A Method and System for Issuing WAPI Wireless Private Network Certificates

The WAPI certificate issuance system with a GW and CIS connected via a bi-directional gateway addresses inefficiencies and security risks by enabling secure, automated certificate issuance for wireless devices in high-security environments.

CN115085938BActive Publication Date: 2025-07-15SHENZHEN ZHIKAI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210773230.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-01
Publication Date
2025-07-15
Estimated Expiration
2042-07-01

AI Technical Summary

Technical Problem

The existing WAPI wireless private network certificate issuance process is inefficient and has safety risks. Especially when the security requirements for internal and external network data interaction in the power industry are high, manual operations are cumbersome and unsafe.

Method used

The WAPI wireless private network certificate issuance system is adopted, including WAPI terminal, certificate authentication server, certificate management server and certificate issuance application gateway. It connects through a two-way network gate, sends authorization codes to authenticate by using mobile phone SMS, and generates and transmits certificates online to ensure security and efficiency.

Benefits of technology

It realizes the online, safe and efficient issuance of WAPI certificates, avoiding inefficiency and safety hazards in manual operations, and significantly improving work efficiency and safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115085938B_ABST
    Figure CN115085938B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for issuing WAPI wireless private network certificates, including a WAPI terminal (STA), a WAPI certificate authentication server (AS), a certificate management server (CIS), and a certificate issuance application gateway (GW). It is characterized in that a two-way network isolation device is connected between the GW and the CIS, the AS and the CIS are located in the internal network, and the GW is located in the external network and has a short message sending module. By using the method and system for issuing WAPI wireless private network certificate applications disclosed in the present invention, WAPI wireless terminal devices can complete the issuance application of WAPI certificates online, and this process is safe, convenient, and efficient, especially meeting the needs of industries such as the power industry where the security requirements for internal and external network data interaction are particularly high. There is no longer a need for the inefficient and cumbersome internal and external network file copying operations in the manual process of WAPI certificate applications, which can significantly improve the convenience and work efficiency of related processes, and can also avoid possible errors in the manual process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method and system for issuing WAPI wireless private network certificates. Background Art

[0002] WAPI is the WLAN security standard and technology specified in the Chinese national standard for wireless local area networks, GB15629.11. WAPI uses digital certificates to identify the identities of wireless access points (APs) and wireless terminals (STAs), and conducts identity authentication of APs and STAs based on a three-factor authentication system, ensuring the security of wireless access authentication. In a WAPI wireless local area network with high security requirements, both APs and STAs need to install WAPI digital certificates for three-factor authentication, which is an important basis for ensuring the security of WAPI wireless networks. There are usually two ways to generate WAPI wireless terminal certificates:

[0003] Method A: The WAPI certificate authentication server (AS) generates a key pair (including a public key and a private key) for the WAPI wireless terminal, generates a WAPI public key certificate based on the public key among them, and signs the public key certificate with the private key of the AS; then, the public key certificate and private key of the terminal device are transmitted to the WAPI terminal for installation through a secure channel; this process requires a secure channel for certificate transmission because it includes sensitive information - the private key. In this process, in addition to checking the identity of the applicant, it is also necessary to ensure the privacy and tamper resistance of the message. If this secure channel is implemented online, it is necessary to encrypt the transmitted information or process it in a secure tunnel.

[0004] Method B: The WAPI terminal generates a key pair (including a public key and a private key) by itself and then generates a certificate signing request file, which is called a P10 file (abbreviation for the international standard PKCS#10). The P10 file includes information about the terminal device (applicant organization, device name, etc.) and public key information, but does not include private key information; the P10 file is transmitted to the AS, and the AS generates a public key certificate file for the applicant based on the P10 file, and signs the public key certificate file with the private key of the AS; then, the public key certificate file is issued to the applicant for installation. In this process, the private key information of the terminal device is not included. In the transmission process, only the identity of the applicant needs to be checked and the transmitted information needs to be checked for tamper resistance, and there are no other security requirements.

[0005] In recent years, with the advancement of digitalization and intelligence, WAPI wireless networks have been increasingly applied in some key infrastructure industries. For example, the WAPI wireless private network constructed in the power industry. Such wireless local area networks have high security requirements. The wireless local area network formed by APs is located in the external network, while the WAPI authentication server (AS) is located in the internal network. With the advancement of the construction of such WAPI wireless private networks, more and more mobile operation terminals are connected to the WAPI wireless private network, such as robots, tablet computers, law enforcement recording instruments, intelligent helmets, etc. However, in actual use, the installation of WAPI certificates for these operation terminals still adopts manual methods, including the aforementioned Method A and Method B, which are inefficient. Moreover, in some cases, based on Method A, there is no secure transmission channel that can ensure confidentiality, thus posing security risks. There is a need for a secure, convenient, and efficient WAPI certificate issuance method and system applicable to such WAPI wireless private networks.

