Authentication Overview

Vocera devices support WPA2 (AES-CCMP encryption), with PEAP (MS-CHAP v2, GTC), EAP-TLS, EAP-FAST, and PSK authentication.

Wi-Fi Protected Access 2 (WPA2), a pre-shared key, is a secure and strong encryption protocol. It is a stronger algorithm for message integrity and confidentiality. It utilizes AES (Advanced Encryption Standard) in conjunction with counter mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP.)

These protocols require back-end authentication servers to authenticate client credentials the first time a client connects to the network, each time the client roams, and at periodic intervals. Various properties control how often the authentication occurs, and in the case of WPA-PEAP and EAP-FAST, whether a full authentication or a fast authentication occurs.

The authentication that occurs the first time a client connects to the network is not noticeable to a badge user because it appears to be part of the general boot and connection procedure. However, the authentication that occurs during roaming or at a timeout interval can interrupt a conversation. This happens because to packets are lost while the authentication server processes credentials and re-authenticates the badge. You can optimize badge performance by allowing fast reconnects and setting a lengthy timeout interval..