An authentication and mass subscriber management technique is provided by
employing a key table derived as a subset of a larger key pool, a network
edge device, and authentication tokens attached on both the network edge
device and on a subscriber's computing device. The network edge device
and subscriber's computing device are provided with secure,
tamper-resistant network keys for encrypting all transactions across the
wired/wireless segment between supplicant (subscriber) and authenticator
(network edge device). In an embodiment of the invention, a secure,
secret user key is shared between a number of subscribers based upon
commonalities between serial numbers of those subscribers' tokens. In
another embodiment of the invention, a unique session key is generated
for each subscriber even though multiple subscribers connected to the
same network connection point might have identical pre-stored secret
keys.