[0006] The current process of WAPI certificate issuance in the power grid industry is as follows: The WAPI wireless terminal generates a P10 file, and the P10 file is transmitted to the certificate application management personnel via email or WeChat. The certificate application management personnel copy the P10 file to a secure USB flash drive on an external network computer, and then insert the secure USB flash drive into an internal network computer, copy the P10 file from the secure USB flash drive to the internal network computer, and then open the WEB interface of the WAPI authentication server to submit the P10 file to generate a new certificate. The newly generated WAPI certificate is stored in the secure USB flash drive on the internal network computer. Then, insert the secure USB flash drive into the external network computer again, and send the newly generated WAPI certificate file and the public key file of the AS to the applicant through the external network computer. This process is very inefficient and inconvenient, and there is an urgent need for an online, convenient, and efficient WAPI certificate issuance method and system to solve the problem of WAPI certificate issuance applications. Summary of the Invention

[0007] The purpose of the present invention is to solve the deficiencies existing in the prior art, and a method and system for issuing WAPI wireless private network certificates are proposed.

[0008] In order to achieve the above purpose, the present invention adopts the following technical solutions:

[0009] A system for issuing WAPI wireless private network certificates includes a WAPI terminal (STA), a WAPI certificate authentication server (AS), a certificate management server (CIS), and a certificate issuance application gateway (GW). It is characterized in that a two-way network isolation device is connected between the GW and the CIS, the AS and the CIS are located in the internal network, and the GW is located in the external network and has a short message sending module.

[0010] As a further technical solution of the present invention, the WAPI terminal, abbreviated as STA, is a terminal device of the WAPI wireless network, including robots, tablets, law enforcement recorders, smart helmets, etc. These WAPI terminal devices have the ability of WAPI wireless connection and non-WAPI network connection. The latter includes the ability to connect to the WI-FI wireless network or through a wired connection network, and have the program of the method described in this patent to connect to the certificate application gateway, send verification code acquisition messages and WAPI certificate application messages, and receive certificate application reply messages from the certificate application gateway.

[0011] As a further technical solution of the present invention, the WAPI certificate authentication server, abbreviated as AS, is a certificate authentication unit of the WAPI wireless network and also generates WAPI certificates based on P10 files; in the system described in this patent, it can also respond to the certificate issuance requests of the WAPI certificate management system.

[0012] As a further technical solution of the present invention, the WAPI certificate management server (WAPI Certificate Information System), abbreviated as CIS, realizes the comprehensive management of certificates, generally including the management of applicants and device information, and also manages the processes such as certificate application and cancellation.

[0013] As a further technical solution of the present invention, the WAPI certificate issuance application gateway, abbreviated as GW, is located outside the network and realizes receiving requests related to WAPI certificate issuance applications from outside the network and forwarding these request messages to the WAPI certificate management server in the internal network through a two-way physical isolation network switch; at the same time, the WAPI certificate issuance application gateway also has the ability to send mobile phone text messages to send text messages to the applicant's mobile phone, and the text message content is mainly the authorization code in the WAPI certificate application process.

[0014] In the present invention, a method for issuing WAPI wireless private network certificates includes the following steps:

[0015] S1: First, the applicant for WAPI certificate issuance needs to register some information of the applicant in the WAPI certificate management server CIS by the system administrator, and the mobile phone number is a necessary information item;

[0016] S2: When a WAPI certificate issuance applicant wants to apply for a WAPI certificate for a certain WAPI terminal device, the certificate applicant operates the WAPI terminal device to temporarily connect the WAPI terminal device to the external network, mainly through a wired connection to the external network; the certificate applicant fills in the mobile phone number registered in the WAPI certificate management server CIS through the authorization code acquisition function interface of the WAPI certificate issuance application program of the WAPI terminal device, and then operates the program interface to send an authorization code acquisition message to the WAPI certificate issuance application gateway GW;

