2. Security
Since both the 802.11 and CAPWAP functions are tightly integrated
into a single physical device, security issues with this architecture
are confined to the WTP. There are no extra implications from the
client authentication and encryption/decryption perspective, as the
AAA interface and the key generation mechanisms required for 802.11i
encryption/decryption are integrated into the WTP.
One of the security needs in this architecture is for mutual
authentication between the WTP and the Ethernet infrastructure. This
can be ensured by existing mechanisms such as 802.1X between the WTP
and the Ethernet switch to which it connects. Another critical
security issue is the fact that the WTP is most likely not under lock
and key, but contains secret information to communicate with back-end
systems, such as AAA and SNMP. Because IT personnel uses the common
management method of pushing a "template" to all devices, theft of
such a device would potentially compromise the wired network.
5. Centralized WLAN Architecture
Centralized WLAN Architecture is an emerging architecture family in
the WLAN market. Contrary to the Autonomous WLAN Architecture, where
the 802.11 functions and network control functions are all
implemented within each Wireless Termination Point (WTP), the
Centralized WLAN Architecture employs one or more centralized
controllers, called Access Controller(s), to enable network-wide
monitoring, improve management scalability, and facilitate dynamic
configurability.
The following figure schematically shows the Centralized WLAN
Architecture network diagram, where the Access Controller (AC)
connects to multiple Wireless Termination Points (WTPs) via an
interconnection medium. This can be a direct connection, an L2-
switched, or an L3-routed network as described in Section 5.1. The
AC exchanges configuration and control information with the WTP
devices, allowing the management of the network from a centralized
point. Designs of the Centralized WLAN Architecture family do not
presume (as the diagram might suggest) that the AC necessarily
intercedes in the data plane to/from the WTP(s). More details are
provided later in this section.
+---------------+ +---------------+ +---------------+
| 802.11 BSS 1 | | 802.11 BSS 2 | | 802.11 BSS 3 |
| ... | | ... | | ... |
| +-------+ | | +-------+ | | +-------+ |
+----| WTP |--+ +----| WTP |--+ +----| WTP |--+
+---+---+ +---+---+ +---+---+
| | |
+------------------+ | +-----------------+
| |...|
+----+--+---+--------+
| Interconnection |
+-------+------------+
|
|
+-----+----+
| AC |
+----------+
Figure 2: Centralized WLAN Architecture Diagram
In the diagram above, the AC is shown as a single physical entity
that provides all of the CAPWAP functions listed in Section 1.2.
However, this may not always be the case. Closer examination of the
functions reveals that their different resource requirements (e.g.,
CPU, memory, storage) may be distributed across different devices.
For instance, complex radio control algorithms can be CPU intensive.
Storing and downloading images and configurations can be storage
intensive. Therefore, different CAPWAP functions might be
implemented on different physical devices due to the different nature
of their resource requirements. The network entity marked ’AC’ in
the diagram above should be thought of as a multiplicity of logical
functions, and not necessarily as a single physical device. The ACs
may also choose to implement some control functions locally, and
provide interfaces to access other global network management
functions, which are typically implemented on separate boxes, such as
a SNMP Network Management Station and an AAA back-end server (e.g.,
Radius Authentication Server).
5.1. Interconnection between WTPs and ACs
There are several connectivity options to consider between the AC(s)
and the WTPs, including direct connection, L2 switched connection,
and L3 routed connection, as shown in Figures 3, 4, and 5.
