A fast authentication and access control method of authenticating a
network access device to a communications network having an access point
communicating with a remote authentication (home AAA) server for the
network access device. The method includes the step of receiving an
access request having an authentication credential from the network
access device at the access point. The authentication credential includes
a security certificate having a public key for the network access device
and an expiration time. The security certificate is signed with a private
key for the remote authentication server. The access point locally
validates the authentication credential by accessing the public key of
the remote authentication server from a local database, and checking the
signature and expiration time of the security certificate. If the
authentication credential is validated at the access point, the access
point grants the network access device conditional access to the network
by sending an access granted message to the network access device. The
access granted message includes a session key encrypted with a public key
for the network access device. The session key is stored in a database
associated with the access point. The access point contacts the remote
authentication server to check a revocation status of the security
certificate for the network access device. If the access point receives a
message from the remote authentication server that the authentication
credential for the network access device has been revoked, it suspends
network access for the network access device.