[0017] S3: After receiving the authorization code acquisition message, the WAPI certificate issuance application gateway GW sends the relevant information to the WAPI certificate management server CIS through the network isolation device; after receiving the authorization code acquisition information, the WAPI certificate management server CIS checks whether the mobile phone number in the authorization code acquisition information is a registered mobile phone number. If it is, it will reply with an authorization code response message to the certificate application gateway. If the relevant mobile phone number is not registered, there will be no response;

[0018] S4: After obtaining the authorization code reply message from the CIS, the WAPI certificate issuance application gateway will send the authorization code to the mobile phone number of the WAPI certificate issuance applicant by SMS;

[0019] S5: After obtaining the authorization code from the mobile phone, the WAPI certificate issuance applicant will operate the WAPI certificate application program of the WAPI wireless terminal to start the certificate application process. This process includes generating a WAPI key pair (including a public key and a private key), a WAPI certificate application file, that is, a P10 file, and generating an application number ID. Then, through the WAPI certificate application program, the application number ID, the P10 file, the applicant's mobile phone number, and the authentication code are sent to the WAPI certificate application gateway; the authentication code is calculated based on the authorization code obtained by the applicant from the mobile phone SMS;

[0020] S6: After receiving the WAPI certificate issuance application message, the WAPI certificate application gateway GW forwards the message in it to the WAPI certificate management server through the network isolation device;

[0021] S7: After the WAPI certificate management server CIS receives the WAPI certificate application message, it decrypts the message content and parses to obtain the application number ID, P10 file, applicant's mobile phone number, and authentication code, and then performs a legality check, including: a) Checking the authentication code: Search for the authorization code in the CIS database according to the mobile phone number. If found, calculate the authentication code. The calculation method is the same as that of the WAPI wireless terminal, and use the calculated result to check the received authentication code. If the authorization code is not found, no response is made; b) Verifying the signature value of the P10 file. If the verification fails, no response is made. If both checks pass, the WAPI certificate management server CIS sends a WAPI certificate issuance request message to the WAPI authentication server, which includes the P10 file.

[0022] S8: After the WAPI authentication server AS receives the WAPI certificate issuance request message from the CIS, it generates a WAPI certificate, and then sends the generated certificate and its own public key certificate to the WAPI certificate management server CIS; The generation of the WAPI certificate is to generate the content of the WAPI certificate based on the P10 file and sign the certificate content with the private key of AS. Because the private key of AS is used in this process, which is private data that other servers except AS do not have, it is necessary to finally send the certificate issuance request message to AS to issue and generate the certificate.

[0023] S9: After the WAPI certificate management server receives the WAPI certificate issued by AS and the public key certificate of AS, it forms a WAPI certificate issuance application response message and sends it to the WAPI wireless terminal device STA through the network gateway; The issuance application response message includes the corresponding application number ID, the newly issued certificate, and the public key certificate of AS. The issuance application response message is not encrypted because there is no information that needs to be kept confidential.

[0024] S10: After the WAPI wireless terminal STA receives the issuance application response message, it parses the message to obtain the application number ID, the newly issued certificate, and the public key certificate of AS. Use the application number ID to find the public key certificate in the local area of STA, and compare the local public key with the public key in the newly issued certificate. If they are the same, further use the public key certificate of AS to check the newly issued certificate. If the signature verification passes, it indicates that the message has not been tampered with, and the newly issued certificate and the public key certificate of AS are trustworthy, and the online issuance application of the WAPI certificate is successfully completed.

[0025] As a further technical solution of the present invention, in S5, the calculation method is: Generate digest information by performing a digest calculation on the authorization code, take the first 16 bits of the digest information as the password, and perform an extended digest calculation on the P10 file and the applicant's mobile phone number based on the generated password to generate the authentication code.

[0026] As a further technical solution of the present invention, in S9, the signing application response message is not encrypted because there is no information that needs to be kept confidential.

[0027] Advantages of the present invention:

[0028] A method and system for signing and issuing WAPI wireless private network certificates. By using the method and system for signing and issuing WAPI wireless private network certificate applications disclosed in the present invention, WAPI wireless terminal devices can complete the signing and issuing applications of WAPI certificates online, and this process is safe, convenient, and efficient. It is especially suitable for industries with particularly high requirements for the security of internal and external network data interactions, such as the power industry. It no longer requires the low efficiency and cumbersome internal and external network file copying operations in the manual process of WAPI certificate applications, can significantly improve the convenience and work efficiency of relevant processes, and can also avoid possible errors in the manual process. Brief Description of the Drawings

[0029] Figure 1 is a schematic diagram of the composition of a WAPI wireless private network certificate signing and issuing application system according to the present invention;

[0030] Figure 2 is a schematic diagram of the WAPI wireless private network certificate signing and issuing application process according to the present invention. Detailed Embodiments

[0031] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0032] Refer to Figure 1-2 , a system for signing and issuing WAPI wireless private network certificates, including a WAPI terminal (STA), a WAPI certificate authentication server (AS), a certificate management server (CIS), and a certificate signing and issuing application gateway (GW). It is characterized in that a two-way network gateway is connected between the GW and the CIS, the AS and the CIS are located in the internal network, and the GW is located in the external network and has a short message sending module.

