A wireless network is connectable to an authentication server. Each access
point in the wireless network includes a supplicant processing unit, an
authenticator processing unit, and a function selector. When an access
point is detected within communication range, the function selector
selects either the supplicant processing unit or the authenticator
processing unit. The selected unit operates to carry out or mediate an
authentication protocol and establish a secure wireless link, protected
by a pairwise encryption key, between the two access points. Because
every access point can operate as either an authenticator or a
supplicant, it is not necessary to invoke the services of a master
authenticator. If an encryption key is compromised, the effect is limited
and does not force the entire network to be shut down.