-------+------ LAN
|
+-------+-------+
| AC |
+----+-----+----+
| |
+---+ +---+
| |
+--+--+ +--+--+
| WTP | | WTP |
+--+--+ +--+--+
Figure 3: Directly Connected
-------+------ LAN
|
+-------+-------+
| AC |
+----+-----+----+
| |
+---+ +---+
| |
+--+--+ +-----+-----+
| WTP | | Switch |
+--+--+ +---+-----+-+
| |
+-----+ +-----+
| WTP | | WTP |
+-----+ +-----+
Figure 4: Switched Connections
+-------+-------+
| AC |
+-------+-------+
|
--------+------ LAN
|
+-------+-------+
| Router |
+-------+-------+
|
-----+--+--+--- LAN
| |
+---+ +---+
| |
+--+--+ +--+--+
| WTP | | WTP|
+--+--+ +--+--+
Figure 5: Routed Connections
5.2. Overview of Three Centralized WLAN Architecture Variants
Dynamic and consistent network management is one of the primary
motivations for the Centralized Architecture. The survey data from
vendors also shows that different varieties of this architecture
family have emerged to meet a complex set of different requirements
for various possible deployment scenarios. This is also a direct
result of the inherent flexibility in the 802.11 standard [1]
regarding the implementation of the logical functions that are
broadly described under the term "Access Point (AP)". Because there
is no standard mapping of these AP functions to physical network
entities, several design choices have been made by vendors that offer
related products. Moreover, the increased demand for monitoring and
consistent configuration of large wireless networks has resulted in a
set of ’value-added’ services provided by the various vendors, most
of which share common design properties and service goals.
In the following, we describe the three main variants observed from
the survey data within the family of Centralized WLAN Architecture,
namely the Local MAC, Split MAC, and Remote MAC approaches. For each
approach, we provide the mapping characteristics of the various
functions into the network entities from each vendor. The naming of
Local MAC, Split MAC, and Remote MAC reflects how the functions, and
especially the 802.11 MAC functions, are mapped onto the network
entities. Local MAC indicates that the MAC functions stay intact and
local to WTPs, while Remote MAC denotes that the MAC has moved away
from the WTP to a remote AC in the network. Split MAC shows the MAC
being split between the WTPs and ACs, largely along the line of
realtime sensitivity. Typically, Split MAC vendors choose to put
realtime functions on the WTPs while leaving non-realtime functions
to the ACs. 802.11 does not clearly specify what constitutes
realtime functions versus non-realtime functions, and so a clear and
definitive line does not exist. As shown in Section 5.4, each vendor
has its own interpretation on this, and there are some discrepancies
about where to draw the line between realtime and non-realtime
functions. However, vendors agree on the characterization of the
majority of MAC functions. For example, every vendor classifies the
DCF as a realtime function.
The differences among Local MAC, Split MAC and Remote MAC
architectures are shown graphically in the following figure:
+--------------+--- +---------------+--- +--------------+---
| CAPWAP | | CAPWAP | | CAPWAP |
| functions |AC | functions |AC | functions |
|==============|=== |---------------| |--------------|
| | | non RT MAC | | |AC
| 802.11 MAC | |===============|=== | 802.11 MAC |
| |WTP | Realtime MAC | | |
|--------------| |---------------|WTP |==============|===
| 802.11 PHY | | 802.11 PHY | | 802.11 PHY |WTP
+--------------+--- +---------------+--- +--------------+---
(a) "Local MAC" (b) "Split MAC" (c) "Remote MAC"
Figure 6: Three Architectural Variants within the Centralized
WLAN Architecture Family
5.3. Local MAC
The main motivation of the Local MAC architecture model, as shown in
Figure 6 (a), is to offload network access policies and management
functions (CAPWAP functions described in Section 1.2) to the AC
without splitting the 802.11 MAC functionality between WTPs and AC.
The whole 802.11 MAC resides on the WTPs locally, including all the
802.11 management and control frame processing for the STAs. On the
other hand, information related to management and configuration of
the WTP devices is communicated with a centralized AC to facilitate
management of the network and maintain a consistent network-wide
configuration for the WTP devices.
Figure 7 shows a tabular representation of the design choices made by
the six vendors in the survey that follow the Local MAC approach,
with respect to the above mentioned architecture considerations.
"WTP-AC connectivity" shows the type connectivity between the WTPs
and AC that every vendor’s architecture can support. Clearly, all
the vendors can support L3 routed network connectivity between WTPs
and the AC, which implies that direct connections and L2 switched