[0033] Further, the WAPI terminal, abbreviated as STA, is a terminal device of the WAPI wireless network, including robots, tablet computers, law enforcement recording instruments, intelligent helmets, etc. These WAPI terminal devices have the ability to connect to the WAPI wireless network and also have the ability to connect to non-WAPI networks, the latter including the ability to connect to a WI-FI wireless network or a wired network, and have the program of the method described in this patent to connect to the certificate application gateway, send verification code acquisition messages and WAPI certificate application messages, and receive certificate application reply messages from the certificate application gateway.

[0034] Further, the WAPI certificate authentication server, abbreviated as AS, is the certificate authentication unit of the WAPI wireless network and also generates WAPI certificates based on P10 files; in the system described in this patent, it can also respond to the certificate issuance requests of the WAPI certificate management system.

[0035] Further, the WAPI Certificate Information System (CIS) manages certificates comprehensively, generally including the management of applicants and device information, and also manages the processes of certificate application, cancellation, etc.

[0036] Further, the WAPI certificate issuance application gateway, abbreviated as GW, is located outside the network and receives requests related to WAPI certificate issuance applications from outside the network, and forwards these request messages to the WAPI certificate management server in the internal network through a two-way physical isolation network gateway; at the same time, the WAPI certificate issuance application gateway also has the ability to send mobile phone text messages, and sends text messages to the applicant's mobile phone. The content of the text message is mainly the authorization code in the WAPI certificate application process.

[0037] In the present invention, a method and system for issuing WAPI wireless private network certificates include the following steps:

[0038] S1: First, for the applicant for WAPI certificate issuance, some information of the applicant needs to be registered in the WAPI certificate management server CIS by the system administrator, and the mobile phone number is a required information item.

[0039] S2: When the applicant for WAPI certificate issuance wants to apply for WAPI certificate issuance for a certain WAPI terminal device, the certificate applicant operates the WAPI terminal device to temporarily connect the WAPI terminal device to the external network, mainly through a wired connection to the external network; the certificate applicant fills in the mobile phone number registered in the WAPI certificate management server CIS through the authorization code acquisition function interface of the WAPI certificate issuance application program of the WAPI terminal device, and then operates the program interface to send an authorization code acquisition message to the WAPI certificate issuance application gateway GW.

[0040] S3: After receiving the authorization code acquisition message, the WAPI certificate issuance application gateway GW sends the relevant information to the WAPI certificate management server CIS through the network gateway; after receiving the authorization code acquisition information, the WAPI certificate management server CIS checks whether the mobile phone number in the authorization code acquisition information is a registered mobile phone number. If it is, it will reply with an authorization code response message to the certificate application gateway. If the relevant mobile phone number is not registered, there will be no response. The so-called authorization code is generally 6 digits and has timeliness, such as 1 minute.

[0041] S4: After the WAPI certificate issuance application gateway obtains the authorization code reply message from the CIS, it will send the authorization code to the mobile phone number of the WAPI certificate issuance applicant via SMS.

[0042] S5: After the WAPI certificate issuance applicant obtains the authorization code from the mobile phone, the applicant will operate the WAPI certificate application program of the WAPI wireless terminal to start the certificate application process. This process includes generating a WAPI key pair (including a public key and a private key), a WAPI certificate application file, i.e., a P10 file, and generating an application number ID. Then, the applicant will send the application number ID, the P10 file, the applicant's mobile phone number, and the authentication code to the WAPI certificate application gateway through the WAPI certificate application program. The authentication code is calculated based on the authorization code obtained by the applicant from the mobile phone SMS. The calculation method is as follows: generate a digest information by performing a digest calculation on the authorization code, take the first 16 bits of the digest information as the password, and generate the authentication code by performing an extended digest calculation on the P10 file and the applicant's mobile phone number based on the generated password.

[0043] S6: After the WAPI certificate application gateway GW receives the WAPI certificate issuance application message, it will forward the message to the WAPI certificate management server through the network isolation device.

[0044] S7: After the WAPI certificate management server CIS receives the WAPI certificate application message, it decrypts the message content and parses to obtain the application number ID, the P10 file, the applicant's mobile phone number, and the authentication code, and then performs a legality check, including: a) Check the authentication code: search for the authorization code in the CIS database according to the mobile phone number. If found, calculate the authentication code using the same method as the WAPI wireless terminal, and check the received authentication code with the calculated result. If the authorization code is not found, no response will be made. b) Verify the signature value of the P10 file. If the verification fails, no response will be made. If both checks pass, the WAPI certificate management server CIS will send a WAPI certificate issuance request message to the WAPI authentication server, which includes the P10 file.

[0045] S8: After the WAPI authentication server AS receives the WAPI certificate issuance request message from the CIS, it generates a WAPI certificate and then sends the generated certificate and its own public key certificate to the WAPI certificate management server CIS. The generation of the WAPI certificate is to generate the content of the WAPI certificate based on the P10 file and sign the certificate content with the private key of AS. Just because the private key of AS is used in this process, which is private data that other servers except AS do not have, it is necessary to finally send the certificate issuance request message to AS to issue and generate the certificate.

[0046] S9: After the WAPI certificate management server receives the WAPI certificate generated by the AS signing and the public key certificate of the AS, it will form a WAPI certificate signing application response message and send it to the WAPI wireless terminal device STA through the air gap; the signing application response message includes the corresponding application number ID, the newly generated certificate by signing, and the public key certificate of the AS. The signing application response message does not need to be encrypted because there is no information that needs to be kept confidential. The signing application response message does not need to be encrypted because there is no information that needs to be kept confidential;

[0047] S10: After the WAPI wireless terminal STA receives the signing application response message, it parses the message to obtain the application number ID, the newly generated certificate by signing, and the public key certificate of the AS. It uses the application number ID to look up the public key certificate in the local area of the STA, and compares the local public key with the public key in the newly generated certificate by signing. If they are consistent, it further uses the public key certificate of the AS to check the newly generated certificate by signing. If the signature verification passes, it indicates that the message has not been tampered with, and the newly generated certificate by signing and the public key certificate of the AS are trustworthy. The online signing application of the WAPI certificate is successfully completed.

[0048] Preferably, the two-way physical isolation air gap (referred to as the air gap) is a commonly used device for importing and exporting data between the internal and external networks, and can complete the import of data from the external network to the internal network and the export of data from the internal network to the external network under the security requirements of realizing network physical isolation; the system described in the embodiments of this patent will use this device, but it does not belong to the invention content of this patent.

[0049] Working principle: As Figure 1 is a schematic diagram of the composition of the WAPI wireless private network certificate signing application system, which includes the WAPI terminal STA 201, the WAPI certificate authentication server AS 205, the WAPI certificate management server CIS 204, and the WAPI certificate signing application gateway GW 202. The GW 202 and the CIS 204 are connected through the two-way air gap 203. The AS 205 and the CIS 204 are located in the internal network, and the GW 202 is located in the external network and has a short message sending and receiving module. As an embodiment, if this system is deployed in the network of the power industry, then (1) the AS 205 and the CIS 204 will be in the power internal network, generally deployed in the management information area of the power; (2) the GW202 and the air gap 203 are located in the internal and external network data exchange area, but it is not connected to the Internet; there will also be a firewall in the direction where the GW 202 faces the external network connection to perform access restriction and attack defense.

[0050] As Figure 2 is a schematic diagram of the WAPI wireless private network certificate signing application process. The embodiments of the process include the following process:

[0051] S0: Before applying for a WAPI certificate for the WAPI wireless terminal STA 301, the WAPI certificate applicant needs to register some information of the applicant in the WAPI certificate management server CIS 303 through the system administrator, generally including name, work unit, and mobile phone number; the mobile phone number is a required information item. Further, as an optimal technical solution, the operator can also initiate an electronic approval process in CIS 301, and multiple approvers can review the identity of the applicant. At the same time, as an optimal technical solution, after the registration review is completed in CIS 301, a text message can also be sent to the WAPI certificate applicant to notify that the review has passed.

[0052] In this embodiment, the process number related to S1* below is the authorization code acquisition sub-process, and the process number related to S2* is the WAPI certificate acquisition sub-process. In these processes, as an optimal technical solution, the relevant messages can be encapsulated in the form of TLV (i.e., Type, Length, Value), where the data type T is defined by the ASN.1 encoding type; the first data item of all messages is the message type, which uses the integer type of ASN.1.

[0053] S11: When the WAPI certificate applicant wants to apply for a certificate for a certain WAPI terminal device, the certificate applicant operates the WAPI terminal device to temporarily connect the WAPI terminal device to the external network, which includes connecting to the Internet through a temporary wired connection. For terminal devices such as PADs, they generally support the TYPE-C interface and can connect to the Ethernet network through a network converter that converts TYPE-C to Ethernet, so as to connect to the external network; for WAPICPE devices, they generally have an Ethernet interface and can directly connect to the external network through the Ethernet network. The WAPI certificate applicant operates the authorization code acquisition function interface of the WAPI certificate application program of the WAPI terminal device STA 301, fills in the mobile phone number registered in the WAPI certificate management server CIS, and then operates the program interface to send an authorization code acquisition message to the WAPI certificate application gateway GW 302. In this embodiment, the definition of the authorization code acquisition message is as follows:

[0054] Data Item Number Meaning of Data Item Data Type T Length L Value V 1 Message Type Integer (0x02) 1 0x01 2 Mobile Phone Number String (0x04) 11 Mobile Phone Number String

[0055] S12: After receiving the authorization code acquisition message, the WAPI certificate application gateway GW 302 sends the relevant information to the WAPI certificate management server CIS 303 through the network isolation device.

[0056] S13: After the WAPI certificate management server CIS 303 receives the authorization code acquisition information, it will check whether the mobile phone number in the authorization code acquisition information is a registered mobile phone number. If it is, it will proceed to S14: Reply with an authorization code response message to the certificate issuance application gateway GW 302. If the relevant mobile phone number is not registered, no response will be made. The authorization code, as a preferred technical solution, can be a combination of 6 digits or alphanumeric characters and has a validity period of 1 minute.

[0057] S15: After the WAPI certificate issuance application gateway GW 302 receives the authorization code reply message from CIS 303, it will send the authorization code to the mobile phone number of the WAPI certificate issuer via SMS.

[0058] In this embodiment, the definition of the authorization code acquisition response message is as follows:

[0059] Data Item Number Meaning of Data Item Data Type T Length L Value V 1 Message Type Integer (0x02) 1 0x02 2 Mobile Phone Number String (0x04) 6 Authorization Code String, such as "127935", "a23y89", etc.

[0060] In this embodiment, the "ciphertext of the issuance application information" is the SM4 encrypted ciphertext of the following information:

[0061] Data Item Number Meaning of Data Item Data Type T Length L Value V 1 Message Type Integer (0x02) 1 0x11 2 Application Number ID Integer (0x02) 4 For example 0x00000001 3 P10 File String (0x04) 64 Content of P10 File 4 Authentication Code String (0x04) 6 32-bit Binary Generated by Calculation

[0062] The authentication code. In this embodiment, preferably, using the SHA-256 digest algorithm of the WAPI technical system, the digest of the authorization code received via SMS is generated, and the 32-bit digest value calculated by SHA-256 is taken. The first 16 bits of this digest value are used as the password. The P10 file is extended with this password. Preferably, the KD-HMAC-SHA256 algorithm in the WAPI technical system is used to calculate the extended digest to generate the authentication code.

[0063] S22: After the WAPI certificate issuance application gateway GW 302 receives the WAPI certificate issuance application message, it will forward the message to the WAPI certificate management server CIS 303 through the network isolation device.

[0064] S23: After the WAPI certificate management server CIS 303 receives the WAPI certificate issuance request message, it parses the message content to obtain the application ID, P10 file, applicant's mobile phone number, and authentication code M0, and then performs the S24 legality check, including: a) Authentication code check: Look up the authorization code in the CIS 303 database according to the mobile phone number. If not found, no response is made. If found, calculate the SHA-256 hash value D of the authorization code. D is 32 bytes. Take the first 16 bits to form the password K. Use K to perform KD-HMAC-SHA256 calculation on the P10 file content and the applicant's mobile phone number to generate the authentication code M1. Compare M1 and M0. If they are the same, this certificate application is a legal application; b) Verify the signature value of the P10 file. If the verification fails, no response is made; if both checks pass, then proceed to S24: The WAPI certificate management server CIS 303 sends a WAPI certificate issuance request message to the WAPI authentication server AS 304, which includes the P10 file. In this embodiment, the definition of the WAPI certificate issuance request message sent by CIS 303 to AS 304 is as follows:

[0065] Data Item Number Meaning of Data Item Data Type T Length L Value V 1 Message Type Integer (0x02) 1 0x21 2 P10 File String (0x04) 64 Content of P10 File

[0066] S25: After the WAPI authentication server AS receives the WAPI certificate issuance request message from CIS, it generates a WAPI certificate, and then proceeds to S26: Sends the generated new certificate and its own public key certificate to the WAPI certificate management server CIS303; The generation of the WAPI certificate is to generate the content of the WAPI certificate based on the P10 file and sign the certificate content with the private key of AS. Exactly because the private key of AS is used in this process, which is private data that other servers except AS do not have, it is necessary to finally send the certificate issuance request message to AS to issue the certificate. In this embodiment, the definition of the certificate message sent by AS 304 to CIS303 is as follows:

[0067] Data Item Number Meaning of Data Item Data Type T Length L Value V 1 Message Type Integer (0x02) 1 0x22 2 P10 File String (0x04) 64 Content of P10 File 3 Newly Generated Certificate File String (0x04) 96 Content of Certificate File 4 Public Key Certificate File of AS String (0x04) 95 Content of Certificate File

[0068] S27: After the WAPI certificate management server CIS 303 receives the newly issued WAPI certificate and the public key certificate of AS issued by AS 304, it forms a WAPI certificate issuance application response message and sends it to the WAPI certificate issuance application gateway GW302 through the network gateway. S28 GW 302 forwards the WAPI certificate issuance application response message to the WAPI wireless terminal device STA301 through the public network; The issuance application response message includes the corresponding application number ID, the newly issued certificate, and the public key certificate of AS; The issuance application response message is not encrypted because there is no information that needs to be kept confidential. In this embodiment, the definition of the WAPI certificate issuance application response message is as follows:

[0069] Data Item Number Meaning of Data Item Data Type T Length L Value V 1 Message Type Integer (0x02) 1 0x23 2 Application ID Integer (0x02) 4 For example 0x00000001 3 P10 File String (0x04) 64 Content of P10 File 4 Newly Generated Certificate File String (0x04) 96 Content of Certificate File 5 Public Key Certificate File of AS String (0x04) 95 Content of Certificate File

[0070] S29: After the WAPI wireless terminal STA 301 receives the signed application response message, it parses the message to obtain the application number ID, the newly generated certificate during signing, and the public key certificate of the AS. It uses the application number ID to search for the public key certificate in the local area of the STA, and if the public key in the local area is consistent with the public key in the newly generated certificate during signing, it further uses the public key certificate of the AS to check the newly generated certificate during signing. If the signature verification passes, it indicates that the message has not been tampered with, and the newly generated certificate during signing and the public key certificate of the AS 304 are trustworthy, and the online signing application of the WAPI certificate is successfully completed.

[0071] Overall, by obtaining the authorization code through the applicant's mobile phone SMS and using the authorization code for applicant identity verification during the WAPI certificate signing application process, the problem of applicant verification for WAPI certificates is solved; through the online WAPI certificate signing application method, and fully considering the actual deployment environment issues of data import and export for high-security WAPI wireless private networks inside and outside the network, the relevant systems and methods have practicability. Through the methods and systems disclosed in the embodiments of the present invention, the security, convenience, and operation efficiency of certificate applications for WAPI wireless private networks can be significantly improved.

[0072] The above shows and describes the basic principles, main features, and advantages of the present invention. For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic features of the present invention, the present invention can be implemented in other specific forms. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present invention, and any reference signs in the claims should not be regarded as limiting the claims involved.

[0073] In addition, it should be understood that although this specification is described according to embodiments, not every embodiment only contains an independent technical solution. This narrative way of the specification is only for clarity. Those skilled in the art should regard the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.

Claims

1. A method for issuing WAPI wireless private network certificates, characterized in that, It includes the following steps: S1: First, for an applicant applying for a WAPI certificate issuance, some information of the applicant needs to be registered by the system administrator in the WAPI certificate management server CIS, and the mobile phone number is a required information item; S2: When a WAPI certificate issuance applicant applies for a WAPI certificate issuance for a certain WAPI terminal device, the certificate applicant operates the WAPI terminal device to temporarily connect the WAPI terminal device to the external network through a wired connection; The certificate applicant fills in the mobile phone number registered in the WAPI certificate management server CIS through the authorization code acquisition function interface of the WAPI certificate issuance application program of the WAPI terminal device, and then operates the program interface to send an authorization code acquisition message to the WAPI certificate issuance application gateway GW; S3: After receiving the authorization code acquisition message, the WAPI certificate issuance application gateway GW sends the relevant information to the WAPI certificate management server CIS through the air gap; after receiving the authorization code acquisition message, the WAPI certificate management server CIS checks whether the mobile phone number in the authorization code acquisition message is a registered mobile phone number. If it is, it will reply with an authorization code response message to the certificate issuance application gateway. If the relevant mobile phone number is not registered, there will be no response; S4: After obtaining the authorization code response message from the WAPI certificate management server CIS, the WAPI certificate issuance application gateway will send the authorization code to the mobile phone number of the WAPI certificate issuance applicant by SMS; S5: After obtaining the authorization code from the mobile phone, the WAPI certificate issuance applicant will operate the WAPI certificate application program of the WAPI wireless terminal to start the certificate application process. This process includes generating a WAPI key pair, a WAPI certificate application file, i.e., a P10 file, and generating an application number ID. Then, through the WAPI certificate application program, the application number ID, the P10 file, the applicant's mobile phone number, and the authentication code are sent to the WAPI certificate issuance application gateway; the authentication code is calculated based on the authorization code obtained by the applicant from the mobile phone SMS; S6: After receiving the WAPI certificate issuance application message, the WAPI certificate issuance application gateway forwards the message in it to the WAPI certificate management server CIS through the air gap; S7: After receiving the WAPI certificate issuance application message, the WAPI certificate management server CIS decrypts the message content and parses to obtain the application number ID, the P10 file, the applicant's mobile phone number, and the authentication code, and then performs a legality check, including: a) checking the authentication code: looking up the authorization code in the CIS database according to the mobile phone number. If it is found, the authentication code is calculated through the mobile phone, and the received authentication code is checked with this calculation result. If the authorization code is not found, there will be no response; b) verifying the signature value of the P10 file. If the verification fails, there will be no response; if both checks pass, the WAPI certificate management server CIS sends a WAPI certificate issuance request message to the WAPI authentication server, which includes the P10 file; S8: After receiving the WAPI certificate issuance request message from the WAPI certificate management server CIS, the WAPI authentication server AS generates a WAPI certificate, and then sends the generated certificate and the public key certificate of the WAPI authentication server AS itself to the WAPI certificate management server CIS; the generation of the WAPI certificate is to generate the content of the WAPI certificate based on the P10 file and sign the certificate content with the private key of the WAPI authentication server AS. Just because the private key of the WAPI authentication server AS is used in this process, which is private data that other servers except the WAPI authentication server AS do not have, it is necessary to finally send the certificate issuance request message to the WAPI authentication server AS to issue and generate the certificate; S9: After receiving the WAPI certificate and the public key certificate of the WAPI authentication server AS issued by the WAPI authentication server AS, the WAPI certificate management server CIS forms a WAPI certificate issuance application response message and sends it to the WAPI wireless terminal device WAPI wireless terminal STA through the network gateway; the issuance application response message includes the corresponding application number ID, the newly issued certificate, and the public key certificate of the WAPI authentication server AS. The issuance application response message is not encrypted because there is no information that needs to be kept confidential; S10: After receiving the issuance application response message, the WAPI wireless terminal STA parses the message to obtain the application number ID, the newly issued certificate, and the public key certificate of the WAPI authentication server AS, uses the application number ID to find the public key certificate of the WAPI wireless terminal STA locally, and compares the public key certificate in the local public key certificate and the newly issued certificate. If they are consistent, it further uses the public key certificate of the WAPI authentication server AS to check the newly issued certificate. If the signature verification passes, it indicates that the message has not been tampered with, and the newly issued certificate and the public key certificate of the WAPI authentication server AS are trustworthy, and the online issuance application of the WAPI certificate is successfully completed.

2. The method for issuing a WAPI wireless private network certificate according to claim 1, wherein In S5, the calculation method is as follows: generate the digest information by calculating the digest of the authorization code, take the first 16 bits of the digest information as the password, and generate the authentication code by calculating the extended digest of the P10 file and the applicant's mobile phone number based on the generated password.

Citation Information

Patent Citations

  • Method and server terminal for obtaining WAPI certification and WAPI authentication system

    CN101800984A

  • Security access gateway and industrial equipment communication management method

    CN112383557A